
Is text message marketing legal?
Key Facts
- TCPA litigation filings rose 95% in 2025 according to regulatory analysis
- Prior express written consent is the federal baseline for marketing texts per SMS marketing rules guide
- Fines for unsolicited texts range from $500 to $1,500 per message per SMS regulations blog
- Texas SB 140 requires a $200 annual fee and $10,000 security deposit for SMS telemarketing per SMS regulations blog
- Connecticut can impose a $20,000 penalty for a single unsolicited commercial text per SMS marketing compliance guide
- Florida and Oklahoma cap messaging at 3 messages per topic per 24 hours per SMS marketing compliance guide
- California bars opt-in requests for at least 12 months after a customer opts out per SMS marketing compliance guide
The Legal Baseline: Why Consent Verification Is Non-Negotiable
The Federal Communications Commission's proposed "one-to-one consent" rule was vacated by the Eleventh Circuit Court of Appeals just days before its January 2025 effective date, leaving the pre-2023 written-consent standard firmly in place. That means prior express written consent remains the operative federal baseline for any marketing text — and it must be actively given, not assumed.
A phone number in your CRM is not consent. Purchased lists, past-transaction records, or unrelated sign-up forms do not meet the legal threshold, and implicit consent does not qualify for promotional messages. TCPA penalties run $500 to $1,500 per unsolicited text, and litigation filings rose 95% in 2025 alone. The Designer Brands settlement — $4.4 million for texting opted-out users — shows how quickly exposure compounds when consent records are missing or incomplete.
Consent also tiers by message type. Conversational texts may rely on implied consent; informational texts require express consent; promotional texts demand express written consent. Adding a coupon or call-to-action to an informational thread can reclassify the entire message as promotional, triggering the higher standard. Many programs stumble here by mixing promotional content into transactional threads without securing written consent first.
Before any campaign launches, the consent record must be verifiable. Defensible documentation captures four elements: timestamp, full disclosure language, channel or source, and the phone number tied to a campaign or brand identifier. Records should be retained for at least four years, aligned with the TCPA statute of limitations. At My AI Call Center, every outbound campaign — whether calls or texts — starts with a list-and-consent review that flags or declines lists lacking clear permission records. We tell you plainly if the list will not support the campaign before you spend anything.
- Prior express written consent is the federal floor for marketing texts — not a best practice, a legal requirement
- Purchased lists and past-transaction numbers do not constitute consent
- Consent must be active, unchecked-by-default, and unbundled from terms or purchases
- Documentation must capture timestamp, disclosure language, source, and phone number with campaign identifier
- Retain consent records for at least four years as your primary defense
State laws layer additional requirements on top of the federal baseline — stricter quiet hours, frequency caps, and registration rules that vary by jurisdiction. Federal compliance alone is no longer sufficient for national programs.
How Message Type and State Laws Create Compliance Layers
A single text message can be perfectly legal at the federal level and still expose you to a five-figure state penalty. That's the trap many businesses fall into: they treat TCPA compliance as the finish line when it's actually just the floor.
Not all texts demand the same consent standard. According to US SMS compliance guidance, conversational texts require only implied consent, informational texts need express consent, and promotional texts demand prior express written consent.
The classification can change mid-stream, though. Adding a call-to-action or coupon to an otherwise informational text can reclassify it as promotional, instantly raising the consent bar. This is why compliance analysts flag mixing promotional content into transactional threads as one of the most common — and most avoidable — mistakes in SMS marketing.
State legislatures are filling enforcement gaps, and TCPA litigation filings rose 95% in 2025, driven largely by unclear consent rules (Omnisend's regulatory analysis). A strategic review of SMS rules puts it bluntly: federal compliance alone is no longer sufficient for national messaging programs.
The state layer adds real complexity:
- Texas SB 140 expanded telemarketing law to SMS/MMS, requiring state registration, a $200 annual fee, and a $10,000 security deposit — though after a November 2025 settlement, consented messages fall outside its telemarketing definition.
- Florida and Oklahoma cap messaging at 3 messages per topic per 24-hour period.
- California bars opt-in requests for at least 12 months after a customer opts out under CCPA.
- Connecticut can impose a $20,000 penalty for a single unsolicited commercial text.
The practical response is verification before launch, not after. My AI Call Center reviews list source and consent records before any campaign runs, flagging or declining lists without clear permission documentation — because purchased lists and past-transaction numbers don't constitute legal consent (Mailchimp's consent guidance is explicit on this point).
Defensible consent records should capture the timestamp, disclosure language, channel or source, and phone number with a campaign identifier, retained for at least four years to align with the TCPA statute of limitations (compliance guidance recommends). When in doubt, collect express written consent for everything — since most messaging ends up promotional anyway, the highest standard is the safest baseline.
Execution: Carrier Rules, Opt-Out Handling, and Record-Keeping That Protects Your Campaigns
Being legally compliant on paper won't save your campaign if carriers block your messages or your opt-out logs can't withstand scrutiny. Enforcement is escalating fast — TCPA litigation filings rose 95% in 2025 — and the programs that survive are the ones that nail execution details, not just consent collection.
Carriers operate independently of the law. Under 10DLC registration requirements, brands must register their identity and use case before sending application-to-person texts — unregistered traffic gets throttled or blocked regardless of whether your consent is airtight. Even legally compliant messages can be filtered when CTIA best practices aren't followed.
Content restrictions add another layer. Carriers prohibit SHAFT content — Sex, Hate, Alcohol, Firearms, Tobacco — and violations can trigger permanent program termination. That means a legally permissible alcohol promotion can still end your entire messaging program at the carrier level.
Opt-outs must be honored through any reasonable method, not just the exact keyword STOP — including live chat, support calls, or natural-language requests like "please stop messaging me," which AI-powered intent detection now recognizes. Programs that only listen for the keyword are, as one compliance analysis puts it, "building a gap a complaint or lawsuit can exploit."
While one source allows up to 10 business days for processing, the safer standard is immediate handling of automated keywords and prompt processing of manual channels within the same messaging cycle. My AI Call Center applies this same discipline to outbound calling campaigns — opt-outs are logged and honored immediately, and DNC requests carry across every campaign.
If a complaint lands, your consent records are your defense. Practitioner guidance recommends capturing four elements for every opt-in:
- Timestamp of when consent was given
- The full disclosure language the recipient saw
- The channel or source of the opt-in
- The phone number, with campaign or brand identifier
Retain these records for at least four years, aligned with the TCPA statute of limitations. Robust record-keeping is your strongest defense in the event of a TCPA complaint — courts have shown willingness to award damages when documentation is thin. This is why verifying consent records before any campaign launches matters more than any other single step: a list you can't prove is a list you shouldn't send to.
Frequently Asked Questions
Is text message marketing actually legal in the US?
Can I text customers whose numbers I already have from past purchases or sign-ups?
Do all texts require the same level of consent?
What do state laws add on top of the federal TCPA rules?
How quickly do I have to honor opt-outs, and does it have to be the word STOP?
What consent records do I need to keep in case of a complaint?
Legal, Provable, and Ready to Send
So, is text message marketing legal? Yes — but only when consent is active, documented, and provable. The rules are clear: prior express written consent is the federal floor, purchased lists and past-transaction numbers don't qualify, promotional content mixed into informational threads raises the consent bar, and state laws like Florida's frequency caps and Connecticut's $20,000 penalty stack additional risk on top. With TCPA litigation filings up 95% in 2025, your consent records — timestamp, disclosure language, source, and phone number, retained for at least four years — are your strongest defense. Before your next campaign, audit your lists against the four documentation elements, separate transactional from promotional messaging, and confirm your opt-out handling catches more than just the word STOP. If you'd rather not carry that risk alone, My AI Call Center reviews list source and consent records before any campaign launches — and tells you plainly if a list won't support it, before you spend anything. Book a free campaign review and start with one clear goal.