Support · Legal
Verified RCS · SMS · MMS

What is 10DLC compliance?

Compliance & Security

Reviewed by , VP of Global Operations, Signalmash · Last reviewed · Editorial standards

Quick answer

Being 10DLC compliant means two things at once: registration and consent. Your sender has to be properly registered, and your messaging has to follow the consent rules that sit on top of registration. Registration is the carrier layer, your brand and each campaign are on file and approved. Consent is the legal layer, largely the TCPA in the US, which requires prior express written consent before marketing texts, a clear disclosure at the point of opt-in, working STOP handling, and records you can produce later. Passing registration does not make you compliant on its own. A registered brand sending unconsented marketing is still breaking the law and will still be filtered.

See this on your own phone in about 30 seconds: get a free sender ID test →

In practice, compliance rests on evidence. The question is never "did you mean well", it is "can you show, for this specific phone number, when and how consent was captured, and that STOP was honoured immediately". That means storing the timestamp, the source of the opt-in, the exact disclosure wording shown, and the full opt-out history for every contact.

Message content matters too. Carriers filter for prohibited categories regardless of registration, and every campaign should identify the sender, keep to the use case it was registered under, and honour HELP and STOP keywords. Sending marketing traffic through a campaign registered as transactional is a common and avoidable violation.

10DLC compliance checklist

Registration, the carrier layer:

  • Brand registered with The Campaign Registry under the exact legal name and EIN, with the trust score checked.
  • One campaign registered per use case, with sample messages and opt-in evidence attached.
  • Traffic sent only through the campaign whose use case it matches; marketing never rides a transactional campaign.
  • Numbers attached to their campaigns before the first send.

Consent, the legal layer:

  • Prior express written consent captured before any marketing text, with the disclosure shown at opt-in (message frequency, "message and data rates may apply", how to opt out).
  • For each phone number: the timestamp, the source of the opt-in and the exact wording shown, stored where you can produce them.
  • STOP honoured automatically and immediately, HELP answered, and the opt-out persisted across every channel and system that can send.
  • Quiet hours respected in the recipient's time zone.

Content and operations:

  • Sender identified in the message, and nothing from the carriers' prohibited categories.
  • Consent and opt-out history retained for the length of the programme plus the limitation period.
  • A named owner for inbound replies, so a STOP or a complaint is seen by a person.

Every item above applies to the SMS fallback of an RCS programme; the RCS agent has its own verification on top, covered in what is a verified sender.

Key facts
  • Two layers: carrier registration (10DLC) and legal consent (TCPA). Both are required.
  • Prior express written consent is required before marketing texts, with a clear disclosure at opt-in.
  • STOP and HELP must be honoured automatically, and opt-outs must persist across channels.
  • Traffic must match the use case its campaign was registered under.
  • On SimplyRCS, STOP and HELP are handled above the AI layer, so they are always honoured, and consent records are retained with a full audit trail.

Frequently asked

Which 10DLC regulations apply to business texting?

Two layers. The carrier layer is 10DLC registration itself, run through The Campaign Registry, which requires an approved brand and campaign before a 10-digit number can send business traffic at volume. The legal layer is the TCPA and the CTIA messaging principles, which set the consent, disclosure, STOP and record-keeping rules. 10DLC regulations bite on both: unregistered traffic is filtered and unconsented traffic is unlawful.

What happens if a business is not 10DLC compliant?

Two different things, from two different parties. Carriers filter or block unregistered and mismatched traffic, so messages simply stop arriving, and a campaign can be suspended. Separately, texting without the consent the TCPA requires carries statutory damages of $500 to $1,500 per message, enforced through private lawsuits rather than by the carriers.

Is 10DLC required for RCS?

Not for the RCS messages themselves, which are sent from a verified RCS agent with its own Google and carrier approval. It is required for the SMS fallback that every RCS programme relies on, because any message that cannot be delivered as RCS is delivered as SMS from a 10DLC, toll-free or short-code number. 10DLC vs RCS explains how the two registrations relate.

How long does 10DLC compliance take to set up?

Brand registration is often approved the same day. Campaign vetting usually takes a few business days, longer for regulated or higher-risk use cases. The consent side has no waiting period, but it does need the evidence in place before the first send: the disclosure at opt-in, and a record of who agreed, when and how.

How verification, consent, and STOP handling actually work on SimplyRCS. Read the trust page →

← All RCS questions