Texting customers without following the rules isn’t just risky — it’s expensive. A single non-compliant message can cost your business $500 to $1,500. Multiply that across a 500-person campaign, and the fines could cost $250K-$750K.
SMS compliance is the set of legal and industry rules that govern how businesses send text messages in the US. The two main frameworks are the TCPA, or Telephone Consumer Protection Act, which requires written consent before sending marketing texts, and CTIA carrier guidelines, which set standards for business messaging. On top of that, you’ll need to register your number for A2P 10DLC, include opt-out instructions in every message, and respect sending hours.
Here’s what each of those requirements actually means — and how to stay on the right side of them.
This article is for informational purposes only and does not constitute legal advice. SMS compliance requirements vary by jurisdiction and change over time. Consult a qualified attorney for guidance specific to your business.
How to send compliant SMS texts
Here’s a basic SMS compliance checklist for your business:
1. Get consent before you text
Before you send anyone a text, they need to have agreed to receive it. The type of consent you need depends on what you’re sending: prior express consent covers conversational texts like appointment reminders or order updates.
Prior express written consent is required for any automated marketing messages. That written consent needs to be a clear, affirmative opt-in — not a pre-checked box or buried fine print.
2. Identify yourself in the first text and include opt-out messaging
Every time you start a new text conversation with a recipient, you need to clearly identify yourself. Include your name and business name.
The initial text you send to a recipient also needs to include clear instructions on how to opt out of future messages, such as “Reply STOP to unsubscribe.” You can also use a different opt-out keyword here, such as STOPALL, UNSUBSCRIBE, QUIT, CANCEL, or END.
A couple of other things to keep in mind:
- You’re required to honor opt-outs even when someone doesn’t use the exact keyword. If a customer replies “please don’t text me anymore,” that still counts. As of April 11, 2025, the FCC requires businesses to honor an opt-out made in any reasonable way and to process it within 10 business days.
- Never text someone who has opted out, even from a different number.
3. Respect quiet hours
Under TCPA compliance guidelines, it’s illegal for companies to send promotional texts or call individuals outside of 8:00 a.m. to 9:00 p.m. These times are based on your recipient’s time zone. It’s also good texting etiquette to text during regular business hours for non-urgent messages.

This is where using a modern business phone system like Quo can come in handy as you can schedule texts ahead of time based on your contact’s time zone.
Some states go further than the federal window. Florida and Oklahoma have their own mini-TCPA laws that can restrict texting to 8 a.m. to 8 p.m. local time and cap how many marketing messages you can send per day. If you text consumers in those states, follow the stricter rule.
4. Register for A2P 10DLC
A2P 10DLC stands for Application-to-Person 10-Digit Long Code. It means that if you use a virtual number to text anyone with a US phone number on behalf of your business, you’ll need to complete US carrier registration. The process for A2P 10DLC varies by provider.
Registration is for Quo users that have local numbers and a paid workspace. You can’t be on a free, seven-day trial. Any owner or admin for your workspace can complete the US carrier registration form using our web or desktop app. If you have a toll-free number, check out our guide to toll-free number verification.
“10DLC registration — which has historically been one of the most painful parts of setting up any business phone system — was completely painless. You get approved once, they handle all the carrier compliance behind the scenes, and you’re up and running.” — Quo user on G2
5. Keep records of consent
You need to keep a copy of your recipient’s consent in your records — whether it’s a copy of the document the recipient signed or a timestamp of when a customer completed a sign-up call to action.
Hold on to your proof of consent even after a contact opts out of receiving messages; you’ll want it in case a dispute arises over TCPA’s opt-in/opt-out guidelines.
One more thing: if a significant amount of time passes between when someone gives you consent and when you first text them, you may need to reconfirm their consent in that first message.
Consent and opt-in requirements
Consent is where most businesses run into compliance trouble. They either didn’t get it properly in the first place, or they assumed consent from one context carried over to another. Here’s exactly what you need to know.
Express consent vs. express written consent
The type of consent you need depends on what you’re sending.
Prior express consent covers conversational and transactional texts — things like appointment reminders, order updates, or customer service replies. You have this when:
- A customer texts you first. Their inbound message counts both as SMS consent and proof of consent — but only for that conversation. So, if someone texts you asking for your hours of operation, you can answer that question — but you don’t have additional consent to send them marketing or sales texts.
- You’re sending informational content to an individual based on a prior relationship: If you have a pre-existing relationship with someone and they’ve provided you with their phone number, you can send them a text. Just make sure they’ve taken some action to initiate communication with you — such as placing an order, requesting an appointment reminder, receiving a one-time password, or setting up an alert — and that they haven’t asked you not to text them.
Prior express written consent is required for any marketing or promotional texts. This is a higher bar: the customer needs to take a clear, affirmative action to opt in. That means a signed form, a required checkbox on a web form, or a keyword opt-in. In practice, this usually means double opt-in: after submitting their number, the customer confirms by replying to a follow-up text.
What a compliant SMS opt-in looks like
Whether you’re collecting explicit consent through a website form, a paper form, or a keyword opt-in, the opt-in needs to include:
- A clear request for consent — it should be obvious the customer is agreeing to receive texts from your business.
- A required action to opt in — a checkbox the customer checks, a keyword they text, a form they sign. Pre-checked boxes don’t count.
- A description of what types of messages they’ll receive — transactional, marketing, or both.
- Message frequency — how often they can expect to hear from you.
- Clear opt-out instructions, such as “Reply STOP at any time.” CTIA’s messaging principles and best practices also recommend sending subscribers opt-out instructions at least once a month.
- Links to your terms and conditions and privacy policy.
- A note that message and data rates may apply.
Keep in mind: you can’t buy, sell, or exchange consent. For instance, if you buy a phone list from another party, you don’t automatically obtain the express consent of those recipients — you still need to obtain it separately.
What doesn’t count as consent
A few things businesses commonly assume are consent but aren’t:
- Buying a phone list. Purchasing contact information from a third party doesn’t transfer consent. You need to obtain it separately from every recipient.
- A customer giving you their number. Someone handing over their phone number — at checkout, on a form, during a call — doesn’t automatically mean they’ve consented to receive marketing texts. They need to have taken a clear, affirmative action.
- Consent from one campaign or business. Consent is specific to the use case a customer signed up for. If someone opts in to receive new listing alerts from your real estate team, that doesn’t give you permission to text them about mortgage products. And if you own two separate businesses, you need separate consent for each.
Who regulates SMS compliance?
Four groups set and enforce the rules for business texting in the US:
| Regulatory body | What they govern | Enforcement |
|---|---|---|
| FCC, or Federal Communications Commission | The TCPA — requires express written consent before sending marketing texts | Fines of $500–$1,500 per violation |
| FTC, or Federal Trade Commission | The CAN-SPAM Act — governs content and identification requirements for marketing messages | Fines of $500 per text |
| CTIA, or Cellular Telecommunications Industry Association | Industry messaging guidelines and best practices | Can report violators to carriers, leading to send suspension |
| Mobile network operators like AT&T, T-Mobile, Verizon, etc. | A2P 10DLC registration and carrier-level filtering rules | Message filtering, number blocking, fines up to $10,000 per violation (T-Mobile) |
If you’d like to learn more, you can check out these resources:
- Telephone Consumer Protection Act rules
- CAN-SPAM Act guidelines
- CTIA’s messaging principles and best practices
Start sending compliant business texts with Quo

SMS compliance guidelines exist for a good reason: they keep individuals protected in the ever-growing fight against spam. To learn more about staying compliant when calling others, check out our explainer on the FCC’s STIR/SHAKEN protocol.
If you’re ready to start sending compliant texts, learn how you can use Quo to message clients seamlessly as a team — complete with automated messaging, scheduled messages, and saved message templates.
FAQs
The TCPA, or Telephone Consumer Protection Act, is a federal law that governs how businesses can contact customers by phone and text. It applies to any business that sends marketing or promotional texts to US numbers — there’s no small business exemption.
Under the TCPA, you must obtain express written consent before sending marketing texts, respect quiet hours from 8 a.m. to 9 p.m. in the recipient’s time zone, and honor opt-out requests immediately. Violations carry fines of $500–$1,500 per message, and because the TCPA allows for class action lawsuits, a single non-compliant campaign can result in significant legal consequences.
US rules like TCPA apply based on where the recipient is located, not where your business is based. If you’re texting Canadian numbers, CASL, or Canada’s Anti-Spam Legislation, applies. It’s stricter than TCPA and requires express consent for all commercial messages. If you’re texting UK/EU numbers, GDPR, or General data protection regulation, and the PECR, or Privacy and Electronic Communications Regulations, apply. Always use the rules that govern the recipient’s location.
Transactional messages contain information a customer needs to use your product or service — order confirmations, appointment reminders, two-factor authentication codes, and password resets all qualify.
Promotional texts advertise a product, service, event, or offer. The distinction matters for compliance: transactional texts require prior express consent, while promotional texts require the higher bar of prior express written consent. When in doubt, treat the message as promotional.
A2P 10DLC registration is completed through your business phone provider. The process varies depending on who you use. If you’re a Quo customer, any owner or admin can complete the US carrier registration form directly from the web or desktop app. For a full walkthrough of the process and what information you’ll need, see our A2P 10DLC registration guide.
You need a record that shows when and how each contact opted in: a timestamp from a web form submission, a copy of a signed physical form, or a log of a keyword opt-in reply all work. The key is that the record needs to be retrievable if a dispute arises, so make sure whatever system you’re using actually stores it. Hold onto consent records even after a contact opts out.
Forbidden categories are content types that carriers and providers prohibit in business text messages. In the US these typically include high-risk financial services like payday loans and cryptocurrency, debt collection or forgiveness, third-party lead generation, illegal substances, gambling, get-rich-quick schemes, and prescription drugs.
It also includes SHAFT content, which stands for sex, hate, alcohol, firearms, and tobacco. One exception: alcohol and tobacco content is permitted on local numbers — not toll-free — if you’ve implemented age-gating. If you’re a Quo customer, see our guide to forbidden categories for the full list.















