US SMS compliance
Get US SMS compliance right before the first send
TCPA consent, CTIA best practices, registered senders and the reasons messages get filtered: a plain-language guide to text messaging in the United States, with pointers to the detail. Not legal advice.
Last reviewed: 11 September 2026
What are the US requirements for business text messaging?
Business text messaging in the US is governed by TCPA, which sets consent standards for calls and texts, and by CTIA Messaging Principles and Best Practices, which cover conduct including keywords and opt-out handling. A2P traffic must run on registered senders: 10DLC brand and campaign registration through The Campaign Registry, or verified toll-free numbers. Marketing texts need prior express consent and a working opt-out, while transactional messages triggered by a customer's own actions are a separate category. Carriers and service providers may impose additional pre-registration requirements. This is not legal advice.
The landscape in one picture
US SMS compliance is not one rulebook; it is three overlapping layers. TCPA governs consent for calls and texts and is the layer most people mean when they say a text needs permission. CTIA Messaging Principles and Best Practices govern how application-to-person traffic behaves: keywords, opt-out handling, message frequency and content expectations. And the registration layer, 10DLC brand and campaign registration through The Campaign Registry plus toll-free verification under the CTIA framework, governs whether carriers trust your sender at all.
The honest summary is that none of these layers is optional in practice, and none is something you should reason about for the first time after delivery problems appear. Carriers and service providers also require pre-registration of message originators in some cases, so check current guidance before launch. Our compliance guide is the thorough version of this page, updated for the current rules, and it is not a substitute for legal advice.
Consent: the layer that gets businesses in trouble
TCPA requires prior express consent for marketing calls and texts, and a higher standard, prior express written consent, for automated or prerecorded calls. Text messages need consent and a working opt-out, and the consent standard attaches to what the thing is: a promotional text has a higher bar than a message a customer's own action triggers.
The practical work is not writing a policy; it is knowing where your numbers came from. Consent evidence means being able to show that a customer agreed to receive texts from this business, whether that is a checkbox, a signup form or a transaction flow, and it means not texting numbers you scraped or inherited without provenance. The second practical point is that consent is not permanent context: a customer can withdraw it, and honor that withdrawal rather than arguing with it. The standards are a compliance question, so treat them that way in your planning.
Opt-out handling and keyword conventions
CTIA best practices establish the conventions US subscribers expect. STOP is the standard opt-out keyword and should do what it says: stop sending to that subscriber, promptly. HELP is the standard request for assistance and should be answered. Where a sender offers keyword-specific flows, the same discipline applies: every keyword should be documented, every reply should be accounted for, and the handling should be observable rather than assumed.
The detail that trips teams is the difference between acknowledging an opt-out and honoring it. An automated reply confirming "you will not hear from us" is not compliance if the next campaign still includes the customer. Keep opt-out state in the system that decides sends, and treat prompt as the standard. Retained, deliverable opt-out records are the practical evidence if a question ever comes up; our antispam policy describes how we treat sender behavior and filter risk.
Document what each keyword does and what reply the customer receives, so behavior is auditable rather than remembered.
Transactional vs marketing: the distinction that matters
The most consequential distinction in US messaging is not between providers; it is between traffic types. Transactional messages are triggered by a specific user action or account event: an order update, a one-time password, an appointment reminder, a payment confirmation. Marketing messages are promotional: offers, announcements, re-engagement. The difference is not content style; it is whether the customer is waiting for the message.
That distinction has real consequences. Transactional and marketing traffic should normally be registered as separate campaigns, consent is considered differently, and a marketing opt-out should not suppress the operational messages a customer's own actions imply. Our transactional vs marketing guide and transactional SMS page cover the practical separation, and getting it wrong is a common cause of both compliance friction and filtered traffic.
The category is defined by the trigger, not the tone, which is why a marketing message can be legal and still subject to a different consent standard than a password reset.
Why messages get filtered, and what records to keep
Filtering is the visible symptom of invisible problems, and the causes are usually identifiable. Unregistered or low-trust senders, because US A2P must be registered: either 10DLC brand and campaign registration or toll-free verification. Poor sender behavior, meaning ignored opt-outs, unexpected frequency or content that looks like spam. And configuration errors, where the provider is fine but the sender is not set up for the traffic type.
What you can do is keep records and monitor the outcome of each campaign. Consent evidence is part of your records; delivery receipts are part of running the channel. Configure a callback or receipt URL, watch message states, and use our message state and errors page to interpret failures, so a filter that quietly drops messages shows up as data rather than as a customer complaint. Our compliance guide, antispam policy and terms and conditions are the reference points we publish, and they are not a substitute for legal advice on your specific situation.
TCPA consent standards
Prior express consent for marketing texts, and prior express written consent for automated or prerecorded calls.
CTIA best practices
STOP and HELP conventions, prompt opt-out handling and conduct rules for A2P traffic in the US.
Registered senders
10DLC brand and campaign registration through TCR, or toll-free verification, because unregistered senders get filtered.
Records and receipts
Keep consent evidence and monitor delivery receipts, so you can see what happened rather than assume it.
Frequently asked questions
Is this page legal advice?
No. These are practical summaries. TCPA, CTIA principles and carrier or service-provider rules can change and can impose extra pre-registration requirements, so use our compliance guide and check current guidance for your situation.
Do I need consent for transactional SMS in the US?
Transactional messages triggered by a customer's own action are treated differently from marketing, but they are still A2P traffic and still require a registered sender. Marketing texts need prior express consent and a working opt-out; keep the categories structured separately.
What is the difference between express and express written consent?
Prior express consent is a clear, documented agreement to receive marketing calls or texts. Prior express written consent is a higher standard applied to automated or prerecorded calls, typically involving a written agreement in a compliant format that discloses the caller. The standards are regulatory, so check the current wording for your channel.
How quickly must I honor a STOP opt-out?
Opt-outs should be honored promptly rather than merely acknowledged. The practical standard is immediate for the next send: if the customer replied STOP, the next campaign should exclude them, and the opt-out should be recorded as evidence.
Why are my US messages being filtered?
The usual causes are an unregistered or low-trust sender, sender behavior such as ignored opt-outs or unexpected frequency, and content that resembles spam. Registered senders plus receipt monitoring and a disciplined frequency are the practical countermeasures; see our antispam policy for how we treat filtering.
Do I need a registered sender for every US message?
Yes for application-to-person traffic. US A2P runs on registered 10DLC numbers or verified toll-free numbers, whether the message is transactional or marketing. Sending without registration risks quiet filtering no matter how clean the submission looks.
Check our compliance guide before you send
Our compliance guide walks through consent, registration and best practices in full, and our policies pages carry the detail. It is not legal advice, but it is the right starting point.