Executive Summary
TCR error codes and Campaign rejection codes tell you why a Brand or Campaign failed review. They are not mystical—most cluster around identity mismatches, website/privacy failures, weak message_flow, sample problems, or use-case mismatches. This guide explains how to read codes, a remediation decision framework, deep focus on privacy failures such as 9108, prevention tactics, and checklists. Exact code catalogs differ by CSP UI; always use the code and plain-language reason your provider returns.
Short answer: Treat TCR rejection codes as a queue item with owner, root cause, fix, and resubmit verification—not a blind retry. For privacy failures (including 9108-class issues), fix the public Privacy Policy SMS language and URL accessibility first, then resubmit through your CSP.
Who This Is For / Who It Is Not For
Who this is for: Messaging ops, compliance, and agency teams fixing failed filings.
Who this is not for: Anyone seeking a guarantee that one edit yields instant approval, or invented “most common code percentages.”
Definitions
| Term | Meaning |
|---|---|
| Rejection code | Machine/human code explaining Campaign/Brand failure |
| DCA / vetting | Downstream review steps in some CSP paths |
| 9108-class | Privacy policy not compliant / missing SMS language themes |
| Message_flow failure | Opt-in story missing, vague, or mismatched to reality |
| Sample failure | Samples missing Brand, mismatched use case, or low quality |
| Resubmission | New review cycle after fixes—may incur fees (CSP-specific) |
How to Read a Rejection
- Capture the raw code + provider message + timestamp.
- Classify: identity, website, privacy, consent/flow, samples, use case, content policy.
- Reproduce the failure (open URLs in private browser).
- Fix root cause; avoid drive-by edits.
- Update packet; resubmit once.
- Log outcome for pattern analysis.
Category Table
| Category | Typical symptoms | First checks |
|---|---|---|
| Identity / EIN | Brand failed | Legal name vs CP 575; tax ID format |
| Website | Unreachable, parked, login | HTTPS live; related to Brand |
| Privacy | 9108 / Twilio 30908 themes | Public SMS section; non-sharing; STOP |
| Message flow | Vague opt-in | List every real method + URLs |
| Samples | No Brand name; promo in care | Rewrite 2–5 honest samples |
| Use case | Wrong enum | Align content to Campaign type |
| Content policy | Forbidden categories | Remove or change program |
Fixing Privacy Rejections (9108 Themes)
MyTCRPlus documents that 9108 generally means the Privacy Policy URL missing, unreliable, or lacking required SMS-related language—especially mobile-number/SMS consent non-sharing for third-party marketing and program/opt-out description including STOP (9108 guide). Twilio error 30908 similarly flags compliant privacy policy requirements during campaign vetting.
Remediation:
- Confirm URL loads anonymously within a few seconds.
- Add dedicated SMS section in the Privacy Policy body (not only Terms).
- State non-sharing of mobile opt-in data for third-party marketing if that is your practice—and make practice match policy.
- Describe program types and STOP/HELP.
- Ensure CTA links to the same policy URL you submit.
- Purge CDN caches; re-test.
- Resubmit with the correct URL.
Decision Framework
- Parse code family.
- Validate public artifacts.
- Diff live CTA vs message_flow.
- Diff samples vs production templates.
- Fix; peer-review; resubmit.
- If second failure, escalate to CSP support with evidence—do not thrash weekly.
Risk and Failure Modes
| Risk | Why | Mitigation |
|---|---|---|
| Blind resubmit | Burns time/fees | Preflight checklist |
| Fixing Terms not Privacy | 9108 persists | Edit Privacy Policy |
| URL mismatch | Old URL in form | Update submission fields |
| JS-only content | Crawler misses text | Static HTML visible |
| Sample theater | Production differs | Change control |
Implementation Checklist
| Step | Owner | Artifact |
|---|---|---|
| Log rejection | Ops | Ticket |
| Reproduce URLs | Web | Screenshots |
| Privacy edit | Legal/web | Policy diff |
| Flow/samples edit | Compliance | Packet |
| Preflight | Ops | Checklist |
| Resubmit | Ops | New status |
| Postmortem | Compliance | Notes |
Soft CTA: Use MyTCRPlus rejection resources and tools to structure fixes—not as guaranteed clearance.
FAQ
What are TCR error codes?
Provider-returned codes explaining Brand/Campaign failures in the 10DLC registration path.
How do I fix 9108?
Repair Privacy Policy accessibility and SMS-specific language, then resubmit via CSP.
Does Twilio 30908 mean the same as 9108?
Related privacy-compliance themes; follow the exact provider message and docs for your path.
Who approves Campaigns?
TCR/CSP ecosystem roles vary; TCR resources note CSPs register Brands and approval paths involve upstream partners—use your CSP’s status model.
Should I change use case to get approval?
Only if it truthfully matches traffic—do not mis-label marketing as care.
Are fees charged again on resubmit?
Often yes—confirm with your CSP; do not invent amounts.
Where is the full code list?
Your CSP’s troubleshooting article is authoritative for codes they surface.
Can tools auto-fix codes?
Tools can validate language/URLs; humans still confirm business truthfulness.
Extended Operating Narrative
Assign a named owner for every SMS journey. Define launch gates: approved Campaign (or verified TFN), consent flag present, STOP tested, samples matched to production, privacy URL healthy. Refuse silent launches. When vendors claim compliance, require written Brand ownership, consent export rights, STOP propagation details, and rejection handling. Keep an evidence pack—IDs, CTA screenshots, disclosure versions, sample packs, field dictionary, RACI—ready within one business day.
Review template diffs monthly; mystery-shop opt-ins quarterly; reconcile suppression lists on a fixed cadence. After privacy edits, verify SMS language in public HTML. After new forms launch, confirm consent objects feed send-time checks. When rejections or STOP spikes occur, run a blameless incident review with root cause and corrective owners. Educate leadership that registration enables 10DLC sending but does not replace TCPA consent, that MPS is account-specific, that fees are provider-quoted, and that approval rates must never be guaranteed in contracts.
Extended Operating Narrative
Assign a named owner for every SMS journey. Define launch gates: approved Campaign (or verified TFN), consent flag present, STOP tested, samples matched to production, privacy URL healthy. Refuse silent launches. When vendors claim compliance, require written Brand ownership, consent export rights, STOP propagation details, and rejection handling. Keep an evidence pack—IDs, CTA screenshots, disclosure versions, sample packs, field dictionary, RACI—ready within one business day.
Review template diffs monthly; mystery-shop opt-ins quarterly; reconcile suppression lists on a fixed cadence. After privacy edits, verify SMS language in public HTML. After new forms launch, confirm consent objects feed send-time checks. When rejections or STOP spikes occur, run a blameless incident review with root cause and corrective owners. Educate leadership that registration enables 10DLC sending but does not replace TCPA consent, that MPS is account-specific, that fees are provider-quoted, and that approval rates must never be guaranteed in contracts.
Extended Operating Narrative
Assign a named owner for every SMS journey. Define launch gates: approved Campaign (or verified TFN), consent flag present, STOP tested, samples matched to production, privacy URL healthy. Refuse silent launches. When vendors claim compliance, require written Brand ownership, consent export rights, STOP propagation details, and rejection handling. Keep an evidence pack—IDs, CTA screenshots, disclosure versions, sample packs, field dictionary, RACI—ready within one business day.
Review template diffs monthly; mystery-shop opt-ins quarterly; reconcile suppression lists on a fixed cadence. After privacy edits, verify SMS language in public HTML. After new forms launch, confirm consent objects feed send-time checks. When rejections or STOP spikes occur, run a blameless incident review with root cause and corrective owners. Educate leadership that registration enables 10DLC sending but does not replace TCPA consent, that MPS is account-specific, that fees are provider-quoted, and that approval rates must never be guaranteed in contracts.
Extended Operating Narrative
Assign a named owner for every SMS journey. Define launch gates: approved Campaign (or verified TFN), consent flag present, STOP tested, samples matched to production, privacy URL healthy. Refuse silent launches. When vendors claim compliance, require written Brand ownership, consent export rights, STOP propagation details, and rejection handling. Keep an evidence pack—IDs, CTA screenshots, disclosure versions, sample packs, field dictionary, RACI—ready within one business day.
Review template diffs monthly; mystery-shop opt-ins quarterly; reconcile suppression lists on a fixed cadence. After privacy edits, verify SMS language in public HTML. After new forms launch, confirm consent objects feed send-time checks. When rejections or STOP spikes occur, run a blameless incident review with root cause and corrective owners. Educate leadership that registration enables 10DLC sending but does not replace TCPA consent, that MPS is account-specific, that fees are provider-quoted, and that approval rates must never be guaranteed in contracts.
Extended Operating Narrative
Assign a named owner for every SMS journey. Define launch gates: approved Campaign (or verified TFN), consent flag present, STOP tested, samples matched to production, privacy URL healthy. Refuse silent launches. When vendors claim compliance, require written Brand ownership, consent export rights, STOP propagation details, and rejection handling. Keep an evidence pack—IDs, CTA screenshots, disclosure versions, sample packs, field dictionary, RACI—ready within one business day.
Review template diffs monthly; mystery-shop opt-ins quarterly; reconcile suppression lists on a fixed cadence. After privacy edits, verify SMS language in public HTML. After new forms launch, confirm consent objects feed send-time checks. When rejections or STOP spikes occur, run a blameless incident review with root cause and corrective owners. Educate leadership that registration enables 10DLC sending but does not replace TCPA consent, that MPS is account-specific, that fees are provider-quoted, and that approval rates must never be guaranteed in contracts.
Implementation Cadence (First 45 Days)
Week 1: Inventory senders, screenshot CTAs, identify legal entity and website gaps.
Week 2: Draft disclosures, consent schema, and sample packs; legal/compliance review.
Week 3: Submit Brand; remediate tax ID/website issues immediately.
Week 4: Submit Campaign(s); prepare number binding plan.
Week 5–6: On approval, bind numbers, enable send-time checks, train staff, pilot one journey, then expand.
Document every status change with dates and ticket IDs.
Extended Operating Narrative
Assign a named owner for every SMS journey. Define launch gates: approved Campaign (or verified TFN), consent flag present, STOP tested, samples matched to production, privacy URL healthy. Refuse silent launches. When vendors claim compliance, require written Brand ownership, consent export rights, STOP propagation details, and rejection handling. Keep an evidence pack—IDs, CTA screenshots, disclosure versions, sample packs, field dictionary, RACI—ready within one business day.
Review template diffs monthly; mystery-shop opt-ins quarterly; reconcile suppression lists on a fixed cadence. After privacy edits, verify SMS language in public HTML. After new forms launch, confirm consent objects feed send-time checks. When rejections or STOP spikes occur, run a blameless incident review with root cause and corrective owners. Educate leadership that registration enables 10DLC sending but does not replace TCPA consent, that MPS is account-specific, that fees are provider-quoted, and that approval rates must never be guaranteed in contracts.
Implementation Cadence (First 45 Days)
Week 1: Inventory senders, screenshot CTAs, identify legal entity and website gaps.
Week 2: Draft disclosures, consent schema, and sample packs; legal/compliance review.
Week 3: Submit Brand; remediate tax ID/website issues immediately.
Week 4: Submit Campaign(s); prepare number binding plan.
Week 5–6: On approval, bind numbers, enable send-time checks, train staff, pilot one journey, then expand.
Document every status change with dates and ticket IDs.
Extended Operating Narrative
Assign a named owner for every SMS journey. Define launch gates: approved Campaign (or verified TFN), consent flag present, STOP tested, samples matched to production, privacy URL healthy. Refuse silent launches. When vendors claim compliance, require written Brand ownership, consent export rights, STOP propagation details, and rejection handling. Keep an evidence pack—IDs, CTA screenshots, disclosure versions, sample packs, field dictionary, RACI—ready within one business day.
Review template diffs monthly; mystery-shop opt-ins quarterly; reconcile suppression lists on a fixed cadence. After privacy edits, verify SMS language in public HTML. After new forms launch, confirm consent objects feed send-time checks. When rejections or STOP spikes occur, run a blameless incident review with root cause and corrective owners. Educate leadership that registration enables 10DLC sending but does not replace TCPA consent, that MPS is account-specific, that fees are provider-quoted, and that approval rates must never be guaranteed in contracts.
Implementation Cadence (First 45 Days)
Week 1: Inventory senders, screenshot CTAs, identify legal entity and website gaps.
Week 2: Draft disclosures, consent schema, and sample packs; legal/compliance review.
Week 3: Submit Brand; remediate tax ID/website issues immediately.
Week 4: Submit Campaign(s); prepare number binding plan.
Week 5–6: On approval, bind numbers, enable send-time checks, train staff, pilot one journey, then expand.
Document every status change with dates and ticket IDs.
Additional Remediation and Budget Controls
Create a shared tracker with columns for code, CSP message, root cause category, owner, fix link, resubmit date, and outcome. Review the tracker in a weekly standup until the backlog clears. For pricing, maintain a living rate card spreadsheet with CSP name, quote date, Brand fees, Campaign fees by use case, vetting options, commitment terms, and per-segment assumptions. Re-quote whenever you add a Brand or Campaign type. Pair finance and compliance so rejection loops and fee surprises surface together. Before approving a new messaging vendor, require their fee schedule and a sample invoice showing pass-through lines. Document whether resubmission fees apply after privacy or sample fixes so leadership is not blindsided. Keep screenshots of the CSP fee pages you relied on (with dates) beside the purchase order. When comparing toll-free versus 10DLC total cost of ownership, include number rental, verification labor, monthly Campaign fees, and expected segment volume—not just the sticker Brand fee. Revisit assumptions quarterly because CSP fee cards and carrier surcharges change. If a quote seems far from a public help article, ask the account manager which lines are TCR pass-through versus platform markup. Never publish internal budget numbers as if they were universal market fees.
Quality Gates Before Resubmit or Go-Live
- Private-browser load of website and privacy URLs succeeds.
- SMS section visible in page source without login.
- Samples name Brand and match use case.
- message_flow lists every real opt-in path.
- Finance acknowledges any resubmit or monthly fees from the current quote.
- STOP/HELP configured on the messaging service.
- Owner signs the launch checklist.
Key Takeaways
- TCR error codes are diagnostic—classify before resubmitting.
- Privacy failures need public SMS policy language and reliable URLs.
- Align message_flow and samples with production.
- Log patterns; fix root causes.
- Avoid guaranteed-approval claims.
Disclaimer
This article is for informational purposes only and is not legal advice. Carrier policies, CSP requirements, fees, TCR processes, and TCPA/state rules change and are fact-specific. Confirm with your provider and qualified counsel before registering or sending commercial messages.