CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
TCPA And DNC Compliance

Are unsolicited marketing texts illegal?

Back to InsightsAre unsolicited marketing texts illegal?

Are unsolicited marketing texts illegal?

Key Facts

  • Unsolicited marketing texts are illegal under TCPA without prior express written consent (PEWC) to wireless numbers
  • TCPA violations carry statutory damages of $500–$1,500 per message, per class member with no proof of injury required per Infobip analysis
  • 100,000 non-compliant marketing texts could exceed $150 million in TCPA exposure per compliance estimates
  • TCPA class actions filed through mid-2025 surged nearly 95% year-over-year per enforcement data
  • FCC extended DNC Registry protections to texts with penalties up to $43,792 per call or text per Infobip
  • Steve Madden paid $10 million for 200,000+ unsolicited promotional texts per settlement records
  • Pizza Hut franchisees paid $6 million for roughly 13,000 unsolicited texts per legal settlements

Yes — if you send a marketing text to someone's cell phone without their permission, you have broken federal law. That is not an opinion or a gray area; it is the plain requirement of the Telephone Consumer Protection Act, and the penalties are calculated per message.

Under the TCPA, businesses must obtain prior express written consent (PEWC) before sending marketing texts to wireless numbers. The FCC treats texts as "calls" under the statute, and virtually all business texting platforms qualify as autodialers, which brings them squarely within the rule.

That consent is not a vague "they gave us their number somewhere." According to regulatory guidance, valid PEWC must be:

  • In writing (electronic signatures count) and clearly authorized by the recipient
  • Specific to one identified seller — blanket consent covering multiple businesses does not qualify
  • Logically and topically associated with the interaction that prompted it
  • Documented, identifying the number that will receive the messages

Crucially, the burden of proof sits with the sender, not the lead generator. If you bought a list and cannot produce consent records naming your business, you have no defense.

The math is unforgiving. TCPA violations carry statutory damages of $500 to $1,500 per message, per class member, with no cap on aggregate liability and no requirement that anyone prove actual injury. A compliance analysis estimates that 100,000 non-compliant messages could exceed $150 million in exposure.

Two additional numbers should get every marketer's attention:

  • TCPA class actions filed through mid-2025 surged nearly 95% year-over-year, meaning plaintiffs' lawyers are actively hunting these cases.
  • The FCC has explicitly extended Do-Not-Call Registry protections to texts, with DNC violations carrying penalties of up to $43,792 per call or text.

Real settlements confirm the stakes: Steve Madden paid $10 million over 200,000+ unsolicited promotional texts, and Pizza Hut franchisees paid $6 million for roughly 13,000 texts — a reminder that even modest list sizes can produce seven-figure outcomes.

This is not just a cold-texting problem. Lead follow-up, appointment reminders with upsell language, and win-back campaigns to old contacts all trigger the same consent requirements — and adding a discount to a transactional message can reclassify it as marketing entirely. That is why list discipline matters more than message craft. At My AI Call Center, every campaign begins with a list and consent review before anything launches, because a campaign built on contacts without documented permission is a liability, not an asset.

The short version: no documented, seller-specific, topically linked written consent means no marketing text. Full stop.

Consent is not a checkbox you can bury in fine print — under the TCPA, it's the entire legal foundation for sending marketing texts. Get it wrong, and statutory damages run $500 to $1,500 per message, per class member, with no proof of actual injury required, according to legal analysis from BCLP.

For marketing texts to wireless numbers, the standard is prior express written consent (PEWC). That means consent must meet all of the following, per guidance from America's Credit Unions:

  • Be in writing, with the recipient's signature — electronic signatures count
  • Be clear and conspicuous, authorizing no more than one identified seller
  • Be logically and topically tied to the interaction that prompted the consent
  • Identify the specific telephone number that will receive messages

Not every text requires this level of consent. Informational messages — appointment reminders, fraud alerts, payment notifications — need only prior express consent, which can be verbal or written. The distinction matters because an opt-out from an informational message halts all future non-emergency communications, including marketing, while an opt-out from marketing stops only the marketing messages.

Here's the trap that catches many businesses: the moment you add an upsell, discount, or promotional offer to a transactional message, you reclassify it as marketing. That appointment reminder with a "20% off your next visit" line suddenly triggers the full PEWC requirement, as compliance researchers at Infobip explain. Keeping informational and marketing content in separate messages, with separate consent tracking, is the safest structure.

One recent wrinkle worth knowing: the FCC's One-to-One Consent Rule, which would have required consent naming each individual seller, was vacated by the 11th Circuit in January 2025 and is not currently in effect. Even so, industry guidance recommends following its principles as best practice — one seller per consent, clearly disclosed — both to reduce legal risk and to build trust with recipients.

This is why consent review happens before anything else in a structured campaign. At My AI Call Center, every campaign launches only against approved, permissioned, or reviewed lists, with consent records checked first — and bought lists without clear permission records are flagged and, in most cases, declined. It's a plain standard: if the consent doesn't clearly name the seller and match the message type, the text doesn't go out.

The New Opt-Out Rules You Must Follow

Getting consent right is only half the battle. Since April 11, 2025, the FCC's new Opt-Out Rule has changed how businesses must handle it when a customer changes their mind — and the penalties for getting this wrong are the same as for texting without consent in the first place.

Under the new rule, consumers may revoke consent "in any reasonable manner" — not just by texting STOP. According to analysis from BCLP, the FCC has endorsed a specific set of keywords businesses must recognize, but the rule goes much further than keywords.

The FCC-endorsed keywords include:

  • STOP, QUIT, END, CANCEL, UNSUBSCRIBE, OPT-OUT, and REVOKE
  • Plain-language requests without exact keywords, such as "please stop messaging me" — platform guidance from Omnisend recommends AI-powered intent detection to catch these
  • Non-traditional channels: voicemail, email, or even telling a cashier or staff member directly

Here is where businesses get into trouble. Non-traditional revocation methods carry a rebuttable presumption of reasonableness — meaning if a customer leaves a voicemail asking you to stop, the law assumes that counts. The burden falls on the business to prove otherwise. You cannot mandate a single exclusive opt-out method, and you cannot ignore a request just because it arrived through the "wrong" channel.

The processing deadline is also tighter. Per Nixon Peabody's analysis of the FCC Consent Order, revocation must now be honored within 10 business days, down from the previous 30-day window. Businesses are allowed one clarification message, but only within 5 minutes of the revocation request — and it cannot contain any marketing content. Because TCPA statutory damages run $500 to $1,500 per message, per class member, with no proof of actual injury required, a slow or sloppy opt-out process can compound into serious class action exposure. Recent enforcement data shows TCPA class actions filed through mid-2025 increased nearly 95% year-over-year.

One provision got a reprieve. On April 7, 2025, the FCC issued a Limited Waiver delaying the "universal revocation" requirement — where revoking consent for one message type halts all non-emergency communications — until April 11, 2026. During the delay, revoking consent for an exempt informational message (like an appointment reminder) stops only that message type, not everything.

For organizations running outbound campaigns, opt-out handling has to be built into the process, not bolted on. My AI Call Center, for example, logs and honors opt-outs immediately across campaigns and carries them into client DNC records, treating revocation as a workflow step rather than an afterthought. Legal experts also recommend documenting opt-out requests for at least four years to match the TCPA statute of limitations — and longer still, since Virginia will require 10-year retention starting January 2026.

State Laws Create a Stricter Patchwork

Federal compliance alone doesn’t guarantee legality when sending marketing texts, as more than a dozen states enforce stricter "mini-TCPA" standards that can override federal rules. The strictest applicable standard based on the recipient’s state of residence must be followed, creating a complex patchwork for businesses operating across state lines. For example, Florida limits marketing texts to no more than three messages per 24 hours per recipient and provides a 15-day safe harbor after an opt-out request, during which no further messages may be sent. Virginia requires businesses to retain opt-out records for 10 years, a rule effective January 2026 that far exceeds the federal recommendation of four years. Connecticut imposes penalties of up to $20,000 per violation, while Arizona fines senders $1,000 per text sent to numbers on the state’s Do-Not-Call list. Additionally, Florida and Washington enforce stricter calling hours of 9 AM to 8 PM local time, compared to the federal window of 8 AM to 9 PM. These variations mean that a single text message compliant in one state could trigger liability in another, making state-law awareness essential for multi-location clients. My AI Call Center integrates these location-based rules into its campaign setup process, ensuring that messaging frequency, timing, and opt-out handling align with the most restrictive applicable standard before any campaign launches. This proactive approach helps clients avoid costly missteps when scaling outreach across diverse jurisdictions.

How to Run Compliant Campaigns at Scale

Running compliant campaigns at scale means turning regulatory requirements into operational guardrails that fire before a single message sends. The FCC's Opt-Out Rule, effective April 11, 2025, requires businesses to honor revocation "in any reasonable manner" within 10 business days — shortened from 30 days — and consumers may now opt out through voicemail, email, or even telling a cashier, with a rebuttable presumption of reasonableness that puts the burden on the sender. Legal analysis confirms that non-traditional opt-out methods carry the same weight as STOP keywords, and the FCC's Limited Waiver delayed only the "universal revocation" requirement until April 11, 2026, leaving the 10-day processing window and reasonable-manner standard fully in effect. The waiver means informational-message opt-outs still halt only that message type during the delay, but marketing opt-outs stop all marketing immediately.

  • Consent verification gate before launch — written consent exists, names the client as seller, topically aligned, timestamps logged
  • Multi-channel opt-out processing with AI intent detection beyond keywords, CRM propagation within 10 business days
  • Campaign classification by message type (marketing vs. informational) with separate consent and opt-out tracking
  • State-rule engine applying the strictest limits by recipient location
  • 10-year immutable audit logs exceeding the 4-year federal statute and satisfying Virginia

Over a dozen states enforce "mini-TCPA" laws stricter than federal baseline — Florida caps messages at three per 24 hours, Connecticut imposes penalties up to $20,000 per violation, and Virginia requires opt-out records retained for 10 years. State-by-state analysis shows the strictest applicable standard based on the recipient's state of residence must govern every campaign. My AI Call Center builds these guardrails into the managed service model: list and consent review happens before any campaign launches, bought lists without clear permission records are flagged and typically declined, and every disposition report includes opt-out and DNC logs routed back to the client's CRM. With TCPA class actions up nearly 95% year-over-year through mid-2025 and statutory damages of $500–$1,500 per message per class member, compliance isn't a constraint — it's the selling point that protects both the sender and the audience.

Frequently Asked Questions

Is it really illegal to send marketing texts to people who didn't opt in?
Yes. Under the TCPA, businesses must have prior express written consent before sending marketing texts to wireless numbers, and the FCC treats texts as "calls" under the statute. Violations carry statutory damages of $500 to $1,500 per message, per class member, with no requirement to prove actual injury.
What if someone just gave me their phone number — doesn't that count as consent?
No. Valid consent must be in writing (electronic signatures count), name one identified seller, be logically tied to the interaction that prompted it, and identify the number receiving messages. The burden of proof sits with the sender, not the lead generator — if you bought a list and can't produce consent records naming your business, you have no defense, per regulatory guidance.
How much trouble can I actually get into for a few unsolicited texts?
More than most businesses expect. Steve Madden paid $10 million over 200,000+ unsolicited promotional texts, and Pizza Hut franchisees paid $6 million for roughly 13,000 texts — modest list sizes can produce seven-figure outcomes. One compliance analysis estimates 100,000 non-compliant messages could exceed $150 million in exposure.
Can I add a discount or upsell to my appointment reminder texts?
That's a trap. Informational messages like appointment reminders only require prior express consent, but the moment you add an upsell, discount, or promotional offer, the message is reclassified as marketing and requires full prior express written consent. Compliance researchers recommend keeping informational and marketing content in separate messages with separate consent tracking.
Do people have to text STOP to opt out, or can they opt out other ways?
Since April 11, 2025, consumers may revoke consent "in any reasonable manner" — including voicemail, email, or even telling a cashier, and non-traditional methods carry a rebuttable presumption of reasonableness. Businesses must honor revocation within 10 business days, down from the previous 30-day window, per Nixon Peabody's analysis.
Do state laws matter, or is federal TCPA compliance enough?
Federal compliance alone doesn't guarantee legality — more than a dozen states enforce stricter "mini-TCPA" laws, and the strictest standard based on the recipient's state of residence must be followed. For example, Florida caps marketing texts at three per 24 hours per recipient, Connecticut imposes penalties up to $20,000 per violation, and Virginia will require opt-out records retained for 10 years starting January 2026.

Turn Compliance Into Your Campaign’s Strongest Asset

Unsolicited marketing texts aren’t just risky — they’re illegal without prior express written consent, and the penalties add up fast: $500 to $1,500 per message, per class member, with no cap on liability. From the FCC’s expanded opt-out rules requiring action within 10 business days to state-level mini-TCPA laws that impose stricter limits, the regulatory landscape leaves no room for guesswork. But here’s the opportunity: businesses that treat consent and opt-out management as core operational steps — not afterthoughts — build campaigns that are not only compliant but more effective. At My AI Call Center, every campaign starts with a rigorous list and consent review, ensuring outreach only goes to permissioned contacts, turning regulatory discipline into a competitive advantage. If you’re ready to run outbound campaigns that protect your brand and respect your audience, explore our managed calling campaigns built on approved, permissioned, or reviewed lists from the first dial.

Get campaign planning tips