SMS Opt-In Consent Requirements: TCPA, TCR and Carrier Rules (2026)

"Get consent before you text" sounds simple until you ask whose definition. Three rulebooks apply simultaneously: the TCPA (federal law, enforced through lawsuits), TCR/DCA review (gatekeeping your registration), and CTIA carrier standards (governing ongoing delivery). A compliant program satisfies all three. Here is what each demands in 2026.

Layer 1. TCPA: the legal floor

The Telephone Consumer Protection Act sets consent tiers by message type:

  • Marketing/promotional messages require prior express written consent: a signed (including electronic) agreement that names the sender, discloses that automated marketing texts will be sent, and states that consent is not a condition of purchase.
  • Informational/transactional messages (reminders, alerts related to an existing relationship) require prior express consent, a lower bar; providing a number in a context where such messages are expected can suffice.
  • Statutory damages run $500–$1,500 per message, and class actions are routine; this is the layer with teeth. Full treatment in our TCPA guide.

Layer 2. TCR/DCA review: consent as registration evidence

Campaign reviewers verify your consent mechanism before approving traffic. Current review standards expect: consent obtained before any message is sent (including the opt-in confirmation), a disclosure at the point of collection (sender, message types, frequency, rates language, STOP, privacy link), an affirmative unchecked action, and optionality for marketing. Reviewers check your website for all of this (concrete patterns in our opt-in flow guide).

Layer 3. CTIA principles: the carrier bar

The CTIA Messaging Principles aren’t law, but carriers enforce them through filtering and campaign suspension. They add operational expectations: confirmation messages for recurring programs, periodic re-disclosure, immediate STOP handling, and consent that matches message content ("consent for one purpose is not consent for another"). Summary in our CTIA guide.

Will your website pass carrier review?

Paste your URL into our free AI scanner and get an instant PASS / WARN / FAIL compliance report. No signup needed.

Run a free compliance scan

The one-to-one consent question (2026 status)

The FCC’s "one-to-one consent" rule, which would have required consent to name each individual seller (killing shared lead-generation consent), was vacated by the Eleventh Circuit in January 2025 before taking effect. So there is currently no federal one-to-one requirement in force. Practically, though, the industry moved anyway:

  • Carriers and DCA reviewers increasingly expect consent language naming the specific brand that will text.
  • Lead-gen consent shared across "marketing partners" remains a red flag in campaign review and a filtering risk, vacated rule or not.
  • The safe architecture is unchanged: collect consent yourself, in your own name, for your own program.

What valid consent looks like, condensed

  1. The subscriber performed an affirmative act (checked an unchecked box, sent a keyword, signed a form).
  2. At that moment, they saw: your name, what you’ll send, how often, "msg & data rates may apply", how to stop, and a privacy policy link.
  3. For marketing: the consent is written/electronic and not a purchase condition.
  4. You stored the evidence: timestamp, source, disclosure version.
  5. The consent covers what you actually send; reminders-consent does not authorize promos.

Consent is also the foundation your privacy policy must document and your registration must describe. The three layers reward the same behavior: ask clearly, record everything, send only what was agreed.

Frequently asked questions

Can I text someone who called or texted my business first?

An inbound message establishes consent for the ensuing conversation (and TCR now expects consent before any outbound, which an inbound text satisfies for that thread). It is not standing consent for marketing; promotional texts still need express written opt-in.

Does consent expire?

The TCPA sets no fixed expiry, but carriers treat long-dormant consent as stale. Texting a list you haven’t messaged in 18+ months invites complaints and filtering. Re-permission old lists through another channel.

Is checkbox consent on my website enough for marketing texts?

Yes, if the checkbox is unchecked by default, the disclosure names you and the program with the required elements, and you keep the record. That combination satisfies TCPA written-consent and passes TCR review.

Check your compliance before you submit

Most 10DLC rejections trace back to the sender's website: a missing SMS clause in the privacy policy, no visible opt-in language, mismatched business details. Our free AI scanner reads your site the way a carrier reviewer does and tells you what to fix.

Scan my website free No signup required  ·  Results in ~30 seconds

Related to this topic: