Your SMS program is failing in the US in one of two ways, and often both simultaneously. The first is compliance failure: messages sent without proper consent, numbers not registered under 10DLC, campaigns that look identical to marketing even though they are not. The second is architectural failure: programs designed as marketing broadcasts trying to do the job of operational messaging, built on tools that cannot handle the verification, acknowledgment, and two-way logic that operational programs require.
Business SMS in the United States operates under the Telephone Consumer Protection Act, enforced by the FCC and through private class action litigation, alongside a carrier-level registration system called A2P 10DLC that became fully mandatory in February 2025. Marketing messages require prior express written consent. Informational and operational messages require prior express consent. 10DLC registration requires both brand registration and campaign registration for each distinct use case. The two systems work in parallel: TCPA governs the legal basis for sending, and 10DLC governs whether the carrier network delivers your messages at all.
For many organizations, especially those sending appointment reminders, operational alerts, dispatch notifications, workforce communications, and account updates, the challenge is not building another marketing campaign. It is building reliable messaging that keeps operations moving while satisfying US carrier and regulatory requirements. That is a meaningfully different design problem from consumer marketing, and it is where most guides written for US SMS get the framing wrong.
The TCPA: what it governs and where the consent lines are
The Telephone Consumer Protection Act, enacted in 1991 and updated significantly since, restricts the use of automated technology to contact consumers without their prior consent. For practical purposes, organizations using business messaging platforms should design their SMS programs around TCPA consent requirements regardless of the specific messaging technology being used. The legal tests around what qualifies as an automated dialing system have evolved significantly through court rulings including Facebook v. Duguid, and treating any business messaging program as potentially within TCPA scope is the operationally sound approach.
Prior express written consent is required for marketing and promotional messages: offers, discounts, advertisements, and solicitations. This means a clear, affirmative, written opt-in specifically authorizing marketing communications from your organization. Pre-ticked boxes do not qualify. Bundled consent hidden inside general terms does not qualify. The consent must be specific, voluntary, and documented with a timestamp and the method by which it was given.
Prior express consent, a lower threshold, is sufficient for informational and transactional messages: account alerts, delivery notifications, appointment reminders, OTPs, and service updates that a recipient reasonably expects as part of an existing relationship. This standard can be established by providing a phone number in the context of a transaction, account signup, or service enrollment.
The distinction matters because most organizations send both types. A healthcare staffing platform that sends shift availability alerts to registered workers and promotional plan upgrades to hospital clients needs separate consent documentation for each category. Mixing content types within a single message can reclassify the entire message as marketing.
TCPA violations carry statutory damages of $500 to $1,500 per message, with no cap on aggregate liability, and a private right of action that enables class action filings. Hundreds of new class actions were filed in single months during 2025. A high-volume campaign sent to a list without proper consent documentation creates potential exposure in the tens of millions. For the foundational eight-step TCPA framework covering consent, the National Do Not Call Registry, time restrictions, and record-keeping, the TCPA Compliance Checklist is the practical starting reference.
10DLC: the registration layer that controls delivery
10DLC stands for 10-Digit Long Code, the standard local phone number format used for most business SMS in the US. Since February 1, 2025, AT&T, T-Mobile, and Verizon reject or block unregistered A2P traffic from 10-digit numbers. Your platform may show messages as sent. They are not delivered.
Registration has two mandatory steps, both required before any traffic is sent.
Brand registration establishes your organization as a legitimate sender through The Campaign Registry. You provide your legal business name, EIN, website, and contact details, which must match your IRS records. Brand registration completes in one to three business days with a one-time fee.
Campaign registration defines each specific use case you intend to send under. Marketing campaigns, appointment reminders, account notifications, employee communications, and two-factor authentication are all separate use cases requiring separate registrations. Each campaign requires a description of what you send, documentation of how recipients opted in, and sample messages. Mixing use cases within a single campaign is a common reason for carrier filtering even after approval.
One structural feature of US SMS programs differs from most other markets: you cannot register an alphanumeric sender name. Messages always arrive from a phone number or short code. In Nigeria, Kenya, Australia, and most of the other markets covered in this series, you register a brand name that appears on the recipient's device. In the US, the registration identifies your organization and use case to carriers but does not change what appears in the sender field. Recipients see a 10-digit number, a toll-free number, or a short code.
The SHAFT content categories, covering sex, hate, alcohol, firearms, and tobacco, are ineligible for 10DLC registration regardless of consent, alongside cannabis, payday lending, and debt relief. Even with a registered campaign, messages containing restricted content will be filtered.
Toll-free numbers and short codes are outside the 10DLC framework and have their own registration paths. Toll-free works well for high-volume one-way programs. Short codes offer the highest throughput and are used by major brands, utilities, and government programs for time-sensitive mass notification.
Consent revocation: what changed in 2025
The FCC's 2024 order established that consumers can revoke consent through any reasonable method, not just by replying STOP. Someone who emails customer service, mentions in a phone call that they want to stop receiving texts, or communicates clearly through any channel has revoked consent. Organizations must honor those requests within 10 business days, with immediate processing as best practice.
A broader provision that would have required revocation to propagate across all channels from a single request was delayed to January 31, 2027 for complex multi-channel organizations. Until that provision takes effect, organizations must honor the specific channel revocation but are not necessarily required to stop all contact across every channel from a single STOP reply.
Practically, opt-out management in the US now requires more than a STOP keyword processor. Customer service inboxes, support lines, and SMS reply handlers should all feed into the same suppression record.
Operational messaging: where US SMS creates the most enterprise value
Most content written about US SMS compliance addresses marketing programs. That framing misses the majority of enterprise SMS activity by volume and by operational importance.
The organizations that depend most heavily on SMS in the US are not primarily running promotional campaigns. They are running programs where the message itself is the operation: a utility notifying 400,000 customers of a planned outage and needing to know which addresses confirmed receipt. A healthcare staffing agency filling a night shift gap at a hospital with available nurses within the hour. A construction company coordinating 80 subcontractors across three active sites after a weather event. A field service organization tracking whether technicians have acknowledged their morning dispatch. A university research team reaching longitudinal study participants on feature phones across three states.
These programs share a set of characteristics that distinguish them from marketing programs in ways that matter for both compliance design and platform selection. The recipients have an existing relationship with the sender, which affects the consent baseline. The messages are expected and operationally necessary, which affects how recipients and regulators evaluate them. Two-way capability, delivery confirmation, and acknowledgment logging matter as much as throughput. And the consequences of a failed message are operational, not just commercial: the shift does not get filled, the safety alert does not reach the worker, the outage response is delayed.
The TCPA treats these programs differently from promotional marketing in important ways. Informational messages that serve an existing relationship, service obligation, or employment context carry a different consent and litigation profile from messages that exist solely to advertise. Building a US SMS program around its actual operational purpose, documented clearly in the campaign registration, is the foundation of both compliance resilience and program quality.
Employee and workforce communications: a different compliance profile
Operational employee messaging presents a substantially different compliance picture from consumer marketing because the messages arise from an existing employment relationship and are not telemarketing. When an employee provides their phone number during onboarding and receives messages relating directly to their employment, including shift schedules, safety alerts, dispatch assignments, crew coordination, or welfare check messages, those communications generally present a lower compliance risk profile than marketing messages sent to the general public.
This does not mean workforce communications are unregulated. Best practice is to disclose at onboarding that employees may receive operational text messages, provide a mechanism to update contact preferences, and maintain records of the communication consent obtained during the employment process. But the strict prior express written consent architecture required for promotional marketing typically does not apply to operational employment communications.
In practical terms, this matters for a wide range of US operators. A logistics company messaging drivers about route changes and weather conditions. A utility coordinating field technicians during emergency restoration. A healthcare staffing agency sending gap-fill alerts to available nurses. A construction firm sending daily safety briefings and site access instructions to subcontractors. A property management company coordinating maintenance crews across hundreds of sites. An event company dispatching ticketing staff and vendors across venues in multiple cities. These programs can generally be designed and deployed without the marketing consent architecture, while maintaining appropriate employment-context documentation.
For any program serving a genuinely distributed workforce at scale, the capability requirements are also distinct from a marketing platform: two-way messaging so workers can acknowledge receipt or request clarification, delivery confirmation that travels with the record rather than living inside a connectivity provider's system, and escalation logic that triggers a follow-up if a safety-critical message goes unacknowledged. Communication orchestration at the workflow level, not just broadcast delivery, is what makes these programs operationally defensible.
State laws: the layer above the federal floor
TCPA sets the federal minimum. Several states have enacted additional telemarketing and privacy laws that impose obligations beyond federal requirements, and the strictest applicable standard governs contacts in that state.
California is the most significant example. The California Privacy Rights Act applies data privacy obligations to phone numbers collected in California, affecting how consent records must be structured, maintained, and acted on when a California resident requests deletion or opts out. The practical standard for any organization sending to a US-wide list is to design the consent and suppression architecture around the California standard, because that approach satisfies the requirements for contacts in all other states as well.
The safest architecture is the one that does not require state-level routing logic: document consent with a timestamp and source for every contact, process opt-out requests immediately regardless of state, and maintain suppression records that are checked before every send.
The one-platform advantage: US organizations operating globally
Most US SMS compliance content is written for US-native organizations sending to US audiences. What it does not address is the situation that defines an increasing share of enterprise messaging programs: a US-headquartered organization that operates in multiple countries and needs the same program logic, the same compliance records, and the same delivery visibility across all of them.
A large event operations company sending updates and crew dispatch in the US, venue notifications in Australia, logistics coordination in the Philippines, and fan communications in the UK is not running four separate messaging programs. It is running one program that happens to touch four regulatory regimes. Building that on four separate platforms, one tuned for TCPA and 10DLC, one for PECR and UK carrier requirements, one for Australian ACMA registration, one for Philippino aggregator requirements, creates the compliance and operational fragmentation that causes programs to fail when they expand or when a single market's requirements change.
BYOC architecture is the structural expression of the alternative: your consent records, suppression lists, and delivery logs sit in a platform layer above connectivity, portable across every market where you operate. Adding US delivery to an existing multi-market program means connecting a 10DLC-registered route, not rebuilding the program from scratch. Adding a new market to a US-anchored program means connecting an approved local route, not creating a separate platform relationship.
A modern US operational messaging program rarely relies on SMS alone. A technician dispatch may begin as an SMS, escalate to voice if unacknowledged after 10 minutes, notify a supervisor after a second missed acknowledgment, and send supporting job documents over email. TCPA determines whether the first message can be sent. The orchestration logic determines what happens when it is not enough on its own. That architecture is the same whether the technician is in Texas or in Tanzania, and the organizations that recognize that are the ones building messaging programs that actually scale.
For organizations operating across the US and Canada specifically, the Canada SMS compliance post covers the closely related CASL and 10DLC cross-border picture. The channel selection guide covers how to sequence SMS alongside voice, WhatsApp, and other channels for programs that need more than broadcast.
Frequently asked questions
Is 10DLC registration mandatory for all business SMS in the US? Yes, for any automated or bulk SMS sent from a 10-digit local number. Since February 1, 2025, all major US carriers reject or block unregistered A2P traffic from 10DLC numbers. Toll-free numbers and short codes are separate from the 10DLC framework and have their own registration requirements.
What consent do I need to send marketing SMS in the US? Prior express written consent. This means a clear, voluntary, specific, written opt-in from each recipient authorizing marketing communications from your organization. The consent must be documented with a timestamp and source. Bundled consent and pre-ticked boxes do not meet the standard. Informational messages such as account alerts and appointment reminders require prior express consent, which is a lower threshold that can be established through an existing service relationship.
Can I use my brand name as the SMS sender in the US? No. Unlike markets such as Nigeria, Kenya, or Australia where you register an alphanumeric sender name, US SMS always comes from a phone number or short code. Recipients see a 10-digit number, a toll-free number, or a short code, not a brand name. The registration you complete identifies your organization and use case to carriers but does not change what appears in the sender field.
Do TCPA consent requirements apply to employee and workforce communications? Operational employee communications generally present a different compliance profile because they arise from an existing employment relationship and are not telemarketing. Shift schedules, safety alerts, dispatch notifications, and similar operational messages sent to employees who provided their number during onboarding typically do not carry the same consent obligations as promotional marketing. Best practice is still to disclose at onboarding that employees may receive operational messages and to maintain appropriate records.
Does TCPA apply to international organizations sending SMS to US recipients? Yes. TCPA applies to messages delivered to US mobile numbers regardless of where the sending organization is based. International organizations with US operations or US-based contacts must comply with TCPA and 10DLC requirements for those contacts.
How do US programs fit into a multi-country messaging operation? The same way any other country does: through a platform layer that sits above connectivity, with consent records and suppression lists that belong to the organization rather than to a specific carrier or provider. US 10DLC registration stays with your organization regardless of which provider carries the traffic. Adding a new market means connecting an approved local route. Building on a single orchestration layer from the start avoids the fragmentation that comes from managing separate platforms for each country.
This article provides general operational information & should not be considered legal advice. Organizations should consult qualified legal counsel regarding their specific obligations under the TCPA, applicable FCC rules, & relevant state laws.
Talk to our team about building operational SMS program across the United States and your other markets from one platform.