
Are unwanted texts illegal?
Key Facts
- Every unauthorized marketing text can cost $500–$1,500 in statutory damages, per Purdue Global Law School's analysis.
- Consumers can sue over illegal texts without proving any actual harm — receiving one noncompliant message establishes legal standing, legal experts confirm.
- Connecticut fines unsolicited texters up to $20,000 per infraction, while Texas allows penalties of $5,000 per text, per state mini-TCPA laws.
- Federal law requires opt-out requests like STOP or UNSUBSCRIBE to be honored within 10 business days, compliance research shows.
- The FCC's January 2025 rule requires 1-to-1 consent per seller, closing the lead generation loophole, per Nelson Mullins attorneys.
- Florida and Oklahoma cap outreach at 3 texts per subject per 24 hours, tighter than any federal limit, state compliance analyses show.
- Virginia requires opted-out numbers to stay on a do-not-text list for 10 years, per state law requirements.
The Legal Reality: Why Unwanted Texts Violate Federal Law
Unwanted text messages aren't just annoying—they're illegal under federal law when sent without proper authorization. The Telephone Consumer Protection Act (TCPA) treats text messages as a form of "call," meaning businesses must obtain prior express written consent before sending any marketing texts to consumers. This requirement exists because the FCC has explicitly interpreted the TCPA's restrictions on automated calls to cover SMS messages delivered via telephone systems, a position consistently upheld by federal courts despite ongoing technological evolution.
Violating these consent rules carries serious financial consequences, with statutory damages ranging from $500 to $1,500 per unlawful text message. Crucially, consumers do not need to prove actual harm or financial loss to pursue legal action—simply demonstrating receipt of an unauthorized text establishes standing under the TCPA. This no-fault liability structure means penalties can accumulate rapidly; a single noncompliant blast to thousands of recipients could trigger multimillion-dollar exposure, especially when considering that willful violations may attract the higher $1,500-per-text penalty.
For businesses like CallMyCustomers that specialize in permission-based customer reactivation, this legal framework reinforces the importance of their core compliance approach. By requiring explicit client approval before any message is sent and maintaining rigorous opt-out protocols—including immediate cessation of promotional texts and processing unsubscribe requests within 10 business days—the service aligns with federal requirements designed to protect consumers while enabling legitimate business communication. This foundation allows US service businesses to re-engage past customers through channels that respect both legal boundaries and consumer preferences.
- Prior express written consent is mandatory for all marketing texts under TCPA
- Statutory damages range from $500–$1,500 per violation, with no need to prove actual harm
- Opt-out requests must be honored within 10 business days under federal law
Consent Requirements: What 'Prior Express Written Consent' Actually Means
Consent is the legal dividing line between a welcome reminder and an illegal text — and the FCC treats "prior express written consent" far more strictly than most business owners realize. Getting the distinction right determines whether your outreach builds revenue or statutory liability.
Under the TCPA's two-tier framework, the type of message you send dictates the type of consent you need. Marketing texts require prior express written consent (PEWC) — a written agreement, paper or electronic, bearing the recipient's signature that clearly authorizes delivery of advertisements or telemarketing messages, according to legal compliance analyses. Informational texts — appointment reminders, delivery notifications, no-show follow-ups — generally require only prior express consent (PEC), which can be oral or implied.
That implied-consent standard matters enormously for service businesses. When a customer knowingly provides their phone number in the normal course of business — booking an HVAC tune-up, scheduling a dental appointment, requesting a quote — compliance experts note that implied consent covers transactional messaging tied to that relationship. What it does not automatically cover is promotional outreach, which is why CallMyCustomers builds explicit consent collection into its booking flow and works only from lists of real customers.
Valid PEWC must meet specific disclosure requirements. SMS compliance guidance confirms consent must be clear and conspicuous and include:
- A statement that consent is not a condition of purchase
- Disclosure of the specific message types the consumer will receive
- Notice of potential message and data rates
- Clear opt-out instructions the consumer can follow at any time
The stakes are concrete: TCPA violations carry statutory damages of $500 per text, up to $1,500 for willful violations, with no cap on total damages, per Purdue Global Law School's compliance analysis. One noncompliant blast could mean multimillion-dollar liability.
A final wrinkle: the FCC's January 2025 rule change requires 1-to-1 consent — separate consent for each individual seller — closing the lead generation loophole where consumer data was resold to hundreds of sellers. For businesses texting their own past customers, this reinforces a simple principle: know exactly who consented, to what, and when.
State-Level Risks: How Mini-TCPA Laws Increase Your Exposure
Staying compliant with the federal TCPA is only half the battle. A growing patchwork of state "mini-TCPA" laws imposes stricter rules and steeper penalties than federal law, meaning a campaign that's legal in one state can expose you to serious liability in another.
Under the federal TCPA, statutory damages run $500–$1,500 per violation — but state laws can multiply that exposure. Texas allows penalties of up to $5,000 per text under its Deceptive Trade Practices Act, and Connecticut permits fines of up to $20,000 per infraction for unsolicited texts sent outside approved hours.
State laws also tighten the operational rules in ways many businesses don't anticipate. Florida and Oklahoma restrict texting to 8:00 a.m.–8:00 p.m. — an hour earlier than the federal cutoff — and cap outreach at 3 texts on the same subject per rolling 24-hour period. Virginia adds a record-keeping twist: opted-out numbers must be retained on a do-not-text list for 10 years.
Key state-level variations to track:
- Florida & Oklahoma: 8:00 a.m.–8:00 p.m. texting window and a 3-text-per-24-hours frequency limit
- Connecticut: no unsolicited texts before 9:00 a.m. or after 8:00 p.m., with penalties up to $20,000 per infraction
- Texas: up to $5,000 per text under the Texas Deceptive Trade Practices Act
- Virginia: 10-year mandatory retention of opted-out numbers on a do-not-text list
- Florida, Maryland & Oklahoma: ban any automated number selection system, eliminating the "not an autodialer" defense
That last point deserves attention. After Facebook, Inc. v. Duguid, platforms using preset number lists generally aren't considered autodialers under federal law — but state mini-TCPAs in Florida, Maryland, and Oklahoma close that loophole by banning any automated number selection system. A defense that works in federal court may fail entirely in state court.
For service businesses running reactivation campaigns across state lines, this is why a one-size-fits-all texting approach is risky. At CallMyCustomers, campaigns are built around state-specific compliance protocols — honoring the strictest quiet hours, respecting frequency caps, and processing opt-outs immediately rather than waiting the 10 business days federal law allows.
The practical takeaway: before any text campaign goes out, know where your recipients live. A single noncompliant blast can trigger violations under both federal and multiple state statutes simultaneously, with penalties stacking per violation element. Segmenting your list by state and applying the strictest applicable rules isn't just cautious — it's the cheapest insurance you'll ever buy.
Compliance in Action: How CallMyCustomers Ensures Legal Text Outreach
Knowing the rules is one thing; running text outreach that actually stays on the right side of them is another. With TCPA violations carrying $500–$1,500 in statutory damages per message and no cap on total liability, a single noncompliant campaign can turn a marketing channel into a legal liability. That's why a permission-based process isn't just good practice — it's the foundation of legal text outreach.
At CallMyCustomers, every campaign starts with a free list review of a business's actual customer records — real customers from a CRM, spreadsheet, or point-of-sale system, not purchased or scraped lists. This matters legally as well as practically: under the FCC's January 2025 "1-to-1 consent rule," consent must be tied to a specific seller, closing the lead generation loophole where consumer data was resold to hundreds of businesses. Working from a business's own customer relationships avoids that problem entirely.
The control process mirrors what regulators look for. The business owner approves every script, offer, and message before anything is sent — "We plan the campaign together, you sign off, we run it." That review step ensures messaging is clear and conspicuous, tied to a genuine customer relationship, and consistent with what the customer originally agreed to receive.
Opt-out handling is where many businesses slip. Federal law requires that opt-out requests — STOP, END, CANCEL, UNSUBSCRIBE, QUIT — be processed within 10 business days, with only one non-promotional confirmation text permitted. Continued texting after a STOP request is treated as a willful violation subject to enhanced penalties. CallMyCustomers honors opt-outs immediately, well inside the legal window, and never sends promotional follow-ups afterward.
Compliance also extends beyond federal rules. State mini-TCPA laws add layers that a responsible outreach partner tracks:
- Quiet hours: Florida and Oklahoma restrict texts to 8:00 a.m.–8:00 p.m., tighter than the federal 8 a.m.–9 p.m. window
- Frequency caps: Florida and Oklahoma limit outreach to 3 texts on the same subject per 24-hour period
- Retention: Virginia requires opted-out numbers to stay on a do-not-text list for 10 years
- Penalties: Connecticut fines reach $20,000 per infraction; Texas allows up to $5,000 per text
For dental, med spa, and clinic clients, outreach runs under the required privacy agreements, including BAA/HIPAA, TCPA, and A2P 10DLC registration, with patient communication handled to clinical standards. The booking flow also collects explicit consent, so every new conversation starts on a documented, permissioned footing.
The result is text outreach that feels like what it is: a business reconnecting with people who already know and chose it. When consent is real, opt-outs are honored, and every message is owner-approved, reactivation stops being a legal risk and becomes what it should be — a second revenue engine built on trust.
Frequently Asked Questions
Are unwanted text messages actually illegal under federal law?
What does 'prior express written consent' really mean for marketing texts?
Do I need different consent for appointment reminders versus promotional texts?
How quickly must I honor a customer's opt-out request via text?
Can state laws create additional liability beyond federal TCPA rules?
What changed with the FCC's January 2025 rule regarding text message consent?
Key Takeaways
{ "title": "The Text That Builds Trust — And The One That Breaks It", "content": "Unwanted texts aren't just annoying — they're expensive. Federal law demands prior express written consent for marketing messages, with statutory damages of $500–$1,500 per violation and no requirement to prove act