
Is SMS blasting illegal?
Key Facts
- SMS blasting is not inherently illegal, but requires prior express written consent to be lawful
- TCPA allows statutory damages of $500–$1,500 per message, per violation, with no cap on aggregate exposure
- A single non-compliant text blast to 1,000 people can trigger fines of $500,000 to $1.5 million
- TCPA class actions filed through mid-2025 were up nearly 95% year-over-year
- Consumers can revoke consent via any reasonable method, not just 'STOP' keywords, effective April 11, 2025
- Opt-outs must be honored within 10 business days and records retained for at least 4 years
- 10DLC registration is mandatory for all A2P traffic since February 2025 — unregistered messages are blocked by carriers
Why Business Owners Fear SMS Blasting — and What the TCPA Actually Says
You've got a list of past customers. You know they'd come back if you reached out. But every time you think about sending a text blast, the same question stops you: Is this going to get me sued?
The short answer: SMS blasting is not inherently illegal. The FCC treats text messages as "calls" under the Telephone Consumer Protection Act (TCPA), which means the same rules that govern robocalls apply to every text you send. What makes it unlawful is texting without prior express written consent — an affirmative opt-in with clear disclosure and a documented record. Pre-ticked boxes, purchase history, or "implied" consent from a past transaction don't count.
The stakes are real. The TCPA allows statutory damages of $500–$1,500 per message, per violation, per class member — with no requirement to prove actual injury and no cap on aggregate damages. A single non-compliant campaign to 1,000 people can trigger fines of $500,000 to $1.5 million. A 100,000-message blast? Exposure exceeding $150 million in class-action liability. And the litigation curve is steepening: TCPA class actions filed through mid-2025 were up nearly 95% year-over-year.
- Marketing texts require prior express written consent — not implied, not purchased, not shared across brands
- Consumers can revoke consent through any reasonable method (email, voicemail, in-person), not just "STOP" keywords
- Opt-outs must be honored within 10 business days; records retained for at least 4 years
- 10DLC registration is mandatory for all A2P traffic — unregistered messages are blocked by carriers
- State laws (Florida, Connecticut, Texas, Virginia, Arizona) apply where stricter
Liability doesn't transfer to your provider. As one law firm puts it, "Even if you're using a third-party SMS marketing provider, you are still responsible for what's sent under your name." That's why CallMyCustomers builds compliance into every step — working only from real customer lists, honoring opt-outs immediately, requiring owner approval on every script and message before send, and collecting explicit consent in the booking flow. The list review happens before any fee, so you know exactly what's compliant and what's not.
The Five Rules That Separate Lawful Texting From Illegal Blasting
The line between a profitable text campaign and a six-figure class action isn't luck — it's five specific rules. Here's the compliance framework that separates lawful texting from illegal blasting.
Rule 1: Prior express written consent. Marketing texts require an affirmative opt-in with clear disclosure and a documented record. A pre-ticked box does not count, and neither does implied consent from a past purchase — "they bought from us" is not permission. Consent must be earned explicitly and stored as proof.
Rule 2: Honor every opt-out, in any form. Since April 11, 2025, consumers can revoke consent by any reasonable method — a reply, an email, a voicemail, even telling a cashier. Businesses must honor it within 10 business days, may send one clarification message within 5 minutes (no marketing content), and must retain opt-out records for at least four years.
Rule 3: One-to-one consent (January 2026). Consent cannot be shared across brands or sold to third parties — each sender must obtain its own consent from each consumer. This closes the lead-generator loophole that fueled the blasting era. If your list came from a shared or purchased source, that consent evaporates.
Rule 4: 10DLC registration. Since February 2025, all application-to-person traffic over 10-digit long codes must be registered with The Campaign Registry — both the brand and the campaign. Unregistered traffic is simply blocked by carriers, so registration is now a delivery gate, not a formality.
Rule 5: Apply the strictest state standard. State mini-TCPA laws stack on top of federal rules, and the stricter law wins. The state patchwork includes:
- Florida (FTSA) — a litigation "hotspot" with a 15-day safe harbor after opt-out and a cap of 3 messages per 24 hours per recipient (per Florida legal analysis)
- Connecticut — written consent required for all telephonic sales, with penalties up to $20,000 per violation
- Virginia — opt-out records must be retained for 10 years starting January 2026
- Arizona and Texas — additional restrictions layered onto TCPA requirements
The safest approach is to apply the strictest standard to every contact, since a single violation carries $500–$1,500 in statutory damages per message with no cap on aggregate exposure.
One trap deserves special attention: the transactional-versus-marketing distinction. Appointment confirmations and service reminders are transactional, but adding a discount offer or upsell reclassifies the message as marketing, triggering the written-consent standard. That "just one promo line" in a reminder text can cost you.
This framework is exactly why CallMyCustomers works only from real customer lists with owner-approved messages and immediate opt-out handling — compliance isn't a bolt-on, it's the operating model. If you'd like your list reviewed against these five rules before you spend a dollar, start with a free list review and see what your past customers could produce — the legal way.
Why Liability Can't Be Outsourced — Your Name Is on Every Text
Hiring someone else to press "send" doesn't transfer the legal risk that comes with it. Under the TCPA, liability for what lands in a customer's inbox follows the business whose name is on the message — not the vendor who sent it. As Trembly Law puts it plainly: "Even if you're using a third-party SMS marketing provider, you are still responsible for what's sent under your name."
This principle — non-delegable liability — matters more than ever. TCPA class actions filed through mid-2025 were up nearly 95% year-over-year, and statutory damages run $500 to $1,500 per message with no cap on aggregate exposure. A single non-compliant blast to 1,000 recipients can mean $500,000 to $1.5 million in fines. "The TCPA is often misunderstood, and too many businesses only realize the consequences after they've been sued," the same Florida law firm warns.
So if you can't outsource the risk, what can you do? You control it. The most effective safeguard is knowing exactly what goes out under your brand — before it goes out. That's why documented owner approval of every script, offer, and message isn't just a nice service feature. It's a compliance control that creates an audit trail showing you exercised oversight over your own campaigns.
A done-for-you reactivation model built the right way reflects this reality. CallMyCustomers, for example, plans each campaign with the business owner and requires sign-off on every message before anything is sent — "We plan the campaign together, you sign off, we run it." Combined with working only from lists of real customers and honoring opt-outs immediately, that approval workflow mirrors the discipline the TCPA demands.
Approval alone isn't the whole picture. A provider acting on your behalf should also be covering the operational bases the FCC and carriers now enforce:
- 10DLC brand and campaign registration, mandatory since February 2025 — unregistered traffic is simply blocked by carriers.
- Opt-out processing that honors revocation within 10 business days, per the FCC's April 2025 Opt-Out Rule, with records retained for at least four years.
- Consent standards that exclude pre-ticked boxes and implied consent, and prepare for the January 2026 one-to-one consent rule that bars shared or purchased consent.
The takeaway for any service business texting past customers: your name on the message means your name on the liability. Choose partners who treat your approval as a control, not a courtesy — and keep the record of every sign-off.
Ready to put your past customers back on the books — with every message approved by you and run by us? Get a free list review and see what your list can produce before you spend a dollar.
How to Run a Compliant Reactivation Campaign: A Practical Checklist
Compliance isn't a single decision — it's a sequence of small operational habits that together keep your campaign on the right side of the TCPA. The good news: a lawful reactivation campaign follows a predictable checklist, and every step maps to a rule regulators have already spelled out.
Start with a consent audit, not a message. Before any campaign fee changes hands, review your list and segment contacts by consent provenance — where each opt-in came from, when, and what it covered. Marketing texts require prior express written consent, and a pre-ticked box or implied consent from a past purchase doesn't count. This is why our free list review at CallMyCustomers exists: you should know exactly what your list can legally produce before spending a dollar.
Text only real customers with documented opt-ins. Purchased leads and scraped numbers are out — the one-to-one consent rule taking effect January 2026 closes the lead-generator loophole entirely, meaning each sender must obtain its own consent from each consumer. Reactivation works precisely because the people on your list already chose you.
Honor opt-outs immediately — and keep the receipts. Under the FCC's April 11, 2025 opt-out rule, consumers can revoke consent by any reasonable method — email, voicemail, even telling a cashier — and you must honor it within 10 business days. Retain opt-out records for at least 4 years; Virginia will require 10 years starting in 2026.
Your practical checklist:
- Register your 10DLC brand and campaign — unregistered traffic has been blocked by carriers since February 2025.
- Tag every contact by state and apply the strictest applicable rule — Florida caps you at 3 messages per 24 hours per recipient.
- Collect explicit consent in your booking flow, with a documented record of source and date per contact.
- Keep quiet hours: 8am–9pm in the recipient's local time zone.
For dental, med spa, and clinic clients, layer privacy obligations on top: patient outreach should operate under the required BAA/HIPAA agreements alongside TCPA and 10DLC registration, with messaging held to clinical standards.
Finally, remember that liability is non-delegable — even with a third party sending on your behalf, you're responsible for what goes out under your name. That's why owner approval of every script and offer before sending isn't just a service feature; it's a compliance control. Your next booked customer already knows your business — reach them the lawful way.
Permissioned Texting Works Better Anyway — The Case for Doing It Right
Permissioned texting isn’t just about avoiding legal risk — it’s about performance. When you text people who already know your business, you’re tapping into a channel with a ~98% open rate and 90% of messages read within 3 minutes, according to industry benchmarks. That kind of attention doesn’t come from cold blasting; it comes from trust and familiarity. Reactivation campaigns work because they’re timely, relevant, and expected — not intrusive. The data shows that messaging past customers converts far better than cold outreach, especially when the offer feels useful, not pushy.
At CallMyCustomers, lawful texting is turnkey because compliance is built into the process. We plan the campaign together, you sign off on every script and offer, and we run it — ensuring every message aligns with TCPA requirements and your brand voice. This owner-approval workflow isn’t just a feature; it’s a documented control that reduces liability while boosting response. By working only from real customer lists and honoring opt-outs immediately, we turn regulatory adherence into a revenue advantage — one booked appointment at a time.
Frequently Asked Questions
Is SMS blasting actually illegal, or just risky?
Can I text customers who have bought from me before, since they already know my business?
How much could a non-compliant text blast actually cost me?
If I hire a third-party service to send texts, does the liability transfer to them?
Do customers have to text "STOP" to opt out, or can they revoke consent other ways?
Can I add a discount or upsell to my appointment reminder texts?
The Legal Answer Is Also the Profitable One
So — is SMS blasting illegal? Not inherently. What's illegal is texting people who never gave you documented, prior express written consent. The TCPA treats every text like a call, penalties run $500–$1,500 per message with no cap, and class actions are up nearly 95% year-over-year. The five rules that keep you lawful are clear: earn explicit consent, honor every opt-out within 10 business days, prepare for one-to-one consent in January 2026, register your 10DLC campaign, and apply the strictest state standard. And remember: liability never transfers to your provider — your name on the message means your name on the risk. Here's the encouraging part: the compliant path is also the profitable one. Texting real customers who already chose you beats cold blasting on every metric, and permissioned texts see a ~98% open rate with 90% read within 3 minutes. Your next step is simple: audit your list by consent provenance before you send anything. If you'd like a second set of eyes, CallMyCustomers offers a free list review — you'll know exactly what your past customers can produce, lawfully, before you spend a dollar.