TCPA compliance for SMS marketing

TCPA-compliant texting software with opt-outs, DNC lookup, quiet hours, and 10DLC built in.

The Telephone Consumer Protection Act has real teeth: $500 per message for unintentional violations and $1,500 per message for willful ones. CampaignCNX+ automates the parts of TCPA compliance that can be automated and flags the parts that can't, so your SMS marketing program stays out of the settlement column.

Hand composing a TCPA-compliant SMS text message on a smartphone

| What TCPA requires

Five TCPA obligations, automated where they can be and surfaced where they can't.

TCPA governs how businesses and campaigns contact consumers by text. The core requirements haven't changed: consent, easy opt-out, time-of-day limits, sender identification, and record-keeping. The platform handles four of those on the send path; consent is still your responsibility, but we log it so you can prove it.

Getting that consent in a form that survives a challenge is its own job: how to build an SMS marketing list that is legal to text.
  • Prior express consent: tracked per contact with source and timestamp
  • Easy opt-out: STOP / HELP / UNSUBSCRIBE honored platform-wide
  • Time-of-day restrictions: 8 a.m. to 9 p.m. local time enforced automatically
  • Sender identification: handled through 10DLC brand registration
  • Record-keeping: full message and consent audit trail, exportable
Contact record showing consent timestamp, opt-in source, and DNC status: the audit trail required for TCPA compliance

Automated TCPA compliance

TCPA compliance features the platform handles automatically.

/01

Opt-out handling

STOP, HELP, and UNSUBSCRIBE honored immediately across every campaign. Confirmation sent. Contact removed from future campaigns.

Opt-outs are one reason a message stops arriving. Carrier filtering is the other, and it is less obvious: why carriers block SMS messages.

/02

Quiet-hours enforcement

Time-zone-aware 8 a.m. to 9 p.m. window per recipient. Messages outside the window are held until it opens.

/03

DNC registry lookup

Run lists against the federal DNC registry via DataZapp as an add-on. Flagged contacts drop out of sends.

/04

STOP language validation

The composer validates that required opt-out language is present before the campaign is allowed to go out.

/05

10DLC registration

Sender identification runs through registered 10DLC brand and campaign records. Toll-free quick-start handles same-day.

/06

Audit trail

Consent timestamp, source, every outbound message, every opt-out: logged and exportable if you ever need to defend a campaign.

Compliance on the send path

Opt-outs, quiet hours, and STOP validation are on by default, not a setting you remember to turn on.

Open an account and send a test to your own staff list before any customer sees it. You start with 100 free SMS and no credit card.

If you are still working out what the rules require before you send anything, start with how to send marketing text messages legally.
Clipboard, pen, and pencil: consent records and audit-trail review for TCPA compliance

How TCPA compliance is enforced

How a text message clears TCPA compliance before it ships.

The review screen doesn't just show the recipient count and total cost. It's also the point where the platform confirms the send is TCPA-clean.

The registration that makes a send deliverable in the first place is separate from the review screen: 10DLC registration explained.
01

Opt-outs filter

Contacts who've said STOP are removed from the recipient count before review.

02

DNC drops

If DNC lookup has been run, flagged contacts drop out too.

03

STOP language validated

The composer checks for required opt-out language. No STOP language, no send.

04

Quiet hours held

Recipients outside their local window queue until the window opens. Everyone else ships on time.

An analog alarm clock in low window light, the 8 a.m. to 9 p.m. local window a TCPA-compliant send has to sit inside

What the TCPA actually says

Four TCPA requirements every SMS marketing program has to meet.

The Telephone Consumer Protection Act of 1991 was written for autodialed phone calls, but it covers SMS, and the FCC has been progressively tightening interpretation since 2012. For a text-marketing program, four things matter in practice:

The longer version, written as something you can work through line by line, is the TCPA compliance checklist.

  1. Express written consent before any promotional message. A pre-checked checkbox doesn't count. The opt-in must be a clear affirmative action by the recipient (texted-in keyword, signed form, unchecked checkbox they ticked).
  2. Disclosure at opt-in: the recipient must be told who's texting them, that message and data rates may apply, and how to opt out (typically "Reply STOP to cancel").
  3. Honored opt-outs: STOP, UNSUBSCRIBE, CANCEL, END, QUIT, and several variants must all stop further messaging. Carriers enforce this at the network level, but you need to handle it cleanly in your own list too.
  4. Quiet hours: most state-level interpretations require sends between 8:00 a.m. and 9:00 p.m. local time of the recipient, not the sender. A noon Eastern blast doesn't land at 9 a.m. Pacific.

CampaignCNX+ enforces (3) and (4) at the send path automatically. (1) and (2) are program responsibilities, but the platform stores the consent timestamp and source per contact so you have the audit trail when you need it.

A person filling out a paper form at a desk, the opt-in moment that creates the consent record a texting program has to be able to produce later

A few things worth knowing if you're building a serious program:

Where the risk actually is

Most TCPA claims start somewhere other than a bad message.

Programs tend to picture a TCPA problem as a message that should never have been sent. In practice the message is usually fine and the record behind it is not. Four situations produce most of the exposure, and none of them are about the copy.

The pattern across all four is that the sending decision was defensible and the surrounding record was not. That is a record-keeping problem, which is good news, because record-keeping is cheap compared to the alternative.

A workable minimum for what to retain, per contact:

CampaignCNX+ stores all four as a matter of course and the audit trail exports, which is what makes an inquiry a short conversation rather than a reconstruction exercise. The part no platform can do for you is the disclosure language at the point of capture, because that lives on your form.

Two further notes worth having in mind rather than discovering later. Several states run their own mini-TCPA statutes that are stricter than the federal baseline on timing and consent, and they change; if you send into a state you do not operate in, that is worth a specific check rather than an assumption. And the exemptions that apply to non-commercial political messaging are narrower than they are often described, which is covered in more depth in the political texting guide.

Getting consent in the first place

Four ways consent gets captured, ranked by how well they hold up.

Every method below can produce valid consent. They differ in how easy it is to prove a year later, which is the only property that matters once somebody asks.

  1. Keyword opt-in. The person texts a word to your number. The strongest of the four by a distance, because the consent arrives as an inbound message from the handset itself, timestamped, from the number in question. There is no form to reconstruct and no question about who ticked what. If you can route new subscribers through a keyword, do.
  2. Web form with an unchecked box. Solid when the box is genuinely unchecked, sits next to the disclosure rather than behind a link, and the submitted values are stored. Weak when the disclosure lives in terms nobody opened, or when the form has been redesigned since and nobody archived the old wording.
  3. Point of sale or paper. Common in retail and clinics, and workable if the slip is retained and the phone number on it is legible. The failure is mundane: the paper goes in a drawer, the number gets keyed in later, and the link between the two is a person's memory.
  4. Imported from another system. The weakest position, because you inherit whatever the previous consent looked like without having seen it. Before importing a purchased or inherited list, ask what people actually agreed to and whether the seller can evidence it. If the answer is vague, treat the list as unconsented and re-permission it.

Whichever method you use, the disclosure has to name you. A person who opted in to a form on a partner site did not consent to hear from your brand, and single-checkbox consent covering several senders at once has been narrowing rather than widening as an acceptable practice.

One practical habit that costs nothing: when you change an opt-in form, keep a dated copy of the wording it replaced. Every consent captured under the old version is defended by the old wording, and reconstructing it after the fact is the part that turns a routine question into a problem.

A law study with bookshelves, a gavel, and a figure of Lady Justice, the statutory-damages end of a non-compliant SMS program

TCPA compliance FAQ

TCPA compliance FAQ for SMS marketing programs.

Does the platform handle all of TCPA for me?

It handles the automatable parts: opt-outs, quiet hours, STOP language validation, DNC lookup, 10DLC sender identification, and audit logging. Consent is still your responsibility (you need documented opt-in before you text someone), but the platform stores the timestamp and source so you can prove it.

Is DNC lookup automatic on every send?

No, DNC lookup is an add-on at $0.015 per lookup via DataZapp. You run it on import or before a campaign that needs it. Once a contact is DNC-flagged in the system, they stay flagged and drop out of future campaigns automatically.

What about 10DLC registration?

10DLC is the carrier registration path for application-to-person messaging. It's the recommended path for any serious program. We handle the brand and campaign registration during onboarding. It runs in parallel with toll-free quick-start, which clears in about three business days.

How are quiet hours decided?

Per recipient, based on the contact's time zone. The platform enforces 8 a.m. to 9 p.m. local time. A campaign scheduled for noon Eastern doesn't land at 9 a.m. Pacific. It waits for Pacific 8 a.m.

Can I export the audit trail?

Yes. Consent records, message history, and opt-outs all export as CSV. If you ever face a complaint, you have the documentation without having to reconstruct it.

What if someone replies STOP but I've already scheduled a campaign to them?

Opt-outs filter at send time, not at schedule time. A scheduled campaign will not deliver to anyone who has opted out between the time you scheduled it and the time it fires.

Does TCPA apply to political text messages?

Partially. Non-commercial political speech is exempt from some of TCPA's most restrictive autodialer provisions, but the FCC has been steadily narrowing that exemption, and the 2024 closing of the political robocall loophole reinforced that political senders should treat consent, quiet hours, and STOP handling the same as commercial senders. The safe path: get written consent, send only 8 a.m. to 9 p.m. local, and honor opt-outs.

What's the penalty for violating TCPA?

$500 per message for negligent violations, $1,500 per message for willful or knowing violations. Class actions are common. At scale, a non-compliant 10,000-recipient send is a potential $5 to $15 million exposure. Most consumer-side TCPA litigation is brought by specialized plaintiff's firms that actively scan for non-compliant senders.

What's the difference between TCPA and CAN-SPAM?

CAN-SPAM regulates commercial email and uses an opt-out framework. You can email someone first and they can ask you to stop. TCPA regulates phone calls and SMS and uses a stricter opt-in framework. You must have express written consent before the first message. Different statutes, different consent regimes, different penalty structures.

What counts as “express written consent” for SMS?

A clear, affirmative agreement to receive automated texts from a specifically named sender, including a disclosure that consent isn't a condition of purchase. In practice: an opt-in form the recipient signed or completed, a keyword opt-in they texted in, or an unchecked checkbox they actively ticked. Pre-checked boxes and buried-in-TOS language don't qualify under the FCC's current interpretation.

Related reading

Start sending

Start your TCPA-compliant SMS marketing program today.

Take the toll-free quick-start: purchase a verified phone number, import your opt-in list, and send your first TCPA-compliant text message as soon as verification clears, usually about three business days. For programs serious about long-term deliverability and DNC hygiene, 10DLC carrier registration is the recommended path and runs in parallel while you're already sending.

Fastest start
Toll-free, about 3 business days
Onboarding
Real person, not a chatbot
Free trial
100 SMS, no card required