
Is it illegal to send unsolicited text messages?
Key Facts
- Each unsolicited promotional text can cost $500 in federal penalties, rising to $1,500 for willful violations, according to Purdue Global Law School.
- Consumers don't need to prove damages to sue — simply receiving one noncompliant text is enough to establish legal standing, legal experts explain.
- The FCC's 2024 rule requires carriers to block texts from numbers flagged for illegal texting, effective March 26, 2024, per the Federal Register.
- Connecticut's mini-TCPA law imposes penalties up to $20,000 per unsolicited text infraction, legal analysis shows.
- Florida and Oklahoma cap marketers at three texts on the same subject per rolling 24-hour period, state law summaries reveal.
- Having a customer's phone number from a past transaction is not legal permission to text them, Mailchimp warns.
- AT&T, Verizon, and T-Mobile require A2P 10DLC registration, and unregistered texts are often blocked outright, industry compliance analysis notes.
The Legal Risk: Why Unsolicited Texts Violate Federal Law
That friendly text you're tempted to send to last year's customers could cost you $1,500 per message — and a single campaign can add up to millions in liability. Under federal law, texting people who never agreed to hear from you isn't just bad manners; it's illegal.
The Telephone Consumer Protection Act (TCPA), enacted in 1991, strictly prohibits businesses from sending promotional texts without prior express written consent. That consent must be a clear agreement, and it cannot be a condition of making a purchase. The FCC reinforced this in its 2024 final rule, which codified National Do-Not-Call Registry protections for text messages and required mobile carriers to block texts from numbers flagged for illegal texting, effective March 26, 2024, according to the Federal Register.
The financial exposure is severe. Each violating text carries a $500 penalty, rising to $1,500 for willful violations, and a single message can trigger multiple violations because any noncompliant element counts. Perhaps most alarming, as Purdue Global Law School explains, a consumer doesn't have to prove actual damages — simply receiving a noncompliant text is enough to establish standing. With no cap on total damages, class actions are perfectly suited to these cases, meaning one noncompliant blast could expose a business to multimillion-dollar liability.
Here's the mistake that trips up so many service businesses: having a customer's phone number is not the same as having permission to text them. As Mailchimp puts it, assuming that a number from a past transaction equals consent is one of the most common errors businesses make — and implied or assumed permission is insufficient under U.S. law. Transactional messages like shipping alerts face lighter requirements, but promotional content always demands express written consent.
The rules don't stop at the federal level, either. State "mini-TCPA" laws in Florida, Maryland, Oklahoma, Connecticut, Texas, and California layer on additional requirements:
- Florida and Oklahoma prohibit texts before 8:00 a.m. or after 8:00 p.m., and cap three texts on the same subject per rolling 24-hour period.
- Connecticut imposes penalties up to $20,000 per infraction and bans unsolicited texts before 9:00 a.m. or after 8:00 p.m.
- Texas requires a telemarketer registration fee and a $10,000 bond, with penalties up to $5,000 per noncompliant text.
- California requires every commercial text to include the business name and clearly identify itself as an advertisement.
Compliance also extends to carrier-level standards. AT&T, Verizon, and T-Mobile require A2P 10DLC registration, and unregistered texts are often blocked outright — hurting deliverability even when your consent practices are sound.
The practical takeaway: any reactivation or retention campaign must start with documented consent, not just a contact list. That's why CallMyCustomers works only from lists of real customers, collects explicit consent in the booking flow, honors opt-outs immediately, and routes every message through owner approval before anything is sent — so reactivating past customers builds repeat revenue without building legal risk.
How Compliance Works: Layered Requirements Beyond Federal Law
Compliance with text messaging laws requires more than just checking a federal box. Businesses must navigate a layered landscape of state "mini-TCPA" laws, carrier registration requirements, and industry standards that go well beyond the Telephone Consumer Protection Act. State-level penalties can reach up to $20,000 per infraction in Connecticut, while Florida and Oklahoma restrict texts to specific hours and limit messaging frequency to avoid consumer fatigue. These rules mean that even a campaign compliant with federal law could trigger violations at the state level if timing, frequency, or registration details are overlooked.
Carrier-level compliance adds another critical dimension. AT&T, Verizon, and T-Mobile mandate A2P 10DLC registration for businesses sending application-to-person messages, and unregistered texts are often blocked or filtered, severely impacting deliverability. Industry standards like those from CTIA further reinforce best practices, advising against rented lead lists and emphasizing immediate opt-out honoring — principles that align with ethical, permission-based outreach. Together, these layers create a compliance framework where cutting corners isn’t just risky; it’s operationally ineffective.
CallMyCustomers builds its process around these requirements from the start. Every client list undergoes a free review that includes scrubbing against do-not-call and reassigned number databases to ensure only valid, consent-based contacts are messaged. All outreach messages are client-approved before deployment, and opt-out requests are honored immediately in accordance with TCPA and state-specific rules. This approach doesn’t just reduce legal exposure — it supports higher engagement by respecting customer preferences and maintaining message deliverability across carriers and jurisdictions.
Turning Compliance into Revenue: The CallMyCustomers Reactivation Model
Many service businesses already have a goldmine of potential revenue sitting in their customer lists — but reaching out without permission can trigger serious legal consequences. Sending unsolicited promotional texts violates the TCPA, which requires prior express written consent for any marketing message, and merely having a customer’s phone number from a past transaction does not qualify as permission. With penalties starting at $500 per violating text and climbing to $1,500 for willful violations, one poorly timed blast could expose a business to multimillion-dollar liability, especially when state mini-TCPA laws in places like Florida, Texas, and California add further restrictions and fines.
CallMyCustomers turns this risk into a revenue opportunity by focusing exclusively on permission-based reactivation — reaching out only to real customers who’ve already done business with you, using lists you approve and messages you sign off on before anything is sent. This approach isn’t just safer; it’s far more efficient. Reactivating an existing customer is approximately 5 times cheaper than acquiring a new one, and consent-based SMS lists consistently outperform purchased or scraped lists in open rates, click-through rates, and conversions. By working from your own CRM, spreadsheet, or point-of-sale data — and scrubbing it against reassigned number databases and opt-out lists before every campaign — the service ensures compliance with TCPA, A2P 10DLC requirements, and carrier standards while maximizing engagement.
- Every script, offer, and message is approved by you before deployment
- Opt-outs are honored immediately and tracked for required retention periods
- Campaigns run from your existing list — no software to buy or learn
- Replies route directly into your booking process for seamless follow-up
This model creates a second revenue engine alongside acquisition: one that’s legal, profitable, and built on trust. Instead of gambling with cold outreach that risks fines and damages brand reputation, service businesses can reactivate dormant customers with timely, useful messages — like seasonal reminders, post-service check-ins, or renewal notices — all sent under your brand, with your approval, and fully compliant. The result? More booked appointments, stronger customer relationships, and repeat revenue that doesn’t come with legal baggage.
Frequently Asked Questions
Is it actually illegal to text my past customers if I already have their phone numbers?
What are the real penalties if I send texts without proper consent?
Do state laws add more restrictions on top of the federal TCPA?
What's the difference between transactional and promotional texts for consent requirements?
Why do carriers block my texts even when I think I'm compliant?
How can I safely reactivate past customers without legal risk?
Turn Compliance Into Your Competitive Advantage
Sending unsolicited texts isn’t just risky — it’s illegal, costly, and damaging to trust, with penalties starting at $500 per message and no cap on liability. But the flip side is powerful: reactivating customers who already know and trust your business is not only safer, it’s up to five times more cost-effective than chasing new leads. By grounding your outreach in documented consent, honoring opt-outs immediately, and working from your own verified lists, you protect your business while unlocking a reliable stream of repeat revenue. The path forward is clear — audit your contact lists, secure proper permission, and let every message reflect your brand’s integrity. Ready to reactivate your past customers the right way? Start with a free list review from CallMyCustomers and see how compliant outreach can drive real results.