
Is someone constantly texting you harassment?
Key Facts
- Each unwanted text can cost a business $500–$1,500 in statutory damages with no aggregate cap, per industry compliance data.
- TCPA class action filings surged nearly 95% year-over-year through mid-2025, industry data shows.
- Since April 11, 2025, consumers can revoke text consent by any reasonable means — even telling a cashier — under new FCC rules.
- A single 'STOP' text must halt both robotexts and automated calls across all channels within 10 business days, legal analysis confirms.
- Florida caps marketing texts at 3 messages per 24 hours per recipient, among the strictest state mini-TCPA limits.
- Do Not Call Registry violations carry fines up to $43,792 per call or text, dwarfing standard TCPA damages, per regulatory summaries.
- Carriers have blocked unregistered business SMS traffic since February 2025 under the mandatory A2P 10DLC framework.
When Repeated Texts Cross the Legal Line
The line between persistent outreach and actionable harassment isn't drawn at a universal text count — it's defined by consent status, opt-out compliance, and state-specific frequency limits. Under the Telephone Consumer Protection Act (TCPA), the FCC treats SMS as equivalent to voice calls, meaning unsolicited or non-consensual text campaigns face the same restrictions and penalties as robocalls. This equivalence is currently under legal challenge in the Ninth Circuit, where Dilanyan v. Hugo Boss Fashions, Inc. acknowledged "strong arguments that texts fall outside the statute" and certified the issue for interlocutory appeal, a rare procedural step that may reshape the landscape.
Statutory damages run $500–$1,500 per message with no aggregate cap, and TCPA class action filings have surged nearly 95% year-over-year through mid-2025, signaling heightened enforcement. For businesses, the risk compounds quickly: a campaign of 100,000 unsolicited messages could exceed $150 million in potential liability. Florida caps marketing SMS at 3 messages per 24 hours per recipient, while Connecticut imposes penalties up to $20,000 per violation and Arizona fines up to $1,000 per violation for texts to DNC-registered numbers. Virginia requires opt-out records to be retained for 10 years.
The April 2025 opt-out rules significantly expanded how consent can be revoked. Consumers may now opt out by any reasonable means — keywords like "STOP," "QUIT," "END," "REVOKE," "OPT-OUT," "CANCEL," "UNSUBSCRIBE," but also email, voicemail, or even telling a cashier — and businesses must honor revocation within 10 business days. A "STOP" text requires ceasing both texts and automated calls across all channels. Adding a discount or upsell to a transactional message reclassifies it as marketing, triggering the higher prior express written consent standard.
- Consent status determines whether outreach is lawful — not message volume alone
- Opt-out requests must be honored within 10 business days across all channels
- State mini-TCPAs impose stricter frequency limits than federal law
- Statutory damages of $500–$1,500 per message carry no aggregate cap
CallMyCustomers operates exclusively from lists of real customers with documented consent, honoring opt-outs immediately and routing replies back into the business's booking process — a permission-based approach that aligns with both the letter and spirit of these regulations. The carrier-level A2P 10DLC framework exists specifically because unregulated routes "started seeing abuse from spam applications and unsolicited messaging," eroding consumer trust in SMS as a communication channel. Registration is now mandatory for anyone sending application-to-person SMS in the US, with unregistered traffic blocked by carriers since February 2025.
The New Opt-Out Rules That Shift Power to Recipients
For years, businesses could hide behind a single "STOP" keyword or a buried unsubscribe link, forcing consumers to jump through hoops to silence unwanted messages. That dynamic shifted on April 11, 2025, when new FCC rules took effect requiring senders to honor consent revocation by any reasonable method — and to do it within 10 business days.
The rule change is sweeping. Consumers can now opt out using keywords like STOP, QUIT, END, REVOKE, OPT-OUT, CANCEL, or UNSUBSCRIBE, but also through voicemail, email, a website form, or even by telling a cashier during an in-person visit. The FCC established a rebuttable presumption of reasonableness for these methods, placing the burden on the sender to prove a revocation request was invalid — not on the consumer to prove it was valid. Businesses can no longer designate an exclusive opt-out channel or require consumers to use a specific portal.
- A single "STOP" text now stops both robotexts and automated calls across all channels — cross-channel revocation is mandatory
- Senders may send exactly one clarification message within five minutes of revocation, containing no marketing content
- Opt-out records must be retained for at least four years (ten years in Virginia) to demonstrate compliance
- Statutory damages run $500 to $1,500 per message with no aggregate cap, making delayed compliance exponentially expensive
These requirements align with how responsible outreach should work. At CallMyCustomers, every campaign is built on permissioned lists of real customers, and opt-outs are honored immediately across all channels — calls, texts, and emails — because the cost of getting it wrong isn't just regulatory. A campaign of 100,000 non-compliant messages could exceed $150 million in potential liability, and TCPA class action filings have surged nearly 95% year-over-year through mid-2025.
The rule also clarifies that informational messages and marketing messages carry different opt-out scopes. Revoking consent for marketing texts stops only marketing outreach; revoking from informational messages applies to all messages. For service businesses running seasonal reminders, renewal notices, or post-service follow-ups, that distinction matters — and it's why every message template is reviewed and approved by the business owner before a single text is sent.
State-Level Thresholds That Are Stricter Than Federal Law
The federal TCPA sets a baseline, but several states have built stricter guardrails that businesses cannot ignore. Florida caps marketing texts at three messages per 24 hours per recipient and provides a 15-day safe harbor after an opt-out request. Connecticut can assess up to $20,000 per violation for telephonic sales made without prior written consent. Arizona targets unsolicited texts to numbers on the Do Not Call Registry with fines up to $1,000 per message, while Virginia mandates that opt-out records be retained for ten years. Industry compliance guides confirm these mini-TCPA provisions create a patchwork where the strictest applicable standard governs any multi-state campaign.
- Florida: 3 marketing messages per 24 hours; 15-day safe harbor after opt-out
- Connecticut: up to $20,000 per violation for telephonic sales without written consent
- Arizona: up to $1,000 per violation for texts to DNC-registered numbers
- Virginia: 10-year opt-out record retention requirement
DNC Registry violations carry a separate federal penalty of up to $43,792 per call or text, a figure that dwarfs the standard TCPA damages of $500–$1,500 per message. Regulatory summaries note that a single campaign of 100,000 non-compliant messages could theoretically exceed $150 million in liability. For businesses running reactivation outreach across state lines, this means every list segment must be scrubbed against the toughest rule in the mix — frequency caps, consent standards, and record-keeping requirements all apply simultaneously.
CallMyCustomers structures every reactivation campaign around these layered requirements, segmenting lists by state and honoring opt-outs immediately across all channels. Legal analysis confirms that a "STOP" text now requires ceasing both texts and automated calls within 10 business days, with only one clarification message permitted. The company's done-for-you model bakes this compliance into the workflow — scripts, offers, and cadences are approved before a single message sends, and replies route straight back to the client's booking process so consent and revocation are handled in real time.
How to Document and Stop Harassing Texts
If your phone keeps buzzing with unwanted marketing texts, you hold more legal power than you might realize — and the steps you take in the next few weeks determine whether those messages become actionable evidence. Here is a practical four-step plan to document and stop the harassment.
Step 1: Revoke consent — in any reasonable way. Since April 11, 2025, new FCC rules allow you to revoke consent by virtually any reasonable method, and businesses cannot force you to use a designated opt-out channel, according to legal analysis of the rules. Texting keywords like "STOP," "QUIT," "REVOKE," or "UNSUBSCRIBE" all qualify — but so do email, voicemail, or even telling a cashier. Whatever method you choose, screenshot or record it immediately. That timestamped proof is the foundation of your case.
Step 2: Track everything after the 10-business-day window. Senders must honor revocation within a reasonable period not exceeding 10 business days, per regulatory guidance. Mark the date you opted out, then log every message that arrives after the window closes. Each one is a potential violation. Note that revocation also crosses channels — a "STOP" text should halt automated voice calls too.
Step 3: File an FCC complaint. The FCC actively polices robotexts, having adopted new text rules in December 2023 and proposed the first AI-generated robocall and robotext regulations in August 2024, per the FCC's consumer policy record. Submit your complaint with your documented evidence:
- Screenshots of your opt-out request with timestamps
- Every message received after the 10-business-day window
- The sender's number, business name, and message content
- Records of any prior consent you originally gave, if known
Step 4: Consult a TCPA attorney. Statutory damages run $500 to $1,500 per message, and — critically — you do not need to prove actual injury to recover them, as legal analysis confirms. With TCPA class action filings up nearly 95% year-over-year through mid-2025, per industry data, attorneys actively pursue these cases.
One legal development worth watching: in Dilanyan v. Hugo Boss Fashions, the Ninth Circuit acknowledged "strong arguments that texts fall outside the statute" under Section 227(c)(5) and certified the question for interlocutory appeal, according to legal commentary. The pending ruling may affect the scope of your private right of action for texts specifically.
The lesson cuts both ways. Legitimate outreach operations — like CallMyCustomers, which honors opt-outs immediately and only texts from approved customer lists — treat consent revocation as a hard stop. Businesses that don't face uncapped per-message liability, and your documentation is what holds them to it.
What Compliant Business Outreach Looks Like
Harassment doesn't start with bad intentions — it starts with weak consent practices. The same TCPA framework that protects consumers from unwanted texts also defines exactly what compliant outreach looks like, and the difference between the two comes down to a handful of deliberate controls.
Permission-based reactivation begins before the first message is ever sent. CallMyCustomers collects explicit consent at the booking stage, so every customer on a reactivation list has already said yes to hearing from the business. This matters because informational messages do not require prior express written consent — but the moment a message includes a discount or upsell, it reclassifies as marketing and triggers the higher consent standard. Keeping transactional messages purely transactional is a compliance decision, not a stylistic one.
Opt-outs are where most campaigns fail. Since April 11, 2025, consumers can revoke consent by any reasonable means — a "STOP" text, an email, even telling a cashier — and a single revocation must stop texts and automated calls across every channel. The stakes are steep: statutory damages run $500–$1,500 per message with no aggregate cap, and TCPA class action filings rose nearly 95% year-over-year through mid-2025.
Compliant outreach, in practice, looks like this:
- Opt-outs honored immediately across all channels — well inside the 10-business-day legal maximum — with records retained for at least 4 years, and 10 years for Virginia under its state requirement.
- A2P 10DLC registration, which carriers have required since February 2025, ensuring traffic is verified and consensual rather than unregistered spam.
- Owner approval of every script and offer before sending, which prevents the frequency creep that creates liability — especially in states like Florida, which caps marketing at 3 messages per 24 hours per recipient.
- A free list review that segments real customers by recency before any fee, so outreach targets people with a genuine relationship to the business.
The owner-approval step deserves emphasis. When the business owner signs off on every message, frequency limits and consent boundaries get enforced at the source rather than retrofitted after a complaint. Consent documented and verifiable is the standard 10DLC compliance guidance recommends, and it is what separates reactivation from harassment in the eyes of both regulators and carriers.
Done this way, outreach to past customers isn't a legal gray zone. It's a permissioned conversation with someone who already chose your business once — and the compliance architecture is what keeps it that way.
Frequently Asked Questions
How many texts does it take before it's legally considered harassment?
What's the fastest way to stop unwanted marketing texts?
How long does a company have to stop texting me after I opt out?
Can I actually sue a company for texting me after I asked them to stop?
Do the texting rules vary by state?
What should I document if I plan to file a complaint about harassing texts?
From Risk to Relationship: Turning Compliance Into Customer Trust
As the article makes clear, the line between helpful outreach and actionable harassment isn’t drawn by message volume alone — it’s defined by consent, timely opt-out compliance, and adherence to both federal and state-specific rules. With statutory damages ranging from $500 to $1,500 per message and no aggregate cap, the financial risk of non-compliance can escalate quickly, especially as TCPA class action filings continue to surge. For businesses, the path forward isn’t just about avoiding penalties — it’s about building outreach that respects customer preferences and strengthens trust. CallMyCustomers helps service businesses do exactly that by operating exclusively from permissioned lists, honoring opt-outs immediately across all channels, and ensuring every message is approved by the business owner before it’s sent. This permission-based approach turns compliance into a competitive advantage, transforming reactivation from a legal gray zone into a reliable second revenue engine. If you’re ready to reconnect with past customers the right way — with consent, clarity, and compliance built in — start with a free list review to see what your audience can produce before spending a dollar. Learn more about TCPA compliance and SMS best practices to protect your business and your customer relationships.