ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

Can you share text messages without consent?

Back to InsightsCan you share text messages without consent?

Can you share text messages without consent?

Key Facts

  • Statutory damages for unsolicited marketing texts range from $500–$1,500 per violation, per class member, with no proof of injury required per BCLP analysis
  • One text to 2,000 customers without consent could expose a business to seven figures in statutory damages per Infobip compliance guidance
  • Marketing texts require prior express written consent, while transactional texts need only prior express consent per SMS compliance guides
  • As of February 2025, all major US carriers block unregistered A2P business SMS entirely per 10DLC registration guidance
  • Businesses must honor consent revocation made 'in any reasonable manner' within 10 business days under the FCC's Opt-Out Rule effective April 11, 2025 per BCLP analysis
  • Defensible consent records must include timestamp, disclosure language, consent channel, and phone number/campaign identifier per SMS compliance guides
  • Consent records should be retained for at least four years to match the TCPA statute of limitations per BCLP analysis

A single unsolicited promotional text can cost your business up to $1,500 — and the person who received it doesn't have to prove they were harmed to collect. That's the reality of texting customers under the Telephone Consumer Protection Act, and it's why consent isn't a nice-to-have for marketing messages. It's the legal floor.

Under the TCPA, businesses must obtain prior express written consent before sending marketing texts, marketing robocalls, or fax advertisements, according to legal analysis of the FCC's 2025 opt-out rules. The law provides a private right of action with statutory damages of $500–$1,500 per violation, per class member — and crucially, no proof of actual injury is required. A recipient who simply received an unpermitted text has standing to sue.

The math gets dangerous fast. One text to a list of 2,000 customers without documented consent could theoretically expose a business to seven figures in statutory damages. As compliance guidance from Infobip puts it plainly: you must have consent before sending marketing texts, and you cannot send unsolicited messages to consumers.

Not all consent is created equal, though. The law recognizes two distinct tiers, and confusing them is one of the most common — and most expensive — mistakes businesses make:

  • Marketing texts (promotions, sales, win-back campaigns) require prior express written consent — a documented, explicit opt-in.
  • Transactional texts (order confirmations, shipping updates, appointment logistics) require only prior express consent, typically satisfied when a customer provides their number during a transaction.
  • Mixing promotional content into a transactional thread without written consent is flagged by SMS compliance guides as a common, avoidable legal exposure.

This distinction matters enormously for reactivation campaigns. A win-back offer to a dormant customer is a marketing message, full stop — even if that customer once bought from you and once handed over their phone number. Past patronage is not written consent to promote.

That's why responsible reactivation programs, like the campaigns CallMyCustomers runs for US service businesses, work only from lists of real past customers with recorded consent, and collect explicit opt-ins in the booking flow before anything promotional goes out. It's also why every message gets owner sign-off before sending — because the burden of proving consent sits entirely with the business, not the recipient.

One recent development deserves a caveat. The Seventh Circuit's Steidinger ruling narrowed one narrow avenue of TCPA liability, but as Nixon Peabody cautions, the TCPA's core consent rules under Section 227(b) remain fully in force nationwide — and that's where most text-message litigation actually lives. Treat the ruling as permission to text freely, and you're gambling with $500–$1,500 per message.

How Carrier Rules and State Laws Layer On Top of Federal TCPA

Navigating text message compliance today means understanding how federal rules, carrier policies, and state laws intersect to create a complex but manageable framework. The landscape has shifted significantly in early 2025, with carriers now blocking unregistered business SMS and new federal opt-out requirements taking effect, all while state-level "mini-TCPA" laws add further obligations.

As of February 2025, every major US carrier — AT&T, T-Mobile, and Verizon — began blocking unregistered A2P business SMS outright, meaning messages fail to deliver if the sending brand isn’t registered through the 10DLC system. This carrier-level enforcement operates independently of federal law but directly impacts deliverability for any business using text messaging for customer outreach. Registration requires documenting the opt-in method, providing sample messages with STOP language, and confirming opt-out handling processes are in place.

Complementing these carrier rules, the FCC’s new Opt-Out Rule took effect on April 11, 2025, tightening requirements for honoring consumer revocations. Businesses must now honor consent withdrawal made "in any reasonable manner" — such as via live chat, email, or a support call — within 10 business days. A one-time clarification message is permitted within five minutes of revocation, provided it contains no marketing content. This rule eliminates the ability to mandate specific keywords like "STOP" as the only valid opt-out method, closing a common compliance gap.

Meanwhile, state laws continue to layer additional requirements that federal rules don’t address. For example, Virginia’s amended Telephone Privacy Protection Act mandates honoring opt-outs for a defined multi-year period and imposes penalties separate from federal TCPA damages. These state "mini-TCPA" statutes remain fully enforceable regardless of federal rulings like the Seventh Circuit’s Steidinger decision, which only narrowed Do-Not-Call claims and left core consent rules intact. For a service like CallMyCustomers, which relies on documented consent and immediate opt-out honoring for its reactivation campaigns, this layered approach underscores why compliance must be built into every message from the start. Businesses must maintain consent records — including timestamp, disclosure language, consent channel, and phone number/campaign identifier — for at least four years to align with the TCPA statute of limitations and defend against potential claims across jurisdictions.

The Seventh Circuit’s Steidinger ruling clarified that text messages are not considered “telephone calls” under the TCPA’s Do-Not-Call provision, eliminating private lawsuits under § 227(c)(5) in Illinois, Indiana, and Wisconsin. However, this decision does not alter the core consent requirements that govern most text message marketing liability nationwide. Section 227(b) of the TCPA—which covers autodialed and prerecorded calls and texts—remains fully enforceable and continues to drive the majority of TCPA litigation related to SMS marketing. Businesses must still obtain prior express written consent before sending marketing texts, as statutory damages of $500–$1,500 per violation, per class member apply regardless of the Steidinger interpretation.

This ruling creates a circuit split, with the First, Second, Ninth, and Eleventh Circuits previously holding that texts do qualify as “calls” under TCPA provisions. Until the Supreme Court resolves this disagreement, businesses operating across state lines cannot rely on Steidinger as nationwide protection. State “mini-TCPA” laws, such as Florida’s Telephone Solicitation Act and Virginia’s amended Telephone Privacy Protection Act, also remain unaffected and continue to impose independent consent and opt-out obligations. For example, Virginia requires honoring opt-outs for a defined multi-year period with penalties separate from federal TCPA damages, meaning a single compliant policy is no longer sufficient.

CallMyCustomers’ model aligns with this reality by requiring documented consent, honoring opt-outs immediately, and operating only from lists of real customers with owner-approved messages. Treating Steidinger as permission to loosen consent practices ignores the layered compliance environment where federal autodialer rules, state laws, carrier requirements, and evolving FCC guidance all converge. Until further judicial clarity emerges, maintaining rigorous consent documentation and opt-out honoring remains the only defensible approach.

Consent you can't prove is consent you don't have. When a TCPA dispute surfaces months after a campaign, the burden falls squarely on the business — and "we're pretty sure they opted in" won't hold up against statutory damages of $500–$1,500 per violation, with no requirement to prove actual injury (per BCLP's analysis).

That's why a defensible consent system starts with documentation, not sending. Compliance guidance recommends that every opt-in record capture four elements: the timestamp of consent capture, the full disclosure language shown at opt-in, the specific channel or source of consent, and the phone number with an associated campaign or brand identifier. As one SMS compliance guide puts it, without those four elements, "a brand is relying on memory instead of evidence when a dispute surfaces months later."

Keep those records for at least four years — the retention period that matches the TCPA statute of limitations. This is why working from lists of real past customers matters so much: a reactivation campaign built on genuine customer relationships, where consent was captured at booking or point of sale, gives you an evidentiary trail a scraped or purchased list never could.

Registration comes before the first message goes out. As of February 2025, every major US carrier — AT&T, T-Mobile, and Verizon — stopped delivering unregistered A2P business SMS entirely: not throttled, not delayed, blocked. Registration itself forces good habits: brands must document their opt-in method, submit sample messages containing business name and STOP language, and confirm opt-out handling. Standard brand registration runs roughly $48 with vetting adding 1–3 business days, per 10DLC registration guidance — a small price for messages that actually get delivered.

Finally, opt-out handling must go beyond keywords. The FCC's Opt-Out Rule, effective April 11, 2025, requires honoring revocation made "in any reasonable manner" within 10 business days, and the rule explicitly prohibits mandating a single opt-out method (per the FCC rule analysis). A practical opt-out system covers:

  • All FCC-endorsed keywords — STOP, QUIT, END, REVOKE, OPT-OUT, CANCEL, UNSUBSCRIBE — not just STOP
  • Opt-outs delivered by any reasonable method, including live chat, a support call, or an email reply
  • Immediate suppression across every campaign, so a customer who opted out of win-back texts isn't pinged by a renewal reminder the next week
  • At most one clarification message within five minutes of revocation — with zero marketing content

"Programs that only listen for the exact keyword STOP are building a gap a complaint or lawsuit can exploit," the same guide warns. Immediate, universal opt-out honoring — the standard CallMyCustomers applies to every campaign it runs — isn't just a legal safeguard. It's what keeps a permission-based reactivation program worthy of the word "permission."

Frequently Asked Questions

Can I text my past customers a promo without asking first?
No. Under the TCPA, marketing texts — including win-back offers — require prior express written consent, with statutory damages of $500–$1,500 per violation and no need for the recipient to prove harm (per BCLP's analysis). Past patronage alone is not written consent to promote.
Do order confirmations and shipping updates need written consent too?
No — transactional texts like order confirmations and appointment reminders only require prior express consent, which is typically satisfied when a customer gives you their number during a transaction (per SMS compliance guidance). But be careful: mixing promotional content into a transactional thread without written consent is a common legal exposure.
Does the Steidinger ruling mean I can text customers without consent now?
No — that's a dangerous misreading. The ruling only narrowed Do-Not-Call lawsuits in three states, while the TCPA's core consent rules under Section 227(b) remain fully in force nationwide and still drive most text-message litigation (per Nixon Peabody). Other courts may disagree with the ruling, so don't assume nationwide protection.
What records do I need to prove a customer consented to texts?
Capture four elements for every opt-in: the timestamp, the full disclosure language shown, the channel or source of consent, and the phone number with a campaign identifier — and keep them for at least four years to match the TCPA statute of limitations (per SMS compliance guidance). Without those elements, you're relying on memory instead of evidence when a dispute surfaces.
If a customer replies 'remove me' instead of STOP, do I have to honor it?
Yes. The FCC's Opt-Out Rule, effective April 11, 2025, requires honoring revocation made 'in any reasonable manner' — including email, live chat, or a support call — within 10 business days, and you can't mandate STOP as the only valid method (per BCLP's analysis). Programs that only listen for the exact keyword STOP are building a gap a complaint can exploit.
Do I have to register my business with carriers before texting customers?
Yes — as of February 2025, AT&T, T-Mobile, and Verizon block unregistered A2P business SMS outright, so your messages simply won't deliver (per 10DLC registration guidance). Registration requires documenting your opt-in method, sample messages with STOP language, and confirmed opt-out handling, and standard brand registration runs roughly $48.

Turning Compliance Into Your Competitive Advantage

The message is clear: consent isn't just a legal checkbox—it's the foundation of trust, deliverability, and sustainable revenue from your existing customer base. From the steep penalties of unsolicited texts under the TCPA to the layered requirements of carrier registration, state mini-TCPA laws, and the FCC's stricter opt-out rules, businesses that treat consent as an afterthought risk far more than blocked messages—they risk seven-figure liability and damaged relationships. But for service businesses that thrive on repeat work, this compliance landscape isn't a barrier; it's an opportunity to stand out. By building a defensible consent system—documenting opt-ins with timestamps and disclosure language, honoring revocations in any reasonable manner, and registering for A2P 10DLC before sending—you transform regulatory rigor into a permission-based reactivation engine that drives booked appointments, not lawsuits. CallMyCustomers helps US service businesses do exactly this: working only from lists of real past customers with verified consent, running owner-approved campaigns, and turning dormant lists into repeat revenue—safely and effectively. Take the first step today: request your free list review to see exactly how many of your past customers are ready to reconnect—and what that could mean for your next booked job.

Stay in the Loop