TCR Vetting Systems Operational
MyTCRPlus Guide

T-Mobile A2P 10DLC Code of Conduct

Plain-language summary of T-Mobile’s commercial messaging Code of Conduct (v2.2): consent, STOP, prohibited practices, disallowed content, and where to get the PDF.

READ TIME: 11 MIN SECTION: MYTCRPLUS GUIDE STATUS: VERIFIED 2026

Executive Summary

This guide expands operational guidance for teams that text or call consumers in regulated US messaging environments. It clarifies definitions, decision steps, risks, checklists, and FAQs so compliance and ops can execute without relying on folklore. Pair carrier registration work with consent evidence and disclosure accuracy. Confirm current CSP and legal requirements before launch.

Short answer: Follow the detailed sections below for practical controls; registration and consent remain separate obligations; download primary PDFs/forms from authoritative hosts when cited.

Who This Is For / Who It Is Not For

Who this is for: Operators, compliance, and vendors implementing the workflows described in this article. Who this is not for: Readers seeking guarantees, invented fine amounts, or universal fee/MPS figures.

Definitions

Term Meaning
A2P / Non-Consumer messaging Business-originated application traffic
Consent evidence Stored proof of opt-in disclosures and assent
STOP/HELP Standard consumer care and opt-out keywords
CSP Communications service provider submitting registrations
Primary source Carrier PDF, IRS page, or CFR text cited in sources

Short answer: T-Mobile’s commercial messaging Code of Conduct (commonly circulated as Version 2.2, November 2020) sets expectations for consent, opt-out, sending practices, and disallowed content on traffic reaching T-Mobile subscribers—including 10DLC long codes, toll-free, and short codes. It supplements CTIA materials; where they conflict, T-Mobile states its Guidelines take precedence. Download/read the live PDF your DCA enforces—do not rely only on blog summaries.

PDF sources commonly cited: Aerialink-hosted v2.2 PDF and T-Mobile public-files path. Confirm which revision your aggregator currently requires.

Scope and Enforcement

The document applies to Direct Connected Aggregators (DCAs) and content providers using T-Mobile’s commercial messaging paths. Enforcement examples include suspension of sending rights, restriction of 10DLC daily quotas, suspension of new number provisioning, and suspension of network services. T-Mobile notes approval of a campaign description is not a legal compliance guarantee.

Table 1-1 in the Code of Conduct distinguishes:

  • Conversational — consumer-initiated back-and-forth; implied consent for timely relevant replies
  • Informational — expressed consent before business-originated alerts/reminders
  • Promotional — expressed written consent before sales/marketing texts

Consent is campaign-specific—not a blanket for other brands. T-Mobile may request proof of opt-in (timestamp, medium, language, campaign, IP, MDN, identity).

Double opt-in is recommended when consent starts off-SMS; some use cases (e.g., shopping cart reminders) require it. If you do not message within 30 days of consent, reconfirm via double opt-in per that document.

Opt-Out Requirements

Support universal keywords including STOP, END, CANCEL, UNSUBSCRIBE, and QUIT; send one confirmation; send no further messages. High opt-out rates can trigger audits—document cites monitoring around 0.5% per blast and suggests stronger action above 4% within 24 hours (read the PDF for exact definitions). Process deactivation files daily.

Prohibited Practices (High Signal)

  • Selling/renting/sharing consent
  • Grey routes for A2P
  • Snowshoeing across numbers to evade filters
  • Filter evasion / number cycling
  • Dynamic routing to dodge blocks
  • Shared codes across multiple content providers (with limited enterprise exception processes)
  • Public URL shortener abuse / deceptive redirect chains

Disallowed Content Categories

Among others, the Code lists high-risk financial services (payday loans, non-direct lenders, debt collection), debt forgiveness themes, illegal substances (including cannabis), certain work-from-home / third-party job alert schemes, gambling, and lead-gen that shares data with third parties. Phishing, fraud, and deceptive marketing are prohibited. Age-gated categories need robust age verification—not a simple yes/no.

Special Use Cases Worth Noting

  • Political 10DLC — Campaign Verify token / dedicated address requirements described for political entities
  • Shopping cart reminders — double opt-in + privacy disclosures + timing limits
  • Charitable — 501(c)(3) and accreditation-oriented qualifications
  • Emergency — points toward official WEA/IPAWS channels rather than ad-hoc blasts

How This Interacts With 10DLC Registration

Registering a Brand/Campaign via TCR/your CSP (Twilio overview) does not waive the Code of Conduct. Samples and message_flow should be truthful relative to these rules—especially content category bans.

Practical Compliance Mapping for Brand Teams

Your activity Code of Conduct focus
Building web CTA Section on calls-to-action & disclosures
Buying a lead list Consent non-transfer / sharing prohibitions
Launching loan ads Disallowed high-risk financial content
Seeing rising STOP rates High opt-out monitoring thresholds
Switching sending numbers Transition / snowshoe / number cycling rules

Assign an owner to re-read the PDF whenever you launch a new use case.

Soft CTA

Before you submit Campaigns that may terminate on T-Mobile, align samples and CTAs with MyTCRPlus tools and keep a copy of the Code PDF your DCA cites. Tools help catch disclosure gaps; they do not override carrier prohibitions.

Decision Framework

  1. Identify whether the topic is legal consent, carrier conduct, tax filing, or script hygiene.
  2. Map owners and systems.
  3. Update public pages/scripts as required.
  4. Align TCR/CSP filings if SMS registration is in scope.
  5. Test STOP/HELP or equivalent controls.
  6. Archive evidence and schedule a quarterly review.

Risk and Failure Modes

Risk Mitigation
Ignoring primary sources Read the PDF/IRS page your CSP enforces
Mixing regimes Keep tax, FEC, TCR, TCPA checklists separate
Script drift Version control and mystery-shop
Missing STOP Configure platform defaults + QA

Implementation Checklist

Step Owner Artifact
Read primary source Compliance Annotated PDF/URL
Update scripts/pages Marketing/Web Screenshots
Train staff Ops Attendance log
QA controls QA Test results
File/register if needed Ops IDs/status
Quarterly re-read Compliance Calendar

Store phone number, program, timestamp with timezone, capture source, disclosure version ID, agent or page URL, confirmation message IDs, and revocation events as append-only history. Train teams that “they said it was fine” is not a record. Run monthly sampling: pull 25 random numbers and verify each field is populated before the first automated send. Align TCR message_flow language with the real capture paths so reviewers and auditors see the same story.

Deep Dive: Template Governance

Prohibit free-form SMS blasts from personal phones for automated programs. Route all production copy through an allowlist tied to Campaign IDs. Require dual approval for marketing templates. Diff production vs filed samples every 30 days. When product managers change a link domain, treat it as a compliance change—update samples and flags for embedded links. Document emergency edit procedures for outages without abandoning Brand identification or STOP language.

Deep Dive: Vendor and CSP Coordination

Write down who submits Brand/Campaign data, who pays which fees, who owns consent exports, and how STOP propagates across modules. Require notice when the vendor changes opt-in UX. On churn, export consent and suppression lists before access ends. Prefer vendors that expose registration status via API so middleware can block unregistered sends automatically.

Deep Dive: Consumer Experience and Trust

Consumers forgive logistical texts they expect and punish surprise promotions. Keep Brand naming consistent, use branded HTTPS links, and answer HELP with a human-reachable path. Monitor STOP reasons qualitatively when consumers reply with natural language. Treat spikes after a campaign as a product signal, not only a compliance metric. Never buy or rent opt-in lists—CTIA principles discourage shared consent lists, and TCPA risk climbs quickly.

Deep Dive: Launch and Rollback

Before enabling a journey: Campaign approved, numbers bound, consent flags true on pilot cohort, STOP/HELP verified, quiet hours configured, support inbox staffed. Rollback plan: disable job, suppress cohort if needed, file incident note, fix root cause, re-enable only after checklist sign-off. Communicate status to frontline staff so they do not improvise personal-phone workarounds during outages.

Deep Dive: Metrics Without Invented Benchmarks

Track registration coverage (% volume on approved numbers), consent completeness on audited samples, time-to-suppress after STOP, rejection backlog age, and template drift incidents. Compare periods against your own baselines. Do not publish fabricated industry averages for complaint rates, fines, or MPS. When leadership asks for “the industry number,” show your CSP documentation and counsel’s risk framing instead.

Deep Dive: Documentation Hygiene

Maintain a single compliance log (ticket system or controlled doc) listing journey name, owner, Campaign ID, consent source, last audit date, and open issues. Link to screenshots rather than pasting stale prose. When IRS, FEC, ethics, or healthcare privacy regimes also apply, keep those checklists adjacent but separate so teams do not conflate Form 8872, Campaign Verify, TCR, and TCPA evidence.

Store phone number, program, timestamp with timezone, capture source, disclosure version ID, agent or page URL, confirmation message IDs, and revocation events as append-only history. Train teams that “they said it was fine” is not a record. Run monthly sampling: pull 25 random numbers and verify each field is populated before the first automated send. Align TCR message_flow language with the real capture paths so reviewers and auditors see the same story.

Deep Dive: Template Governance

Prohibit free-form SMS blasts from personal phones for automated programs. Route all production copy through an allowlist tied to Campaign IDs. Require dual approval for marketing templates. Diff production vs filed samples every 30 days. When product managers change a link domain, treat it as a compliance change—update samples and flags for embedded links. Document emergency edit procedures for outages without abandoning Brand identification or STOP language.

Deep Dive: Vendor and CSP Coordination

Write down who submits Brand/Campaign data, who pays which fees, who owns consent exports, and how STOP propagates across modules. Require notice when the vendor changes opt-in UX. On churn, export consent and suppression lists before access ends. Prefer vendors that expose registration status via API so middleware can block unregistered sends automatically.

Deep Dive: Consumer Experience and Trust

Consumers forgive logistical texts they expect and punish surprise promotions. Keep Brand naming consistent, use branded HTTPS links, and answer HELP with a human-reachable path. Monitor STOP reasons qualitatively when consumers reply with natural language. Treat spikes after a campaign as a product signal, not only a compliance metric. Never buy or rent opt-in lists—CTIA principles discourage shared consent lists, and TCPA risk climbs quickly.

Deep Dive: Launch and Rollback

Before enabling a journey: Campaign approved, numbers bound, consent flags true on pilot cohort, STOP/HELP verified, quiet hours configured, support inbox staffed. Rollback plan: disable job, suppress cohort if needed, file incident note, fix root cause, re-enable only after checklist sign-off. Communicate status to frontline staff so they do not improvise personal-phone workarounds during outages.

Deep Dive: Metrics Without Invented Benchmarks

Track registration coverage (% volume on approved numbers), consent completeness on audited samples, time-to-suppress after STOP, rejection backlog age, and template drift incidents. Compare periods against your own baselines. Do not publish fabricated industry averages for complaint rates, fines, or MPS. When leadership asks for “the industry number,” show your CSP documentation and counsel’s risk framing instead.

Deep Dive: Documentation Hygiene

Maintain a single compliance log (ticket system or controlled doc) listing journey name, owner, Campaign ID, consent source, last audit date, and open issues. Link to screenshots rather than pasting stale prose. When IRS, FEC, ethics, or healthcare privacy regimes also apply, keep those checklists adjacent but separate so teams do not conflate Form 8872, Campaign Verify, TCR, and TCPA evidence.

Store phone number, program, timestamp with timezone, capture source, disclosure version ID, agent or page URL, confirmation message IDs, and revocation events as append-only history. Train teams that “they said it was fine” is not a record. Run monthly sampling: pull 25 random numbers and verify each field is populated before the first automated send. Align TCR message_flow language with the real capture paths so reviewers and auditors see the same story.

Deep Dive: Template Governance

Prohibit free-form SMS blasts from personal phones for automated programs. Route all production copy through an allowlist tied to Campaign IDs. Require dual approval for marketing templates. Diff production vs filed samples every 30 days. When product managers change a link domain, treat it as a compliance change—update samples and flags for embedded links. Document emergency edit procedures for outages without abandoning Brand identification or STOP language.

Deep Dive: Vendor and CSP Coordination

Write down who submits Brand/Campaign data, who pays which fees, who owns consent exports, and how STOP propagates across modules. Require notice when the vendor changes opt-in UX. On churn, export consent and suppression lists before access ends. Prefer vendors that expose registration status via API so middleware can block unregistered sends automatically.

Deep Dive: Consumer Experience and Trust

Consumers forgive logistical texts they expect and punish surprise promotions. Keep Brand naming consistent, use branded HTTPS links, and answer HELP with a human-reachable path. Monitor STOP reasons qualitatively when consumers reply with natural language. Treat spikes after a campaign as a product signal, not only a compliance metric. Never buy or rent opt-in lists—CTIA principles discourage shared consent lists, and TCPA risk climbs quickly.

Deep Dive: Launch and Rollback

Before enabling a journey: Campaign approved, numbers bound, consent flags true on pilot cohort, STOP/HELP verified, quiet hours configured, support inbox staffed. Rollback plan: disable job, suppress cohort if needed, file incident note, fix root cause, re-enable only after checklist sign-off. Communicate status to frontline staff so they do not improvise personal-phone workarounds during outages.

Deep Dive: Metrics Without Invented Benchmarks

Track registration coverage (% volume on approved numbers), consent completeness on audited samples, time-to-suppress after STOP, rejection backlog age, and template drift incidents. Compare periods against your own baselines. Do not publish fabricated industry averages for complaint rates, fines, or MPS. When leadership asks for “the industry number,” show your CSP documentation and counsel’s risk framing instead.

Key Takeaways

  • Use authoritative sources cited in the front matter.
  • Separate legal, tax, and carrier tracks.
  • Version scripts and disclosures.
  • Test consumer control keywords.
  • Keep an evidence pack ready.

FAQ

Where is the official PDF?

Use the file your DCA/CSP links in onboarding. Public mirrors include the Aerialink and T-Mobile public-files URLs above; hashes/versions can differ—prefer the copy named in your agreement.

Does this replace CTIA handbooks?

No. It supplements them and states precedence if conflict arises.

Are credit unions banned from SMS?

No. Disallowed categories target high-risk lending/debt themes—not ordinary first-party account servicing. Still read financial sections carefully.

Will following this PDF make us TCPA compliant?

T-Mobile explicitly says Guidelines are not comprehensive legal advice. TCPA remains separate.

Disclaimer

This is a plain-language educational summary of a carrier policy PDF. It is not legal advice. Consult the current Code text, your DCA, and counsel for operational decisions.

// Ready To Go Live?

BOOK YOUR TCR SOLUTIONS DISCOVERY CALL

KEEP READING

// Stop guessing. Start messaging.

ELIMINATE TCR
REJECTION RISK TODAY

SMB & Enterprise businesses achieve up to 90% approval rates with our diagnostic tools and carrier-validated templates.