Executive Summary
10DLC compliance is the operating discipline that lets US businesses send application-to-person SMS and MMS over local 10-digit numbers without flying blind into carrier filters, registration rejections, or consent gaps. It is not a government certificate you hang on the wall. It is a stack: register your Brand and Campaign(s) through The Campaign Registry (TCR) ecosystem via your communications service provider (CSP); send only what you registered; collect and honor consent appropriate to the message type under TCPA/FCC rules and CTIA best practices; and keep public disclosures, samples, and production templates aligned. This guide is a practical 10DLC 101 for operators—covering definitions, registration, consent, disclosures, laws vs carrier rules, rejection remediation, risks, and checklists.
Short answer: 10DLC compliance means (1) registering Brand + Campaign(s) for US A2P traffic on 10-digit long codes, (2) sending content that matches your Campaign with working STOP/HELP, and (3) documenting consent that fits the message type—especially prior express written consent for marketing. There is no single “10DLC certification” issued by the FCC; carriers and CSPs enforce registration, while FCC TCPA rules address consent separately.
Who This Is For / Who It Is Not For
Who this is for
- Business owners launching SMS for the first time
- Ops and marketing leads inheriting an unregistered texting tool
- Compliance teams building a reusable 10DLC control framework
- ISVs who must explain registration to their customers
Who this is not for
- Teams seeking a laminated “certified compliant” badge that ends legal risk
- Pure toll-free or short-code programs (related but separate paths)
- Non-US messaging programs
- Readers wanting invented fine schedules or universal MPS numbers
Definitions (10DLC 101)
| Term | Meaning |
|---|---|
| 10DLC | 10-digit long code used for registered A2P messaging in the US |
| A2P / Non-Consumer | Business/application-originated messaging (vs consumer P2P chat) |
| Brand | Who is sending — legal business identity in TCR |
| Campaign | What you send — use case, samples, opt-in/out, HELP |
| TCR | The Campaign Registry — industry registry used in the 10DLC path |
| CSP | Your messaging provider that submits and routes |
| Trust Score / vetting | Outcome that can influence throughput eligibility (provider-dependent) |
| PEWC | Prior express written consent for telemarketing texts |
| Message flow | Narrative of how end users opt in |
| Unregistered traffic | 10DLC sends without approved Brand/Campaign — often blocked |
What 10DLC Compliance Is — and Is Not
Is: Carrier/CSP registration + consent discipline + disclosure accuracy + ongoing monitoring.
Is not: A substitute for counsel; a one-time form; a guarantee against filtering; automatic TCPA immunity; the same as toll-free verification.
Per Twilio’s A2P 10DLC docs, anyone sending SMS/MMS over a 10DLC number from an application to the US must register. Toll-free and short codes are outside the 10DLC system.
The Three Layers of 10DLC Registration Compliance
Layer 1 — Brand (identity)
Collect legal name matching tax records, business type, industry, registration number (e.g., EIN), address, authorized representative, and website. Twilio documents that website_url must be functional and related to the business, and rejects parked, login-gated, or unrelated redirects (collect business info).
Brand types commonly include Sole Proprietor, Low-Volume Standard, and Standard—with different campaign limits and daily volume eligibility. Choose based on volume needs and tax ID reality; Sole Proprietor rules are narrow.
Layer 2 — Campaign (use case)
Provide description (typically 40–4096 characters), message_flow (how users opt in), 2–5 sample messages naming the Brand, use-case enum, and flags for embedded links/phones. Privacy Policy and Terms must be publicly accessible when web opt-in is used, including mobile-number non-sharing, frequency, and rates language themes reviewers expect.
Layer 3 — Number assignment
Bind 10DLC numbers to the approved Campaign/Messaging Service only after approval. Buying more numbers does not reliably multiply throughput and can look like snowshoeing if abused.
TCR resources emphasize that CSPs register Brands and that campaign approval timing varies (Campaign Registry resources).
10DLC Laws vs Carrier Rules vs Best Practices
| Question | Frame | Primary references |
|---|---|---|
| May we text this person this content? | Legal consent | 47 CFR § 64.1200; state rules |
| Is our sender/use case registered? | Carrier registration | TCR + CSP onboarding |
| Do our CTAs and opt-outs meet ecosystem norms? | Industry best practices | CTIA Messaging Principles (May 2023) |
| Will this content be filtered? | Network security | CSP AUP + carrier filters |
Calling something “10DLC laws” in search queries usually blends these layers. Be precise in board decks: registration compliance ≠ TCPA compliance.
Consent Requirements Mapped to Message Types
CTIA Exhibit-style framing (informational vs promotional) remains a useful operator model:
- Conversational replies to consumer-initiated texts — still register the number path; document the flow
- Informational reminders, account alerts — purpose-specific express consent; document it
- Promotional offers — express written consent expectations; PEWC under FCC rules for covered telemarketing texts
Registration never creates consent for a recipient. See verbal consent documentation and SMS double opt-in.
Disclosures That Reviewers and Consumers Expect
At opt-in and in program messages as appropriate:
- Brand identity
- Message types / program description
- Message frequency (or “frequency varies” with honest explanation)
- “Message and data rates may apply”
- STOP and HELP instructions
- Link to Privacy Policy (and Terms when required)
Public privacy pages should state non-sharing of mobile numbers for unrelated third-party marketing when that is your practice—and your practice must match the policy.
Step-by-Step Operating Procedure (Decision Framework)
- Inventory every system that can send SMS.
- Classify use cases (care, notifications, delivery, marketing, mixed).
- Fix identity surfaces — legal name, website, privacy, Terms.
- Design consent UX per program; store evidence.
- Select Brand type with finance (fees are CSP-specific).
- Draft Campaign packet — description, message_flow, samples.
- Submit via CSP; track statuses.
- Bind numbers only when approved.
- Enforce send-time consent + suppression.
- Monitor errors, complaints, template drift; remediate.
Detailed walkthrough: How to register with TCR.
Requirements Matrix
| Control | Minimum | Stronger |
|---|---|---|
| Brand registration | Approved Brand | Secondary vetting where beneficial |
| Campaign per use case | One accurate Campaign | Separate marketing Campaign |
| Consent store | Timestamp + source | Full disclosure version + confirmation SID |
| STOP | Platform default keywords | Natural-language opt-out handling |
| Website | Live HTTPS related to Brand | Preference center + SMS Terms page |
| Sample governance | Filed samples | Change control tickets |
| Audit pack | IDs + screenshots | Quarterly evidence refresh |
Risk and Failure Modes
| Risk | Signal | Mitigation |
|---|---|---|
| Unregistered sends | CSP hard fail / block | Gate production on approval |
| Privacy rejection (e.g., 9108-class) | Campaign denied | Fix public privacy SMS clauses |
| Sample drift | Filtering after go-live | Template allowlist |
| Marketing on care consent | Complaints / disputes | Split programs + PEWC |
| EIN / name mismatch | Brand failure | Use CP 575 / 147C exact legal name |
| Snowshoeing | Many numbers, similar content | Request capacity properly |
| Shared opt-in lists | AUP issues | First-party consent only |
Twilio has documented full blocking of unregistered US A2P 10DLC traffic in its changelog for the September 2023 timeframe—confirm current enforcement on your CSP.
Implementation Checklist
| Step | Owner | Artifact |
|---|---|---|
| Sender inventory | IT | System list |
| Use-case matrix | Compliance | Campaign map |
| Legal name + EIN pack | Finance/Legal | CP 575 / docs |
| Website + privacy live | Web | URLs |
| Consent schema | Engineering | Field dictionary |
| Brand submit | Messaging ops | Brand ID |
| Campaign submit | Messaging ops | Campaign ID |
| Number bind | Engineering | Config |
| STOP/HELP QA | QA | Test log |
| Quarterly audit | Compliance | Audit folder |
Pre-submission consistency checks are available via MyTCRPlus tools—useful packaging aids, not approval guarantees.
Common Myths
- “We’re certified.” There is no universal 10DLC certificate replacing ongoing controls.
- “TCR approved us, so TCPA is done.” Consent remains separate.
- “Low volume means no registration.” Application traffic on 10DLC still registers on enforcing CSPs.
- “More numbers = more speed.” Often false; can increase risk.
- “Privacy PDF behind login is fine.” Reviewers typically need public pages.
FAQ
What is 10DLC compliance?
The combined practice of registering Brand/Campaign for local A2P SMS, aligning content and disclosures, collecting appropriate consent, and monitoring ongoing carrier/CSP requirements.
Is there 10DLC certification?
Not as a single FCC-issued certificate. Providers may complete vetting; you still maintain consent and content controls.
Do 10DLC laws come from the FCC?
FCC/TCPA rules address consent for covered calls/texts. 10DLC registration is primarily a carrier ecosystem requirement administered through TCR/CSPs. People search “10dlc laws” for both—answer both layers.
How long does registration take?
Provider- and queue-dependent. Some CSP guides cite multi-week campaign vetting windows; treat any blog average as non-binding.
What is the difference between Brand and Campaign?
Brand = who. Campaign = what/why/how opt-in. You need both for standard 10DLC sending.
Can Sole Proprietors register?
Yes, under Sole Proprietor rules when eligible; if you have an EIN, many paths require Standard/Low-Volume Brand types instead—follow your CSP’s doc.
What happens if I do not comply with 10DLC registration?
Expect blocking, filtering, and/or additional fees depending on CSP enforcement. See related drafts on noncompliance outcomes.
Does compliance require double opt-in?
Not universally for every informational use case, but confirmation messages are a strong best practice for recurring programs, and marketing needs PEWC-grade consent. See double opt-in guide.
How do I fix repeated rejections?
Treat codes systematically—privacy, website, samples, message_flow mismatches. Start with 9108 privacy guidance.
Key Takeaways
- 10DLC compliance = registration + consent + disclosures + monitoring.
- No universal “10DLC certificate” replaces ongoing controls.
- Brand identity accuracy and public privacy pages are foundational.
- Campaign samples and message_flow must match production.
- TCPA consent is separate from TCR registration.
- Unregistered traffic is frequently blocked on major CSPs.
- Build an audit folder you can produce in one day.
- Use tools to package—file through your CSP.
Deep Dive: Building a Reusable Control Framework
Enterprises that treat 10DLC as a ticket (“register us”) relapse into noncompliance when marketing launches a new journey. Instead, create a lightweight control framework:
Policy — Written standard: which message classes exist, required consent per class, retention, and escalation.
Process — Intake form for any new SMS journey: owner, audience, template, links, consent source, Campaign impact.
Systems — Consent service, suppression list, template CMS, CSP status webhook.
Assurance — Quarterly sample-vs-production diff; mystery-shop opt-in pages; random consent evidence pulls.
Vendors — RACI with PMS/CRM/CPaaS partners; contract language for STOP propagation.
This framework scales from a single clinic to a multi-brand portfolio without rewriting folklore each time staff turns over.
Deep Dive: Website and Privacy Failure Patterns
Twilio’s collect-business-info guidance is explicit about website failures: unreachable URLs, parked domains, login walls, and redirects to unrelated brands. Privacy failures often include missing mobile-number non-sharing language, missing frequency/rates disclosures when the site is the opt-in surface, or Terms hosted off-domain behind auth. Before you blame “the algorithm,” open your URLs in a private browser with cookies cleared. If you cannot see the SMS language in two clicks from the homepage footer or opt-in form, reviewers may not either.
Deep Dive: Content After Approval
Approval is not a forever stamp. If you change from appointment reminders to daily promotional blasts, update Campaigns and consent. If you add affiliate offers, revisit sharing language in privacy and CTAs. If complaint rates rise, pause and remediate—CTIA principles emphasize containing unwanted messaging and honoring opt-outs quickly. Keep a change log tying template edits to Campaign versions.
Comparison Table: Immature vs Mature 10DLC Programs
| Dimension | Immature | Mature |
|---|---|---|
| Ownership | One marketer “did TCR once” | Named compliance + ops owners |
| Evidence | Screenshots in Slack | Immutable consent events |
| Templates | Edited live in ESP | Allowlisted, versioned |
| Marketing | Mixed into care sends | Separate Campaign + PEWC |
| Metrics | Only “messages sent” | Consent coverage, STOP, rejects |
| Vendors | Verbal assurances | Contracted RACI + exports |
Extended FAQ Addendum
Does nonprofit status change 10DLC compliance?
Special use cases and fee treatments may exist for eligible charities—confirm with your CSP. Consent and truthful samples still apply.
Are political texts different?
Political messaging often has distinct verification paths (including Campaign Verify tokens in some CSP flows). Do not reuse a standard marketing Campaign for political traffic.
What about RCS?
RCS may ride related business messaging rules as ecosystems evolve; do not assume RCS bypasses consent or brand identity expectations. Confirm with your CSP for 2026 product behavior.
90-Day Maturity Roadmap
Days 1–30 — Stabilize
Register Brand and core Campaigns, fix privacy/website issues, gate unregistered sends, implement STOP tests, and create the audit folder.
Days 31–60 — Separate
Split marketing from transactional journeys, upgrade consent capture to PEWC where needed, align ISV or franchise entity maps, and train staff on verbal scripts.
Days 61–90 — Assure
Run the first quarterly sample-vs-production review, reconcile suppression lists across systems, document vendor RACI, and present a compliance dashboard to leadership (registration coverage, consent completeness, rejection backlog)—without inventing external benchmarks.
Fee Awareness Without Universal Price Claims
Registration and monthly Campaign fees vary by CSP and use case. Provider-published examples (always verify live): Bandwidth publicly lists Brand registration and monthly Campaign fees by type with a three-month commitment note for most campaigns; Telnyx and Twilio publish their own Brand, vetting, and Campaign fee tables. Carrier pass-through segment fees also apply. Never budget from a blog’s “average 10DLC cost” without a CSP quote. See the dedicated 10DLC pricing draft for attributed tables.
Connecting Compliance to Deliverability
Compliance work improves the odds of trusted delivery, but filters still evaluate content, velocity, and complaint behavior. Pair registration with:
- Reasonable send cadences
- Accurate FROM identity in message bodies
- Fast opt-out
- Avoidance of deceptive links
- Separate traffic classes so a promo spike does not contaminate OTP/care reputation narratives inside your own ops
Disclaimer
This article is for informational purposes only and is not legal advice. Carrier policies, CSP requirements, fees, TCR processes, and TCPA/state rules change and are fact-specific. Confirm current requirements with your provider and qualified counsel before registering or sending commercial messages.