SMS Marketing and A2P 10DLC: What You Have to Do Before You Send

The way most businesses discover A2P 10DLC is this: they set up texting, send a batch, and the platform reports every message as delivered. Nobody replies. Nobody complains. The texts simply never arrived, and no error was generated anywhere.

Carriers block unregistered business texting silently. There is no bounce, no notification, no queue of failures to review. You find out when a customer mentions they never got the appointment reminder.

Registration is the gate. It is also only one of four things you need to have right, and the other three are the ones that carry legal exposure.

This is a marketing guide, not legal advice. Telemarketing law carries statutory damages per message and a private right of action. Have counsel review your consent language before you launch a program.

The four layers

Carrier registration (A2P 10DLC) determines whether your messages get delivered.
The TCPA determines whether you were allowed to send them.
State telemarketing laws add their own requirements on top, and they multiply.
Industry guidelines, principally the CTIA messaging principles, are what carriers actually vet your registration against.

Registration gets your texts through. It does not make you compliant. Those are separate problems and a lot of businesses conflate them.

Layer one: getting registered

A2P 10DLC stands for application-to-person messaging over a ten-digit long code, which is to say business texting from a normal local phone number. It is a carrier program rather than a law, administered through The Campaign Registry.

The registration has two parts.

Brand registration identifies your business: legal name, EIN, address, website, contact. A vetting process confirms the business is real and the details match public records. Accuracy matters more than anything here. A legal name that does not match your EIN registration is the most common cause of a rejection.

Campaign registration describes what you will send: the use case, sample messages, how people opt in, and where that opt-in lives. Each distinct type of messaging is its own campaign.

Two points that surprise people.

Volume does not determine whether this applies to you. Automation does. If you send templated messages through a platform, whether that is GoHighLevel, Twilio, a scheduling tool, or anything else, you need to be registered. Sending forty texts a month from software still counts.

One EIN equals one brand. An agency managing fifty clients needs fifty brand registrations under fifty EINs. You cannot register once and run everyone’s messaging under it, and attempting to is a fast route to having everything suspended.

Timelines vary, but brand verification generally runs a few business days and campaign approval usually follows within a week once the brand clears, assuming the submission is clean.

What actually gets you rejected

Almost always the website, not the form.

Reviewers visit the opt-in URL you submit and check that what you described is actually there. The frequent failures:

  • The opt-in is not publicly visible. A form behind a login, or one that no longer exists at the URL submitted.
  • No SMS consent checkbox, or one that is pre-checked, or one bundled with email consent. It needs to be separate and unchecked.
  • The disclosure is incomplete. The consent language has to name your business, say what kind of messages you will send, indicate frequency, state that message and data rates may apply, and explain how to opt out.
  • No privacy policy, or one missing the required clause. Carriers look for explicit language that mobile opt-in data and consent will not be shared with third parties or affiliates for marketing purposes. Generic privacy policies do not contain this and it is the single most common fix we make for clients.
  • No terms of service covering the messaging program.
  • Sample messages that do not match the stated use case. If you registered for appointment reminders and your samples are promotional, that is a mismatch.
  • Prohibited content. The SHAFT categories (sex, hate, alcohol, firearms, tobacco) plus lead generation and affiliate marketing, high-risk lending, and several other categories are restricted or barred outright.

Fixing the website first and registering second turns a multi-week back-and-forth into a single clean submission.

Layer two: consent under the TCPA

This is the layer with financial teeth. The TCPA and the FCC rules implementing it at 47 CFR 64.1200 govern when you may text someone, and violations carry statutory damages per message with a private right of action attached. Class actions in this area are a functioning industry.

The standard for marketing texts is prior express written consent. In practice that means:

  • A clear, affirmative action by the person. An unchecked box they check, or a keyword they text to you.
  • Consent for SMS specifically, not bundled into a general communications agreement.
  • Disclosure of who is texting, what about, and roughly how often.
  • A statement that consent is not a condition of purchase.
  • Opt-out instructions.

And critically, you have to be able to prove it later. Retain the record: what the person saw, when they agreed, from what IP or phone number, and what the page said at that moment. A consent you cannot document is a consent you did not get, as far as a court is concerned.

One area worth watching: the FCC’s proposed one-to-one consent requirement, which would have forced lead generators to obtain separate consent for each advertiser, did not survive court challenge. That does not mean shared or purchased lists are safe. Carriers and registry reviewers apply their own expectations during vetting regardless of the federal rule’s status, and ordinary TCPA exposure for weak consent is unchanged. Document consent per business as though the rule were in force.

Layer three: state law

A growing number of states have their own telemarketing statutes that apply to any business texting their residents, regardless of where the business is located. Several carry their own statutory damages and private rights of action, and some add calling-hour restrictions tighter than federal law.

Oklahoma has its own telephone solicitation statute. Texas, Florida, Washington, Maryland, and others have theirs. If you text customers in multiple states, you are subject to the rules of each one. This is the layer most businesses have never heard of and it is expanding every legislative session.

Layer four: ongoing operational rules

Getting approved is the start, not the finish.

STOP and HELP have to work. STOP must remove the person immediately and reliably. HELP must return your business name and contact information. Test both from a real phone after launch rather than assuming the platform handles it.

Honor opt-outs across the whole system. Someone who replies STOP to a marketing message and then receives an appointment reminder from a different campaign is a problem. Suppression should be account-wide unless you have a genuinely separate consent basis.

Avoid public URL shorteners. Shared shortener domains get flagged because spammers use them. Use a branded short domain or full URLs.

Keep content matching the registered use case. Drifting from appointment reminders into promotional blasts under the same campaign is how approved campaigns get suspended.

Mind the hours. Federal rules restrict calling hours and several state laws are stricter. An automated sequence that fires at 7:40am in one time zone is 5:40am in another.

The CTIA messaging principles are the industry reference for most of this and are what carriers evaluate against.

A pre-launch checklist

  1. Legal business name and EIN confirmed and matching your registration exactly.
  2. Opt-in form live at a public URL, with a separate unchecked SMS checkbox.
  3. Consent language containing business name, message type, frequency, rates disclosure, and opt-out instructions.
  4. Privacy policy published, including the clause stating mobile opt-in data is not shared with third parties for marketing.
  5. Terms of service published and covering the messaging program.
  6. Two or three sample messages written that genuinely represent what you will send.
  7. Consent records being captured and retained automatically.
  8. STOP and HELP tested from an actual handset.
  9. Send windows configured for the time zones you actually message into.
  10. Each distinct message type registered as its own campaign.

Why it is still worth doing

All of that is friction, and it is worth pushing through. Text is the highest-engagement channel available to a small business by a wide margin, and the compliance burden is precisely what keeps it from being flooded the way email was. The barrier protects the channel.

The businesses that do this properly get a direct line to their customers that nobody else is crowding. The ones that skip it either never reach anyone or find out about the TCPA the expensive way.

We set up compliant email and SMS programs including the registration, the consent architecture, and the policy language on the website side. You own the account, the number, and the list. Get in touch if your texts have stopped arriving and nobody can tell you why.

More from Design Thumbprint

Want this kind of thinking applied to your marketing?

We are a boutique agency in Edmond working with businesses across Oklahoma and beyond. If something here raised a question about your own marketing, ask us directly.

Get a free marketing audit See all services

Call
405-766-6169
Email
info@designthumbprint.com