
How to scrub a DNC list?
Key Facts
- A scrub older than 31 days voids your FTC safe harbor defense entirely, per compliance research.
- TCPA statutory damages run $500 to $1,500 per call with no proof of monetary loss required, according to compliance guidance.
- FTC civil penalties reach $53,088 per violation, while Florida can impose up to $30,000 per willful call, state penalty data shows.
- Over 258 million active phone numbers sit on the National Do Not Call Registry, according to PossibleNOW.
- Internal DNC lists must be retained at least five years — up to ten in some states, federal rules require.
- Real-time DNC lookups cost just $0.01–$0.05 each, the gold standard for operations making 10,000+ daily calls, per ClickPoint Software.
- Class action settlements averaged $6.6 million in 2024–2025, according to ActiveProspect.
Why Most DNC Scrubbing Fails Compliance Tests
Most teams think a quick federal registry check covers their compliance exposure. It doesn't. The gap between a basic lookup and true compliance is where enforcement actions and class actions live — and where businesses discover that "we checked the list" is not a defense.
Regulatory guidance identifies five distinct scrub layers: the National Do Not Call Registry, state DNC lists, wireless identification, litigator files, and reassigned-number databases. Each carries its own data source, legal weight, and update cadence. Over 30 states maintain telemarketing statutes that frequently exceed federal requirements, with separate fees, quarterly update schedules, and penalty structures. Florida, for example, can impose up to $30,000 per call for willful violations, while the FTC's civil penalty reaches $53,088 per violation and TCPA statutory damages run $500–$1,500 per call without any proof of actual harm.
- Federal safe harbor requires registry synchronization at least every 31 days — older scrubs void the defense
- Internal opt-out requests must propagate across every system (dialer, CRM, affiliated operations) immediately
- Internal DNC lists must be retained for a minimum of five years, up to ten in some states
- Every seller needs its own Subscription Account Number; sharing a vendor's SAN is expressly prohibited
Dialer-built-in suppression tools maintain list hygiene after a proper scrub — they do not replace third-party verification against current registry data. The compliant workflow is explicit: scrub with a third-party service against live data, import the clean file, then use the dialer's native features only for post-scrub maintenance. My AI Call Center builds this discipline into every campaign launch, treating list source, consent records, and scrub timestamps as gating criteria before a single call is placed. Documentation — scrub logs, consent receipts, staff training records, system architecture — must be preserved for five years to support any safe-harbor claim.
The Compliant Scrubbing Workflow: SAN, Third-Party, Import
Scrubbing a DNC list is where compliance stops being theory and becomes a documented, repeatable process. The workflow that survives an audit has four steps: your own Subscription Account Number, third-party scrubbing, a clean import, and five years of internal logs.
Step one: obtain your own SAN. Every seller needs its own subscription and Subscription Account Number for the National Do Not Call Registry. As compliance guidance makes clear, dividing registry access costs among a vendor's clients is expressly prohibited — no scrubbing vendor can legally share one account across its customers. Access is affordable: your first five area codes are free, with each additional area code costing $82 per year.
Step two: scrub through a third-party service. Run your list against current federal and state registry data before anything touches your dialer. A proper scrub actually involves five distinct checks — the federal registry, state lists, wireless identification, litigator files, and reassigned-number databases. The FTC requires that you access registry data no more than 31 days before making a call; an older scrub means you lose the safe harbor defense entirely.
Step three: import the clean file. Only after scrubbing does the list enter your dialing system. This ordering matters because built-in dialer DNC features are maintenance tools, not scrubbers — no dialer's internal features replace third-party scrubbing against the national and state registries. They keep a list clean after import; they cannot verify it in the first place.
Step four: maintain internal DNC logs. Federal rules require internal DNC lists to be kept for at least five years, with some states extending that to ten. Your documentation should cover:
- Scrub logs proving when each check ran and against which data
- Opt-out records, processed across dialer, CRM, and internal lists immediately upon request
- Consent receipts and staff training records supporting safe-harbor eligibility
The stakes justify the discipline. TCPA statutory damages run $500 to $1,500 per call with no proof of monetary loss required, and FTC civil penalties reach $53,088 per violation. A compliance analysis frames it well: DNC compliance is not a dialing tactic — it is a system design decision.
This is why My AI Call Center reviews list source and consent records before any campaign launches, and delivers opt-out and DNC logs as standard campaign outputs. The scrubbing workflow only protects you if it runs on every list, every cycle, with proof.
State-by-State Complexity and Frequency Decisions
Scrubbing against the federal registry is only half the job. More than 30 states maintain their own telemarketing statutes that often exceed federal requirements, and several operate separate DNC lists with their own fees, update schedules, and penalties, according to compliance research.
The major state lists vary widely in cost and cadence. State fee schedules show Texas charges $200 per quarter per list (statewide DNCL and Electric No Call are separate), with updates every quarter on January 1, April 1, July 1, and October 1 — and numbers go stale after 60 days. Florida runs $30 per area code per quarter or $100 quarterly statewide, while Missouri charges $50 per area code per quarter. Colorado refreshes its list four times yearly on the 10th of January, April, July, and October, plus an annual telemarketer registration ranging from $0 to $500 based on headcount.
Penalties escalate just as unevenly. Florida imposes up to $10,000 per call — tripled to $30,000 for willful violations — while Pennsylvania levies $1,000 per illegal call ($3,000 if the recipient is 60 or older), and Texas ranges from $1,000 to $3,000 civil with criminal penalties reaching $5,000, per state penalty data. State fine ranges run from $500 to $25,000+ per violation depending on jurisdiction, legal analyses show. Federal exposure stacks on top: TCPA statutory damages of $500–$1,500 per call and FTC civil penalties of $53,088 per violation.
How often should you scrub? Match frequency to call volume and risk:
- 31-day minimum — the FTC floor for low-volume, lower-risk B2B calling; anything older loses safe harbor protection.
- Weekly scrubs for mid-volume programs, the cadence many enterprise compliance teams adopt.
- Real-time API lookups (under 100ms) for 10k+ calls per day, checking numbers at the point of contact before dialing.
Cost scales accordingly. Federal registry access is free for your first five area codes, then $82 per additional area code, with nationwide coverage capped at $22,626 per year. Real-time DNC lookups typically run $0.01–$0.05 per lookup, which is why high-volume operations treat real-time checking as the gold standard rather than an expense.
This layered, risk-based approach is how My AI Call Center structures every outbound campaign — state quiet hours, registration rules, and DNC suppression are built into campaign setup before any list is dialed. For multi-state calling, budget for state list fees the same way you budget for the federal SAN, and let volume dictate your scrub cadence.
Internal DNC Lists, Opt-Out Propagation, and Documentation
Federal DNC compliance doesn't end when you scrub your calling list — it ends when your internal records can prove you did it right. The internal Do Not Call list is where most operations quietly fail, because an opt-out that lives in one system but not another is still a violation waiting to happen.
Under the Telemarketing Sales Rule, when someone asks not to be called again, you must add their number to your internal DNC list within 10 business days of the request. That number then stays suppressed for at least five years, and some states push that requirement to ten. Ignoring an internal opt-out triggers TCPA statutory damages of $500 to $1,500 per call — with no proof of monetary loss required, according to ActiveProspect's compliance guidance.
The harder part is propagation. An opt-out request must be processed across every system immediately upon receipt — the dialer, the CRM, the internal DNC list, and any affiliated operations sharing the same contacts. If a number is suppressed in your dialer but still sits in a CRM-driven follow-up queue, the next call is a separate violation. As ClickPoint Software's CMO Anders Uhl puts it, "National, state, and internal opt-out lists must be unified, checked in real-time or near real-time, and logged automatically with proof of execution."
Documentation is what turns all of this into a defensible safe harbor. To qualify for FTC safe-harbor protection, you need a complete paper trail, retained for five years:
- Scrub logs showing when each list was checked against registry data
- Consent receipts proving prior express consent for every contact
- Staff training records covering opt-out handling and calling windows
- System architecture documentation showing where suppression is enforced
The cycle matters as much as the records. The honest compliance workflow — hold your own SAN, scrub via a third-party service, import clean files, maintain internal DNC logs — must repeat on a 31-day-or-better cycle with documented proof of execution, as Enzo Dialer explains. If your scrub is older than 31 days when a call goes out, you lose the safe harbor defense entirely.
This is why opt-out discipline is built into how we run campaigns at My AI Call Center. Opt-out requests are logged and honored immediately, carried across all campaigns, and delivered back to clients as part of the DNC logs in every outcome report — so the suppression record travels with the number, not just the campaign. As PossibleNOW notes, automated scrubbing works when it is consistent and timely, with suppression applied as close to the point of dial as possible.
Treat suppression as infrastructure, not an afterthought. The operations that survive TCPA scrutiny are the ones where every opt-out, every scrub, and every training record exists on paper before anyone asks for it.
How My AI Call Center Builds This Into Every Campaign
Scrubbing a DNC list once is not the hard part — the hard part is doing it before every campaign, in every state, without anything slipping through. That is why My AI Call Center builds list review and opt-out handling directly into how campaigns run, rather than treating compliance as a checkbox at the end.
Before any campaign launches, every contact list goes through a review of its source, permission records, and calling windows. Lists without clear consent records are flagged, and in most cases declined. This mirrors what compliance experts identify as the most common failure: assuming consent from a lead supplier is automatically valid, when many buyers never actually verify the consent records attached to the leads they purchase. Bought lists without documentation simply do not support a compliant campaign — and clients are told that plainly, before spending anything.
Once calls are live, opt-out handling is automated rather than manual. Keyword triggers like STOP and REVOKE are honored immediately, and every DNC request is respected across all campaigns and carried into the client's DNC records. This matters because failure to propagate opt-outs across all systems results in separate TCPA violations for each subsequent call. With statutory damages of $500 to $1,500 per call and no proof of monetary loss required, a single unprocessed opt-out is expensive.
The campaign workflow follows a consistent discipline:
- List and consent review — source, permission records, and calling windows checked before launch; only approved, permissioned, or reviewed lists are used.
- Script, disclosure, opt-out handling, and escalation path approved by the client — nothing launches until sign-off.
- AI disclosure on every call, with recipients able to ask if the call is AI-assisted, request a human, or opt out.
- Outcome reporting with dispositioned contact lists, per-call notes, and complete opt-out and DNC logs delivered at campaign end.
Calling runs only in approved windows, consistent with the federal standard of 8 a.m. to 9 p.m. local time, and state-specific quiet hours and registration rules are honored. Internal DNC records are maintained for the federally required five years, since some states extend that to ten.
The reporting piece is where the discipline becomes visible. Every campaign closes with disposition codes — confirmed, qualified, renewed, opted out, no answer — plus opt-out and DNC logs. No invented numbers, no inflated metrics. What the report says happened is what happened, and the DNC log proves that every suppression request was captured and honored.
Frequently Asked Questions
How often do I legally need to scrub my calling list against the DNC registry?
Can I just rely on my dialer's built-in DNC features instead of a scrubbing service?
Do I need to check state DNC lists, or is the federal registry enough?
Can I share my scrubbing vendor's Subscription Account Number (SAN) to save money?
What happens if someone asks to be removed from my call list?
How much does a non-compliant call actually cost?
Scrub Once, Scrub Right, Then Make It a System
Scrubbing a DNC list properly comes down to a repeatable workflow, not a one-time checkbox: hold your own SAN, run every list through a third-party service against all five layers (federal, state, wireless, litigator, and reassigned-number data), import only the clean file, and keep scrub logs, consent receipts, and opt-out records for at least five years. Scrub on a 31-day-or-better cycle matched to your call volume, and remember that dialer suppression features maintain a clean list — they never create one. The stakes are real: with TCPA statutory damages of $500 to $1,500 per call and FTC penalties reaching $53,088 per violation, a stale scrub or a missed opt-out is expensive. Start by auditing your current process against the four-step workflow above, then set a scrub cadence your volume justifies. If you'd rather have list review, opt-out handling, and DNC logging built into every campaign from day one, My AI Call Center runs managed outbound campaigns against approved, permissioned lists — from 9¢ per connected minute. Book a free campaign review and we'll tell you plainly whether your list will support the campaign before you spend anything.