Suped

What are the SMS marketing rules regarding consent and the Do Not Call list?

Published 1 Jul 2025
Updated 28 Jul 2026
11 min read
Summarize with
A phone, consent checkbox, and registry card introduce SMS consent rules.
Updated on 28 Jul 2026: We updated this guide for current FCC opt-out rules and Texas SMS requirements.
The direct answer is this: in the United States, automated promotional texts generally need prior express written consent. Marketing texts to a number on the National Do Not Call Registry also require the consumer's prior express invitation or permission for the specific seller, evidenced by a signed written agreement, unless another exception applies. A registry entry does not erase valid permission, but the sender must be able to prove that permission and show it has not been revoked.
The common mistake is treating phone validation as the first question. A valid mobile number is not permission. A clean phone lookup can tell you whether a number exists, whether it looks mobile, or whether it has format problems. It does not tell you whether the person agreed to receive promotional texts from you. The first operational question is consent. The second is suppression, including federal Do Not Call, company-specific Do Not Call, reasonable revocation requests, state rules, and internal exclusion lists.
Compliance note
This is operational guidance, not legal advice. For borderline cases, especially lead generation, co-registration, state mini-TCPA laws, healthcare, finance, or political messaging, have counsel review the exact consent language and sending workflow before launch.
The simplest way to think about the rules is that Do Not Call status blocks unsolicited telemarketing, while valid seller-specific permission allows messages that match the permission given. The FCC robocall guidance covers unwanted texts and robocalls, and the FCC expressly extended National DNC protections to marketing texts effective March 26, 2024. The FTC DNC guidance explains that sellers and telemarketers must access the registry when required and synchronize covered lists at least every 31 days.
When you have valid permission
  1. Send path: You can send marketing texts that match the written agreement, even if the number is on the federal registry.
  2. Proof: Store the seller name, phone number, disclosure version, affirmative action or signature, timestamp, source page, and IP address when available.
  3. Revocation: STOP or any other reasonable message that clearly withdraws permission ends the covered marketing permission.
When permission is missing
  1. DNC match: Suppress the number unless documented permission or a counsel-approved exception applies.
  2. No match: Do not treat absence from the registry as opt-in consent for promotional texts.
  3. Purchased list: Treat third-party lists as unusable unless the permission record clearly covers your seller and SMS marketing.
The private-right-of-action part is why this gets serious fast. A consumer can bring a TCPA claim directly, and damages can reach $500 per violation, or up to $1,500 for willful or knowing violations. That makes recordkeeping more than admin cleanup. It is the defense file.

Situation

Send?

Action

Permission stored
Yes
Send within scope
DNC, no permission or exception
No
Suppress
Revocation received
No
Honor opt-out
Receipt or service notice only
Depends
Confirm a nonmarketing basis
Common SMS marketing send decisions
For automated promotional SMS, use explicit written consent that is specific to text marketing. For marketing texts to a number on the National DNC Registry, keep the signed written permission required by the FCC's DNC rule. Email consent is not enough. A website account, purchase, webinar registration, or app install is not enough unless the person also agreed to receive marketing text messages from the named seller.
The consent language should name the seller, name text messages, state that messages are promotional or marketing, say that consent is not a condition of purchase, give the expected frequency or recurring nature, mention message and data rates, and explain how to stop. If the signup uses a checkbox, leave it unchecked by default. If the opt-in happens by keyword, preserve the keyword, number, disclosure, and timestamp.
SMS signup disclosure exampletext
By checking this box, I agree to receive recurring automated marketing text messages from Example Brand at the mobile number provided. Consent is not a condition of purchase. Message and data rates apply. Reply STOP to unsubscribe and HELP for help.
Keep the exact version
Screenshots are useful, but they are not enough by themselves. Store the actual disclosure text, form version, seller named, phone number authorized, and affirmative action or electronic signature. If the signup page changes six months later, you still need to know what the person saw and did on the day they opted in.

How to process SMS opt-outs

A consumer can revoke consent by any reasonable means that clearly expresses a desire to stop covered calls or texts. Standard keywords make automation easier, but a sender cannot force people to use one exclusive keyword or channel. Capture free-form replies, requests made to support staff, and other reasonable methods that reach the business.
  1. Timing: Honor covered company-specific DNC and consent-revocation requests within a reasonable time, no later than 10 business days. Immediate suppression is the safer operational target.
  2. Keywords: Recognize STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, and UNSUBSCRIBE, while also reviewing plain-language requests.
  3. Confirmation: Send at most one confirmation text with no marketing content. A confirmation sent within five minutes has the clearest federal presumption.
  4. Scope: Do not keep sending the campaign the person rejected. The FCC delayed the requirement to apply one category's revocation to unrelated robocalls and robotexts until January 31, 2027.
STOP is not the only opt-out
A reply such as "do not text me again" can revoke permission even if an automated keyword parser misses it. Route unrecognized replies for prompt review, suppress the number when the intent is clear, and retain the request and processing timestamp.

When to check the Do Not Call list

If your SMS program relies on a DNC exception, or you are screening numbers because written permission is incomplete or uncertain, the list needs to be current. The FTC standard is to synchronize at least every 31 days when you are required to use the registry. Use a send-time suppression gate for triggered campaigns so the system checks the latest available permission, revocation, and opt-out state before a message leaves.
Triggered SMS is possible. The trigger still needs to run through compliance controls. A cart reminder, renewal offer, or loyalty promotion counts as marketing when it promotes a product or sale. The event can fire instantly, but the send decision should check consent, federal DNC status where required, state exclusions, all captured revocations, local time, and frequency caps before delivery.
Flowchart showing consent, DNC, opt-out checks, and suppression before SMS sending.
Flowchart showing consent, DNC, opt-out checks, and suppression before SMS sending.
Triggered send gatetext
1. Confirm SMS marketing consent or permission for this seller and number. 2. Check company DNC records and every captured revocation, not only STOP. 3. Check federal or state DNC rules when required. 4. Check message category, recipient local time, and frequency caps. 5. Send only if every required control passes.
Phone validation still has value. It can reduce typos, identify impossible numbers, flag landlines, and detect some reassigned-number risk. Use it as list hygiene, not legal permission. A validated number can belong to someone who never opted in. An opted-in number can later be reassigned. Both problems require different controls.
  1. Validation: Checks whether the phone number looks reachable, formatted correctly, and usable for SMS.
  2. Consent: Shows that the current user of that number agreed to receive your marketing texts.
  3. Suppression: Stops sends when consent is absent, revoked, too narrow, or blocked by DNC rules.
  4. Audit trail: Proves the decision later, including the record used and the suppression outcome.
Consent evidence strength
A practical way to rate whether a number is safe enough for SMS marketing.
Strong record
Sendable
SMS-specific consent, exact disclosure, timestamp, source, and no opt-out.
Weak record
Review
Consent exists, but the source, wording, or seller scope is unclear.
No record
Suppress
No proof of SMS marketing consent for the current seller and number.

The rules that matter in daily sending

A compliant SMS program has several controls that run together. Policy language alone is not enough. The sending system needs to enforce consent, suppression, timing, and message-scope rules every time a campaign, automation, or triggered message runs.
  1. Written permission: Use clear consent or permission for marketing texts, tied to the seller and phone number.
  2. DNC screening: Where required, access current federal and state DNC data, synchronize on schedule, and keep access records.
  3. Internal controls: Maintain written procedures, train staff and partners, monitor compliance, and keep a company-specific DNC list.
  4. Opt-outs: Honor any reasonable revocation method promptly and within the applicable federal deadline.
  5. Message controls: Identify the seller, keep promotions within the consent scope, and schedule by the recipient's local time.
  6. State review: Check state DNC lists, registration rules, contact hours, disclosures, and exemptions before nationwide campaigns.
Texas has treated solicitation texts as telephone solicitations under SB 140 since September 1, 2025. The Texas Secretary of State now says, based on the state's position and an agreement in federal litigation, that a business sending texts with the consumer's prior consent does not need to file the Chapter 302 Telephone Solicitation Registration Statement. That registration position does not remove other federal or Texas duties, so document the consent and have counsel check the current exemptions and campaign details.
The risky shortcut
Do not rely on implied consent plus DNC suppression for promotional SMS. A person buying a product, giving an email address, or entering a phone number for shipping updates is not the same as agreeing to recurring marketing text messages.
The same principle applies to email consent, even though the laws and mechanics differ. If you manage both channels, keep separate consent fields and read the email consent rules before moving contacts between programs.

Where email reputation and Suped fit

SMS consent rules do not get solved by DMARC, SPF, DKIM, or email deliverability tools. The operational pattern is still similar: prove permission, authenticate the sender, monitor failures, and fix issues before they scale. Weak SMS consent records often point to the same gap in email acquisition and suppression.
For the email side of that work, Suped's product centralizes DMARC monitoring, hosted SPF, hosted MTA-STS, SPF flattening, real-time alerts, and blocklist monitoring. That workflow helps when email and SMS share customer data, campaign calendars, and compliance reviews, while keeping each channel's permission records separate.
Suped DMARC dashboard showing email volume, authentication health, and source breakdown
Blocklists (blacklists) are not the same as the Do Not Call Registry. A blacklist or blocklist is usually a reputation signal used by mail systems, network operators, or security systems. The DNC list is a legal preference registry. If your team is reviewing cross-channel health, use blocklists for reputation context and keep SMS consent evidence in your SMS compliance system.
A quick domain review also helps when the same campaign has email and SMS branches. The domain health checker can show whether DMARC, SPF, and DKIM are in good shape before email follow-ups go out.
?

What's your domain score?

Deep-scan SPF, DKIM & DMARC records for email deliverability and security issues.

Keep that email health check separate from SMS legal consent. It helps the same team manage sender reputation, but it does not approve a text message send or replace a DNC review.

Views from the trenches

Best practices
Capture SMS-specific consent with timestamp, source page, phone number, and disclosure text.
Treat phone validation as hygiene, not consent, because a valid number can still be off limits.
Use a company DNC list even when federal DNC screening is handled by your SMS platform.
Common pitfalls
Assuming email consent covers SMS creates a gap when the opt-in language named email only.
Sending triggered promos without current consent records leaves little defense after a complaint.
Relying on old exports misses DNC changes, local opt-outs, and reassigned phone numbers.
Expert tips
Keep signup screenshots or page versions so the exact consent language can be proven later.
Separate transactional texts from marketing texts so useful notices do not become promotions.
Review state SMS rules before national campaigns because stricter local rules change risk.
Expert from Email Geeks says explicit SMS marketing consent can override DNC status only when the sender can prove it.
2023-05-03 - Email Geeks
Marketer from Email Geeks says phone validation helps, but it should never be mistaken for marketing permission.
2023-05-04 - Email Geeks

Build the program around proof

The practical rule is simple: do not send SMS marketing unless you can show SMS-specific consent or another valid legal basis that counsel has approved. The Do Not Call list does not prevent someone from joining your SMS program, but it raises the cost of sloppy records. If the person later says they never opted in, your answer is the stored consent event, not a guess about how the list was built.
Build the workflow in this order: collect clear consent, store evidence, validate the number, screen required suppressions, send only within scope and permitted hours, and honor opt-outs promptly. That order keeps the program defensible and makes triggered SMS possible without treating automation as an exemption.
A clean send rule
If you cannot produce the required permission record, suppress the number. If the person opted out by any reasonable means, suppress the number. If the message contains a promotion, treat it as marketing even when user behavior triggered it.

Frequently asked questions

DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing