← All articles
Compliance & Trust

10DLC, TCPA, and the Rules That Actually Govern Business Texting

A plain-English compliance primer for operators, not lawyers: registration, consent, revocation, quiet hours, SHAFT filtering, and what non-vetted traffic quietly costs you in deliverability.

The Verbose CX teamJuly 26, 2026 · 8 min read

Business texting has two rulebooks, and most operators only find out about the second one after their messages stop landing. The first is the law — the TCPA, enforced by the FCC and by anyone with a lawyer. The second is the carrier layer — 10DLC registration and content filtering, enforced silently by whoever decides whether your text reaches a phone. You can be perfectly legal and still invisible. This is the working map of both, written for the person who has to run the program, not defend it in court.

None of this is legal advice, and your counsel gets the final word. But the day-to-day of staying compliant isn’t exotic. It comes down to five things you can actually operate: register your traffic, get real consent, honor opt-outs fast, respect the clock, and stay off the content filters. Get those right and the rest is paperwork.

The two rulebooks: the law and the carriers

The TCPA (Telephone Consumer Protection Act) is federal law. It governs whether you’re allowed to text someone — consent, timing, opt-out rights — and it carries statutory damages of $500 to $1,500 per message under the FCC’s TCPA rules. That “per message” is the part that ends companies: a single non-compliant blast to ten thousand people is not one problem, it is ten thousand of them.

10DLC (“10-digit long code”) is the carrier rulebook. It governs whether your text actually gets delivered. Since the major U.S. carriers moved application-to-person traffic onto registered 10DLC, every legitimate business sender is expected to register their brand and campaigns through The Campaign Registry. Unregistered or misregistered traffic gets throttled, filtered, or blocked outright — no court, no notice, just silence.

The trap most operators fall into

Legal and deliverable are two different tests. You can have airtight consent and still watch your delivery rate collapse because your campaign registration doesn’t match what you’re actually sending. Both boxes have to be checked, every time.

Registration: getting your traffic vetted

Registration is a two-part disclosure. You register your brand (who you are, your legal entity, your EIN) and your campaigns(what you’ll send and why — appointment reminders, lead follow-up, customer care). Carriers use that to assign a trust score and a throughput limit. The more transparent and verified your brand, the higher your ceiling.

The single most common failure isn’t skipping registration — it’s drift. You register a campaign as “appointment reminders,” then start sending promotional offers or two-way conversational threads that don’t match the use case you declared. The mismatch is exactly what content filters are built to catch. Register for what you actually do, and update the registration when the program changes.

LayerWhat it establishesWhat breaks if you skip it
Brand registrationYour verified legal identityLow trust score, low throughput
Campaign registrationThe declared use case for your messagesFiltering when content doesn't match
Consent recordsProof the recipient opted inTCPA liability, complaints
Opt-out handlingHonoring STOP and revocationTCPA liability, carrier penalties
What each registration layer controls. Treat them as one system, not two forms.

Consent is the hinge of the entire law. Under the TCPA, marketing texts sent with an autodialer require prior express written consent— a clear, affirmative opt-in that isn’t buried in terms nobody reads and isn’t a condition of purchase. Transactional or informational messages (an appointment you booked, an order you placed) sit on a lower bar, but the safe operating rule is simpler: get a real, documented yes, and keep the record.

If you can’t produce the moment someone said yes, in a dispute you never had consent at all.

Two practical rules cover most situations. First, consent is channel- and purpose-specific: a phone number given to book a service call is not blanket permission to enroll them in a weekly promo list. Second, consent is evidence, not vibes — store what they agreed to, when, and how, because the burden of proof is on you, not the recipient.

Revocation and quiet hours: the clock is the rule

Two timing rules trip up more programs than any consent technicality, because they’re easy to get wrong at scale.

Opt-out.The recipient can revoke consent at any time, by any reasonable means. The FCC’s updated rules require senders to honor a revocation request within a reasonable time, not to exceed 10 business days per the FCC. In practice that’s far too slow to be safe: standard opt-out keywords like STOP should suppress the number immediately and automatically. Manual opt-out handling is how numbers keep getting texted after someone said stop — and every one of those is a fresh violation.

Quiet hours. The TCPA restricts telemarketing calls and texts to the window between 8 a.m. and 9 p.m. in the recipient’s local time, under FCC rules. The catch is theirtime zone, not yours. A blast scheduled for 8:30 a.m. Eastern reaches the West Coast at 5:30 a.m. — a violation before anyone’s had coffee. Time-zone-aware sending isn’t a nicety; it’s the difference between a campaign and a claim.

$500–$1,500
TCPA statutory damages per message (FCC)
≤10
business days to honor an opt-out (FCC)
8a–9p
permitted texting window, recipient's local time (FCC)

SHAFT and content filtering: what carriers quietly block

Beyond the law, carriers filter on content. The industry shorthand is SHAFT — Sex, Hate, Alcohol, Firearms, Tobacco — the categories the CTIA’s messaging principles flag as prohibited or age-restricted, now extended to cannabis and CBD regardless of state legality. If your business touches any of these, you’re not just navigating consent; you’re navigating whether the carrier will carry you at all.

Filtering isn’t limited to SHAFT, either. Public URL shorteners, messages that don’t match your registered use case, high complaint rates, and “gray route” traffic all raise flags. The maddening part is that filtering is mostly silent — you rarely get a bounce, just a slow bleed in delivery you won’t notice until you check the numbers against sends.

  • Match your content to your registration. The fastest way onto a filter is sending promo through a campaign you registered as care or notifications.
  • Use a branded, dedicated link domain rather than a shared public shortener that other senders may have poisoned.
  • Watch your complaint and opt-out rates. A rising STOP rate is the earliest signal that carriers are about to trust you less.

The operator’s checklist

If you do nothing else, do these five in order. They map to the five ways a texting program actually gets into trouble.

  1. Register brand and campaigns for the use cases you truly send, and re-register when the program changes.
  2. Capture consent as evidence — what they agreed to, when, and how — and keep it retrievable.
  3. Suppress opt-outs automatically and permanently the moment someone sends STOP, and keep a global suppression list.
  4. Send in the recipient’s local 8 a.m.–9 p.m. window, time-zone aware, every time.
  5. Keep content clean of SHAFT and mismatch, and monitor delivery, complaints, and opt-out rate as a health dashboard.

The honest bottom line

Compliance here is not one big legal project. It’s five operational habits enforced by software, because the failure mode of every one of them is “a human forgot at scale.” If any of these five depends on someone remembering, it will eventually cost you — in damages, in deliverability, or both.

Sources

Keep reading