CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
TCPA And DNC Compliance

Does the TCPA apply to text messages?

Back to InsightsDoes the TCPA apply to text messages?

Does the TCPA apply to text messages?

Key Facts

  • The TCPA applies to robotexts just like robocalls, requiring prior express written consent for marketing texts to mobile numbers under FCC rules.
  • TCPA statutory damages run $500 per violation, or $1,500 for willful ones, with no need to prove actual harm per a compliance guide.
  • Businesses must honor opt-out requests within 10 business days under new FCC rules effective April 11, 2025 according to legal analysis.
  • Reply texts like STOP, REVOKE, or UNSUBSCRIBE are per se reasonable ways to revoke consent under the new opt-out rules.
  • The one-to-one consent rule would have cost industries over $4.2 million annually before being vacated per the Federal Register.
  • TSR civil penalties can exceed $53,000 per non-compliant contact according to compliance research.
  • A 2026 Seventh Circuit ruling held texts aren't 'telephone calls' under one TCPA provision, creating a circuit split per Kirkland & Ellis.

Why Text Messages Are Legally Treated Like Robocalls Under the TCPA

The Federal Communications Commission and federal courts have drawn a clear line: text messages are regulated under the Telephone Consumer Protection Act (TCPA) in the same way as robocalls. The FCC's final rule codified that National Do Not Call Registry protections extend to text messages, and the agency routinely refers to "robotexts" alongside robocalls as requiring prior express written consent under 47 CFR 64.1200(f)(9). This means any marketing text sent to a mobile number using an autodialer or artificial voice must be backed by documented, verifiable consent before the first message goes out.

The legal basis rests on the TCPA's prohibition against autodialed or prerecorded calls to wireless numbers without consent. Because modern texting platforms use automated systems to send messages at scale, the FCC treats those texts as "calls" under Section 227(b) of the statute. The burden of proof sits with the sender — businesses must be able to produce consent records if challenged. Statutory damages run $500 per violation, trebling to $1,500 for willful violations, with no requirement for consumers to prove actual harm. TSR civil penalties can exceed $53,000 per non-compliant contact.

  • Prior express written consent is required for marketing texts to mobile numbers
  • National Do Not Call Registry protections now cover text messages
  • The sender bears the burden of proving valid consent
  • Consent records must be retained for at least five years federally

This regulatory framework is why My AI Call Center builds consent review into every campaign before launch. Our process checks list source, permission records, and calling windows — flagging or declining bought lists without clear documentation. Keyword opt-outs (STOP, REVOKE) are logged and honored immediately, aligning with the FCC's per se reasonable revocation terms and the 10-business-day processing window that took effect April 11, 2025. Opt-out and DNC logs are delivered with every campaign, giving clients the documentation the TCPA demands.

The rules governing text message compliance have shifted significantly in recent years, creating both challenges and opportunities for businesses that rely on SMS for customer engagement. Understanding these changes is critical to avoiding costly violations and maintaining trust with your audience.

One of the most notable developments was the FCC’s one-to-one consent rule, which had a compliance date of January 27, 2025, but was effectively vacated before taking effect due to legal challenges from the Eleventh Circuit and subsequent FCC actions. This rule would have required businesses to obtain separate consent for each seller when sharing consumer data through lead generators, imposing an estimated annual burden of 48,000 hours and over $4.2 million in costs across affected industries. While no longer in force, its brief existence underscored the heightened scrutiny around consent practices in text-based marketing.

More immediately impactful are the new opt-out requirements that took effect on April 11, 2025. Under these rules, businesses must honor consumer revocation requests within 10 business days — a significant reduction from the previous 30-day window. Consumers can now withdraw consent “in any reasonable manner,” including through keyword replies like STOP, REVOKE, or UNSUBSCRIBE, which are considered per se valid methods of opting out. A one-time confirmation message may be sent within five minutes of a revocation request, but it must not contain any marketing content. These changes place greater responsibility on businesses to implement real-time suppression processes and maintain accurate opt-out logs for at least four years.

For companies using third-party messaging services, these rules heighten vendor liability risks. The TCPA places the burden of proof on the sender to demonstrate valid consent, meaning businesses can be held liable for texts sent by vendors on their behalf if proper consent and opt-out procedures are not followed. This makes pre-launch consent verification and ongoing list hygiene essential components of compliant texting programs.

addresses these requirements through its structured campaign process, which includes a mandatory list and consent review before any outreach begins. The service flags purchased lists lacking clear permission records and declines campaigns that cannot be supported by verifiable consent — aligning directly with the TCPA’s expectation that senders validate their right to contact recipients. Opt-out requests, whether received via keyword or free-form language, are logged immediately and honored in real time, with dispositioned contact lists and compliance reports delivered as part of every campaign’s completion package.

While legal interpretations continue to evolve — including a 2026 Seventh Circuit ruling that created a circuit split on whether texts qualify as “telephone calls” under certain TCPA provisions — the core obligation remains clear: businesses must obtain prior express written consent for marketing texts and provide simple, accessible ways for consumers to opt out. Staying compliant means building these principles into your messaging workflow from the start, not treating them as afterthoughts.

If a contact texts "STOP" mid-campaign, what happens in the next five minutes matters more than what your consent form said a year ago. Under the TCPA, the burden of proving valid consent sits with the caller or texter — not the consumer — so your records either hold up or they don't (Federal Register).

That reality shapes how My AI Call Center handles texting before a single message goes out. Every campaign starts with a list and consent review: we check where the list came from, what permission records exist, and whether those records actually support the campaign's goal. Bought lists without clear permission records get flagged and, in most cases, declined — before you spend anything.

This discipline matters because TCPA statutory damages run $500 to $1,500 per violation, with no requirement for consumers to prove actual harm (PossibleNOW's compliance guide). And businesses can be held liable for texts sent by third-party vendors on their behalf, which makes vendor-side consent discipline a client protection, not just an internal policy.

Opt-out handling follows the 2025 rules directly. The FCC's opt-out regulations, effective April 11, 2025, require businesses to honor revocation requests within 10 business days (BCLP's analysis). Our keyword opt-outs — STOP and REVOKE — match the FCC's list of per se reasonable revocation terms, and we honor them immediately, well inside that window. We also monitor free-form responses, since informal requests like "please take me off the list" must be honored too (Carlton Fields).

Every campaign delivers:

  • Opt-out and DNC logs as standard deliverables, so clients hold documentation in their own records
  • DNC requests carried across all campaigns and into client DNC records
  • Disposition codes that flag opted-out contacts in the outcome report

That documentation matters for retention rules: consent records should be kept at least five years federally — some states require ten — and opt-out documentation for at least four years (PossibleNOW; BCLP).

One honest caveat: the rules keep moving. The one-to-one consent rule was vacated before taking effect, and a 2026 circuit split on whether texts are "calls" may reach the Supreme Court (Kirkland & Ellis). None of that changes the baseline: prior express consent, honored opt-outs, and clean records. Campaign requirements vary by location, industry, and consent status, and clients are responsible for getting appropriate legal guidance before launch.

Frequently Asked Questions

Do text messages fall under the same TCPA rules as robocalls?
Yes, the FCC and federal courts treat text messages as 'calls' under the TCPA, requiring prior express written consent for marketing texts sent via autodialer to mobile numbers, just like robocalls. This means businesses must obtain documented consent before sending any automated marketing text.
What kind of consent is required to send marketing text messages?
Prior express written consent is required for any marketing text sent to a mobile number using an autodialer or artificial voice. This consent must be documented and verifiable, with the burden of proof on the sender if challenged.
How long must businesses keep consent records for text messaging under TCPA rules?
Consent records must be retained for at least five years under federal TCPA rules, though some states require retention for up to ten years. Opt-out documentation should be kept for at least four years.
What are the current opt-out requirements for text message campaigns after April 11, 2025?
Businesses must honor consumer revocation requests within 10 business days, down from the previous 30-day window. Consumers can opt out using any reasonable method, including keywords like STOP, REVOKE, or UNSUBSCRIBE, which are considered per se valid under FCC rules.
Can a business be held liable for texts sent by a third-party vendor on its behalf?
Yes, under the TCPA, the sender bears the burden of proving valid consent, meaning businesses can be held liable for texts sent by vendors if proper consent and opt-out procedures are not followed. This makes pre-launch consent verification and list hygiene essential.
What are the penalties for violating TCPA rules on text messaging?
TCPA violations carry statutory damages of $500 per violation, or $1,500 for willful violations, with no requirement for consumers to prove actual harm. TSR civil penalties can exceed $53,000 per non-compliant contact.

The Bottom Line on Texting Compliance

Yes — the TCPA applies to text messages, and the rules are only getting stricter. Marketing texts to mobile numbers require prior express written consent, Do Not Call protections now cover texts, and the sender bears the burden of proving that consent exists. With statutory damages of $500 to $1,500 per violation and no need for consumers to show actual harm, one sloppy list can turn into a serious liability. The April 2025 opt-out rules add another layer: revocation requests must be honored within 10 business days, and keyword replies like STOP and REVOKE are automatically valid. If your business texts customers, your next steps are practical ones: audit where your lists came from, verify you can produce consent records on demand, and confirm your opt-out process works in real time — not within a month. My AI Call Center builds these checks into every campaign, reviewing list source and consent records before launch and delivering opt-out and DNC logs with the completion package, so you hold the documentation the TCPA expects. Ready to run compliant outreach against lists that can stand up to scrutiny? Plan your campaign at myaicallcenter.app and get a clear quote before anything launches.

Get campaign planning tips