SMS Compliance and Opt-In Rules: What Every Business Needs to Know

Texting is one of the most effective ways a business can reach customers. People read their texts, usually within minutes. That’s exactly why the rules around business texting are so strict, and why getting them wrong can be so expensive.

SMS compliance isn’t governed by a single rule. It’s a stack of federal law, federal regulations, carrier requirements, and state laws, all built around one basic idea: you should only text people who agreed to hear from you, and you have to stop when they tell you to. Here’s a plain-English guide to how those layers fit together, what proper opt-in looks like, and how to handle opt-outs the right way.

The usual reminder: I’m not a lawyer, and this is a general explainer rather than legal advice. SMS rules change often and vary by state, so work with a professional who can review your specific program.

The Layers of SMS Compliance

Business texting in the US is shaped by four main sources of rules:

  1. The Telephone Consumer Protection Act (TCPA), a federal law that restricts automated calls and texts.
  2. FCC regulations that interpret and enforce the TCPA.
  3. Carrier and industry requirements, including CTIA guidelines and 10DLC registration.
  4. State laws, several of which add their own restrictions on top of the federal rules.

A text program has to satisfy all of them at once. Carrier rules decide whether your messages get delivered. The TCPA and state laws decide whether you can be sued.

The TCPA: Why SMS Compliance Matters So Much

The TCPA is the reason SMS compliance gets so much attention. It allows people who receive unlawful texts to sue, with statutory damages of $500 per message, which can increase to $1,500 per message for willful violations. Because damages are counted per text, a single campaign sent to thousands of people without proper consent can turn into a large class action.

Under the TCPA, the kind of consent you need depends on the kind of message you send:

  • Informational and transactional texts, like appointment reminders, order updates, or account alerts, generally require prior express consent. That’s often satisfied when a customer provides their number in connection with the relevant service.
  • Marketing texts, like promotions, coupons, and sales announcements, generally require prior express written consent. That’s a higher standard, requiring a clear written agreement, which can be electronic, that authorizes marketing texts to a specific number.

The line between informational and marketing messages matters. A reminder that also pushes a promotion can be treated as marketing, so it’s safest to design your consent around the most promotional message you plan to send.

sms compliance

What Proper SMS Opt-In Looks Like

Strong opt-in practices protect you under the TCPA and are also required for carrier registration. A compliant opt-in generally includes:

  • A clear call to action. People should know they’re signing up for texts, not just entering a phone number for some other reason.
  • Your business name. Customers should know exactly who will be texting them.
  • A description of the messages. Say what kind of texts they’ll receive, such as order updates, reminders, or promotions.
  • Frequency information. Something like “message frequency varies” or a specific number of messages per month.
  • Cost disclosure. The standard “message and data rates may apply.”
  • Opt-out instructions. Explain that people can reply STOP to unsubscribe and HELP for help.
  • Links to your terms and privacy policy.
  • No purchase requirement. For marketing texts, consent can’t be a condition of buying something.

A few practical details: checkboxes should never be pre-checked, consent for texts should be separate from agreeing to general terms, and each method of signup (web forms, checkout pages, keywords, paper forms) needs its own compliant language.

Confirmation Messages and Double Opt-In

Most businesses send an automatic confirmation text as soon as someone subscribes, restating the program name, message frequency, cost disclosure, and how to opt out. Many also use double opt-in, where the person has to reply to confirm before receiving further messages. Double opt-in isn’t required in every case, but it’s strong evidence that the person actually wanted the texts and that you have the right number.

Opt-Out Rules: Stopping When Customers Say Stop

Honoring opt-outs is just as important as collecting consent, and the rules here have gotten stricter.

Under the FCC’s updated consent revocation rules, which largely took effect in April 2025, consumers can revoke consent through any reasonable means. Replying to a text with words like “stop,” “quit,” “end,” “revoke,” “opt out,” “cancel,” or “unsubscribe” is considered a reasonable way to opt out, but it isn’t the only way. A customer who asks to stop texts in an email, over the phone, or in person has also revoked consent. Businesses must honor revocation requests promptly, and no later than 10 business days after receiving them.

That has a big practical implication. If your SMS platform only processes STOP replies, opt-out requests that come in through your support inbox or phone line can slip through the cracks. You need a process to capture those requests and add them to your suppression list.

After someone opts out, businesses are generally allowed to send one final confirmation message acknowledging the request, without any marketing content.

The “Revoke All” Question

One part of the FCC’s 2024 rules, sometimes called “revoke all,” would treat an opt-out from one type of message as an opt-out from all of a company’s robocalls and robotexts on unrelated topics. The FCC has delayed that provision more than once, and as of fall 2026, it’s actively revising how revocation should work. The FCC’s original order delaying this provision explains the background, and the law firm Wiley has a summary of the FCC’s later extension. Because this area is changing quickly, check the current status with your texting provider or counsel before designing your opt-out system.

Carrier Rules and 10DLC

Even if you’re fully compliant with the TCPA, carriers have their own requirements, and they control whether your messages actually get delivered. If you send business texts from a standard 10-digit number, you’ll need to register through the 10DLC system. If you’re new to it, here’s a plain-English look at what 10DLC is and why carriers require it, along with a walkthrough of the registration process.

Carrier review focuses heavily on consent. You’ll need to describe your opt-in process, provide sample messages with your business name and opt-out language, and have a privacy policy that says mobile information won’t be shared with third parties for marketing. Carriers also restrict or ban certain types of content, and messages that drift away from your registered use case can be filtered or suspended.

State Laws: The Extra Layer

Several states have passed their own telemarketing and texting laws, often called “mini-TCPAs,” that add requirements beyond federal rules. Depending on the state, these can include:

  • Quiet hours, limiting what times of day marketing texts can be sent.
  • Frequency limits on how many messages can be sent to one person in a given period.
  • Broader definitions of automated systems, which can bring more messages under the law.
  • Private rights of action, letting consumers sue directly.

Because recipients’ area codes don’t always reflect where they live, many businesses apply the strictest common rules, like avoiding marketing texts early in the morning or late at night, across their whole audience.

Other Rules Worth Knowing

  • Do Not Call registry. Marketing texts to numbers on the National Do Not Call Registry generally require proper consent.
  • Time-of-day limits. Federal telemarketing rules restrict marketing contacts to reasonable hours in the recipient’s local time, and some states are stricter.
  • Reassigned numbers. Phone numbers get recycled. Consent from a previous owner doesn’t carry over, so maintaining clean lists matters.
  • Purchased lists. Buying or renting phone lists almost always means you don’t have valid consent, and carriers prohibit it.

Keeping Records of Consent

If your consent is ever challenged, the burden is typically on you to prove it. Good records include:

  • The phone number and the date and time of opt-in
  • How the person opted in, such as the form, keyword, or checkout page
  • The exact disclosure language they saw
  • Any confirmation or double opt-in replies
  • Opt-out requests and when they were processed

Scattered consent records are hard to defend. Keeping them in one authoritative place, rather than spread across your texting platform, CRM, and spreadsheets, makes compliance far easier. That’s the idea behind building a single source of truth for your customer data.

Does RCS Change Any of This?

No. Richer channels like RCS change what your messages look like, not the rules about who you can message. Consent and opt-out obligations still apply, and RCS messages often fall back to SMS when a customer’s phone doesn’t support RCS. It’s one of several differences worth understanding if you’re weighing RCS against traditional texting.

A Quick SMS Compliance Checklist

  • Get the right level of consent for every message type, especially written consent for marketing.
  • Use clear, complete opt-in language at every signup point.
  • Send a confirmation message when someone subscribes.
  • Honor opt-outs through any reasonable method, within 10 business days.
  • Register with the carriers through 10DLC or toll-free verification.
  • Follow quiet hours and check state-specific rules.
  • Never buy or rent phone lists.
  • Keep detailed, centralized records of consent and opt-outs.
  • Review your program regularly, since the rules keep changing.

The Bottom Line

SMS compliance comes down to consent: getting it clearly, documenting it carefully, and honoring it when someone takes it back. The TCPA sets the legal stakes, the FCC keeps refining the rules, carriers enforce their own standards through registration, and state laws add another layer on top.

That sounds like a lot, but most of it flows from the same simple principle. Text people who asked to hear from you, tell them clearly what they’re signing up for, and stop as soon as they ask. Build your program around that, and you’ll be on solid ground with regulators, carriers, and customers alike.

You may also like...

Shares