Executive Summary
This guide expands operational guidance for teams that text or call consumers in regulated US messaging environments. It clarifies definitions, decision steps, risks, checklists, and FAQs so compliance and ops can execute without relying on folklore. Pair carrier registration work with consent evidence and disclosure accuracy. Confirm current CSP and legal requirements before launch.
Short answer: Follow the detailed sections below for practical controls; registration and consent remain separate obligations; download primary PDFs/forms from authoritative hosts when cited.
Who This Is For / Who It Is Not For
Who this is for: Operators, compliance, and vendors implementing the workflows described in this article. Who this is not for: Readers seeking guarantees, invented fine amounts, or universal fee/MPS figures.
Definitions
| Term | Meaning |
|---|---|
| A2P / Non-Consumer messaging | Business-originated application traffic |
| Consent evidence | Stored proof of opt-in disclosures and assent |
| STOP/HELP | Standard consumer care and opt-out keywords |
| CSP | Communications service provider submitting registrations |
| Primary source | Carrier PDF, IRS page, or CFR text cited in sources |
Short answer: T-Mobile’s commercial messaging Code of Conduct (commonly circulated as Version 2.2, November 2020) sets expectations for consent, opt-out, sending practices, and disallowed content on traffic reaching T-Mobile subscribers—including 10DLC long codes, toll-free, and short codes. It supplements CTIA materials; where they conflict, T-Mobile states its Guidelines take precedence. Download/read the live PDF your DCA enforces—do not rely only on blog summaries.
PDF sources commonly cited: Aerialink-hosted v2.2 PDF and T-Mobile public-files path. Confirm which revision your aggregator currently requires.
Scope and Enforcement
The document applies to Direct Connected Aggregators (DCAs) and content providers using T-Mobile’s commercial messaging paths. Enforcement examples include suspension of sending rights, restriction of 10DLC daily quotas, suspension of new number provisioning, and suspension of network services. T-Mobile notes approval of a campaign description is not a legal compliance guarantee.
Consent Themes (Conversational / Informational / Promotional)
Table 1-1 in the Code of Conduct distinguishes:
- Conversational — consumer-initiated back-and-forth; implied consent for timely relevant replies
- Informational — expressed consent before business-originated alerts/reminders
- Promotional — expressed written consent before sales/marketing texts
Consent is campaign-specific—not a blanket for other brands. T-Mobile may request proof of opt-in (timestamp, medium, language, campaign, IP, MDN, identity).
Double opt-in is recommended when consent starts off-SMS; some use cases (e.g., shopping cart reminders) require it. If you do not message within 30 days of consent, reconfirm via double opt-in per that document.
Opt-Out Requirements
Support universal keywords including STOP, END, CANCEL, UNSUBSCRIBE, and QUIT; send one confirmation; send no further messages. High opt-out rates can trigger audits—document cites monitoring around 0.5% per blast and suggests stronger action above 4% within 24 hours (read the PDF for exact definitions). Process deactivation files daily.
Prohibited Practices (High Signal)
- Selling/renting/sharing consent
- Grey routes for A2P
- Snowshoeing across numbers to evade filters
- Filter evasion / number cycling
- Dynamic routing to dodge blocks
- Shared codes across multiple content providers (with limited enterprise exception processes)
- Public URL shortener abuse / deceptive redirect chains
Disallowed Content Categories
Among others, the Code lists high-risk financial services (payday loans, non-direct lenders, debt collection), debt forgiveness themes, illegal substances (including cannabis), certain work-from-home / third-party job alert schemes, gambling, and lead-gen that shares data with third parties. Phishing, fraud, and deceptive marketing are prohibited. Age-gated categories need robust age verification—not a simple yes/no.
Special Use Cases Worth Noting
- Political 10DLC — Campaign Verify token / dedicated address requirements described for political entities
- Shopping cart reminders — double opt-in + privacy disclosures + timing limits
- Charitable — 501(c)(3) and accreditation-oriented qualifications
- Emergency — points toward official WEA/IPAWS channels rather than ad-hoc blasts
How This Interacts With 10DLC Registration
Registering a Brand/Campaign via TCR/your CSP (Twilio overview) does not waive the Code of Conduct. Samples and message_flow should be truthful relative to these rules—especially content category bans.
Practical Compliance Mapping for Brand Teams
| Your activity | Code of Conduct focus |
|---|---|
| Building web CTA | Section on calls-to-action & disclosures |
| Buying a lead list | Consent non-transfer / sharing prohibitions |
| Launching loan ads | Disallowed high-risk financial content |
| Seeing rising STOP rates | High opt-out monitoring thresholds |
| Switching sending numbers | Transition / snowshoe / number cycling rules |
Assign an owner to re-read the PDF whenever you launch a new use case.
Soft CTA
Before you submit Campaigns that may terminate on T-Mobile, align samples and CTAs with MyTCRPlus tools and keep a copy of the Code PDF your DCA cites. Tools help catch disclosure gaps; they do not override carrier prohibitions.
Decision Framework
- Identify whether the topic is legal consent, carrier conduct, tax filing, or script hygiene.
- Map owners and systems.
- Update public pages/scripts as required.
- Align TCR/CSP filings if SMS registration is in scope.
- Test STOP/HELP or equivalent controls.
- Archive evidence and schedule a quarterly review.
Risk and Failure Modes
| Risk | Mitigation |
|---|---|
| Ignoring primary sources | Read the PDF/IRS page your CSP enforces |
| Mixing regimes | Keep tax, FEC, TCR, TCPA checklists separate |
| Script drift | Version control and mystery-shop |
| Missing STOP | Configure platform defaults + QA |
Implementation Checklist
| Step | Owner | Artifact |
|---|---|---|
| Read primary source | Compliance | Annotated PDF/URL |
| Update scripts/pages | Marketing/Web | Screenshots |
| Train staff | Ops | Attendance log |
| QA controls | QA | Test results |
| File/register if needed | Ops | IDs/status |
| Quarterly re-read | Compliance | Calendar |
Deep Dive: Consent Evidence Standards
Store phone number, program, timestamp with timezone, capture source, disclosure version ID, agent or page URL, confirmation message IDs, and revocation events as append-only history. Train teams that “they said it was fine” is not a record. Run monthly sampling: pull 25 random numbers and verify each field is populated before the first automated send. Align TCR message_flow language with the real capture paths so reviewers and auditors see the same story.
Deep Dive: Template Governance
Prohibit free-form SMS blasts from personal phones for automated programs. Route all production copy through an allowlist tied to Campaign IDs. Require dual approval for marketing templates. Diff production vs filed samples every 30 days. When product managers change a link domain, treat it as a compliance change—update samples and flags for embedded links. Document emergency edit procedures for outages without abandoning Brand identification or STOP language.
Deep Dive: Vendor and CSP Coordination
Write down who submits Brand/Campaign data, who pays which fees, who owns consent exports, and how STOP propagates across modules. Require notice when the vendor changes opt-in UX. On churn, export consent and suppression lists before access ends. Prefer vendors that expose registration status via API so middleware can block unregistered sends automatically.
Deep Dive: Consumer Experience and Trust
Consumers forgive logistical texts they expect and punish surprise promotions. Keep Brand naming consistent, use branded HTTPS links, and answer HELP with a human-reachable path. Monitor STOP reasons qualitatively when consumers reply with natural language. Treat spikes after a campaign as a product signal, not only a compliance metric. Never buy or rent opt-in lists—CTIA principles discourage shared consent lists, and TCPA risk climbs quickly.
Deep Dive: Launch and Rollback
Before enabling a journey: Campaign approved, numbers bound, consent flags true on pilot cohort, STOP/HELP verified, quiet hours configured, support inbox staffed. Rollback plan: disable job, suppress cohort if needed, file incident note, fix root cause, re-enable only after checklist sign-off. Communicate status to frontline staff so they do not improvise personal-phone workarounds during outages.
Deep Dive: Metrics Without Invented Benchmarks
Track registration coverage (% volume on approved numbers), consent completeness on audited samples, time-to-suppress after STOP, rejection backlog age, and template drift incidents. Compare periods against your own baselines. Do not publish fabricated industry averages for complaint rates, fines, or MPS. When leadership asks for “the industry number,” show your CSP documentation and counsel’s risk framing instead.
Deep Dive: Documentation Hygiene
Maintain a single compliance log (ticket system or controlled doc) listing journey name, owner, Campaign ID, consent source, last audit date, and open issues. Link to screenshots rather than pasting stale prose. When IRS, FEC, ethics, or healthcare privacy regimes also apply, keep those checklists adjacent but separate so teams do not conflate Form 8872, Campaign Verify, TCR, and TCPA evidence.
Deep Dive: Consent Evidence Standards
Store phone number, program, timestamp with timezone, capture source, disclosure version ID, agent or page URL, confirmation message IDs, and revocation events as append-only history. Train teams that “they said it was fine” is not a record. Run monthly sampling: pull 25 random numbers and verify each field is populated before the first automated send. Align TCR message_flow language with the real capture paths so reviewers and auditors see the same story.
Deep Dive: Template Governance
Prohibit free-form SMS blasts from personal phones for automated programs. Route all production copy through an allowlist tied to Campaign IDs. Require dual approval for marketing templates. Diff production vs filed samples every 30 days. When product managers change a link domain, treat it as a compliance change—update samples and flags for embedded links. Document emergency edit procedures for outages without abandoning Brand identification or STOP language.
Deep Dive: Vendor and CSP Coordination
Write down who submits Brand/Campaign data, who pays which fees, who owns consent exports, and how STOP propagates across modules. Require notice when the vendor changes opt-in UX. On churn, export consent and suppression lists before access ends. Prefer vendors that expose registration status via API so middleware can block unregistered sends automatically.
Deep Dive: Consumer Experience and Trust
Consumers forgive logistical texts they expect and punish surprise promotions. Keep Brand naming consistent, use branded HTTPS links, and answer HELP with a human-reachable path. Monitor STOP reasons qualitatively when consumers reply with natural language. Treat spikes after a campaign as a product signal, not only a compliance metric. Never buy or rent opt-in lists—CTIA principles discourage shared consent lists, and TCPA risk climbs quickly.
Deep Dive: Launch and Rollback
Before enabling a journey: Campaign approved, numbers bound, consent flags true on pilot cohort, STOP/HELP verified, quiet hours configured, support inbox staffed. Rollback plan: disable job, suppress cohort if needed, file incident note, fix root cause, re-enable only after checklist sign-off. Communicate status to frontline staff so they do not improvise personal-phone workarounds during outages.
Deep Dive: Metrics Without Invented Benchmarks
Track registration coverage (% volume on approved numbers), consent completeness on audited samples, time-to-suppress after STOP, rejection backlog age, and template drift incidents. Compare periods against your own baselines. Do not publish fabricated industry averages for complaint rates, fines, or MPS. When leadership asks for “the industry number,” show your CSP documentation and counsel’s risk framing instead.
Deep Dive: Documentation Hygiene
Maintain a single compliance log (ticket system or controlled doc) listing journey name, owner, Campaign ID, consent source, last audit date, and open issues. Link to screenshots rather than pasting stale prose. When IRS, FEC, ethics, or healthcare privacy regimes also apply, keep those checklists adjacent but separate so teams do not conflate Form 8872, Campaign Verify, TCR, and TCPA evidence.
Deep Dive: Consent Evidence Standards
Store phone number, program, timestamp with timezone, capture source, disclosure version ID, agent or page URL, confirmation message IDs, and revocation events as append-only history. Train teams that “they said it was fine” is not a record. Run monthly sampling: pull 25 random numbers and verify each field is populated before the first automated send. Align TCR message_flow language with the real capture paths so reviewers and auditors see the same story.
Deep Dive: Template Governance
Prohibit free-form SMS blasts from personal phones for automated programs. Route all production copy through an allowlist tied to Campaign IDs. Require dual approval for marketing templates. Diff production vs filed samples every 30 days. When product managers change a link domain, treat it as a compliance change—update samples and flags for embedded links. Document emergency edit procedures for outages without abandoning Brand identification or STOP language.
Deep Dive: Vendor and CSP Coordination
Write down who submits Brand/Campaign data, who pays which fees, who owns consent exports, and how STOP propagates across modules. Require notice when the vendor changes opt-in UX. On churn, export consent and suppression lists before access ends. Prefer vendors that expose registration status via API so middleware can block unregistered sends automatically.
Deep Dive: Consumer Experience and Trust
Consumers forgive logistical texts they expect and punish surprise promotions. Keep Brand naming consistent, use branded HTTPS links, and answer HELP with a human-reachable path. Monitor STOP reasons qualitatively when consumers reply with natural language. Treat spikes after a campaign as a product signal, not only a compliance metric. Never buy or rent opt-in lists—CTIA principles discourage shared consent lists, and TCPA risk climbs quickly.
Deep Dive: Launch and Rollback
Before enabling a journey: Campaign approved, numbers bound, consent flags true on pilot cohort, STOP/HELP verified, quiet hours configured, support inbox staffed. Rollback plan: disable job, suppress cohort if needed, file incident note, fix root cause, re-enable only after checklist sign-off. Communicate status to frontline staff so they do not improvise personal-phone workarounds during outages.
Deep Dive: Metrics Without Invented Benchmarks
Track registration coverage (% volume on approved numbers), consent completeness on audited samples, time-to-suppress after STOP, rejection backlog age, and template drift incidents. Compare periods against your own baselines. Do not publish fabricated industry averages for complaint rates, fines, or MPS. When leadership asks for “the industry number,” show your CSP documentation and counsel’s risk framing instead.
Key Takeaways
- Use authoritative sources cited in the front matter.
- Separate legal, tax, and carrier tracks.
- Version scripts and disclosures.
- Test consumer control keywords.
- Keep an evidence pack ready.
FAQ
Where is the official PDF?
Use the file your DCA/CSP links in onboarding. Public mirrors include the Aerialink and T-Mobile public-files URLs above; hashes/versions can differ—prefer the copy named in your agreement.
Does this replace CTIA handbooks?
No. It supplements them and states precedence if conflict arises.
Are credit unions banned from SMS?
No. Disallowed categories target high-risk lending/debt themes—not ordinary first-party account servicing. Still read financial sections carefully.
Will following this PDF make us TCPA compliant?
T-Mobile explicitly says Guidelines are not comprehensive legal advice. TCPA remains separate.
Disclaimer
This is a plain-language educational summary of a carrier policy PDF. It is not legal advice. Consult the current Code text, your DCA, and counsel for operational decisions.