The CTIA guidelines for text messaging are the wireless industry's rules for business (non-consumer) messaging in the US. The core document is the CTIA Messaging Principles and Best Practices, which covers consent, opt-out, calls to action, message content and abuse prevention. CTIA guidelines are not federal law, but US carriers build them into their policies and the contracts that flow down to your Campaign Service Provider (CSP), so they decide whether your 10DLC Campaign is approved and whether your messages are filtered. MyTCRPlus is an independent 10DLC compliance diagnostic platform: it is not a CSP, does not send SMS, and is not affiliated with CTIA or The Campaign Registry.
Short answer: Follow the CTIA guidelines by getting the right level of consent for each message type, disclosing your program clearly at opt-in, honoring STOP and HELP, keeping content to what the consumer signed up for, avoiding prohibited content, and keeping records. Federal law (the TCPA) still applies on top of the CTIA rules.
What CTIA Is and Why Its Guidelines Matter
CTIA is the trade association for the US wireless industry. Its messaging guidance sets shared expectations for how businesses use text messaging so that consumers keep trusting the channel. Carriers reference the CTIA principles in their own codes of conduct, and CSPs pass those expectations to you through their acceptable use policies. In practice, that means:
- A 10DLC Campaign whose opt-in flow does not meet CTIA expectations can be rejected in review.
- Traffic that breaks CTIA content or consent norms can be filtered or blocked after approval.
- Repeated violations can lead your CSP to suspend your account or numbers.
Read the source document directly: CTIA Messaging Principles and Best Practices (PDF).
CTIA Guidelines vs the TCPA
| CTIA guidelines | TCPA | |
|---|---|---|
| What it is | Industry best practices enforced by carriers through contracts | Federal statute, 47 U.S.C. § 227, with FCC rules |
| Who enforces | Carriers and CSPs | FCC, state attorneys general, and private lawsuits |
| Consequence | Campaign rejection, filtering, suspension | Statutory damages of $500 per violation, up to $1,500 if willful or knowing |
| Scope | All non-consumer messaging on carrier networks | Calls and texts using regulated technology or to numbers on Do Not Call lists |
Meeting one does not satisfy the other. A program can be TCPA-compliant and still be filtered for breaking CTIA content norms, and a carrier-approved Campaign does not protect you from a TCPA lawsuit. See TCPA text message rules for the legal side.
Message Types and Consent Under the CTIA Principles
The CTIA principles group business messages by type and match each type to a level of consent:
| Message type | Example | Expected consent |
|---|---|---|
| Conversational | A customer texts you first and you reply to that question | The consumer starting the conversation implies consent for the reply |
| Informational | Appointment reminders, order updates, account alerts the customer asked for | Express consent, such as providing a number for that purpose |
| Promotional | Sales, coupons, new-product announcements | Express written consent, consistent with TCPA requirements for marketing |
Consent is specific to the business and the purpose. Consent to receive order updates is not consent to receive promotions, and consent given to one brand does not carry over to another.
Calls to Action and Opt-In Disclosure
The CTIA guidelines expect every opt-in point (web form, keyword, paper form, verbal script) to tell the consumer clearly what they are agreeing to. A compliant call to action includes:
- The brand or program name.
- A description of the messages the consumer will receive.
- Message frequency (for example, "Up to 4 msgs/month" or "Message frequency varies").
- "Msg & data rates may apply."
- How to opt out (STOP) and get help (HELP).
- Links to the terms and the privacy policy.
For marketing programs under the TCPA, the written agreement also has to make clear that consent is not a condition of purchase. See SMS opt-in language for templates and SMS disclaimer examples for compliant disclosure wording.
Opt-In Confirmation Message
After a consumer opts in, CTIA practice is to send a confirmation message that repeats the essentials: program name, frequency, "Msg & data rates may apply", and STOP and HELP instructions. Example:
Oak Dental: You're subscribed to appointment reminders. Msg frequency varies. Msg & data rates may apply. Reply HELP for help, STOP to cancel.
See opt-in confirmation messages for more patterns.
Opt-Out: STOP and HELP
- STOP. Consumers must be able to opt out by replying with STOP and common equivalents such as CANCEL, END, QUIT and UNSUBSCRIBE. Send one confirmation that they will receive no further messages, then stop.
- HELP. A HELP reply must return the program name and how to get support, such as a phone number, email address or website.
- Honor opt-outs everywhere. An opt-out applies to the program across all numbers and tools you use for it.
Federal rules now also require honoring opt-outs made through any reasonable means; see SMS opt-out requirements.
Content Rules
The CTIA guidelines and carrier codes restrict several content categories, commonly summarized as SHAFT: sex, hate, alcohol, firearms and tobacco. Cannabis and CBD, certain high-risk financial offers, third-party lead generation and other categories are prohibited or heavily restricted by carriers. Some restricted categories can be sent only with age gating and specific Campaign types.
Other content expectations:
- Messages should match the use case and samples you registered.
- Use full branded links; avoid public URL shorteners, which carriers associate with spam.
- Identify the sender in messages so recipients know who is texting.
- Do not use deceptive, misleading or phishing-style content.
The SMS Message Validator checks samples against these patterns.
Abuse Prevention: Snowshoeing and Number Cycling
The CTIA principles prohibit techniques used to evade filtering, such as snowshoeing (spreading similar traffic across many numbers to stay under detection thresholds) and number cycling. Carriers treat these as serious violations. Throughput on 10DLC is set by your Brand and Campaign, not by how many numbers you use. See duplicate campaigns and snowshoeing.
Privacy and Data Handling
The CTIA guidelines expect a privacy policy that explains how you use mobile information. Carriers and CSP reviewers specifically look for a statement that mobile numbers and SMS opt-in data are not shared with third parties for their marketing. Missing SMS language is behind the common 9108 rejection; see how to fix code 9108 and the 10DLC privacy policy template.
Record Keeping
Keep records that show when, where and how each consumer opted in, what the disclosure said at that time, and when they opted out. These records support both carrier audits and TCPA defense. See consent evidence trail.
How CTIA Guidelines Show Up in 10DLC Review
| CTIA expectation | 10DLC Campaign field reviewers check | Common rejection |
|---|---|---|
| Clear call to action | Message flow / call to action | Opt-in cannot be verified |
| Program disclosure | Opt-in form and samples | Missing frequency or rates disclosure |
| STOP and HELP | Opt-out and help messages | Missing or incomplete keywords |
| Content matches consent | Use case and samples | Marketing in a care Campaign |
| Privacy | Privacy policy URL | No SMS section; 9108 |
| No evasion | Number count and traffic | Snowshoeing flags |
Short Codes and CTIA
Short code programs historically had the most detailed CTIA audit regime, including the short code monitoring handbook. The same principles apply to 10DLC and toll-free traffic. See short code laws and A2P messaging options.
CTIA Compliance Checklist
- [ ] Consent level matches each message type
- [ ] Call to action names the program, frequency, rates, STOP, HELP, terms and privacy
- [ ] Confirmation message sent after opt-in
- [ ] STOP and synonyms honored immediately and everywhere
- [ ] HELP returns program name and support contact
- [ ] No SHAFT or prohibited content without the right Campaign type and age gate
- [ ] No public URL shorteners
- [ ] Privacy policy with SMS non-sharing language
- [ ] Consent and opt-out records kept
How to Audit Your Program Against the CTIA Guidelines
Run this audit before you register a Campaign and again every quarter:
- Inventory every opt-in point. List each web form, checkout, keyword, paper form, kiosk and verbal script that collects mobile numbers. Programs often have a forgotten opt-in, such as an old landing page or a store sign, that still uses outdated wording.
- Screenshot each one. Capture the disclosure as a consumer sees it on mobile and desktop. These screenshots double as evidence for your consent records and your Campaign message flow.
- Check each disclosure against the call-to-action elements. Program name, message description, frequency, "Msg & data rates may apply", STOP, HELP, terms and privacy links. Mark anything missing.
- Compare message types. Pull a sample of messages actually sent in the last 30 days and check each against what the opt-in promised. Promotional content sent to subscribers who only agreed to alerts is the most common gap.
- Test STOP and HELP. From a test handset on each major carrier, reply STOP, CANCEL and HELP and confirm the responses and the suppression.
- Check links. Every link in messages should be a full branded URL on a domain you control and should load quickly on mobile.
- Review your privacy policy and terms for SMS-specific language and consistency with the opt-in.
- Review volume patterns for spikes or traffic spread across numbers.
- Record the results with dates and owners so you can show what you fixed.
Applying the CTIA Guidelines by Industry
| Industry | Common message types | CTIA pressure points |
|---|---|---|
| Healthcare | Appointment reminders, care instructions | Keep protected health information out of texts; separate reminders from marketing |
| Retail and e-commerce | Order updates, promotions | Separate transactional and marketing consent at checkout |
| Real estate | Showing updates, listing alerts | Purchased leads lack consent for your brand |
| Financial services | Account alerts, payment reminders | Phishing-like content triggers filtering; name the institution |
| Restaurants and hospitality | Reservations, offers | Keyword programs need full disclosure on signage |
| Collections | Payment reminders | Restricted handling; opt-out in every message |
Industry guides: healthcare 10DLC registration, real estate SMS marketing, debt collection texting.
Where CTIA Guidelines and Carrier Codes Differ
Each carrier publishes its own code of conduct that builds on the CTIA principles. The codes are broadly consistent, but they differ in detail on content categories, throughput, and enforcement steps. Your CSP applies the strictest combination that affects your traffic, so a message that one carrier delivers can be filtered by another. When you see filtering on only one carrier, read that carrier's code alongside the CTIA principles; see how AT&T, T-Mobile and Verizon enforce the rules and the T-Mobile A2P code of conduct.
Keeping Up With Changes
The CTIA principles are revised from time to time, and carriers update their codes more often. Assign one owner to check the CTIA document, your CSP's policy page and the major carrier codes each quarter, and to record what changed. When a change affects your program, update the opt-in, terms, templates and Campaign together so they stay consistent. MyTCRPlus tracks policy changes on the carrier policy updates page.
FAQ
What are the CTIA guidelines?
The wireless industry's Messaging Principles and Best Practices for business texting, covering consent, disclosures, opt-out, content and abuse prevention.
Are CTIA guidelines law?
No. They are industry standards that carriers enforce through their policies and contracts. The TCPA and state laws apply separately.
What happens if I violate CTIA guidelines?
Your Campaign can be rejected, messages can be filtered, and your CSP can suspend numbers or your account.
What does CTIA require in an opt-in?
Program name, description of messages, frequency, "Msg & data rates may apply", STOP and HELP instructions, and links to terms and privacy policy.
What is SHAFT content?
Sex, hate, alcohol, firearms and tobacco, the content categories carriers restrict under CTIA-aligned policies.
Do CTIA guidelines apply to 10DLC?
Yes. They apply to non-consumer messaging on US carrier networks, including 10DLC, toll-free and short codes.
Where can I read the CTIA Messaging Principles?
On CTIA's site; the current Messaging Principles and Best Practices is published as a PDF.
Disclaimer
Informational only, not legal advice. CTIA guidance and carrier policies change; read the current documents and your CSP's policies. MyTCRPlus is not affiliated with CTIA, carriers or The Campaign Registry.