Executive Summary
US mobile carriers and their CSP partners enforce A2P 10DLC rules that go beyond “register once and forget.” Carrier guidelines typically expect verified Brand identity, accurate Campaign use cases, consensual traffic, functional STOP/HELP, and avoidance of evasion techniques such as snowshoeing. Provider documents (for example Bandwidth’s T-Mobile 10DLC article) also describe non-compliance pass-through fee categories for certain Code of Conduct violations. CTIA Messaging Principles supply industry best-practice framing for informational versus promotional programs. This guide translates carrier expectations into an operating checklist without inventing universal MPS or fine schedules.
Short answer: Follow carrier/CSP 10DLC expectations by registering Brand + Campaign, aligning samples to real traffic, collecting verifiable opt-in, honoring STOP, and avoiding evasion. Exact fees and throughput are provider- and carrier-specific—read your CSP’s current docs.
Who This Is For / Who It Is Not For
Who this is for
- Brands sending US A2P SMS on long codes
- Platforms enforcing policy for many customers
- Compliance teams writing SMS standards
Who this is not for
- Teams seeking a single universal fee table
- Non-US domestic-only messaging
Definitions
| Term | Meaning |
|---|---|
| 10DLC | Registered US long code A2P path |
| MNO | Mobile network operator / carrier |
| CSP | Campaign Service Provider |
| Code of Conduct | Carrier messaging rules referenced in CSP docs |
| Snowshoeing | Spreading traffic across numbers to evade filters |
| SHAFT-C | Common prohibited content shorthand in industry docs |
What Carrier Guidelines Usually Cover
Carrier and CSP materials commonly address: Brand/Campaign registration; number association; consent and opt-out; prohibited content; throughput and daily caps; and enforcement for evasion or repeated content violations. Always read the documents your CSP points to for each MNO—AT&T, T-Mobile, and Verizon policies are not identical in presentation.
Registration and Number Association
Unregistered US 10DLC traffic is widely blocked on major platforms. Approval of a Campaign is not enough if production From numbers are not associated. Sole Proprietor paths often allow only one long code—confirm with your CSP.
Consent, Content, and CTIA Framing
CTIA principles distinguish conversational, informational, and promotional messaging. Promotional programs need written promotional consent. Adding coupons to informational texts can reclassify them. Carrier filtering still applies after registration.
Non-Compliance Categories (Provider-Documented Examples)
Bandwidth’s T-Mobile 10DLC documentation lists pass-through categories such as text enablement before ownership verification, program evasion (snowshoeing/dynamic routing/unauthorized number replacement), and repeated content violations. Treat dollar amounts as provider-published and date-specific—not universal law.
Decision Framework
1) Inventory policies your CSP links for each MNO. 2) Map your templates to use cases. 3) Verify Brand/Campaign/number status. 4) Audit consent and STOP. 5) Remove evasion patterns. 6) Document exceptions with counsel. 7) Re-read CSP changelogs monthly.
Requirements Matrix
Risks and Failure Modes
| Risk | Mitigation |
|---|---|
| Ignoring MNO-specific CSP docs | Assign owner to read linked carrier articles |
| Snowshoeing after blocks | Consolidate onto approved Campaign numbers |
| Assuming registration equals consent | Run separate TCPA audit |
| Stale samples vs live traffic | Monthly template sync |
| Unregistered senders in production | Daily error-code monitor |
Implementation Checklist
| Step | Owner | Artifact |
|---|---|---|
| Collect CSP MNO policy links | Messaging admin | Policy binder |
| Audit Brand/Campaign/numbers | Eng | Status export |
| Consent + STOP review | Compliance | Audit report |
| Remove evasion patterns | Ops | Change ticket |
| Re-read changelogs monthly | Admin | Runbook update |
Soft CTA
Use MyTCRPlus tools to catch packaging issues before submit—not as a substitute for CSP policy pages.
FAQ
Are carrier guidelines the same as TCPA?
No. Guidelines/CSP policies are commercial enforcement; TCPA is law.
Do I need to read every MNO PDF?
Read what your CSP requires; escalate edge cases.
Can throughput differ by carrier?
Yes—e.g., T-Mobile daily caps appear in provider docs.
Is registration enough?
Necessary but not sufficient—consent and content still matter.
What is snowshoeing?
Spreading similar traffic across many numbers to evade limits/filters—high risk.
Where do fees appear?
On CSP invoices as pass-throughs when applicable—confirm current schedules.
Do CTIA rules bind me legally?
Industry best practices; carriers/CSPs may enforce related expectations.
How often do guidelines change?
Periodically—monitor CSP changelogs.
Key Takeaways
- Register and associate correctly
- Align samples to live traffic
- Honor STOP quickly
- Avoid evasion tactics
- Read CSP-specific MNO docs
- Separate TCPA analysis
- Use tools to preflight packaging only
Operating Appendix
Expanded Operating Playbook
90-day compliance calendar
| Day range | Milestone |
|---|---|
| 1–7 | Inventory senders, templates, consent sources; freeze risky blasts |
| 8–21 | Website + privacy SMS section + opt-in UI fixes live |
| 15–30 | Brand verified; Campaign submitted through CSP |
| 30–45 | Remediate rejections; attach numbers; soak test |
| 45–60 | Enable full operational volume with monitoring |
| 60–90 | Marketing enablement after consent audit; set quarterly review |
RACI snapshot
| Activity | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Legal entity / EIN accuracy | Controller | General counsel | CSP admin | Exec sponsor |
| Campaign samples | Marketing ops | Compliance lead | Legal | Support |
| Opt-in capture | Product | Compliance lead | Engineering | Marketing |
| STOP suppression sync | Engineering | Ops director | Support | Compliance |
| Incident response | Eng on-call | Ops director | CSP support | Executives |
Evidence pack to retain
Dated opt-in screenshots or videos, privacy policy HTML/PDF captures, versioned sample message sets, Brand and Campaign IDs from your CSP, STOP test threads, rejection reason exports with fix notes, sender-pool association audits, and a changelog for every production From number.
Metrics you can actually observe
Track unregistered/block error rates, Campaign rejection cycles, STOP rates by program, time-to-suppress after opt-out, quarterly template-drift findings, and privacy URL uptime. Do not invent search volumes, keyword difficulty, or industry-wide fine totals for leadership decks.
Submit quality gate checklist
Confirm legal name and EIN match tax records where required; website loads publicly; privacy and terms URLs are SMS-aware; opt-in is one-to-one and not pre-checked; samples name the Brand and match the use case; content attributes match samples; STOP and HELP work; an owner is assigned to associate numbers after approval.
First 24 hours after a production SMS outage
Freeze marketing sends; pull CSP error codes; classify whether the failure is unregistered traffic, Campaign rejection, carrier filtering, or consent complaints; notify customer support; open one structured CSP ticket with Brand/Campaign IDs; do not rotate new unregistered long codes; write a timeline memo for leadership; schedule a postmortem with preventive owners.
Sustaining compliance after go-live
Monthly, compare live templates to registered samples. Quarterly, re-test STOP across every system that can send and re-verify privacy URLs. After mergers or DBA changes, treat Brand identity as a migration project. Assign someone to read CSP and FCC changelogs within one business day of publication and update the internal runbook.
Cross-Functional Training Outline
Module A — Why carriers care: Explain application-to-person versus person-to-person messaging in plain language. Show a redacted unregistered-block screenshot so staff understand why “just send it” fails.
Module B — Brand identity: Walk through mismatches between EIN letters, legal footers, and website trade names using anonymized examples.
Module C — Campaign packaging: Workshop rewriting a vague “we text customers” description into a who/whom/why paragraph. Critique sample messages missing Brand names or opt-out language.
Module D — Consent: Contrast operational versus marketing checkboxes. Practice documenting verbal consent with timestamps and script versions.
Module E — Incident response: Role-play a Friday marketing blast that spikes STOP replies and complaint emails. Practice containment language for support.
Module F — Vendors: Evaluate CRM claims that “we handle TCR,” including which legal Brand is actually registered and who owns rejection fixes.
Require quizzes for anyone with blast permissions. Store completion records. Refresh training after major policy updates or any severity-1 messaging outage.
Vendor and CSP Coordination Tips
Send your CSP a single well-structured ticket that includes Brand ID, Campaign ID, raw failure_reason text, links to live opt-in and privacy pages, and before/after screenshots. Avoid fragmented emails from five stakeholders that create contradictory instructions. Ask explicitly whether a rejected field is editable or requires Campaign recreation. Confirm how Sole Proprietor, Low-Volume Standard, and Special use cases behave on that specific CSP—names, limits, and fees differ by provider and change over time. If you use multiple CSPs, do not assume identical attribute enums or identical error codes. For ISVs and agencies, clarify reseller ID / Other Responsible Parties requirements before the first submit. Keep a shared internal FAQ so customer-success teams never promise “24-hour TCR approval” or universal message-per-second figures.
Documentation Templates (Illustrative — Customize With Counsel)
Campaign description starter: “Messages are sent by [Legal Brand] to [customers who opted in via URL or process] for [specific purposes such as appointment reminders or order updates]. Recipients may reply STOP to opt out and HELP for help. Message frequency varies based on [orders, appointments, or account activity].”
Opt-in disclosure starter: “By checking this box, you agree to receive [program type] text messages from [Brand] at the number provided. Consent is not required as a condition of purchase. Message frequency varies. Message and data rates may apply. Reply STOP to opt out, HELP for help. Privacy Policy: [URL].”
Incident memo starter: Date and time detected; error codes observed; customer impact summary; which layer failed (Brand, Campaign, number association, or consent); immediate containment steps; fix owner; ETA; and prevention actions with due dates.
Do not paste these starters unchanged into healthcare, insurance, financial, political, or other highly regulated programs without specialized review.
Extended Stewardship Narrative
Treat messaging compliance as an operating system, not a one-time registration event. The teams that stay out of rejection loops are the teams that keep public disclosures, registered samples, and production templates synchronized every month. When marketing launches a new promo calendar, update samples or add a Marketing Campaign instead of silently drifting content on a Customer Care registration. When legal refreshes privacy policies, notify the messaging admin the same day so Campaign URLs still resolve to accurate language. When finance changes legal entities after an acquisition, pause assumption that the old Brand record remains valid. When support hears “stop texting me” by phone, ensure that request reaches the same suppression list as a STOP keyword. These habits are mundane—and they prevent most of the dramatic outages that leadership only notices when revenue texts stop landing.
Expanded Operating Playbook
90-day compliance calendar
| Day range | Milestone |
|---|---|
| 1–7 | Inventory senders, templates, consent sources; freeze risky blasts |
| 8–21 | Website + privacy SMS section + opt-in UI fixes live |
| 15–30 | Brand verified; Campaign submitted through CSP |
| 30–45 | Remediate rejections; attach numbers; soak test |
| 45–60 | Enable full operational volume with monitoring |
| 60–90 | Marketing enablement after consent audit; set quarterly review |
RACI snapshot
| Activity | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Legal entity / EIN accuracy | Controller | General counsel | CSP admin | Exec sponsor |
| Campaign samples | Marketing ops | Compliance lead | Legal | Support |
| Opt-in capture | Product | Compliance lead | Engineering | Marketing |
| STOP suppression sync | Engineering | Ops director | Support | Compliance |
| Incident response | Eng on-call | Ops director | CSP support | Executives |
Evidence pack to retain
Dated opt-in screenshots or videos, privacy policy HTML/PDF captures, versioned sample message sets, Brand and Campaign IDs from your CSP, STOP test threads, rejection reason exports with fix notes, sender-pool association audits, and a changelog for every production From number.
Metrics you can actually observe
Track unregistered/block error rates, Campaign rejection cycles, STOP rates by program, time-to-suppress after opt-out, quarterly template-drift findings, and privacy URL uptime. Do not invent search volumes, keyword difficulty, or industry-wide fine totals for leadership decks.
Submit quality gate checklist
Confirm legal name and EIN match tax records where required; website loads publicly; privacy and terms URLs are SMS-aware; opt-in is one-to-one and not pre-checked; samples name the Brand and match the use case; content attributes match samples; STOP and HELP work; an owner is assigned to associate numbers after approval.
First 24 hours after a production SMS outage
Freeze marketing sends; pull CSP error codes; classify whether the failure is unregistered traffic, Campaign rejection, carrier filtering, or consent complaints; notify customer support; open one structured CSP ticket with Brand/Campaign IDs; do not rotate new unregistered long codes; write a timeline memo for leadership; schedule a postmortem with preventive owners.
Sustaining compliance after go-live
Monthly, compare live templates to registered samples. Quarterly, re-test STOP across every system that can send and re-verify privacy URLs. After mergers or DBA changes, treat Brand identity as a migration project. Assign someone to read CSP and FCC changelogs within one business day of publication and update the internal runbook.
Cross-Functional Training Outline
Module A — Why carriers care: Explain application-to-person versus person-to-person messaging in plain language. Show a redacted unregistered-block screenshot so staff understand why “just send it” fails.
Module B — Brand identity: Walk through mismatches between EIN letters, legal footers, and website trade names using anonymized examples.
Module C — Campaign packaging: Workshop rewriting a vague “we text customers” description into a who/whom/why paragraph. Critique sample messages missing Brand names or opt-out language.
Module D — Consent: Contrast operational versus marketing checkboxes. Practice documenting verbal consent with timestamps and script versions.
Module E — Incident response: Role-play a Friday marketing blast that spikes STOP replies and complaint emails. Practice containment language for support.
Module F — Vendors: Evaluate CRM claims that “we handle TCR,” including which legal Brand is actually registered and who owns rejection fixes.
Require quizzes for anyone with blast permissions. Store completion records. Refresh training after major policy updates or any severity-1 messaging outage.
Vendor and CSP Coordination Tips
Send your CSP a single well-structured ticket that includes Brand ID, Campaign ID, raw failure_reason text, links to live opt-in and privacy pages, and before/after screenshots. Avoid fragmented emails from five stakeholders that create contradictory instructions. Ask explicitly whether a rejected field is editable or requires Campaign recreation. Confirm how Sole Proprietor, Low-Volume Standard, and Special use cases behave on that specific CSP—names, limits, and fees differ by provider and change over time. If you use multiple CSPs, do not assume identical attribute enums or identical error codes. For ISVs and agencies, clarify reseller ID / Other Responsible Parties requirements before the first submit. Keep a shared internal FAQ so customer-success teams never promise “24-hour TCR approval” or universal message-per-second figures.
Disclaimer
This article is for informational purposes only and is not legal advice. Carrier policies, CSP fees, Campaign outcomes, and TCPA or TSR exposure depend on your facts. Confirm current requirements with your provider and qualified counsel. MyTCRPlus does not guarantee approval, deliverability, or legal outcomes.