
Are text messages covered under the TCPA?
Key Facts
- Text messages are legally treated as calls under the TCPA, requiring prior express written consent for marketing SMS per FCC consent rules.
- A single 10,000-person text blast without valid consent creates $5 million to $15 million in statutory exposure, compliance analysis shows.
- TCPA statutory damages run $500 to $1,500 per text, with a four-year statute of limitations and no need to prove actual injury, per TCPA research on SMS compliance.
- Since April 11, 2025, businesses must honor opt-outs made in any reasonable manner within 10 business days, per BCLP legal analysis.
- Uber paid $20 million and Wells Fargo $17.85 million to settle text-related TCPA claims, enforcement reporting confirms.
- Valid written consent requires all four elements of 47 C.F.R. § 64.1200(f)(9) — skip one and the consent is legally worthless, per compliance analysis.
- Virginia's amended mini-TCPA law effective January 1, 2026 requires honoring STOP text replies for 10 years, with damages starting at $500 per violation, per TCPA compliance research.
Yes, Texts Are Calls Under the TCPA — and the Stakes Just Went Up
Yes — text messages are covered under the TCPA, and the FCC has treated SMS as a "call" under the statute for years. That means marketing texts to cell phones require prior express written consent — the exact same standard that applies to marketing robocalls, according to compliance analysis of the FCC's consent rules.
The financial stakes are not theoretical. Statutory damages run $500 to $1,500 per violation — per text — with a four-year statute of limitations and an active class-action bar, as TCPA research on SMS compliance lays out. Do the math on a single campaign: one 10,000-person blast sent without valid consent creates $5 million to $15 million in exposure, and plaintiffs do not need to prove actual injury to collect.
This is active enforcement, not a hypothetical risk. Recent and notable actions include:
- DSW — $4.42 million lawsuit filed in March 2025 over unwanted marketing SMSs
- Uber — $20 million settlement (2017) for text-related TCPA claims
- Wells Fargo — $17.85 million settlement (2019)
- Credit One Bank — $9.25 million, and UnitedHealthcare — $2.5 million
These figures come from reporting on recent TCPA enforcement actions, and they share a pattern: large, sophisticated companies with legal teams still got it wrong on consent records.
Here is where multi-location businesses get burned. A clinic sending a "quick reminder," a franchise running a reactivation text to 12-month dormants, or a membership business texting lapsed members often assumes these are low-risk courtesy messages. The rules say otherwise. Informational texts need prior express consent; anything promotional needs written consent with all four elements of 47 C.F.R. § 64.1200(f)(9) — in writing, signed, naming the specific seller, and stating consent is not a condition of purchase. Skip one element and the consent is legally worthless.
And since April 11, 2025, the stakes went up again. New FCC revocation rules require businesses to honor opt-outs made "in any reasonable manner" within 10 business days, per analysis from international law firm BCLP. A "STOP" text reply now ends both texts and calls — revocation is medium-agnostic.
That is why list discipline matters more than message content. At My AI Call Center, every campaign begins with a review of list source and consent records before anything launches, and lists without clear permission records are flagged or declined. If the list will not support the campaign, we tell you plainly — before you spend anything.
The Two-Tier Consent Standard: Marketing Texts vs. Informational Texts
The FCC has treated a text message as a "call" under the TCPA for years, which means every SMS you send carries the same legal weight as a robocall. That classification creates a two-tier consent framework that determines whether your campaign is compliant or a liability waiting to happen.
Marketing texts demand prior express written consent — a standard with four non-negotiable elements under 47 C.F.R. § 64.1200(f)(9): it must be in writing, bear a signature (electronic is fine under E-SIGN), clearly authorize the specific seller, and state that consent is not a condition of purchase. Skip one and the consent is legally worthless. Informational texts such as appointment reminders, payment notices, and delivery updates need only prior express consent, a lower bar that fits notification campaigns but does not cover any promotional content.
- You cannot text someone to ask permission to text them — first contact must come through a channel the person already engaged with
- Simple text-to-join keyword campaigns are legally risky; a keyword response alone may not constitute full marketing consent
- Consent naming "our marketing partners" instead of a specific seller fails the standard
- The one-to-one consent rule was vacated by the 11th Circuit in January 2025, reverting to the pre-2023 multi-seller standard
A 10,000-person SMS blast without proper consent creates $5M–$15M in statutory exposure at $500–$1,500 per violation, and the four-year statute of limitations gives plaintiffs a long window to act. My AI Call Center reviews list source and consent records before any campaign launches — bought lists without clear permission records are flagged and in most cases declined. We tell you plainly if the list will not support the campaign before you spend anything. Recordkeeping is your strongest defense; retain consent documentation for at least four years to match the TCPA's statute of limitations.
ctaText: Plan my campaign — free review, full quote before launch socialProofText: Managed outbound calling for approved, permissioned lists — from 9¢ per connected minute
The April 2025 Opt-Out Rules: Revocation Now Works in Any Channel
Effective April 11, 2025, the FCC’s new opt-out rules fundamentally changed how businesses must handle consumer revocation of consent under the TCPA. Consumers can now revoke consent "in any reasonable manner" — whether by replying STOP, QUIT, or REVOKE to a text, saying "leave me alone" in a voicemail, sending an email, or even pressing a key during a call — and the burden of proving a method unreasonable falls squarely on the business. As Eric J. Troutman of Troutman Amin Firm puts it, "If the message is clear, it counts."
This shift means revocation is medium-agnostic: a single "STOP" text now terminates both future texts and calls, and businesses must honor opt-out requests within 10 business days — down from the previous 30-day window. Only one non-marketing clarification message is permitted within five minutes of an opt-out, and any delay requires documented proof of reasonable cause. These changes demand agile, centralized systems capable of tracking and acting on revocations across channels in real time.
While the universal "revoke-all" rule remains delayed — with sources citing either April 11, 2026 or January 31, 2027 as potential effective dates — state-level mini-TCPA laws are already fragmenting compliance requirements. Virginia’s amended Telephone Privacy Protection Act, effective January 1, 2026, requires honoring do-not-call requests — including "STOP" or "UNSUBSCRIBE" text replies — for 10 years, with escalating damages starting at $500 per violation. Meanwhile, Washington and California enforce technology-neutral bans on unsolicited marketing texts, regardless of the platform used.
For organizations like My AI Call Center, which runs managed outbound campaigns only on approved, permissioned, or reviewed lists, these rules reinforce the critical importance of list discipline and immediate opt-out logging. Campaigns must be built to capture and honor revocations instantly, whether they come via SMS, email, or voice, to avoid exposure to statutory damages of $500–$1,500 per violation. In an environment where a single unclear opt-out can trigger liability, precision in consent and revocation handling isn’t just compliant — it’s essential to sustainable outreach.
Beyond Consent: Quiet Hours, DNC Scrubbing, and the Records That Save You
Beyond consent, operational missteps can derail even the most carefully permissioned campaigns. Quiet hours remain a foundational rule: no texts before 8 a.m. or after 9 p.m. in the recipient’s local time, though many states enforce stricter windows — some banning messages entirely on Sundays or holidays. Federal and state Do Not Call (DNC) registry scrubbing is mandatory before any outreach, as is checking the FCC’s Reassigned Number Database to avoid contacting reassigned numbers that may still carry another party’s consent. These aren’t optional best practices; they’re enforceable requirements where ignorance offers no defense.
Recordkeeping transforms compliance from aspiration to audit readiness. As LeadCompliant emphasizes, “consent is only as good as the record you can hand a judge.” Every campaign must document how and when consent was obtained, the exact language used, and the specific seller named — because vague or borrowed consent fails TCPA scrutiny. Given the four-year statute of limitations for TCPA violations, retaining consent documentation for at least that long isn’t prudent; it’s necessary. This means preserving opt-in timestamps, disclosure copies, and revocation logs with the same rigor as financial records, especially since regulators now scrutinize AI-driven messaging systems for consent handling and disclosure adequacy.
Even without an autodialer, risk persists. Post-Facebook v. Duguid, the TCPA still covers prerecorded and AI-voice messages to cell phones regardless of dialing method — meaning an AI-powered reminder call or text isn’t exempt simply because it’s not using sequential number generation. Regulators are increasing scrutiny of AI systems used for personalized messaging, particularly around whether opt-out mechanisms function across channels and whether disclosures meet TCPA’s conspicuity standards. For businesses using managed calling services, this reinforces why list discipline and verified consent records aren’t just operational details — they’re the core of defensible outreach. Industry analyses confirm that detailed consent records remain the strongest defense in TCPA disputes, turning regulatory exposure into manageable risk when properly maintained.
How to Run Compliant Text and Calling Campaigns: A Practical Checklist
A single 10,000-person SMS blast sent without proper consent can create $5 million to $15 million in statutory exposure, at $500 to $1,500 per violation — which is why the checklist below matters more than any clever script. The good news: TCPA compliance is mostly operational discipline, not legal guesswork. Here is a practical pre-launch checklist for any text or calling campaign.
1. Verify list source and consent records first. Consent is only as good as the record you can hand a judge. Valid written consent requires all four elements of 47 C.F.R. § 64.1200(f)(9) — in writing, signed, naming the specific seller, and not conditioned on purchase — and consent naming "our marketing partners" instead of a specific seller fails. Bought lists without clear permission records get flagged, and in most cases declined, before anything launches.
2. Match consent tier to campaign type. Marketing texts need prior express written consent; informational texts need only prior express consent, a lower standard that still must be documented. A reminder campaign and a promotional blast are not the same legal animal — scope each campaign around one clear goal and confirm the consent on file supports it.
3. Build opt-out handling for any-reasonable-manner revocation. Since the FCC's April 11, 2025 rules took effect, consumers may revoke consent through any reasonable channel — keywords like STOP or REVOKE, key-press, email, even "leave me alone" — and businesses must honor it within 10 business days. Revocation is medium-agnostic: a STOP text ends calls too. Only one non-marketing clarification message is allowed, within five minutes.
4. Scrub, window, and retain. Complete the remaining operational checks before launch day:
- Scrub federal and state DNC registries and the Reassigned Number Database before dialing or texting.
- Text and call only inside approved windows — no contact before 8 am or after 9 pm recipient's local time, and many states are stricter.
- Retain consent records for at least four years, matching the TCPA statute of limitations; detailed records are your strongest defense in a dispute.
This is exactly how My AI Call Center structures its managed campaigns: list and consent review before launch, opt-outs logged and honored immediately, and calls run only against approved, permissioned, or reviewed lists. Structured campaigns with that discipline are the practical way to run outreach without TCPA exposure.
One final note: requirements vary by location, industry, contact type, and consent status — and state "mini-TCPA" laws keep fragmenting. Get legal guidance for your specific situation before launching any campaign.
Frequently Asked Questions
Are text messages considered calls under the TCPA, and what does that mean for my marketing campaigns?
What’s the difference between marketing texts and informational texts under TCPA rules?
How did the April 2025 FCC opt-out rule change how I handle consumer revocations?
Do I need to scrub the DNC list and Reassigned Number Database before sending texts?
How long should I keep consent records for text campaigns, and why does it matter?
Can I use a simple 'text-to-join' keyword to get valid consent for marketing texts?
The Bottom Line: Texts Are Calls, and Your Records Are Your Defense
Text messages are calls under the TCPA — full stop. Marketing texts need prior express written consent with all four elements of 47 C.F.R. § 64.1200(f)(9), informational texts need documented prior express consent, and since April 11, 2025, opt-outs made in any reasonable manner must be honored within 10 business days across every channel. With $500 to $1,500 in statutory damages per text and a four-year statute of limitations, a single unpermissioned campaign can turn into seven-figure exposure — just ask the companies behind the multi-million-dollar settlements named above. The good news is that compliance is mostly operational discipline: verify consent records before launch, scrub DNC and reassigned numbers, respect quiet hours, honor opt-outs instantly, and retain documentation for at least four years. That is exactly how My AI Call Center runs managed campaigns — lists reviewed before anything launches, and a plain answer if your list won't support the campaign. Ready to plan a compliant campaign? Start with a free campaign review and a full quote before anything goes live.