If your agency runs Facebook ads for roofers, HVAC companies, or any home-services business, SMS is almost certainly the backbone of your follow-up. It is also the channel with the most rules. This guide explains SMS compliance for business texting in plain English — the A2P 10DLC registration system, consent, required behaviors, and why non-compliant traffic quietly disappears before it ever reaches a phone.
One disclaimer up front, and it applies to this entire guide: carrier rules and regulations change regularly and vary by country. This article describes the US landscape at a high level and is not legal advice. For anything binding, check current carrier documentation and talk to a qualified attorney.
Why is SMS compliance a growth lever, not a tax?
Compliance is what makes your texts actually arrive. An unregistered or non-compliant number gets filtered by carriers, which means your speed-to-lead automation is firing into a void. Agencies that register properly and collect consent correctly get better deliverability, faster contact rates, and a follow-up system that works as designed.
Most agency owners think of compliance like taxes: a cost to minimize and ignore. That framing gets the economics backwards. Your entire value proposition rests on one chain: lead fills out a form, gets a text within minutes, replies, books. Every link depends on the text being delivered. If carriers are filtering your traffic — and they filter unregistered traffic aggressively — the chain breaks at step two and nobody tells you. Your speed-to-lead system becomes an expensive illusion.
Agencies that treat registration, consent, and opt-out handling as core infrastructure get three compounding advantages:
- Deliverability. Registered, well-behaved traffic reaches phones at meaningfully higher rates. Your automations do what you sold the client.
- Throughput. Registered campaigns earn higher message-per-second limits — which matters when a database reactivation blast goes out to thousands of contacts.
- Durability. Numbers that behave keep working. Flagged numbers burn down, and every swap costs contact rate while the new one warms up.
So read everything below as deliverability engineering, not legal chores. The rules exist because SMS is the one inbox people still trust, and carriers are ruthless about keeping it that way. Play inside the lines and that trust works for you.
What is A2P 10DLC, and how does the system actually work?
A2P 10DLC is the US carrier framework for application-to-person messaging sent from standard ten-digit local numbers. Businesses register a brand (who is sending), then a campaign (what they send and why), which is vetted before approval. Registered traffic gets sanctioned delivery routes; unregistered traffic gets heavily filtered.
Break the acronym apart and it's less intimidating. "A2P" means application-to-person — software sending texts, rather than one human texting another. "10DLC" means ten-digit long code, the ordinary local numbers your clients' customers recognize. Carriers built the framework so businesses can legitimately send automated messages from local numbers, in exchange for declaring who they are and what they're sending.
Brand registration: who is sending
The first layer is the brand — a verified identity for the business behind the messages: legal business name, EIN or equivalent tax ID, address, website, and contact details. This gets checked against business registries, so it must match official records. A mismatched EIN and legal name is one of the most common reasons registration stalls.
Campaign registration: what is being sent
The second layer is the campaign — a declared use case attached to a brand. You describe the type of messaging (lead follow-up, appointment reminders, marketing), provide sample messages, and explain how recipients opt in. Campaigns go through vetting before approval, and some use cases draw more scrutiny than others. Plan for days, not minutes — longer if anything looks inconsistent.
What registration buys you — and what it costs
Registered campaigns get assigned throughput and trust levels, and their messages travel sanctioned routes. There are real costs: carriers charge per-message fees on A2P traffic, plus typical one-time and recurring registration fees for brands and campaigns. Budget for them and pass them through — don't try to dodge them by sending unregistered. Here's the difference in practice:
| | Registered A2P traffic | Unregistered traffic | | --- | --- | --- | | Delivery | Travels sanctioned routes; high delivery rates when content behaves | Heavily filtered; messages silently dropped with no bounce notice | | Throughput | Defined messages-per-second limits based on trust level | Severely throttled, unpredictable | | Number health | Stable long-term sender reputation | Numbers get flagged and blocked; constant churn | | Fees | Known per-message carrier fees, predictable | Possible surcharges and penalties from carriers or your provider | | Risk | Low, when consent and content rules are followed | Provider suspension, carrier blocking, client campaigns going dark mid-flight |
This guide covers 10DLC at the strategic level. For the step-by-step registration walkthrough — trust scores, use-case selection, sample messages that pass vetting, and what to do when a campaign gets rejected — see our dedicated A2P 10DLC guide for agencies.
Rules change. Verify before you build.
The specific fees, vetting criteria, and throughput tiers in the 10DLC system are set by carriers and The Campaign Registry, and they have changed multiple times since the system launched. Treat any specific number you read online — including here — as a snapshot. Check current carrier documentation and your messaging provider's compliance pages before making commitments to clients. This is not legal advice.
How do you get SMS consent right on lead forms?
Consent means the lead knowingly agreed to receive texts from the specific business texting them. On lead forms, that means clear disclosure language near the phone field stating who will text, why, that message frequency varies, that message and data rates may apply, and how to opt out.
Consent is the load-bearing wall of the whole system. Registration tells carriers who you are; consent is your answer when anyone — a carrier auditor, a messaging provider, or a lawyer — asks why you texted a particular person.
The good news for lead-generation agencies: a lead who fills out a form asking for a quote and provides their phone number, with proper disclosure, is about the cleanest consent scenario there is. The person raised their hand, gave their number, and was told texting would follow. The key phrase is with proper disclosure. That means your Facebook lead forms and landing pages need:
- Named sender. The disclosure states the actual business that will be texting — "Summit Roofing," not "we" or a vague brand umbrella. Consent belongs to a specific sender.
- Stated purpose. What the texts will be about: following up on the request, scheduling, appointment reminders. If you later want to send marketing or reactivation messages, disclose that too — consent for one purpose is not blanket consent for everything.
- The standard mechanics. Language along the lines of "message frequency varies, message and data rates may apply, reply STOP to opt out, reply HELP for help." Your messaging provider's documentation will have current recommended phrasing.
- A link to terms and a privacy policy that describes how phone numbers are used. Campaign vetting frequently checks that the opt-in flow you described actually exists on the page you cited.
Just as important: keep records. Store what the lead submitted, when, from which form, and what disclosure language was on it at the time. If consent is ever questioned, "this lead submitted this form on this date, and here's the form" is a complete answer. "They're in our list somehow" is not.
And the hard line every agency needs to internalize: a phone number you have is not a phone number you may text. Purchased lists, scraped numbers, and contacts from a client's old spreadsheet with no consent trail are how numbers get burned and accounts get suspended. In the US, the TCPA — the federal law governing calls and texts to consumers — is why consent is not optional, and it comes with private lawsuits attached. We're deliberately not summarizing its specifics; they're legally nuanced and litigated constantly. Know that it exists, that it has teeth, and get a lawyer's eyes on your intake flows if you're in doubt.
What behaviors are required once you start texting?
Four behaviors are non-negotiable: honor STOP immediately and confirm it once, respond to HELP with useful information, identify the business in your messages, and keep frequency reasonable. Add quiet hours — no texting late at night or early morning in the recipient's time zone — as a firm best practice.
Registration gets you onto the road. These behaviors are the traffic laws that keep you on it.
STOP and other opt-out keywords
When someone replies STOP (or variants like UNSUBSCRIBE, CANCEL, QUIT), messaging must stop — immediately, permanently, across all automations. The standard pattern is one final confirmation acknowledging the opt-out, then silence. This must be enforced at the system level, not by hoping a VA notices the reply. Drip messages that keep firing after STOP generate carrier complaints, and complaints are the metric that kills sender reputation.
HELP
A HELP reply should return the business name and a way to reach a human — phone or email — plus a reminder of how to opt out. Most platforms handle this automatically; verify yours does, per number, per client.
Identification
Every conversation should make clear who is texting, especially the first message. "Hi Sarah, this is Mike with Summit Roofing — you requested a quote on our site" is compliant and converts better. An anonymous "Hey, still interested?" reads as spam to both the recipient and the carrier's filters.
Quiet hours and frequency
Don't text people at 11pm. Confining sends to daytime and early-evening hours in the recipient's time zone is a widely-followed best practice, and some state laws impose specific windows — get current guidance rather than guess. Frequency matters too: a handful of well-spaced messages is normal; a barrage is a complaint generator. If a lead ignored eight messages, the ninth won't close them.
Compliance quick checklist
- Brand registered with legal name and EIN matching official records
- Campaign registered, vetted, and approved for the actual use case
- Every lead form and landing page carries full consent disclosure naming the sender
- Consent records stored: source, timestamp, and form language
- STOP/UNSUBSCRIBE enforced automatically and permanently, with a single confirmation
- HELP returns business name and contact info
- Business identifies itself in the first message of every conversation
- Sends restricted to reasonable hours in the recipient's time zone
- Message frequency capped; sequences end rather than loop
- No purchased, scraped, or consent-free lists — ever
Why do business texts silently fail to deliver?
Carriers run filtering systems that score every message and sender, and they drop traffic that looks unregistered, spammy, or complaint-prone — usually without any bounce or error. Your dashboard says "sent," the phone shows nothing. Filtering is triggered by unregistered numbers, bad content patterns, link shorteners, volume spikes, and opt-out violations.
This is the part of SMS that surprises agencies most: "sent" does not mean "delivered." Between your platform and the recipient's phone sits carrier infrastructure deciding whether your message gets through. When it decides no, the message frequently just vanishes — no error code. The first symptom is usually a client asking why response rates fell off a cliff.
The common triggers, roughly in order of how often they bite agencies:
- Unregistered or misregistered traffic. Sending A2P volume from a number with no approved campaign behind it, or under a campaign registered for a different use case, is the number-one cause. The fix is upstream, in registration — content tweaks won't save unregistered traffic.
- Content that pattern-matches spam. ALL-CAPS urgency, heavy emoji, "FREE!!!", and messages that read like broadcast ads rather than conversation. Conversational, personalized follow-up — the kind an AI qualification flow naturally produces — scores far better than blast copy.
- Public link shorteners. Shared-domain shorteners are so abused by spammers that their presence alone can sink a message. If you must send links, use full branded domains or a dedicated branded short domain.
- Volume spikes from cold numbers. A brand-new number that goes from zero to thousands of messages in an hour looks exactly like a spam operation. Warm numbers up gradually, and throttle big sends like reactivation campaigns.
- Complaints and opt-out violations. Recipients reporting messages as junk, or continued sends after STOP, damage the sender's standing quickly and are slow to recover from.
Two habits keep you ahead of filtering. First, watch delivery rates per client, per number — a sudden drop is your smoke alarm. Second, test regularly from real handsets on the major carriers; a monthly two-minute test will catch silent filtering months before a client does.
What are your responsibilities when texting on a client's behalf?
When your agency sends texts for a client, the messages legally represent the client's business — so each client generally needs their own brand registration, their own campaign, and their own consent trail. You can't shelter client traffic under your agency's registration, and you own making sure their forms and follow-up behave compliantly.
This is where agencies get into structural trouble. It feels efficient to run every client through one master account, one registration, a shared pool of numbers. It is wrong on two levels.
First, it misrepresents who is sending. Texts inviting homeowners to book with Summit Roofing are Summit Roofing's messages, regardless of whose software sent them. Registering them under "Your Agency LLC" is inaccurate at best. The correct pattern is one brand and campaign per client business, registered with the client's legal details — so collect EIN, legal name, address, and website from every client during onboarding.
Second, shared infrastructure means shared fate. If one client on a pooled setup runs a sloppy blast to a cold list, the reputation damage lands on every client sharing that registration or number pool. Isolation per client isn't just compliant; it's risk containment.
Beyond registration, texting on a client's behalf means the compliance perimeter extends to things you build and things they do:
- Their lead sources are your problem. If the client hands you "our list" for a reactivation campaign, ask where it came from and whether those contacts consented. See our database reactivation guide for vetting a list before a single message goes out — blasts are where consent shortcuts blow up loudest.
- Your forms carry their disclosures. Every landing page and lead form you build needs the consent language above, naming the client.
- Get the relationship on paper. Your service agreement should spell out who owns compliance obligations, what data the client provides, and what list practices you refuse. Have a lawyer review it.
Not legal advice — and worth repeating
Agency-client messaging arrangements sit at the intersection of carrier policy, federal and state law, and contract law. This guide describes common industry practice, not the requirements for your specific situation. When you're structuring how your agency registers and sends on behalf of clients, check current carrier and provider documentation, and get a qualified attorney's review.
How do you set up a new client correctly from day one?
Correct setup means collecting the client's legal business details at onboarding, registering their brand and campaign before launch, putting compliant disclosure on every form, configuring STOP/HELP and quiet hours in the platform, and warming numbers before full volume. Done in order, this takes days — and prevents the weeks-long mess of retrofitting.
Here is the sequence that works, in the order it should happen:
- Collect registration data at intake. Legal business name exactly as registered, EIN, address, website, and a contact — required fields in your onboarding form, so no launch starts without them.
- Register brand and campaign immediately. Vetting is the long pole in your launch timeline; submit on day one so approval lands before ads do. Sample messages that match what you'll actually send prevent rejection loops.
- Build forms with disclosure baked in. Consent language on every lead form and landing page, naming the client, before any traffic runs.
- Configure the platform guardrails. STOP/HELP auto-handling on, quiet hours set to the client's market time zone, frequency caps sane, opt-outs syncing across every automation.
- Warm the number. Start with conversational volume before ramping to full campaign flow. Never point a fresh Facebook campaign at a number registered yesterday.
- Verify with real phones. Send test messages through the full automation to handsets on the major carriers. Confirm delivery, confirm STOP works, confirm HELP responds.
The pattern to notice: every step is dramatically cheaper before launch than after. Retrofitting consent language onto forms that already collected thousands of leads is the expensive version of this list.
What should good platform tooling automate for you?
A serious messaging platform should automate the mechanical layer of compliance: guided A2P registration, automatic STOP/HELP handling, opt-outs enforced across all automations, quiet-hour scheduling, per-client sender isolation, consent record-keeping, and delivery-rate monitoring. What no platform can automate is consent itself — where your contacts came from is always on you.
Compliance done by hand is compliance done inconsistently. The failure stories rarely involve an agency that decided to break rules — they involve one automation that didn't check the opt-out list, or one blast that went out at 6am because nobody set a time zone. The mechanical layer has to live in software. Look for:
- Registration built into onboarding. The platform collects brand and campaign details during client setup and walks the submission through vetting, rather than leaving you to navigate registry portals per client.
- Opt-out enforcement at the sending layer. STOP suppresses a contact globally — every sequence, blast, and AI conversation — not just the automation that received the reply. The single most important guardrail to verify.
- Quiet hours and throttling as defaults. Time-zone-aware send windows and ramped sending for large campaigns, on by default.
- Consent trails attached to contacts. Source form, timestamp, and page recorded automatically, so "why did you text this person" always has an answer.
- Per-client isolation. Each client's brand, campaign, numbers, and reputation stand alone, so one client's mistake can't take down the roster.
- Deliverability visibility. Delivery rates per client and per number, with alerting when they sag — silent filtering is only silent if nothing is listening.
This is the philosophy Peak Logic OS is built on: the AI that qualifies and books leads over SMS sits on top of a compliance layer that handles registration, opt-outs, quiet hours, and consent records automatically — because follow-up that doesn't deliver isn't follow-up.
One closing note, same as the opening one: this guide reflects the US 10DLC landscape as commonly practiced, and rules change. Check current carrier documentation and involve a lawyer for the legal layer. None of this is legal advice — it's the operating knowledge that keeps the channel working.
FAQ
What is A2P 10DLC?
A2P 10DLC is the US carrier framework for application-to-person (A2P) messaging sent from standard ten-digit long code (10DLC) phone numbers. Businesses register a brand (their verified identity) and a campaign (their declared messaging use case), which is vetted and approved. Registered traffic gets sanctioned delivery routes and defined throughput; unregistered automated traffic is heavily filtered by carriers.
Do I need consent to text a lead who filled out a form?
Yes. The submission itself can constitute consent — but only if the form disclosed that texting would follow, named the business doing it, and included standard opt-out language. A number collected without texting disclosure is not consent to text. Keep records of what each lead submitted, when, and what the form said. For legal specifics, consult an attorney.
Why are my business texts not delivering?
The most common cause is sending automated traffic from a number without an approved A2P campaign — carriers filter that silently, with no bounce or error. Other causes: spam-patterned content, public link shorteners, volume spikes from cold numbers, and complaint or opt-out violations. Check registration first, then content, then test on real handsets across major carriers.
Can my agency register one brand and text for all our clients under it?
No — the standard, correct practice is one brand and campaign per client business, registered with that client's legal details, because the messages represent the client, not your agency. Pooling clients under one registration misrepresents the sender and means one client's bad behavior damages deliverability for everyone. Collect each client's legal name, EIN, address, and website at onboarding.
What happens when someone replies STOP?
All messaging to that contact must stop immediately and permanently, across every automation, sequence, and campaign — the standard pattern is one final confirmation message and then silence. This should be enforced automatically by your platform at the sending layer, not handled manually. Continuing to text after STOP generates carrier complaints and is one of the fastest ways to destroy a number's deliverability.
How long does 10DLC registration take?
Brand registration is often quick when details match official business records exactly, but campaign vetting typically takes days — longer if the use case draws extra scrutiny or the submission has inconsistencies. Timelines vary by provider and change over time; check your provider's current documentation. The practical rule: submit registration on day one of onboarding, before ads launch.