Learn what businesses need to know about SMS compliance in 2026: rules, risks, and best practices for global and U.S. texting.
Build compliant SMS campaignsTelnyx handles 10DLC registration, opt-out keywords, and carrier compliance so you can send with confidence. Explore the SMS API
Get startedSMS compliance means following the laws, industry guidelines, and carrier requirements that govern business text messaging. In the US, that covers four things. That means documented consent before messaging, prompt opt-out honoring, restricted content avoidance, and carrier campaign registration before sending A2P traffic.
No single rulebook covers all of it. The requirements come from four separate layers, and a message has to clear every one of them to reach a handset legally and reliably.
| Layer | Enforced by | What it covers |
|---|---|---|
| TCPA (federal law) | FCC, courts | Consent, revocation, statutory damages |
| CTIA guidelines | Wireless industry | Content rules, disclosures, opt-out keywords |
| 10DLC | US carriers | Brand and campaign registration, throughput |
| State statutes | State regulators, courts | Quiet hours, added consent rules, private lawsuits |
Businesses that treat compliance as a one-time checklist tend to learn about these layers the hard way. Carriers filter their traffic. Plaintiffs' attorneys find their unsubscribe bugs. The better approach treats compliance as part of the messaging pipeline itself, with consent records, suppression lists, and registration handled in code and process rather than in someone's memory.
One note before going further. This guide explains the rules as they apply to most US A2P senders, but it is not legal advice. Talk to counsel about your specific use case.
The Telephone Consumer Protection Act is the federal foundation of US text message compliance. Passed in 1991 and interpreted by the FCC ever since, it restricts automated calls and texts to consumers without the right level of consent. The FCC publishes current guidance at fcc.gov.
The consent bar depends on what you send. Marketing and promotional messages require prior express written consent. That means the recipient agreed, in writing or its electronic equivalent, to receive marketing texts from your business specifically. A purchase or an existing relationship is not enough on its own. Transactional and informational messages carry a lower bar, but consent of some form still applies.
| Message type | Consent required | Example |
|---|---|---|
| Transactional | Express consent | Order shipped, appointment reminder |
| Informational | Express consent | Service outage alert, account notice |
| Promotional | Prior express written consent | Sale announcement, product launch |
Two TCPA facts matter more than the rest. First, statutory damages apply per message, with higher amounts for willful violations, and there is no cap tied to actual harm. A campaign sent to a stale list multiplies exposure by every number on it. Second, recipients can revoke consent through any reasonable method under current FCC revocation rules, and you have to honor that revocation promptly. A STOP reply is the obvious case, but "unsubscribe" or "please stop texting me" counts too. Your system needs to catch all of it.
The FCC has also tightened consent rules for lead-generated traffic, which would have required consent tied to one identified seller, though the rule was vacated by the Eleventh Circuit in January 2025 (Insurance Marketing Coalition v. FCC). If you buy leads, review how that consent was captured before you text them.
The CTIA is the US wireless industry's trade association, and its Messaging Principles and Best Practices sit one layer below federal law. The guidelines are not statutes. Carriers enforce them anyway, and they enforce them through the mechanism that hurts most, which is filtering or blocking your traffic.
The guidelines cover the practical mechanics of consumer messaging. Senders should identify themselves in messages. Opt-in flows should disclose message frequency and that message and data rates may apply. STOP and HELP keywords should work on every campaign. Consent for one message program does not transfer to another.
Carriers also expect message content to match the registered campaign. If you registered a campaign for delivery notifications and start sending promotions through it, filtering algorithms will notice. So will carrier audits. Content-to-campaign mismatch is a common and avoidable cause of blocked traffic.
Treat the CTIA guidelines as the operating manual for staying deliverable. The TCPA tells you what is legal. The CTIA guidelines tell you what carriers will actually let through.
A2P 10DLC is the carrier framework for business messaging over standard 10-digit long code numbers in the US. Before it existed, businesses sent A2P traffic over local numbers with no registration and unpredictable deliverability. Now registration is mandatory, and it happens in two steps.
First, brand registration. You register your legal business entity, including tax ID and contact details, with The Campaign Registry. Second, campaign registration. You declare each messaging use case, such as marketing, notifications, or two-factor authentication, along with sample messages and opt-in details. Campaigns go through vetting, and the outcome affects your throughput tier with each carrier. Telnyx walks through the full process in its messaging compliance docs.
Unregistered traffic performs worse. Carriers filter it, block it, and apply pass-through fees to it. Registration errors, like a vague campaign description or missing opt-in language, delay approval and keep traffic offline. Getting the registration right the first time is worth the extra hour of care.
The numbers you send from matter too. Telnyx provisions phone numbers with messaging enablement on its own network, so the number, the campaign, and the traffic all live in one place. That removes a whole category of misconfiguration between your number provider and your messaging provider.
Federal compliance is the floor, not the ceiling. Several states have passed their own telemarketing and texting statutes, often called mini-TCPAs, and some of them reach further than federal law.
Texas is the anchor example. The state's telephone solicitation rules require certain businesses that market by text to register with the state before soliciting Texas residents, and violations carry state-level penalties alongside any federal exposure. Florida, Oklahoma, and Washington have passed their own statutes with private rights of action, meaning individual recipients can sue directly. Several state laws also impose quiet hours that restrict marketing messages to a daytime window in the recipient's local time zone, and some define that window more narrowly than federal norms.
| State consideration | What it means for senders |
|---|---|
| Registration requirements | Some states require sellers to register before soliciting residents |
| Quiet hours | Marketing sends restricted to local daytime windows |
| Private right of action | Recipients can sue directly, including private parties, not only regulators |
The practical consequence is that compliance depends on where your recipients are, not where your business is. A sender in New York texting a list with Texas and Florida numbers is subject to Texas and Florida law for those recipients. If you send marketing traffic nationally, build to the strictest applicable standard. Statute specifics change, so confirm current registration thresholds and quiet-hour windows with counsel before launching a campaign.
Consent lives or dies in implementation. The rules above describe outcomes. This section covers the mechanics that produce them.
On the opt-in side, capture consent with clear language at the point of collection. State who is sending, what kind of messages, roughly how often, and that message and data rates may apply. Store the record with a timestamp, the source, and the exact language shown. When a TCPA dispute happens, that record is your defense. Send a confirmation message after opt-in that repeats the program name and the STOP instruction.
On the opt-out side, automate everything. A human reviewing STOP replies in an inbox does not meet the standard. Telnyx delivers inbound messages through inbound message webhooks with signature verification, so your suppression logic runs on trusted events. Here is a working pattern in Python.
In production, back the suppression list with a database rather than in-memory state, and verify the webhook signature before processing. The full example, including signature verification and persistent storage, is in the Telnyx code repo. Sends go through the standard send message endpoint, so the suppression check slots in front of your existing send logic.
Use this as the working checklist for any US A2P messaging program.
If your program passes all eight, you are ahead of most senders. If it fails any one of them, that gap is where filtering or legal exposure will show up first.
Telnyx gives you the tools to stay on the right side of every regulation:
Compliance rules are set by regulators and carriers. The infrastructure that meets them is set by your provider, and that is where the practical difference shows up. The Telnyx SMS API includes built-in opt-out handling and signature-verified inbound webhooks, so STOP requests flow into your suppression logic without custom plumbing. Telnyx supports 10DLC brand and campaign registration directly, documents the requirements in public messaging compliance docs, and runs traffic over its own carrier-grade network rather than reselling someone else's.
Numbers, registration, sending, and receiving live on one platform, which removes the coordination gaps where compliance failures usually hide. Current rates are published on the SMS Pricing page, and the Send SMS API guide covers implementation from the first request. Compliance is not a reason to slow down your messaging program. With the right tooling, it runs in the pipeline and stays out of your way.
This article is for informational purposes only and does not constitute legal advice. Regulatory requirements are based on publicly available information as of 2026 and are subject to change. Consult qualified counsel about your specific messaging program, and contact Telnyx for current guidance on registration and compliance tooling.
Related articles