
What is an opt-in for texting?
Key Facts
- One unconsented marketing text can cost $500 to $1,500 under the TCPA, with no need to prove injury, according to BCLP's legal analysis.
- TCPA lawsuits can reach back four years, so a sloppy campaign from 2021 can still land on your desk today, per ActiveProspect's compliance guidance.
- A compliant U.S. SMS opt-in form requires 11 elements, including an unchecked consent box and manually entered number, per carrier registration requirements.
- 93% of surveyed U.S. patients have opted in to receive texts from their providers, a 2026 survey of 1,000 patients found.
- Under the FCC's Opt-Out Rule effective April 11, 2025, consent revocation must be honored within 10 business days, BCLP reports.
- Opting out of an informational text revokes all future non-emergency calls and texts — not just that message type, per legal analysis of the rule.
- 97% of patients would opt in to appointment reminder texts, but only 20% to health education messages, Sinch's patient survey shows.
Why Texting Without Real Permission Is an Expensive Gamble
Texting your customers sounds simple — until one unconsented message turns into a four-figure liability. Under the U.S. Telephone Consumer Protection Act (TCPA), every marketing text sent without proper consent can cost $500 to $1,500 per message, and plaintiffs don't even need to prove actual injury, according to legal analysis from BCLP.
The exposure doesn't fade quickly, either. TCPA lawsuits can reach back four years, meaning a sloppy campaign from three years ago can still land on your desk today. Multiply even a small list by per-message damages, and a "quick blast" becomes an existential financial risk. And it's not just lawyers you need to worry about — U.S. carriers review your opt-in forms during sender registration and can block non-compliant programs entirely, cutting off your channel before you even start.
So what actually counts as permission? A text opt-in is a person's explicit, active permission for you to send them messages. AWS's compliance guidance defines it as "the intentional action taken by an end-user to request a specific message from your service." The person enters their own number, sees what they're agreeing to, and takes a deliberate step to say yes.
That's why passive consent doesn't count. These common shortcuts all fail the standard:
- Pre-checked consent boxes — the checkbox must be unchecked by default
- Pre-filled or inferred phone numbers — the user must manually enter their own
- Bundled signups — SMS consent can't ride along with email opt-ins or terms acceptance
Each of these creates the appearance of permission without the substance, and carrier registration requirements treat them as no consent at all.
The stakes are real enough that consent verification deserves to happen before any outreach, not after. At My AI Call Center, list source and consent records are reviewed before a campaign ever launches — bought lists without clear permission records are flagged, and in most cases declined. It's cheaper to be told a list won't support the campaign than to discover that in a courtroom.
The good news: when you ask properly, people say yes. In healthcare, a recent survey of 1,000 U.S. patients found 93% have already opted in to receive texts from providers. Real permission isn't a barrier — it's the foundation that makes texting work.
What a Compliant Opt-In Actually Looks Like
A compliant opt-in isn't just a phone number in your database — it's a documented, intentional act by a real person. Get it wrong, and TCPA statutory damages run $500–$1,500 per text, with lawsuits reaching back four years.
The anatomy of a valid opt-in is specific. According to carrier registration requirements, a compliant U.S. form contains 11 required elements, and the non-negotiables are:
- A manually entered mobile number — pre-filled or inferred numbers fail TCPA standards
- An unchecked, single-purpose consent box — SMS consent can't be bundled with email signup or terms acceptance
- The brand name, a program description, and message frequency disclosure
- "Message and data rates may apply" plus visible HELP and STOP keywords
- Links to the privacy policy and terms, shown before consent is given
Consent also comes in tiers. ActiveProspect's compliance guidance distinguishes three TCPA levels: prior express written consent (required for marketing texts sent via autodialers — verbal consent doesn't count here), prior express consent (sufficient for informational messages like appointment reminders), and prior express invitation or permission (for manually dialed contacts). BCLP's legal analysis confirms the asymmetry: written consent is required for marketing but not for transactional updates or prescription notifications.
Here's what most businesses miss: collection is only half the job. You must retain the exact consent language shown, the timestamp, the collection platform, and proof a real human submitted the form — for at least four years. Bot-submitted leads equal no valid consent at all, and if you buy leads, you — not the seller — bear the liability, so demand independent proof for every contact.
Even the shifting legal landscape doesn't change this. In February 2026, the Fifth Circuit ruled the TCPA doesn't strictly require written consent, but that ruling is geographically limited and state laws may still demand it. As Holland & Knight note, oral consent must be "carefully documented and independently verifiable to withstand future scrutiny."
This is why My AI Call Center checks list source and consent records before any campaign launches — a list without clear permission records simply won't support compliant outreach. As AWS puts it plainly: "There are no exceptions to having an opt-in workflow and explicit consent is always required."
Opt-Outs Are Part of the Opt-In: The Full Consent Lifecycle
Getting consent right is only half the job. The other half — honoring it when someone changes their mind — is where many businesses stumble, and the rules changed significantly in April 2025.
Under the FCC's Opt-Out Rule that took effect April 11, 2025, consumers may revoke consent "in any reasonable manner," businesses cannot mandate an exclusive opt-out method, and revocation must be honored within 10 business days. As BCLP notes, "it will be the business's burden to demonstrate why the opt-out request was not reasonable." Practically, that means treating opt-outs as immediate, not a deadline to run down.
One detail catches many organizations off guard: opting out of an informational message revokes everything — all future non-emergency calls and texts — while opting out of a marketing message stops only marketing. If a customer replies STOP to an appointment reminder, you cannot keep sending them promotional texts. The rule also permits one clarification text within five minutes of revocation, and opt-out records must be retained for at least four years.
The broader legal landscape is shifting, too. The FCC's one-to-one consent rule was vacated by the Eleventh Circuit in January 2025, leaving the older, broader standard in place. Then in February 2026, the Fifth Circuit ruled in Bradford v. Sovereign Pest Control that the TCPA requires only "prior express consent," whether oral or written — rejecting the FCC's 2012 written-consent rule. But that ruling applies only within the Fifth Circuit, and state laws and other circuits may still require written consent.
Why does this matter for your opt-in process?
- Written, documented consent remains the safest standard regardless of where courts land, because litigation is active and standards vary by jurisdiction.
- Holland & Knight attorneys advise that oral consent should be "carefully documented and independently verifiable to withstand future scrutiny."
- Companies must still demonstrate that the contacted party provided "clear, direct and unequivocal consent" — a burden that never disappears.
- The stakes stay high: TCPA damages run $500–$1,500 per violation with a four-year lookback, so sloppy records compound fast.
The practical takeaway is simple: treat consent as a full lifecycle — collect it actively, document it thoroughly, and honor its revocation instantly. My AI Call Center applies this discipline to every campaign, reviewing list source and consent records before launch and logging opt-outs so they are honored immediately and carried into client DNC records. Consent you cannot prove is consent you do not have.
How to Verify Opt-Ins Before You Ever Send a Campaign
Collecting an opt-in is only half the job. The other half — the one that actually protects you — is verifying that consent before a single message goes out, because under the TCPA, the burden of proving consent falls on the business sending the text, not the one that collected it.
Start by auditing where each list came from and what consent records exist. You need the exact consent language shown, the timestamp, the collection platform, and proof that a real person submitted the form — retained for at least four years, since TCPA lawsuits can reach back that far. With statutory damages running $500 to $1,500 per message, a list with thin records is a liability, not an asset.
Bot-submitted leads deserve special attention. A lead filled out by a bot equals no valid consent at all, so reject anything that lacks proof of human submission. The same discipline applies to purchased lists: liability sits with the buyer, not the seller, so you must require independent proof of consent for every lead before you text it. As compliance guidance puts it, "independent proof is your strongest defense."
A practical pre-launch checklist looks like this:
- Confirm the list source and what consent language contacts actually saw
- Verify timestamps and collection platforms for every record
- Reject bot-submitted leads and purchased leads without clear permission records
- Confirm your opt-out handling covers STOP and REVOKE keywords
Opt-out handling matters as much as opt-in collection. Under the FCC's Opt-Out Rule effective April 11, 2025, consumers may revoke consent "in any reasonable manner," and revocation must be honored within 10 business days — though practically, you should honor it immediately. Remember that opting out of an informational message stops all future non-emergency calls and texts, not just that message type, according to legal analysis of the rule.
This is exactly why My AI Call Center checks list source and consent records before any campaign launches, and flags — and in most cases declines — bought lists without clear permission records. Opt-outs are logged and honored immediately, and DNC requests carry across all campaigns into client records. The philosophy is simple: tell the client plainly if the list will not support the campaign, before they spend anything.
Even with recent court rulings softening written-consent requirements, legal analysis still advises documented, independently verifiable consent as the safest standard. Verify first, send second — and get appropriate legal guidance before launch, since requirements vary by location, industry, and contact type.
Frequently Asked Questions
What counts as a valid opt-in for texting?
How much can it cost to text someone without proper consent?
Do I need written consent, or is verbal permission enough?
What does a compliant opt-in form need to include?
Can I use a purchased lead list if the seller says people opted in?
What happens if someone replies STOP to an appointment reminder instead of a marketing text?
Permission First, Outreach Second
A text opt-in is explicit, active, single-purpose permission — a manually entered number, an unchecked consent box, clear disclosures, and records you can produce on demand. Anything less (pre-checked boxes, bundled signups, bought lists without proof) isn't consent, it's a liability that can cost $500 to $1,500 per message and reach back four years. And consent is a lifecycle: collect it properly, document it for at least four years, and honor every opt-out immediately — remembering that a STOP on an informational message revokes everything. The encouraging part? When asked properly, people say yes: 93% of surveyed U.S. patients have already opted in to texts from their providers. Before your next campaign, audit your lists against the checklist above — confirm what contacts actually saw, when, and whether a real human submitted it. If you'd rather not carry that review alone, My AI Call Center checks list source and consent records before any campaign launches, and tells you plainly if a list won't support it. Plan your first campaign with the goal in mind, and get appropriate legal guidance for your location and industry before launch.