SMS Consent Requirements: Why Registration, Consent and Phone Verification Are Three Different Things
A2P registration lets you send, consent lets you market, verification proves the number works. What each layer requires and the evidence to keep.
Published 9 min read
On this page
- The three-layer model
- Layer 1: registration lets you send
- Layer 2: consent lets you market
- Layer 3: verification proves the number works, nothing more
- Where the layers meet: rejection codes that are really consent problems
- Consent wording for opt-in pages, lead ads and event registrations
- The evidence file
Key takeaways
- Three layers decide whether a text is OK to send. Registration lets you send. Consent lets you market. Verification proves the number works. Passing one never covers another.
- Each layer has its own evidence: the approved campaign record, the consent record (form version, disclosure, timestamp, IP, checkbox state) and the lookup or OTP log.
- The FCC's one-to-one consent rule was vacated, and the earlier definition of prior express written consent was formally reinstated on 2025-08-29.[1] Written consent is still the federal standard for autodialed marketing texts.[2]
- Most form requirements people call "TCPA" (unchecked boxes, STOP and HELP, frequency, rates, no data sharing) are carrier and aggregator vetting rules. Label each element by where it comes from.
- An OTP proves someone controls the phone. It doesn't prove they agreed to marketing, and consent doesn't survive the number being reassigned.
Registration, consent and verification are three separate layers, and each one answers a different question. Carrier registration tells carriers your business may send from a number. Legal consent tells you a specific person agreed to your marketing texts. Verification tells you the number is real and reachable. Teams blur them all the time: "we're A2P approved, so we're compliant," or "they verified with a code, so they opted in." Neither is true.
We run the texting for coaching, course and event funnels, and consent captured at registration feeds every reminder that follows. Get it right once, on the form, and the rest of the sequence stands on it.
The three-layer model
Framework
Registration, consent, verification
- Registration: may this brand send from this number? Governed by carrier policy through The Campaign Registry and your provider. Evidence: the approved brand and campaign IDs, and the numbers attached. It does not prove any person consented.
- Consent: may we send this person marketing texts? Governed by the TCPA, the FCC's rules and state laws. Evidence: form version, disclosure text, timestamp, IP address, checkbox state, source page and the opt-out log. It does not prove the number is real or still theirs.
- Verification: is this number real, mobile and controlled by the registrant? No governing rule; it's operational. Evidence: the lookup result or OTP log. It does not grant permission to market or carrier approval.
Victory's three-layer model for SMS compliance. Rules credited to the FCC, CTIA, carriers and the platforms cited.
The layers meet in places. Carrier reviewers read your consent wording during registration, and a reassigned number can quietly break consent you once had. But they never merge. Keep three records, not one.
Layer 1: registration lets you send
A2P 10DLC is the carrier framework for business texts from ordinary 10-digit numbers. Twilio describes its purpose as making that traffic verified and consensual. You register a brand, then a campaign describing the use case and opt-in flow, then attach numbers.[3] Send from a number that isn't on an approved campaign and Twilio blocks it with error 30034.[4]
Notice what's being registered: a description of how people opt in. Approval means carriers accept that description. It isn't an audit of your list, and it doesn't make any individual's consent valid. Our A2P 10DLC guide covers getting approved.
Layer 2: consent lets you market
What prior express written consent requires
For autodialed or prerecorded marketing, the FCC's rule requires prior express written consent. That means a written agreement bearing the person's signature, where an E-SIGN electronic signature counts, authorizing the seller's marketing to a specific number. It must disclose that agreeing isn't a condition of purchase.[2]
That's the federal list. It's shorter than most templates suggest.
One 2026 qualification. The Fifth Circuit held on 2026-02-25 that the TCPA itself permits oral or written consent for autodialed and prerecorded calls, contrary to the FCC's written-consent rule.[5] That ruling binds only Texas, Louisiana and Mississippi. Carriers and several states still expect written consent for marketing texts, so it's no reason to drop the written opt-in.
Opt-outs are part of consent. The rule says people can revoke by any reasonable method, including replies such as "stop", "quit", "end", "revoke", "opt out", "cancel" or "unsubscribe", and you must honor it within 10 business days.[2]
What changed when one-to-one was vacated (and what didn't)
In 2023 the FCC adopted a rule limiting consent to one seller at a time. The Eleventh Circuit vacated that part of the order on 2025-01-24.[6] The FCC then formally reinstated the earlier definition of prior express written consent, effective 2025-08-29.[1] The one-to-one text never took effect.
Plenty of pages haven't caught up. One compliance site's consent article still says consent "now has to be one-to-one" as of our 2026-10-04 check.[7] Under the federal rule, forms don't need a checkbox per seller.
What didn't change is carrier policy. CTIA says consent collected for one campaign isn't transferable to another, and that lists that were rented, sold or shared shouldn't be texted.[8] So even without one-to-one, you can't move a list between brands or programs.
State rules: Florida as the example
States add their own layer. Florida's Telephone Solicitation Act requires prior express written consent for autodialed telephonic sales calls, which include texts. Before suing over texts, a recipient must reply STOP and give the seller 15 days to stop. Violations carry $500 each, up to three times that if willful.[9] Oklahoma's law also requires prior express written consent for automated solicitations.[10] If you text nationally, counsel should map your list against the state rules.
Where each form element comes from
Most "TCPA consent language" templates mix three sources together. Separating them tells you which elements are law and which are carrier policy:
| Element | Source |
|---|---|
| Signed written agreement, the number, the seller, "not a condition of purchase" | Federal rule, 47 CFR 64.1200(f)(9)[2] |
| Revocation by any reasonable method, honored in 10 business days | Federal rule, 64.1200(a)(10)[2] |
| Program description, sender identity, fees and opt-out in the call to action | CTIA guidance[8] |
| Checkbox unchecked by default; marketing separate from transactional | HighLevel rejection codes 30925 and 30913[11] |
| SMS box separate from general terms, and optional if the phone field is required | Telnyx 10DLC vetting rules[12] |
| Privacy policy says mobile opt-in data won't be shared | Twilio rejection code 30932[13] |
| Confirmation text on opt-in; reconfirm if no message within 30 days | T-Mobile Code of Conduct[14] |
| Florida written consent for autodialed sales texts | Fla. Stat. 501.059[9] |
Carrier and aggregator rules aren't law, but a campaign that breaks them doesn't get approved, and approved campaigns that drift can be suspended.
The T-Mobile row matters for events. A registrant who signs up seven weeks out and gets no text for 30 days should be reconfirmed before the reminder sequence starts.[14] Send the confirmation text at registration and you avoid the problem.
Layer 3: verification proves the number works, nothing more
A line-type lookup tells you whether a number is mobile, landline, VoIP, toll-free or one of several other types.[15] An OTP proves the person typing the form controls that phone right now. Both are worth doing. Neither is consent.
Consent also decays. The FCC estimated in 2018 that about 35 million US numbers are disconnected and made available for reassignment each year.[16] Consent belongs to the person who gave it, not the number. The FCC's safe harbor protects you only if you had consent and its Reassigned Numbers Database wrongly reported the number as not disconnected.[2] Old consent on an aged list is weaker than it looks.
We haven't found a court that has held an OTP, a double opt-in or a bare keyword text, on its own, establishes prior express written consent. Don't treat verification as a shortcut. Our phone verification statistics cover what verification does deliver.
Where the layers meet: rejection codes that are really consent problems
Registration reviewers are your first consent audit. HighLevel's rejection codes include:[11]
- 30909: the call to action or message flow can't be verified.
- 30913: marketing consent has to be separate from transactional consent.
- 30924: consent language is missing frequency, opt-out or rates disclosures.
- 30925: the checkbox must be unchecked by default.
Twilio adds 30932, a rejection when the privacy policy or opt-in flow allows mobile opt-in data to be shared with third parties or lead generators.[13] Fix these and you've also fixed the most common holes in your consent record.
Consent wording for opt-in pages, lead ads and event registrations
These are drafts in our own words, written to show which elements go where. They are examples for your counsel to review, not approved language. Put the text right next to the checkbox. A court in a different context found that an inconspicuous hyperlink to terms didn't bind a buyer.[17] Visibility is the point.
Opt-in page, marketing box (unchecked): "Yes, send me recurring automated marketing texts from [Brand] at the number above. Message frequency varies. Msg & data rates may apply. Reply STOP to opt out, HELP for help. Consent is not a condition of purchase. See our [Privacy Policy]."
Event registration, two unchecked boxes: "Text me reminders about [Event]: dates, access details and schedule changes." And separately: "Also send me recurring automated marketing texts about future events and offers from [Brand]." Each box carries the frequency, rates, STOP and HELP, and "not a condition of purchase" lines, and neither is required to register.
Meta lead ad, consent checkbox (optional, unchecked): "I agree to receive recurring automated marketing and reminder texts from [Brand] at the number provided. Message frequency varies. Msg & data rates may apply. Reply STOP to opt out. Consent is not a condition of purchase." Link the privacy policy in the form.
One case comes up often on our calls: the person who texts you first. CTIA treats a conversation the consumer starts as consent to reply to that conversation, not as consent to marketing.[8] A keyword text is a good start. Route it to counsel before you use it for promotions.
The evidence file
Keep one record per layer, per contact:
Consent evidence file
- Registration: brand and campaign IDs, approval date, numbers attached.
- Consent: form URL and version, the exact disclosure text shown, checkbox state, timestamp, IP address, and the lead source.
- Confirmation: the opt-in confirmation text and when it went out.
- Opt-outs: every STOP or revocation and the date it was honored.
- Verification: the lookup result or OTP log, kept separately from consent.
For how consent fits with email authentication, A2P and list hygiene, start with our deliverability and compliance guide. We track which TCPA rules are actually in force in TCPA in 2026. If you'd like us to audit your opt-in flow, book a strategy call.
Frequently asked questions
Sources
- 1.Final rule reinstating the prior version of 47 CFR 64.1200(f)(9), 90 FR 42137. FCC via Federal Register, 2025-08-29.
- 2.47 CFR 64.1200, Delivery restrictions (sections (a)(10), (f)(9) and (m)). eCFR via Cornell LII, current, checked 2026-10-04.
- 3.A2P 10DLC overview. Twilio Docs, 2026-07-07.
- 4.Error 30034: US A2P 10DLC, message from an unregistered number. Twilio Docs, living doc, checked 2026-10-04.
- 5.Bradford v. Sovereign Pest Control, No. 24-20379. US Court of Appeals for the Fifth Circuit, 2026-02-25.
- 6.Insurance Marketing Coalition v. FCC, No. 24-10277. US Court of Appeals for the Eleventh Circuit, 2025-01-24.
- 7.FCC TCPA marketing text messages: prior express written consent. LeadCompliant, checked 2026-10-04.
- 8.Messaging Principles and Best Practices. CTIA, 2023-05.
- 9.Fla. Stat. 501.059, Telephone solicitation (Florida Telephone Solicitation Act). Florida Legislature, 2026 statutes, amended ch. 2023-150.
- 10.Oklahoma Telephone Solicitation Act, Enrolled HB 3168. Oklahoma Legislature, 2022, effective 2022-11-01.
- 11.A2P campaign rejections: required fixes and vetting errors. HighLevel Help Center, 2026-09-09.
- 12.10DLC opt-in form. Telnyx Support, 2026-07-22, checked 2026-10-04.
- 13.Error 30932: mobile data sharing in privacy policy. Twilio Docs, living doc, checked 2026-10-04.
- 14.T-Mobile Code of Conduct, v2.2. T-Mobile, 2020-11.
- 15.Lookup v2 API: Line Type Intelligence. Twilio Docs, 2026-07-24.
- 16.Second Report and Order (FCC 18-177), Reassigned Numbers Database. Federal Communications Commission, 2018-12-13.
- 17.Valiente v. NexGen Global, No. 23-13308 (unpublished). US Court of Appeals for the Eleventh Circuit, 2025-11-10.
- 18.Oztix case study. Google Wallet partner case studies, undated, checked 2026-10-04.

Written by
Ray GillespieCo-Founder & COO
Ray runs day-to-day operations across every Victory engagement, building the systems, automations and AI-powered workflows that hold the machine together. He has overseen operations behind more than $120M in revenue.
Part of the guide: Deliverability and Compliance in 2026: Gmail, Yahoo and Microsoft Sender Rules, A2P 10DLC and the TCPA