What Is the TCPA?
The Telephone Consumer Protection Act (TCPA) is the federal law that governs unsolicited commercial communications in the United States. It was originally passed in 1991 to curb telemarketing calls and fax blasts — but through FCC regulation and court rulings, it now fully covers business text messaging.
The FCC writes and enforces the specific rules. Courts interpret them in litigation. And the law gives individuals the right to sue directly — no need to wait for a regulator to act.
This guide is practical education, not legal advice. For compliance specific to your business, consult a qualified attorney.
Why TCPA Matters for SMS Marketing
The penalties aren’t theoretical. TCPA violations carry statutory damages of 500to500to1,500 per message. If you send a non-compliant campaign to 5,000 contacts, you’re looking at potential exposure in the millions.
Class-action lawsuits are the most significant risk. Plaintiffs’ attorneys actively recruit recipients of non-compliant texts, and a single campaign sent without proper consent or to contacts who opted out can generate massive litigation. The FCC has also increased enforcement activity in recent years, particularly around lead generation and affiliate texting.
The practical takeaway: TCPA compliance isn’t just a legal checkbox. It’s the infrastructure that keeps your business texting sustainable at scale. For current FTC guidance on the DNC registry, see the FTC website.
The good news is that the rules are straightforward. Follow them and you can send aggressive, high-volume campaigns with confidence. The businesses that get burned are almost always those that cut corners on consent or don’t have reliable opt-out systems.
The Core Rules: What the TCPA Actually Requires
TCPA compliance for business texting comes down to four fundamental requirements:
1. Get Prior Express Consent Before You Text
You cannot send marketing texts to someone without their permission. Period. The consent has to be obtained before the first message, it has to be specific to you (not transferable from another list or business), and it has to cover the type of messages you’re sending.
2. Identify Your Business in Every Message
Every text you send must make clear who it’s from. Your business name should appear in the message itself — don’t assume the recipient knows or has your number saved.
3. Honor Opt-Outs Immediately and Permanently
When someone replies STOP (or any other standard opt-out keyword), texting to that number must cease immediately. There’s no grace period. There’s no “one more follow-up.” STOP means stop.
4. Respect Quiet Hours
You cannot text before 8:00 a.m. or after 9:00 p.m. in the recipient’s local time zone — not yours. If you’re in California texting a contact in Florida, you need to apply Eastern time to that send.
Consent Explained: Express vs. Express Written
The TCPA has two tiers of consent, and the right one depends on what you’re sending.
Express Written Consent (Required for Marketing)
Marketing texts — promotional messages, sales follow-ups, offers, lead generation campaigns — require prior express written consent. This means the contact clearly and explicitly agreed to receive promotional texts from your business. Qualifying methods include:
- An unchecked opt-in checkbox at a form submission (pre-checked boxes don’t count)
- A keyword opt-in campaign (“Text HOMES to 55555”)
- A signed paper or digital consent form that specifically mentions SMS marketing
- A verbal agreement confirmed in writing
The word “written” in the statute is interpreted broadly — digital consent counts — but the intent must be unambiguous.
Express Consent (Sufficient for Transactional Messages)
Appointment reminders, order confirmations, delivery updates, and account notifications require express consent, but not the full written version. The bar is lower — if someone gave you their phone number in the context of a transaction, there’s an argument for implied consent. That said, collecting written consent at the point of signup is always the safer approach. When in doubt, get it in writing.
What Doesn’t Count as Consent
- Buying or renting a list from a third party
- Obtaining a phone number in an unrelated context and assuming it applies
- Burying opt-in language in general terms and conditions
- Consent given to another company that “shares” it with you
If your consent is questionable, it’s not consent. List hygiene starts at acquisition.
Opt-Outs: The STOP Command and What It Means
The TCPA requires that you honor opt-out requests immediately and permanently. The standard opt-out keyword is STOP, but you also need to respect UNSUBSCRIBE, CANCEL, END, and QUIT — all are recognized opt-out signals.
What “Immediately” Means
The moment a contact replies with an opt-out keyword, they must not receive another marketing text from your number. Not a confirmation message with an offer, not a re-engagement text three days later, not a “just one more thing” follow-up. Immediately means the next send they’re excluded.
What “Permanently” Means
An opt-out doesn’t expire. You can’t remove someone from your opt-out list after six months and start texting them again on the theory that enough time has passed. The only way to re-engage an opted-out contact is if they explicitly re-subscribe — and you have documentation of it.
The Confirmation Exception
Sending a single opt-out confirmation message is acceptable — something like “You’ve been unsubscribed from [Business Name] and will receive no further texts.” That confirmation cannot contain any marketing content.
ZeitBlast handles opt-out processing automatically. When a contact replies STOP, they’re removed from active sending lists in real time. No manual list management required, and the record is maintained so future campaigns don’t re-include them.
Quiet Hours: When You Can and Can’t Text
The TCPA prohibits sending marketing texts before 8:00 a.m. or after 9:00 p.m. in the recipient’s local time zone. This applies to the recipient’s timezone — not yours, not the server’s.
Why This Gets Businesses in Trouble
If you batch a campaign at 7:00 p.m. Pacific time, your East Coast contacts are receiving those messages at 10:00 p.m. local time. That’s a TCPA violation, even though it felt like a reasonable send time on your end.
Some common quiet-hours mistakes:
- Scheduling campaigns using the sender’s timezone without adjusting for recipient timezone
- Setting up drip sequences without accounting for timezone offsets
- Running re-engagement campaigns in the early morning when prospects on the other coast are still asleep
How ZeitBlast Handles It
ZeitBlast enforces quiet-hour compliance automatically based on recipient phone area codes. Messages scheduled for times outside the legal window are held and delivered at the next available compliant time — you don’t have to manually segment by timezone.
What Every Compliant Message Should Include
Each text you send to a marketing list should contain:
- Business identification — Who is texting. State your name or business name clearly.
- Relevant content — Material that matches what the contact opted in to receive.
- Opt-out instruction — At minimum, periodically include “Reply STOP to opt out.” This should appear in your initial welcome message and at regular intervals in ongoing campaigns.
- “Not a condition of purchase” language — If you’re offering something of value in exchange for consent, the message must clarify that receiving texts is not required to complete a transaction.
Short messages don’t leave a lot of room, so build the opt-out instruction into your message template defaults and you won’t have to think about it manually.
SHAFT Content: The Prohibited Categories
The TCPA and carrier policies both prohibit certain content categories regardless of consent. The acronym SHAFT covers them:
- S — Sex / Adult content
- H — Hate speech
- A — Alcohol (without proper age gating)
- F — Firearms
- T — Tobacco / Vaping
Beyond SHAFT, carriers also restrict: cannabis, high-risk financial services (payday loans, debt consolidation), online gambling, and sweepstakes. These restrictions apply at both the TCPA level and the carrier network level — meaning even with proper consent, SHAFT content can result in filtered messages and carrier penalties.
If any of your campaign content touches these categories, stop and consult a compliance attorney before sending.
TCPA vs. 10DLC: How They Fit Together
These two compliance systems confuse a lot of people. Here’s the distinction:
TCPA is the law. It governs your conduct — how you obtain consent, how you handle opt-outs, what you can send and when. It’s enforced by the FCC and through private lawsuits. Not following TCPA is a legal liability.
10DLC is the carrier infrastructure. It’s the registration system, administered by The Campaign Registry (TCR), that allows your messages to reach the carrier network. Not following 10DLC means your messages get filtered or blocked. For more detail, see our guide to 10DLC registration.
You need both. 10DLC gets your messages technically delivered. TCPA keeps you legally protected. A business can be fully 10DLC registered and still face TCPA litigation if they’re texting without consent or ignoring opt-outs.
DNC Lists and Litigator Scrub: The Layer Most Businesses Skip
The National Do Not Call (DNC) Registry is one layer of compliance. But there’s a more dangerous list that most businesses don’t know to check: litigator lists.
Litigators are individuals who have filed TCPA lawsuits in the past — often serially. Some people deliberately sign up for marketing lists with the intention of triggering a violation and suing. These names circulate on known litigator databases, and sending to them is a fast track to litigation.
ZeitBlast includes unlimited DNC & litigator scrub on every plan. Before your campaign sends, every number is checked against both the DNC registry and current litigator databases. Flagged contacts are automatically suppressed.
This is not a feature most platforms offer at all, let alone include at every price tier. For businesses doing high-volume lead generation — especially in real estate, where contact lists can be large and bought from various sources — it’s one of the most important compliance safeguards available.
Pre-Send Compliance Checklist
Run through this before every campaign:
- Consent documented — Every contact on this list has verifiable prior express written consent
- Opt-outs current — List has been checked against your current suppression list
- DNC & litigator scrub run — Numbers verified against DNC registry and litigator databases
- Quiet hours verified — Campaign will send within 8 a.m.–9 p.m. in each recipient’s local timezone
- Business identification — Messages clearly identify your business
- Opt-out instruction included — “Reply STOP to opt out” or equivalent appears in messages
- 10DLC registered — Sending number is registered and your campaign use case matches what you’re sending
- Content clear of SHAFT categories — No prohibited content in message body
This checklist won’t replace a legal review for complex situations, but for standard marketing campaigns it covers the bases where most violations occur.
How ZeitBlast Handles Compliance Automatically
Manual compliance tracking breaks down at scale. When you’re managing thousands of contacts across multiple campaigns, the probability of a human error — a missed opt-out, a timezone slip, an outdated suppression list — goes up with every send.
ZeitBlast’s platform is built with compliance in the infrastructure, not as an afterthought:
Automatic opt-out processing: When someone replies STOP, they’re suppressed in real time across all active campaigns. No manual work, no risk of an accidentally re-included contact.
Quiet-hour enforcement: Messages are automatically held and rescheduled if they’d land outside the 8 a.m.–9 p.m. window in the recipient’s timezone. You schedule when you want to send; we handle the timezone math.
Unlimited DNC & litigator scrub: Every campaign send is pre-screened against DNC and litigator databases before messages go out. Flagged contacts are suppressed without affecting your send.
10DLC built in: ZeitBlast handles 10DLC registration and keeps your campaign compliance aligned with your actual sending behavior. You’re not managing two separate compliance systems independently.
Carrier-safe batching: Messages are sent at carrier-approved rates, which reduces the risk of triggering spam filters that could impact your domain reputation with carriers.
For a deeper look at how 10DLC registration fits into this picture, see our step-by-step 10DLC registration guide.
Frequently Asked Questions
Is business texting legal? Yes — with proper consent, identification, and opt-out mechanisms. The TCPA doesn’t prohibit business texting; it sets the rules for doing it legally.
What consent do I need before texting a lead? For marketing messages, you need prior express written consent. The contact must have clearly agreed to receive promotional texts from your business specifically. Buying a list doesn’t provide this — each contact needs to have opted in directly.
What happens when someone texts back STOP? You must immediately and permanently stop sending marketing messages to that number. ZeitBlast processes STOP replies in real time and suppresses the contact across all campaigns.
Does the TCPA apply to appointment reminders? Yes, but the consent standard is lower. Transactional messages like reminders require express consent, not the full “express written” standard needed for marketing. Collecting phone numbers with clear consent at booking covers you.
What are the TCPA penalties? Statutory damages are 500perviolationforstandardviolationsandupto1,500 for willful violations. Each non-compliant message counts as a separate violation — a campaign sent to 10,000 contacts without consent could create 5M–15M in potential exposure.
What’s a litigator scrub? A litigator scrub checks your contact list against databases of individuals who have filed TCPA lawsuits. Some people deliberately trigger violations to sue. Scrubbing these contacts before you send removes the most litigious individuals from your list. ZeitBlast includes this on all plans.
Do quiet hours apply to transactional texts? The strict TCPA quiet-hours rule was written for marketing messages, but sending any text at 2 a.m. is a bad idea from both a legal and engagement standpoint. Apply quiet-hour logic to all your sends as a best practice.
Text Smarter, Not Riskier
TCPA compliance isn’t something to figure out after a lawsuit lands on your desk. The businesses that scale SMS successfully treat compliance as infrastructure — built into how they send, not bolted on afterward.
ZeitBlast gives you the tools to send aggressively and stay clean: automatic opt-out handling, quiet-hour enforcement, unlimited DNC & litigator scrub, and 10DLC compliance built into every account from day one.
Ready to run compliant SMS campaigns that actually convert? Request a ZeitBlast Demo and see the platform in action.
For more on SMS marketing fundamentals, see our What Is 10DLC guide and our 10DLC Registration walkthrough.