
What are the disadvantages of using SMS?
Key Facts
- One SMS campaign sent to 100,000 people without proper consent creates $50M–$150M in potential liability before attorney fees, according to TCPA risk research.
- TCPA fines run $500 per text, tripling to $1,500 per message for willful violations, per legal compliance analysis.
- Dish Network settled a TCPA case for $280 million, and Papa John's paid $16.5 million over a text-message class action, per compliance research.
- Unlike email, SMS marketing requires prior express written consent — pre-checked boxes don't count, per legal compliance analysis.
- Since April 11, 2025, businesses must honor any reasonable text opt-out, not just 'STOP,' within 10 business days, per legal experts.
- GDPR fines can hit €20 million or 4% of global revenue, and Canada's CASL carries penalties up to $10 million CAD per violation, per enterprise compliance research.
- Consent records must be retained for at least four years to match the TCPA statute of limitations, per compliance guidance.
Why SMS Compliance Is a Different Beast Than Email
Most marketers assume SMS and email play by similar rules. They don't — and the difference in legal exposure between the two channels is measured in millions of dollars.
Under CAN-SPAM, email marketing requires no prior consent at all. You need a working opt-out mechanism and honest disclosure, and you're largely compliant. SMS is the opposite: autodialed marketing texts require prior express written consent under the TCPA, including a signature, company name, phone number, and clear disclosure — and pre-checked boxes or buried terms-of-service checkboxes don't count, according to legal compliance analysis.
The stakes explain why this distinction matters. TCPA statutory damages run $500 per text, escalating to $1,500 per message for willful or knowing violations — a single campaign to 100,000 people without proper consent could create $50M–$150M in potential liability before attorney fees, per TCPA risk research. The burden of proof falls entirely on the sender, meaning you can run a flawless opt-in flow and still lose a lawsuit if you cannot prove the specific plaintiff consented.
What makes SMS uniquely difficult is that compliance isn't one law — it's four stacked layers, each with its own enforcement mechanism:
- **TCPA statute** — federal consent and damages rules, with a four-year statute of limitations driving record retention requirements
- **FCC regulations** — including the One-to-One Consent Rule effective January 27, 2025, and new opt-out rules effective April 11, 2025, requiring businesses to honor any reasonable revocation method, not just "STOP"
- **CTIA and carrier rules** — 10DLC registration required by all US carriers as of 2023, with violations punished by message filtering or campaign delisting
- **State laws** — Florida's FTSA caps texts at three per day and shortens quiet hours to 8 p.m.; New Jersey's "Seinfeld Bill" requires a physical address in every marketing text
Add international reach and the stack grows: GDPR fines can hit €20 million or 4% of global revenue, and Canada's CASL carries penalties up to $10 million CAD per violation, according to enterprise compliance research. Even the courts add uncertainty — as of December 2025, courts are split on whether texts count as "calls" under the TCPA following the Supreme Court's McLaughlin v. McKesson decision.
The only workable strategy is compliance by the highest standard: satisfying the strictest rule that applies anywhere you operate, rather than maintaining jurisdiction-by-jurisdiction policies. This is why disciplined list practices matter so much — My AI Call Center reviews list source and consent records before any campaign launches and flags bought lists without clear permission records, because in this regulatory environment, your consent documentation is your only real defense.
The Math Behind the Risk: Per-Message Penalties That Scale Fast
A single text message seems harmless — until you multiply it by six figures and a $500 penalty. The Telephone Consumer Protection Act doesn't fine you per campaign; it fines you per message, and that distinction is what turns a marketing mistake into an existential financial event.
Under the TCPA, statutory damages run $500 per violation, rising to $1,500 per message for willful or knowing violations — a tripling that courts apply when a business exceeds the frequency it disclosed at opt-in or ignores obvious consent gaps, according to legal compliance analysis. And because TCPA liability is strict, intent doesn't matter: incomplete consent records leave you exposed no matter what you meant to do.
Run the math on a realistic scenario. A single SMS campaign to 100,000 contacts without proper consent creates $50 million to $150 million in theoretical exposure — before attorney fees — as compliance research makes clear. Even a smaller 50,000-text campaign carries roughly $25 million in exposure, or $75 million if the conduct is deemed willful, per another analysis.
These aren't hypothetical numbers. Real settlements show what happens when the math plays out:
- Dish Network settled a TCPA/TSR case for $280 million in 2019.
- Papa John's settled a text-message class action for $16.5 million.
- Class actions stack damages per class member — $500 to $1,500 each — which is why plaintiff law firms actively recruit TCPA claimants.
The exposure doesn't expire quickly, either. The TCPA carries a four-year statute of limitations, which effectively becomes your minimum consent-record retention period, as compliance guidance notes. Every consent record, timestamp, and opt-out log from a campaign must survive for years — and legal experts confirm that record-keeping is where most teams fall apart.
This is why list discipline matters more than message craft. Providers like My AI Call Center review list source and consent records before any campaign launches, and decline bought lists without clear permission trails — precisely because the per-message penalty structure punishes volume without consent. A list that can't prove where it came from isn't just risky; it's a liability calculator running in the wrong direction.
Operational Burdens That Break Small Teams
Sending a few thousand texts sounds simple until you realize every message sits on top of a compliance machine that has to run perfectly, forever. The rules themselves aren't the hard part — it's the daily operational machinery a small team must maintain just to stay out of court.
Start with opt-outs. Under the TCPA's new rules, effective April 11, 2025, businesses must honor any reasonable revocation method — not just the keyword "STOP." A reply saying "please stop texting me" counts, and all communications must cease within 10 business days. You're allowed one confirmation message to clarify opt-out scope, but only if it goes out within five minutes of the request; no response means you assume a full opt-out.
Then there's the scheduling layer. Federally, marketing texts are permitted only between 8 a.m. and 9 p.m. in the recipient's local time zone, and many states enforce stricter windows — Florida's Telephone Solicitation Act cuts the window off at 8 p.m. and caps campaigns at three messages per day. Frequency caps add another trap: there's no federal limit, but exceeding what you disclosed at opt-in can be treated as evidence of willfulness, bumping damages from $500 to the $1,500 tier per text, according to compliance analysis of the 2025–2026 landscape.
The background maintenance never stops either:
- 10DLC registration — as of 2023, all US carriers require it through The Campaign Registry, and violations mean filtered messages or campaign delisting.
- Reassigned Number Database scrubbing — before every send, to avoid texting someone who never consented.
- Re-consent campaigns for leads older than 6–12 months, since stale consent is treated as no consent.
This is why recordkeeping is where most teams actually fail. As one industry analysis puts it, "Record-keeping is where most small teams fall apart." The burden of proof falls entirely on the sender — you can run a flawless opt-in flow and still lose a lawsuit if you can't produce the exact consent language, timestamp, and disclosures for a specific plaintiff. Records must be retained for at least four years, matching the TCPA statute of limitations.
For teams without compliance staff, that's the real disadvantage: the operational load of a regulated channel, applied to a tool most businesses assumed was lightweight. It's the same reason list discipline matters in any outbound channel — My AI Call Center reviews list source and consent records before any campaign launches, and flags lists without clear permission records, because the alternative is discovering the gap in litigation.
Explore managed outbound campaigns — structured, consent-reviewed calling from 9¢ per connected minute, with opt-outs logged and honored immediately.
Regulatory Uncertainty and the Shifting Goalposts
Even if you build a compliant SMS program today, the rules underneath it can shift before your next campaign goes out. That is the core problem with SMS in 2025: the regulatory ground keeps moving, and businesses carry the risk of guessing wrong.
The pace of change has been relentless. The FCC's One-to-One Consent Rule took effect January 27, 2025, tightening who can be texted and under what conditions, according to current compliance analysis. Then, on April 11, 2025, new TCPA opt-out rules required businesses to honor any reasonable revocation method — not just keywords like "STOP" — and to stop all messages within 10 business days.
The Supreme Court added another layer of uncertainty. Its June 20, 2025 McLaughlin Chiropractic Associates v. McKesson Corp. decision removed judicial deference to FCC interpretations, and as of December 13, 2025, courts remain split on whether texts even count as "calls" under the TCPA. The practical takeaway from legal experts is blunt: if you market by text, assume TCPA risk unless you can prove compliant consent and opt-out handling.
State legislatures are layering on their own rules, each with different damage provisions:
- Florida's FTSA imposes $500 per call or text in statutory damages, trebled for willful violations, and caps texts at three per day between 8 a.m. and 8 p.m.
- Oklahoma's OTSA expands autodialer restrictions and bans deceptive practices like caller ID masking or altered voices.
- New Jersey's S921 "Seinfeld Bill" requires a physical business address in every marketing text.
The stakes compound quickly. A single campaign to 100,000 people without proper consent creates potential liability of $50M–$150M before attorney fees, per recent estimates. Trade associations have even requested pauses on new rules, citing the administrative and financial burden of implementation timelines.
This is why experts recommend a "compliance by the highest standard" approach — meet the strictest applicable rule everywhere you operate. It is also why disciplined list practices matter more than channel choice. My AI Call Center reviews list source and consent records before any campaign launches, flags bought lists without clear permission records, and honors opt-outs immediately across every campaign type.
The regulatory goalposts will likely keep moving. Businesses that treat consent documentation as a living record — retained for at least four years to match the TCPA statute of limitations — are the ones positioned to absorb the next shift without starting over.
A Safer Path: Structured Voice Campaigns on Permissioned Lists
When SMS campaigns run into compliance trouble, the financial exposure can be staggering—far beyond the cost of the messages themselves. A single campaign to 100,000 people without proper consent creates potential liability of $50 million to $150 million before attorney fees, based on statutory damages ranging from $500 to $1,500 per violation according to industry research. This risk isn't theoretical; major brands have faced eight- and nine-figure settlements for TCPA violations, highlighting how quickly costs escalate when consent processes fail as documented in legal analyses.
Beyond fines, SMS marketing demands operational rigor that strains resources. Businesses must honor opt-out requests within 10 business days—a strict window that applies equally to text messages and email under TCPA and CAN-SPAM rules per compliance guidelines. They also need auditable consent records retained for at least four years to match the TCPA statute of limitations, maintain time-of-day restrictions (8 a.m. to 9 p.m. local time), and scrub against reassigned number databases as experts emphasize. For multi-location organizations, layering state-specific rules like Florida’s FTSA or New Jersey’s address requirement compounds the burden, making compliance a full-time job rather than a marketing tactic.
This is where structured voice campaigns on permissioned lists offer a clearer path forward. My AI Call Center runs managed outbound calling only on approved, permissioned, or reviewed lists with consent verified before launch—never using purchased lists without clear permission records. Every call includes AI disclosure, honors keyword opt-outs (STOP, REVOKE) immediately, respects DNC requests across all campaigns, and routes outcomes back to your CRM with full disposition codes. By focusing on list discipline and transparent processes, organizations can reduce compliance complexity while achieving goals like appointment reminders, lead qualification, or retention outreach—starting at 9¢ per connected minute with setup and management fees quoted upfront.
Frequently Asked Questions
How much can a business actually be fined for sending non-compliant SMS marketing?
Why is SMS compliance so much harder than email marketing?
Do I have to honor every opt-out method, or just replies that say "STOP"?
How long do I need to keep SMS consent records?
Are there state-level SMS rules I need to worry about beyond federal law?
Is it risky to buy a contact list for SMS campaigns?
When the Cheapest Channel Carries the Biggest Risk
SMS looks like the simplest channel on the surface — but as we've seen, it demands prior express written consent, per-message penalties that can reach $1,500 per text, opt-out handling within 10 business days, four-year record retention, and constant adaptation to shifting federal, state, and carrier rules. A single campaign to 100,000 people without proper consent can create $50M–$150M in potential liability before attorney fees. That's why the real question isn't whether to send texts — it's whether your consent records and list sources can survive scrutiny. If you're rethinking your outbound approach, structured voice campaigns on approved, permissioned, or reviewed lists offer a clearer path: one clear goal per campaign, consent verified before launch, and outcomes routed back to your CRM. My AI Call Center runs managed campaigns starting at 9¢ per connected minute, with the full cost quoted before you approve anything. Start with a free campaign review — we'll tell you plainly whether your list will support the campaign, before you spend anything.