Business text messaging is not personal texting with a company logo attached. It operates under a different set of carrier requirements, federal regulations, and recipient expectations. A business that treats outbound SMS as an unregulated direct channel is taking on legal exposure that the compliance landscape makes very real — and expensive.
This guide covers what business SMS is, the use cases it serves, the sender number types involved, the carrier ecosystem requirements (10DLC and toll-free verification), the federal law that governs consent (TCPA), and the opt-in/opt-out mechanics that every business text program must implement correctly.
This article describes regulatory context but does not constitute legal advice. For specific compliance programs, consult qualified legal counsel.
What is business SMS? Business SMS is commercial text messaging sent from an organization to customers, prospects, or other recipients — as distinct from personal peer-to-peer texting. It is subject to carrier requirements that govern how application-generated messages are delivered over mobile networks, and to federal regulations — primarily the Telephone Consumer Protection Act (TCPA) and rules from the FCC — that govern consent, content, and opt-out handling. These requirements do not apply to personal texting.
Business SMS Use Cases
The specific use case matters — not just for strategy, but because different message types carry different consent requirements under the law.
Customer support: two-way text conversations
One of the fastest-growing uses of business SMS is conversational support — customers text a business number with questions, issues, or requests, and agents respond in real time or asynchronously. Text-based support allows customers to interact on their own schedule and is particularly effective for non-urgent issues where a phone call is inconvenient.
Two-way support conversations initiated by the customer (inbound) are typically treated differently from outbound marketing messages for consent purposes, though the details depend on context and applicable law.
Transactional and informational notifications
These are messages the customer has a reasonable expectation of receiving in connection with a transaction or service relationship they have initiated:
- Order confirmations and shipping updates
- Appointment reminders and schedule changes
- Account alerts: balance thresholds, payment due reminders, security notifications
- Service status updates: outage notifications, delivery window updates
- Verification codes (OTP) for authentication
- Post-call follow-up texts
Transactional messages generally carry less demanding consent requirements than promotional messages, though they still require that recipients have provided their phone number in the relevant context and that opt-out requests are honored.
Outbound marketing and promotional messaging
Promotional SMS — messages primarily intended to market a product, service, or offer — carries the most stringent consent requirements. Under the TCPA, automated marketing text messages to mobile numbers require written consent from the recipient, obtained prior to the first message. This is a meaningful threshold: the consent must be documented, it must be clear about what the consumer is agreeing to receive, and it must be revocable.
The significance of this distinction — transactional vs promotional — is that a message can cross the line from one category to the other through the addition of marketing content. An order confirmation with a promotional offer embedded may be treated differently than a pure transactional notification.
Sender Number Types
Business SMS requires a registered sender number. The choice of number type affects throughput, deliverability, cost, and the registration process required.
10-digit local numbers (long codes)
These are standard 10-digit phone numbers — the same format as a business's main line. They are widely used for business text messaging because they appear local and familiar to recipients. When used for A2P (Application-to-Person) messaging — automated or semi-automated business texting at scale — 10-digit local numbers require registration through the 10DLC ecosystem (discussed below).
Short codes (5–6 digit numbers)
Short codes are purpose-built for high-volume A2P messaging. They can handle substantially higher message throughput than long codes and generally achieve higher deliverability because carriers recognize them as pre-approved A2P senders. The trade-off is cost and lead time: short code provisioning requires a carrier application and approval process, involves higher monthly fees, and takes longer to obtain than a long code. Short codes are well-suited for large-scale marketing campaigns or high-volume notification programs.
Toll-free numbers for SMS
10-digit toll-free numbers (800, 888, 877, etc.) can be used for business SMS and MMS. They support moderate throughput — more than a local long code, less than a short code — and are a practical choice for businesses that want the credibility of a toll-free number with SMS capability. Toll-free numbers used for A2P messaging require a toll-free SMS verification process with carriers (separate from 10DLC), described below.
The 10DLC Ecosystem
10DLC — 10-Digit Long Code — refers to the industry-developed framework that major US wireless carriers use to manage A2P messaging from 10-digit local phone numbers. It is important to understand what 10DLC is and is not:
10DLC is not a federal law or FCC regulation. It is a carrier-industry ecosystem requirement developed by wireless carriers and the CTIA (the wireless industry trade association). Carriers apply 10DLC rules as a condition of delivering A2P traffic over their networks — not because a government regulation mandates the specific registration process. The purpose is to reduce spam, improve deliverability for legitimate senders, and create accountability for A2P messaging at scale.
How 10DLC registration works
The 10DLC registration process has two components:
- Brand registration: The business registers its identity — legal business name, EIN, business type, and contact details. This tells carriers who is sending the messages.
- Campaign registration: Each distinct messaging use case is registered separately — for example, "appointment reminders for dental practice" or "marketing promotions for [brand]." Campaign registration describes the message content, consent method, and expected volume. This tells carriers what the messages are about.
Registration is processed through a registry organization and submitted to carriers for vetting. There are fees associated with brand and campaign registration, which vary by registry and may include ongoing monthly costs per campaign.
Unregistered A2P traffic from long codes is treated with suspicion by carriers. It is subject to filtering, throttling, or blocking — particularly by major carriers. Businesses that send A2P SMS from long codes without 10DLC registration risk having their messages filtered before they reach recipients.
10DLC registration is typically initiated and managed through your SMS platform or carrier, not directly by the business with the registry.
Toll-Free SMS Verification
Toll-free numbers used for business SMS require a separate verification process — distinct from 10DLC. Toll-free verification is a carrier review process that evaluates the business, its messaging use case, and consent practices before approving the number for A2P traffic. Verified toll-free numbers receive better deliverability and are less likely to be filtered.
Like 10DLC, toll-free verification is a carrier-industry requirement, not a federal regulation, and it is typically processed through the SMS platform the business uses.
TCPA: The Federal Law That Governs Business Texting
The Telephone Consumer Protection Act (TCPA) is a federal law enacted in 1991 and enforced by the Federal Communications Commission (FCC). It governs automated calls and text messages to US consumers and imposes consent requirements, opt-out requirements, and time-of-day restrictions. TCPA violations carry statutory damages of $500 to $1,500 per violation, and because violations occur per message rather than per campaign, exposure in a large SMS program can be significant.
Understanding TCPA requires distinguishing between message types:
Transactional / informational messages
Messages sent in relation to a transaction the recipient has initiated — order updates, appointment reminders, account alerts — generally require prior express consent, which can be implied from the transaction itself (e.g., providing a phone number at checkout in a context that reasonably implies text notifications). The consent requirements are less prescriptive than for marketing messages, but opt-out requests must still be honored immediately.
Marketing / promotional messages
Automated marketing or promotional text messages to mobile numbers require prior express written consent under the TCPA. This is a specific standard: the consent must be in writing (which includes electronic records), must clearly authorize the specific type of messages the recipient will receive, must identify the sender, and must be obtained before the first message is sent.
Verbal consent, general terms-of-service agreement, or purchasing a product does not automatically satisfy the written consent requirement for promotional SMS.
The FCC adopted a "one-to-one consent" rule intended to require that consent for marketing calls and texts be specific to a single seller — addressing consent obtained through lead generation platforms that authorize contact from multiple companies. The Eleventh Circuit Court of Appeals vacated that rule before it took effect, so it should not be treated as a current binding consent requirement. Businesses should rely on the currently applicable TCPA consent framework and current FCC guidance rather than the vacated rule. Consult legal counsel for current consent standards applicable to specific programs.
The specifics of what constitutes adequate consent, how it must be documented, and how it applies to particular message types and delivery methods are questions that depend on the facts of each program. The description here is informational context, not legal advice.
TCPA is enforced through private lawsuits
Unlike many regulatory frameworks that are primarily enforced by government agencies, TCPA violations are frequently enforced through class action litigation. Plaintiffs' attorneys have brought numerous class actions under TCPA in contexts where businesses sent automated messages — including texts — to consumers without adequate consent. The $500–$1,500 per-violation damages multiplied across thousands or millions of messages creates potential exposure that makes TCPA one of the most consequential compliance areas in business communications.
Businesses with any meaningful SMS program should review their consent documentation, opt-out processes, and message content with legal counsel familiar with TCPA before launching.
Opt-In and Opt-Out Mechanics
Regardless of message type, every business SMS program needs clear opt-in and opt-out processes. These are both regulatory requirements and operational necessities.
Opt-in: how recipients consent
Opt-in methods vary by message type and consent standard. Common mechanisms include:
- Keyword subscription: Texting a keyword (e.g., "JOIN") to a short code or business number
- Web form: Checking a checkbox on a website or landing page that explicitly describes what texts will be received
- Point of transaction: Providing a phone number at checkout, in-person, or over the phone in a context where the consent language is presented
- Verbal during a call: An agent reads consent language and the customer verbally agrees (the verbal agreement must be documented appropriately)
For promotional messages, the opt-in must be specific, documented, and preserved. Broad consent language buried in general terms of service is not an adequate basis for sending marketing texts.
STOP: the mandatory opt-out keyword
Texting "STOP" to a business sender is an industry-standard opt-out mechanism, and honoring it is a non-negotiable requirement. Consumers may also use other recognized revocation methods — verbal request, a web-based opt-out form, or other reasonable means the business has established. Failure to honor valid opt-out requests is both a TCPA concern and a carrier violation.
Applicable FCC rules require that covered revocation requests be honored within the timeframe permitted under current regulations. Carrier and messaging-industry practices — including CTIA guidelines — commonly expect automated STOP keyword responses to be processed operationally without avoidable delay. The number must be added to the business's opt-out list and excluded from all future outbound messaging for that program. Verify current regulatory timing requirements with legal counsel for your specific program.
HELP keyword
Responding to "HELP" with sender identification and a way to contact the business is another industry-standard requirement. A compliant HELP response typically includes the business name, the program description, message frequency disclosure, and a way to get additional help (e.g., a phone number or website).
Opt-out lists and DNC parallels
Maintaining and honoring an internal opt-out list for SMS is functionally similar to managing an internal DNC (Do Not Call) list for outbound calling. The principles are the same: once someone has opted out, they cannot receive further messages from that program, and the opt-out must be honored across all messaging channels that share that audience. For a comparison, see the guide to what is the DNC registry.
EaseDial Omnichannel
Two-way SMS and MMS for business — managed alongside voice, WhatsApp, and all other channels in a unified agent workspace.