A2P 10DLC rule registry
This is where most real rejections happen. These rules cover the opt-in surface itself, the disclosures that must appear on it, consent scope and gating, the sixteen collection methods each with its own evidence burden, and the artifacts an offline programme has to supply instead of a URL.
The consent wording quoted in the message flow must be the wording actually printed on the live opt-in surface.
The subscriberOptin, subscriberOptout and subscriberHelp campaign attributes must each be set true, and the HELP declaration must have a keyword set behind it.
A campaign must not declare a subscriber attribute that its supplied opt-in, STOP and HELP message bodies contradict.
A submitted evidence URL must resolve, be publicly reachable, and not require authentication.
The opt-in URL must present a valid, verifiable TLS certificate — not expired, self-signed, or issued for another hostname.
The page at the submitted opt-in URL must contain the opt-in form itself, not merely mention or link to it.
The business name visible on the consent artifact must match the registered brand legal name or DBA.
Where consent is collected on a platform, agency, or franchisee surface, the evidence must identify the end business the consumer is agreeing to hear from.
The submission must rest on a consumer act that agreed to messaging — not on an existing relationship, a published number, or a prior transaction.
The opt-in form must collect a mobile number through a field of its own.
Where the phone field is mandatory for another purpose, an additional and separately optional SMS consent control is required.
The registered opt-in page must load for an anonymous visitor, not sit behind a login, paywall, or member area.
SMS opt-in language and a consent control must appear on every page of the site that collects a mobile number, not only the page named in the registration.
The consent language on a secondary phone-collecting page must carry the opt-out instruction and the policy links, not merely mention texting.
The label on the consent control must say what the consumer is subscribing to — a bare "Text me" or "Contact me" is not specific enough.
The consent wording must name text messaging explicitly rather than referring generally to being contacted.
A consumer who declines SMS at signup must retain the same access to the underlying service as one who accepted.
A programme must not make receiving text messages the only way to sign up or to be served, with no other channel offered.
Where the disclosure says consent is not a condition of purchase, the form or checkout must actually complete with the SMS box unticked.
A messaging opt-in must not be offered in exchange for entry to a prize draw, giveaway, raffle or contest.
Paper forms, till screens and printed advertising must not make SMS consent a condition of the purchase, the discount, or completing the form.
The point-of-consent disclosure must carry a programme or product description — what this particular messaging programme is.
The Terms and Privacy Policy links beside the consent control must resolve to live pages carrying those documents — not 404s, placeholders, or unfinished templates.
The disclosure, or the privacy policy it links to, must state that mobile information is not shared with third parties for marketing purposes.
No part of the opt-in surface or its linked policy may indicate that opt-in data is shared with third parties.
The consent disclosure and the programme advertising must not misrepresent what the programme is, what it costs, or what the consumer gets.
The consent disclosure must appear on the same page, popup, or form as the phone-number field — not on a separate linked page.
The consent disclosure must be rendered on the page as it loads — not behind a tooltip, an accordion, a "read more" toggle, or pushed out of the main content.
The consent disclosure must be clear and conspicuous, and set apart from the advertising copy and any other disclosures around it.
The consent language must name each business that will send under it, not only the one the consumer is transacting with.
The authorised sending entities must be disclosed before the consumer acts, not on the confirmation screen or in the first message.
The opt-in language must not purport to grant consent to "our partners", "affiliates", "third parties", or a linked partner list.
A single opt-in control must not enrol the consumer into several messaging programmes or use cases at once.
Consent collected for email or phone calls must not be treated as consent to text, and an email list must not be migrated to SMS without a fresh opt-in.
Messaging consent must not share a control or a sentence with email or phone-call consent.
The consent record must store the specific telephone number the consumer authorised messages to be sent to.
A campaign whose business model is acquiring, aggregating or monetising opt-in subscriber lists must not be registered.
Permission to message obtained by court order, or by any other mechanism the consumer did not initiate, is not consent.
An organisational or governmental exemption from the TCPA does not remove the requirement to obtain an opt-in.
Where a 47 CFR 64.1200(a)(9) exemption is relied on, every condition attached to it must be satisfied — free to the end user, within the message caps, sender identified, and opt-out in each message.
A single toll-free number must be associated with exactly one business.
A campaign carrying promotional content must rest on prior express written consent, and the submission must describe that consent as a written record.
A recording of the consumer agreeing does not satisfy a requirement for consent in writing.
For a marketing campaign, the call to action, the message flow and the campaign description must each state that the messages are marketing or promotional.
A campaign declaring age-gated content must verify age at the point of consent, not merely ask for self-attestation.
The opt-in / message flow must reference a durable artifact evidencing how consent is collected — a screenshot of the opt-in screen, a PDF or scan of the paper form, the verbal script, or a capture of the QR landing page.
The attached artifact must depict the point of consent collection, not an unrelated page, logo, or product screen.
The messaging opt-in must be its own control, not bundled into a general "I accept the Terms and Privacy Policy" checkbox.
Consent must be captured by a deliberate affirmative action — a checkbox, toggle, or signature — never inferred from form submission.
The opt-in control must not be pre-selected; consent must be a deliberate act.
The required disclosures must be visible on the consent surface itself; burying them in a linked Terms page does not satisfy the requirement.
The disclosure at the point of consent must name the business that will send the messages.
A promotional opt-in must carry the explicit statement that consent is not a condition of any purchase.
The consumer must be told what kind of messages they are agreeing to receive.
The disclosure must tell the consumer they can reply STOP to stop receiving messages.
Abandoned-cart messaging requires a confirmed double opt-in and must not treat cart placement as consent.
The message flow must name where consent happens concretely enough for a reviewer to find and verify it.
A campaign declaring HELP keywords must supply the help reply that will be sent.
The auto-reply sent after a keyword opt-in must carry the brand, frequency, rates, STOP and HELP.
A text-to-join campaign must supply the advertisement wherever the keyword is promoted, carrying the full disclosure.
Only the business that collected the consent may message the consumer; purchased lists and shared opt-ins are prohibited.
The consumer must be able to decline SMS and still complete the purchase, signup, or account creation.
The opt-out confirmation must confirm no further messages will be sent, name the brand, and contain no promotional content.
The form must show the full consent disclosure, a messaging tick box separable from the phone field, and a signature and date.
A campaign collecting consent on paper must supply the form, showing the disclosure and the consent control.
A QR code used for opt-in must land on a page carrying the full consent disclosure, or the disclosure must be printed beside the code.
A single opt-in must not bundle promotional marketing with informational or transactional messaging.
The script must capture explicit consent and state the brand, message types, frequency, rates, opt-out, help, and the privacy policy.
A campaign collecting consent by phone must supply the exact script read to the consumer.
A brand collecting consent entirely offline must still have a verifiable online presence a reviewer can find.
The artifact must depict the brand's own working opt-in surface — not stock imagery, a design template, or a mockup of a page that does not exist yet.
An informational campaign collecting consent by phone must supply both a mockup of the opt-in workflow and the message content that will be sent under it.
On a form that exists for something other than SMS signup, the phone-number field must not be required to submit.
Where the phone-number field is mandatory, the text next to it must say whether the number will be used for text messages.
A payment terminal or kiosk collecting messaging consent must require the consumer to enter their number, not present one already filled in.
The control that lets a consumer skip or decline messaging must not be disabled, greyed out, or hidden.
Participation in a promotion, loyalty scheme or offer must not require the consumer to be enrolled in text messaging.
The call-to-action must give the consumer a way to reach a person — a support email, phone number, or help page.
The links to the Privacy Policy and the Terms & Conditions must be labelled as those documents, and the pages they open must title themselves the same way.
The consent language must appear directly beneath the phone field or immediately above the submit control.
Consent inferred from a chat widget or an inbound conversation must not be used to justify a marketing use case.
Consent given by texting a keyword extends only to the programme advertised alongside that keyword.
A marketing text-to-join CTA must carry the federal written-consent elements — the ATDS disclosure, the not-a-condition statement, and the number being authorised.
Where the programme solicits donations, the point of consent must say so.
The artifact must be readable at the resolution supplied — cropped, blurred, or truncated evidence does not establish consent.
The consumer must be told the messages are automated and recurring — a TCPA express-written-consent element.
The disclosure must tell the consumer how often messages will arrive.
The disclosure must tell the consumer they can reply HELP for assistance.
A link to the Privacy Policy must be present beside the opt-in control, not only in the page footer.
"Message and data rates may apply" (or a clear equivalent) must appear at the point of consent.
A link to the Terms of Service must be present beside the opt-in control, not only in the page footer.
The collection method described in the message flow must be consistent with the artifact and the website.
A campaign messaging a pre-existing list must describe when and how that consent was originally obtained.
An IVR flow must require a distinct keypress or spoken confirmation specifically for messaging consent.
The declared opt-out keywords should include the FCC per-se revocation words: STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, UNSUBSCRIBE.
The flow must state how the consumer’s spoken agreement is captured and retained — recording, transcript, IVR log, or timestamped CRM entry.
The messaging consent control should be labelled optional where the form around it collects anything required.
The call-to-action should state the phone number or short code the programme will send from.
The word "free" must not appear in the CTA except for genuine free-to-end-user programmes; synonyms must be paired with the rates disclosure.
A modal or pop-up is not an acceptable method of displaying the required terms.
The flow should evidence retention of the consent record: number, timestamp, medium, the exact wording agreed to, and the consenting party.
Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.