CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
TCPA And DNC Compliance

Is it legal to text a sales message that is unsolicited?

Back to InsightsIs it legal to text a sales message that is unsolicited?

Is it legal to text a sales message that is unsolicited?

Key Facts

  • Unsolicited marketing texts require prior express written consent under TCPA and CASL regulations
  • TCPA statutory damages range from $500 to $1,500 per violation with no requirement to prove actual damages
  • Federal civil penalties for willful TCPA violations can reach up to $53,088 per violation
  • DSW Shoe Warehouse settled a TCPA class action for over $4.4 million after sending unsolicited marketing texts
  • Uber faced a $20 million settlement in 2017 for promotional texts sent without proper consent
  • Federal TCPA requires honoring opt-out requests within 10 business days, with Florida mandating compliance within 15 days
  • Messaging is restricted to 8 a.m.–9 p.m. recipient local time federally, with states like Texas enforcing quiet hours from 9 p.m.–9 a.m.

The Short Answer: No — and the Penalties Are Steeper Than You Think

Unsolicited sales texts are illegal under U.S. and Canadian telecommunications law without proper consent. In the United States, the Telephone Consumer Protection Act (TCPA) requires prior express written consent for marketing text messages, treating them similarly to robocalls under federal regulation according to industry guidance. In Canada, the Canadian Anti-Spam Legislation (CASL) governs commercial electronic messages including SMS, requiring express or implied consent with clear identification and unsubscribe mechanisms as outlined in regulatory summaries. This legal reality means that sending promotional texts without verified consent exposes businesses to immediate liability, regardless of intent or perceived harm.

The financial penalties for TCPA violations are structured to create significant risk even for small-scale noncompliance. Statutory damages range from $500 to $1,500 per violation, with no requirement to prove actual damages — simply receiving an unsolicited marketing text establishes standing for a claim as noted by legal educators. For willful violations, federal civil penalties can reach up to $53,088 per violation, and there is no aggregate cap on regulatory fines, meaning a single campaign could generate millions in liability according to recent legal analyses. These penalties apply per message, so a blast to 10,000 recipients could theoretically exceed $500 million in exposure.

Real-world settlements demonstrate that these risks are not theoretical. DSW Shoe Warehouse settled a TCPA class action for over $4.4 million after sending unsolicited marketing texts, with final approval granted in July 2025 per legal compliance tracking. Uber faced a $20 million settlement in 2017 for similar allegations involving promotional texts sent without proper consent as documented in enforcement records. These cases reflect how quickly costs accumulate when consent verification is overlooked, particularly given that continued texting after a STOP request is treated as a willful violation per academic legal analysis.

  • Federal TCPA requires honoring opt-out requests within 10 business days, with Florida mandating compliance within 15 days per compliance timelines
  • Messaging is restricted to 8 a.m.–9 p.m. recipient local time federally, with states like Texas enforcing quiet hours from 9 p.m.–9 a.m. and banning promotional texts after noon Sunday per state-specific rules
  • Consent records should be retained for at least 5 years, and opt-out documentation for 4 years under the FCC’s Opt-Out Rule effective April 2025 per regulatory updates

For organizations using managed outbound services like My AI Call Center, this underscores the necessity of list discipline — only contacting individuals with verified, documented consent for the specific communication type being sent. The absence of a damages cap and the ease of establishing standing make TCPA compliance not just a legal obligation, but a critical financial safeguard. Businesses that treat SMS marketing as subject to TCPA requirements — the safest approach given ongoing legal interpretations — position themselves to avoid the steep costs associated with noncompliance per expert consensus. The message is clear: when it comes to unsolicited sales texts, the cost of guessing wrong far exceeds the effort of getting consent right.

Having a customer's phone number in your database feels like permission. Legally, it isn't. The gap between "we have their number" and "we have their consent" is where multimillion-dollar TCPA lawsuits begin.

The law draws a hard line between two types of texts. Marketing texts require prior express written consent — the strictest standard — while informational and transactional texts need only prior express consent, according to ActiveProspect's compliance analysis. The FCC has stated explicitly that unsolicited marketing texts violate the TCPA, and Purdue Global Law School notes the statute "strictly prohibits businesses from sending promotional texts without prior express written consent."

Many businesses assume shortcuts count. They don't. Consent must be separate from purchase history, prior business relationships, and verbal conversations — meaning that customer who gave their number at checkout, that lead list you purchased, or that promising phone call still don't authorize a sales text. When a recipient doesn't have to prove damages — simply receiving one noncompliant text is enough to win a judgment — those shortcuts get expensive fast, at $500 to $1,500 per violation with no damages cap.

Then the state laws stack on top. Because the TCPA doesn't supersede state law, plaintiffs can sue under federal and state mini-TCPA laws simultaneously:

  • Texas SB 140 — effective September 1, 2025, requires registration with the Secretary of State, a $10,000 bond, and a $200 annual renewal fee, with quiet hours from 9 p.m. to 9 a.m. and no promotional texts after noon Sunday.
  • Connecticut — allows fines up to $20,000 per infraction.
  • Florida — requires opt-outs processed within 15 days, limits senders to three texts on the same topic per 24 hours, and enforces an 8 a.m.–8 p.m. window.
  • Virginia — requires opted-out numbers to stay on do-not-text lists for 10 years.

Layered liability means one noncompliant blast can trigger claims under multiple statutes at once. That's why list discipline matters more than list size — a practice My AI Call Center applies by reviewing list source and consent records before any campaign launches, and declining bought lists without clear permission documentation. If you can't show who opted in, when, and to what, the number in your database is a liability, not an asset.

The April 2025 Opt-Out Rule Changed the Game for Texting Programs

For years, businesses treated opt-out handling as a back-office detail. On April 11, 2025, the FCC's new Opt-Out Rule turned it into a front-and-center legal obligation — and texting programs that weren't built for it are now exposed.

The rule's biggest shift is simple but sweeping: consumers may revoke consent "in any reasonable manner" — and the law presumes their method was reasonable. As BCLP's legal analysis explains, businesses carry a rebuttable presumption that any opt-out request is valid, meaning the burden falls on you to prove why a request shouldn't count. A customer replying "stop texting me," mentioning it on a call, or emailing support can all qualify.

Once a request lands, the clock starts. Revocations must be honored within ten business days, per the FCC's requirements — and compliance experts note that window is too demanding to handle manually for most organizations.

The rule also draws a critical distinction between message types:

  • Revocation in response to a marketing message stops marketing texts only.
  • Revocation in response to an informational message — like an appointment reminder — requires discontinuing all future non-emergency communications.
  • Businesses may send exactly one clarification message, within five minutes of the request, containing no marketing content — and only if the consumer affirmatively responds can contact continue.

Two operational realities make this harder than it sounds. First, the reassigned number database has become a critical tool for avoiding texts to numbers that have changed hands, since a new owner never consented to anything. Second, many commercial liability policies don't cover TCPA claims at all — companies absorb the full financial hit themselves, which is why multiple sources recommend retaining timestamped, unalterable consent records for at least five years.

This is why list discipline matters more than volume. My AI Call Center checks list source and consent records before any campaign launches, and declines bought lists without clear permission records — because under this rule, an undocumented list isn't a shortcut, it's an unpriced liability.

How to Run Text and Call Campaigns That Stay on the Right Side of the Law

Running text and call campaigns that stay on the right side of the law starts with list discipline. Verified consent records are not optional — they are the foundation of compliance, and bought lists without clear permission documentation represent a liability, not an asset. My AI Call Center reviews list source, consent records, and calling windows before any campaign launches, ensuring only approved, permissioned, or reviewed lists are used.

Before launch, verify that prior express written consent exists for each recipient, specifically authorizing automated marketing messages from your brand, with clear disclosures that consent is not a condition of purchase. Retain timestamped, unalterable digital consent certificates that capture who opted in, which brand is authorized, which message type was approved, and the exact timestamp — records should be kept for at least five years as recommended by multiple compliance sources. Honor state-specific quiet hours: while federal TCPA rules restrict texts to 8 a.m.–9 p.m. recipient local time, Florida and Oklahoma enforce an 8 a.m.–8 p.m. window, and Texas prohibits promotional texts after noon Sunday with quiet hours from 9 p.m.–9 a.m. Log and honor STOP or REVOKE requests immediately — under the FCC’s Opt-Out Rule effective April 2025, revocation requests must be honored within ten business days, and businesses may send only one clarification message within five minutes, which must contain no marketing content. Finally, scrub your list against both the National Do Not Call Registry and the reassigned number database to avoid contacting numbers that have changed hands or are protected under DNC rules. These practices transform compliance from a risk into a competitive advantage. Statutory damages under the TCPA can reach $500–$1,500 per violation, with federal civil penalties now up to $53,088 per violation, making proactive list hygiene essential. 84% of consumers reported opting in to business texts in a 2025 survey, showing that permission-based outreach aligns with consumer preference when done correctly. Opt-out requests must be processed within ten business days under current federal rules, with stricter timelines in states like Florida requiring action within 15 days.

  • Verify consent records before launch — confirm who opted in, for which brand, and for which message type
  • Honor state-specific quiet hours — 8 a.m.–9 p.m. federally, tighter in Florida, Oklahoma, and Texas
  • Log and honor STOP/REVOKE immediately — honor within 10 business days federally, with state variations
  • Scrub against DNC and reassigned-number databases — prevent calls to reassigned or protected numbers

By embedding these disciplines into your campaign workflow, you protect your organization from costly violations while building trust with your audience. My AI Call Center integrates these checks into every campaign review, ensuring that outreach is not only effective but legally sound from the first message to the last.

What Compliant Outbound Looks Like in Practice

Compliant outbound texting isn't a mystery — it's a checklist. The campaigns that stay out of court share the same DNA: permissioned lists, documented consent, and opt-outs honored before the next message ever goes out.

Start with the list itself. Every contact should trace back to a consent record showing who opted in, which brand they authorized, and when. Compliance experts recommend retaining these timestamped, unalterable consent records for at least five years, because in a TCPA dispute, documentation is your strongest defense. Bought lists without clear permission records are a red flag — at My AI Call Center, those lists are flagged and, in most cases, declined before a campaign ever launches.

Then match the message type to the consent you actually have. Marketing texts require prior express written consent under the TCPA, while informational messages like appointment reminders and renewal notices fall under a lighter standard — but the line matters. Under the FCC's Opt-Out Rule effective April 2025, revoking consent in response to an informational message ends all future non-emergency contact, not just marketing. A reminder campaign can quietly become a liability if consent is missing.

In practice, a compliant program looks like this:

  • Consent checked before launch — list source and permission records reviewed against the campaign's message type
  • Calls and texts run inside approved windows, respecting the federal 8 a.m.–9 p.m. standard and stricter state rules like Florida's 8 a.m.–8 p.m. limit
  • Opt-outs logged and honored immediately — keyword opt-outs like STOP and REVOKE processed well inside the 10-business-day federal deadline
  • DNC requests carried across all campaigns, never re-contacted on a future blitz

One wrinkle worth noting: AI-generated voices are treated as artificial voices under the TCPA, so the same consent and disclosure rules that govern robocalls apply. That means AI-assisted outreach demands the same discipline as any other automated contact — recipients can ask whether a call is AI-assisted, request a human, or opt out on the spot. Disclosure isn't optional; it's part of the call structure.

The stakes justify the rigor. Statutory damages run $500 to $1,500 per violation with no cap on total exposure, and state mini-TCPA laws can stack on top of federal claims. One noncompliant blast to a large list can mean multimillion-dollar liability.

A final note: requirements vary by location, industry, contact type, and consent status — quiet hours, registration rules, and opt-out timelines differ by state and country. Businesses should obtain appropriate legal guidance for their specific situation before launching any campaign.

Frequently Asked Questions

Is it actually illegal to send unsolicited sales texts, or just risky?
It's illegal. In the U.S., the TCPA requires prior express written consent before sending marketing text messages, and the FCC has explicitly stated that unsolicited marketing texts violate the law. In Canada, the Canadian Anti-Spam Legislation (CASL) similarly requires express or implied consent with clear identification and unsubscribe mechanisms for commercial texts according to compliance guidance.
How much can one unsolicited text actually cost my business?
Statutory damages run $500 to $1,500 per violation, and the recipient doesn't need to prove any actual harm — simply receiving one noncompliant text is enough to establish standing. Federal civil penalties can reach $53,088 per violation with no aggregate cap, so a single blast to 10,000 contacts could theoretically exceed $500 million in exposure per legal analysis.
If a customer gave me their phone number at checkout, can I text them marketing messages?
No — having someone's number is not consent. Consent must be separate from purchase history, prior business relationships, and verbal conversations, so a checkout number, a purchased lead list, or a promising phone call still doesn't authorize a sales text per regulatory summaries. Marketing texts specifically require prior express written consent, the strictest standard under the TCPA.
What happens if someone replies STOP but I keep texting them?
Continued texting after a STOP request is treated as a willful violation, which pushes damages toward the $1,500-per-message end of the range. Under the FCC's Opt-Out Rule effective April 2025, revocation requests must be honored within ten business days, and consumers can revoke consent in any reasonable manner — the burden is on you to prove their method wasn't reasonable per the rule's legal analysis.
Have companies actually been sued over unsolicited marketing texts?
Yes. DSW Shoe Warehouse settled a TCPA class action for over $4.4 million after sending unsolicited marketing texts, and Uber paid a $20 million settlement in 2017 over promotional texts sent without proper consent per enforcement records. These cases show how quickly costs pile up when consent verification is skipped — and many commercial liability policies don't cover TCPA claims at all, so companies often absorb the full cost themselves.
What does a compliant text campaign look like in practice?
Verified, timestamped consent records kept for at least five years, texts sent only between 8 a.m. and 9 p.m. recipient local time (tighter windows in states like Florida and Texas), opt-outs honored immediately, and lists scrubbed against the DNC registry and reassigned-number database. At My AI Call Center, list source and consent records are reviewed before any campaign launches, and bought lists without clear permission documentation are declined. Notably, 84% of consumers say they opt in to business texts willingly, so permission-based outreach works when done right per a 2025 survey.

Consent Isn't a Hurdle — It's How You Keep the Right to Reach People

The answer to whether unsolicited sales texts are legal is clear: not without verified consent, and the penalties make guessing expensive. With statutory damages of $500 to $1,500 per violation, no damages cap, and real settlements like DSW's $4.4 million payout, one noncompliant campaign can turn a contact list into a multimillion-dollar liability. The rules stack, too — federal TCPA requirements, state mini-TCPA laws, and the FCC's April 2025 Opt-Out Rule all apply at once. The good news is that 84% of consumers reported opting in to business texts in a 2025 survey, so permission-based outreach isn't a limitation — it's what your audience actually prefers. Your next step is practical: audit your lists, verify that consent records show who opted in, when, and for what, and confirm your opt-out handling meets the ten-business-day federal deadline. If your list can't answer those questions, it isn't ready to launch. My AI Call Center reviews list source and consent records before any campaign runs — and tells you plainly if a list won't support the campaign. Start with a free campaign review at myaicallcenter.app and find out where your outreach stands before you spend anything.

Get campaign planning tips