Compliance·22 Jul 2022·7 min read

US Laws for SMS Opt-in and Opt-out

Learn about US laws for SMS Opt-in and Opt-out, including CAN-SPAM, TCPA, and CCPA regulations, with tips for compliance and best practices.

Are you wondering what the US laws for SMS Opt-in and Opt-out are when sending business-related text messages? Understanding these regulations is essential to ensure your business stays compliant and avoids hefty fines.

In 2023, the number of scam reports in the U.S. reached 2.6 million, with financial losses exceeding $10 billion, which was a 14% increase from 2022. Most of the reported scams involved investment and imposter scams, with investment scams alone accounting for $4.6 billion in losses. The FBI's Internet Crime Complaint Center (IC3) also reported a record number of 880,418 complaints in 2023, with total losses exceeding $12.5 billion, reflecting a 22% increase from 2022.

This rise in scam-related complaints highlights the growing threat to both individuals and businesses, making it more crucial than ever for companies to adhere to privacy and consent regulations when conducting SMS marketing campaigns.

Privacy is more important to consumers than ever before, and businesses must comply with privacy laws to build trust. This article outlines key US SMS Opt-in and Opt-out laws, compliance tips, and best practices to help your business navigate these regulations.

Before exploring the legal specifics, it's essential to understand the basics of gaining consent for SMS communication. For consent to be valid, individuals must be fully informed about how their information will be processed. Any consent obtained through vague terms or coercion is considered invalid.

What is SMS Opt-in?

SMS Opt-in is the process where a customer or website visitor gives explicit permission for a company to send them text messages. Without Opt-in consent, it is illegal for a business to collect and process personal data, including sending marketing text messages.

What is SMS Opt-out?

SMS Opt-out allows customers to revoke their consent to receive further messages. Under the CAN-SPAM Act, businesses must offer recipients an easy way to opt-out after they have opted-in.

Top 3 US Laws for SMS Opt-in and Opt-out

1. The CAN-SPAM Act.

The CAN-SPAM Act protects consumers from unwanted marketing and advertising messages. Companies cannot send promotional text messages without the recipient's consent, although transactional messages (e.g., order confirmations) are allowed without prior Opt-in.

Key requirements of the CAN-SPAM Act:

  • Accurate header information: Must clearly identify the sender.
  • Clear subject lines: Must not be deceptive.
  • Labeling of advertisements: The message must be marked as an ad.
  • Valid postal address: Every message must include the company's postal address.
  • Easy opt-out mechanism: Recipients must have a clear way to opt-out of future messages.

CAN-SPAM is primarily an email marketing law. Its reach into text messaging is narrow: it mainly covers "mobile service commercial messages" sent to a wireless subscriber's email-to-text address, which the FCC regulates separately. Most standalone SMS marketing in the US is governed primarily by the TCPA, not CAN-SPAM.

2. The Telephone Consumer Protection Act (TCPA)

The Telephone Consumer Protection Act (TCPA), enforced by the Federal Communications Commission (FCC) under 47 U.S.C. § 227, was passed in 1991 to limit telemarketing calls and messages, and it restricts the use of automated dialing systems, SMS, and pre-recorded messages without express consent. Companies must have written consent before sending text messages, and even if a business relationship exists, explicit permission is still required.

Consumers who receive unsolicited messages can sue for TCPA violations, with penalties ranging from $500 to $1,500 per violation, depending on whether the violation was intentional.

2025 TCPA Updates

As of this update (2026), two TCPA developments from 2025 are worth flagging:

  • The FCC's "one-to-one consent" rule was vacated. This rule would have required businesses to get separate consent from each individual seller before sending autodialed or prerecorded marketing calls and texts. In January 2025, the Eleventh Circuit Court of Appeals vacated the rule before it took effect, so it is not current law.
  • New revocation-of-consent rules took effect in April 2025. Under these FCC rules, a consumer can revoke consent through any reasonable means, and the sender must honor that revocation within 10 business days.

This area of TCPA regulation has moved quickly: confirm the current status of both points with the FCC or legal counsel before relying on them.

3. The California Consumer Privacy Act (CCPA)

The CCPA grants California residents greater control over their personal data and requires businesses to disclose what information they collect and how it's used. Businesses must allow customers to opt-out of data collection and delete personal information upon request.

Key CCPA provisions:

  • Right to know what personal data is collected.
  • Right to opt-out from data sharing with third parties.
  • Right to request data deletion.
  • Right to non-discrimination for exercising privacy rights.

Businesses that fail to comply with CCPA can be fined up to $7,500 per violation.

Also Required: A2P 10DLC Registration

Beyond these laws, US carriers require application-to-person (A2P) text messages sent over standard 10-digit long code numbers to be registered. Brands and campaigns must register through The Campaign Registry, following requirements set by CTIA (the wireless industry association) in its Messaging Principles and Best Practices. Traffic sent from unregistered numbers is commonly filtered or blocked by carriers, so 10DLC registration is a practical prerequisite for compliant SMS at scale in the US, even though it comes from carriers and industry bodies rather than a statute.

Tips for SMS Opt-in and Opt-out Compliance

Obtaining valid consent can be done in multiple ways, such as using a keyword query (e.g., texting "START" to a specific number) or including a checkbox for customers when they sign up online. Here are a few essentials to include in your consent form:

  • A link to your privacy policy.
  • Clear instructions on how to opt-out.
  • Details on how many messages customers can expect.
  • Information on how to get help.

For example, your consent form could read, "Subscribe to receive text messages from [Company Name]" with a link to relevant disclosures. For companies selling personal data, a separate opt-in checkbox is required.

SMS Opt-in Example

ValueText, a Salesforce native messaging app, allows businesses to create an automated consent process using keywords like "START" to initiate Opt-in. A typical call-to-action might say, "Text [KEYWORD] to [NUMBER] for updates on [Product Name]."

You can enhance the process with a double Opt-in by sending a confirmation message like, "We'd like to send you helpful updates. Is that okay? Reply YES or NO." This approach ensures explicit consent and can be automated using tools like ValueText.

How to Handle SMS Opt-outs

To make the opt-out process easy, customers should be able to text keywords like "STOP," "UNSUBSCRIBE," "OPT-OUT," or "CANCEL." ValueText offers a Salesforce-based opt-out automation process, ensuring customers are instantly removed from marketing lists.

Fig 01 · SMS consentDrawn
01 · Opt-inKeyword or checkboxPolicy, frequency and help all stated.
→
02 · Double opt-inReply YES to confirmThe confirmation is recorded on the record.
→
03 · Opt-outSTOP, UNSUBSCRIBE, CANCELHonoured automatically, sends stop.
Fig 01 · Consent in, confirmation, and a way out that needs no one to action it.

If you are interested in more details regarding the topic check here.

WhatsApp Opt-in

When using WhatsApp for business messaging, conversations must be initiated with pre-approved templates. Once a customer replies, consent is considered given, and a 24-hour communication window opens. If the customer sends the first message, consent is automatically assumed.

Fig 02 · WhatsApp consentDrawn
01 · TemplatePre-approved message outConversations start no other way.
→
02 · ReplyConsent givenThe customer's answer is the opt-in.
→
03 · Session24 hoursFree-form messaging until it expires.
Fig 02 · WhatsApp conversations start on a template, and the reply is what opens the session.

Summary: Best Practices for SMS Opt-in and Opt-out Compliance

Complying with US laws for SMS Opt-in and Opt-out may seem complex, but following these steps can simplify the process:

  • Obtain consent using a keyword query.
  • Double Opt-in to confirm permission using automated tools like ValueText.
  • Make it easy to opt-out by providing clear instructions.
  • Ensure compliance with regulations such as CAN-SPAM, TCPA (FCC, 47 U.S.C. § 227), and CCPA.
  • Avoid selling or sharing personal data without consent.

Once you've established your SMS Opt-in and Opt-out processes, it's essential to continually monitor compliance and make adjustments as needed. You can learn more about SMS marketing best practices with Salesforce to stay ahead of the curve.

Key Takeaway About SMS Opt-in and Opt-out

It's important to remember that sending unsolicited text messages is illegal. Penalties range from $500 to $1,500 per violation. Stay compliant with US laws by ensuring that all SMS communications follow the proper Opt-in and Opt-out procedures.

Navigating the complexities of SMS marketing compliance can be overwhelming, but at ValueText, we're here to help. You can BOOK A DEMO with our team to go over your use cases or you can start a free trial. You don't need to do this alone.

Questions about this guide? Write to us. Talk to us→

Keep reading

All posts→
Compliance WhatsApp pricing changes, October 2026 Meta begins charging for service and session messages on 1 October, including messages sent from the WhatsApp Business app. What changes, what does not, and what it means for your spend. 4 Sep 2026 · 6 min read Compliance ContactPointConsent in Salesforce Best Practices Guide Unlock the power of ContactPointConsent in Salesforce to streamline messaging consent and ensure compliance with your automation. 23 Dec 2025 · 7 min read Compliance Salesforce SMS Compliance: ValueText's AI Solutions Navigate SMS compliance in Salesforce with ValueText's AI-driven tools: stay ahead of regulations effortlessly. 23 Jun 2025 · 4 min read
Compliance·22 Jul 2022·7 min read

US Laws for SMS Opt-in and Opt-out

Learn about US laws for SMS Opt-in and Opt-out, including CAN-SPAM, TCPA, and CCPA regulations, with tips for compliance and best practices.

Are you wondering what the US laws for SMS Opt-in and Opt-out are when sending business-related text messages? Understanding these regulations is essential to ensure your business stays compliant and avoids hefty fines.

In 2023, the number of scam reports in the U.S. reached 2.6 million, with financial losses exceeding $10 billion, which was a 14% increase from 2022. Most of the reported scams involved investment and imposter scams, with investment scams alone accounting for $4.6 billion in losses. The FBI's Internet Crime Complaint Center (IC3) also reported a record number of 880,418 complaints in 2023, with total losses exceeding $12.5 billion, reflecting a 22% increase from 2022.

This rise in scam-related complaints highlights the growing threat to both individuals and businesses, making it more crucial than ever for companies to adhere to privacy and consent regulations when conducting SMS marketing campaigns.

Privacy is more important to consumers than ever before, and businesses must comply with privacy laws to build trust. This article outlines key US SMS Opt-in and Opt-out laws, compliance tips, and best practices to help your business navigate these regulations.

Before exploring the legal specifics, it's essential to understand the basics of gaining consent for SMS communication. For consent to be valid, individuals must be fully informed about how their information will be processed. Any consent obtained through vague terms or coercion is considered invalid.

What is SMS Opt-in?

SMS Opt-in is the process where a customer or website visitor gives explicit permission for a company to send them text messages. Without Opt-in consent, it is illegal for a business to collect and process personal data, including sending marketing text messages.

What is SMS Opt-out?

SMS Opt-out allows customers to revoke their consent to receive further messages. Under the CAN-SPAM Act, businesses must offer recipients an easy way to opt-out after they have opted-in.

Top 3 US Laws for SMS Opt-in and Opt-out

1. The CAN-SPAM Act.

The CAN-SPAM Act protects consumers from unwanted marketing and advertising messages. Companies cannot send promotional text messages without the recipient's consent, although transactional messages (e.g., order confirmations) are allowed without prior Opt-in.

Key requirements of the CAN-SPAM Act:

  • Accurate header information: Must clearly identify the sender.
  • Clear subject lines: Must not be deceptive.
  • Labeling of advertisements: The message must be marked as an ad.
  • Valid postal address: Every message must include the company's postal address.
  • Easy opt-out mechanism: Recipients must have a clear way to opt-out of future messages.

CAN-SPAM is primarily an email marketing law. Its reach into text messaging is narrow: it mainly covers "mobile service commercial messages" sent to a wireless subscriber's email-to-text address, which the FCC regulates separately. Most standalone SMS marketing in the US is governed primarily by the TCPA, not CAN-SPAM.

2. The Telephone Consumer Protection Act (TCPA)

The Telephone Consumer Protection Act (TCPA), enforced by the Federal Communications Commission (FCC) under 47 U.S.C. § 227, was passed in 1991 to limit telemarketing calls and messages, and it restricts the use of automated dialing systems, SMS, and pre-recorded messages without express consent. Companies must have written consent before sending text messages, and even if a business relationship exists, explicit permission is still required.

Consumers who receive unsolicited messages can sue for TCPA violations, with penalties ranging from $500 to $1,500 per violation, depending on whether the violation was intentional.

2025 TCPA Updates

As of this update (2026), two TCPA developments from 2025 are worth flagging:

  • The FCC's "one-to-one consent" rule was vacated. This rule would have required businesses to get separate consent from each individual seller before sending autodialed or prerecorded marketing calls and texts. In January 2025, the Eleventh Circuit Court of Appeals vacated the rule before it took effect, so it is not current law.
  • New revocation-of-consent rules took effect in April 2025. Under these FCC rules, a consumer can revoke consent through any reasonable means, and the sender must honor that revocation within 10 business days.

This area of TCPA regulation has moved quickly: confirm the current status of both points with the FCC or legal counsel before relying on them.

3. The California Consumer Privacy Act (CCPA)

The CCPA grants California residents greater control over their personal data and requires businesses to disclose what information they collect and how it's used. Businesses must allow customers to opt-out of data collection and delete personal information upon request.

Key CCPA provisions:

  • Right to know what personal data is collected.
  • Right to opt-out from data sharing with third parties.
  • Right to request data deletion.
  • Right to non-discrimination for exercising privacy rights.

Businesses that fail to comply with CCPA can be fined up to $7,500 per violation.

Also Required: A2P 10DLC Registration

Beyond these laws, US carriers require application-to-person (A2P) text messages sent over standard 10-digit long code numbers to be registered. Brands and campaigns must register through The Campaign Registry, following requirements set by CTIA (the wireless industry association) in its Messaging Principles and Best Practices. Traffic sent from unregistered numbers is commonly filtered or blocked by carriers, so 10DLC registration is a practical prerequisite for compliant SMS at scale in the US, even though it comes from carriers and industry bodies rather than a statute.

Tips for SMS Opt-in and Opt-out Compliance

Obtaining valid consent can be done in multiple ways, such as using a keyword query (e.g., texting "START" to a specific number) or including a checkbox for customers when they sign up online. Here are a few essentials to include in your consent form:

  • A link to your privacy policy.
  • Clear instructions on how to opt-out.
  • Details on how many messages customers can expect.
  • Information on how to get help.

For example, your consent form could read, "Subscribe to receive text messages from [Company Name]" with a link to relevant disclosures. For companies selling personal data, a separate opt-in checkbox is required.

SMS Opt-in Example

ValueText, a Salesforce native messaging app, allows businesses to create an automated consent process using keywords like "START" to initiate Opt-in. A typical call-to-action might say, "Text [KEYWORD] to [NUMBER] for updates on [Product Name]."

You can enhance the process with a double Opt-in by sending a confirmation message like, "We'd like to send you helpful updates. Is that okay? Reply YES or NO." This approach ensures explicit consent and can be automated using tools like ValueText.

How to Handle SMS Opt-outs

To make the opt-out process easy, customers should be able to text keywords like "STOP," "UNSUBSCRIBE," "OPT-OUT," or "CANCEL." ValueText offers a Salesforce-based opt-out automation process, ensuring customers are instantly removed from marketing lists.

Fig 01 · SMS consentDrawn
01 · Opt-inKeyword or checkboxPolicy, frequency and help all stated.
→
02 · Double opt-inReply YES to confirmThe confirmation is recorded on the record.
→
03 · Opt-outSTOP, UNSUBSCRIBE, CANCELHonoured automatically, sends stop.
Fig 01 · Consent in, confirmation, and a way out that needs no one to action it.

If you are interested in more details regarding the topic check here.

WhatsApp Opt-in

When using WhatsApp for business messaging, conversations must be initiated with pre-approved templates. Once a customer replies, consent is considered given, and a 24-hour communication window opens. If the customer sends the first message, consent is automatically assumed.

Fig 02 · WhatsApp consentDrawn
01 · TemplatePre-approved message outConversations start no other way.
→
02 · ReplyConsent givenThe customer's answer is the opt-in.
→
03 · Session24 hoursFree-form messaging until it expires.
Fig 02 · WhatsApp conversations start on a template, and the reply is what opens the session.

Summary: Best Practices for SMS Opt-in and Opt-out Compliance

Complying with US laws for SMS Opt-in and Opt-out may seem complex, but following these steps can simplify the process:

  • Obtain consent using a keyword query.
  • Double Opt-in to confirm permission using automated tools like ValueText.
  • Make it easy to opt-out by providing clear instructions.
  • Ensure compliance with regulations such as CAN-SPAM, TCPA (FCC, 47 U.S.C. § 227), and CCPA.
  • Avoid selling or sharing personal data without consent.

Once you've established your SMS Opt-in and Opt-out processes, it's essential to continually monitor compliance and make adjustments as needed. You can learn more about SMS marketing best practices with Salesforce to stay ahead of the curve.

Key Takeaway About SMS Opt-in and Opt-out

It's important to remember that sending unsolicited text messages is illegal. Penalties range from $500 to $1,500 per violation. Stay compliant with US laws by ensuring that all SMS communications follow the proper Opt-in and Opt-out procedures.

Navigating the complexities of SMS marketing compliance can be overwhelming, but at ValueText, we're here to help. You can BOOK A DEMO with our team to go over your use cases or you can start a free trial. You don't need to do this alone.

Questions about this guide? Write to us. Talk to us→

Keep reading

All posts→
Compliance WhatsApp pricing changes, October 2026 Meta begins charging for service and session messages on 1 October, including messages sent from the WhatsApp Business app. What changes, what does not, and what it means for your spend. 4 Sep 2026 · 6 min read Compliance ContactPointConsent in Salesforce Best Practices Guide Unlock the power of ContactPointConsent in Salesforce to streamline messaging consent and ensure compliance with your automation. 23 Dec 2025 · 7 min read Compliance Salesforce SMS Compliance: ValueText's AI Solutions Navigate SMS compliance in Salesforce with ValueText's AI-driven tools: stay ahead of regulations effortlessly. 23 Jun 2025 · 4 min read
Compliance·22 Jul 2022·7 min read

US Laws for SMS Opt-in and Opt-out

Learn about US laws for SMS Opt-in and Opt-out, including CAN-SPAM, TCPA, and CCPA regulations, with tips for compliance and best practices.

Are you wondering what the US laws for SMS Opt-in and Opt-out are when sending business-related text messages? Understanding these regulations is essential to ensure your business stays compliant and avoids hefty fines.

In 2023, the number of scam reports in the U.S. reached 2.6 million, with financial losses exceeding $10 billion, which was a 14% increase from 2022. Most of the reported scams involved investment and imposter scams, with investment scams alone accounting for $4.6 billion in losses. The FBI's Internet Crime Complaint Center (IC3) also reported a record number of 880,418 complaints in 2023, with total losses exceeding $12.5 billion, reflecting a 22% increase from 2022.

This rise in scam-related complaints highlights the growing threat to both individuals and businesses, making it more crucial than ever for companies to adhere to privacy and consent regulations when conducting SMS marketing campaigns.

Privacy is more important to consumers than ever before, and businesses must comply with privacy laws to build trust. This article outlines key US SMS Opt-in and Opt-out laws, compliance tips, and best practices to help your business navigate these regulations.

Before exploring the legal specifics, it's essential to understand the basics of gaining consent for SMS communication. For consent to be valid, individuals must be fully informed about how their information will be processed. Any consent obtained through vague terms or coercion is considered invalid.

What is SMS Opt-in?

SMS Opt-in is the process where a customer or website visitor gives explicit permission for a company to send them text messages. Without Opt-in consent, it is illegal for a business to collect and process personal data, including sending marketing text messages.

What is SMS Opt-out?

SMS Opt-out allows customers to revoke their consent to receive further messages. Under the CAN-SPAM Act, businesses must offer recipients an easy way to opt-out after they have opted-in.

Top 3 US Laws for SMS Opt-in and Opt-out

1. The CAN-SPAM Act.

The CAN-SPAM Act protects consumers from unwanted marketing and advertising messages. Companies cannot send promotional text messages without the recipient's consent, although transactional messages (e.g., order confirmations) are allowed without prior Opt-in.

Key requirements of the CAN-SPAM Act:

  • Accurate header information: Must clearly identify the sender.
  • Clear subject lines: Must not be deceptive.
  • Labeling of advertisements: The message must be marked as an ad.
  • Valid postal address: Every message must include the company's postal address.
  • Easy opt-out mechanism: Recipients must have a clear way to opt-out of future messages.

CAN-SPAM is primarily an email marketing law. Its reach into text messaging is narrow: it mainly covers "mobile service commercial messages" sent to a wireless subscriber's email-to-text address, which the FCC regulates separately. Most standalone SMS marketing in the US is governed primarily by the TCPA, not CAN-SPAM.

2. The Telephone Consumer Protection Act (TCPA)

The Telephone Consumer Protection Act (TCPA), enforced by the Federal Communications Commission (FCC) under 47 U.S.C. § 227, was passed in 1991 to limit telemarketing calls and messages, and it restricts the use of automated dialing systems, SMS, and pre-recorded messages without express consent. Companies must have written consent before sending text messages, and even if a business relationship exists, explicit permission is still required.

Consumers who receive unsolicited messages can sue for TCPA violations, with penalties ranging from $500 to $1,500 per violation, depending on whether the violation was intentional.

2025 TCPA Updates

As of this update (2026), two TCPA developments from 2025 are worth flagging:

  • The FCC's "one-to-one consent" rule was vacated. This rule would have required businesses to get separate consent from each individual seller before sending autodialed or prerecorded marketing calls and texts. In January 2025, the Eleventh Circuit Court of Appeals vacated the rule before it took effect, so it is not current law.
  • New revocation-of-consent rules took effect in April 2025. Under these FCC rules, a consumer can revoke consent through any reasonable means, and the sender must honor that revocation within 10 business days.

This area of TCPA regulation has moved quickly: confirm the current status of both points with the FCC or legal counsel before relying on them.

3. The California Consumer Privacy Act (CCPA)

The CCPA grants California residents greater control over their personal data and requires businesses to disclose what information they collect and how it's used. Businesses must allow customers to opt-out of data collection and delete personal information upon request.

Key CCPA provisions:

  • Right to know what personal data is collected.
  • Right to opt-out from data sharing with third parties.
  • Right to request data deletion.
  • Right to non-discrimination for exercising privacy rights.

Businesses that fail to comply with CCPA can be fined up to $7,500 per violation.

Also Required: A2P 10DLC Registration

Beyond these laws, US carriers require application-to-person (A2P) text messages sent over standard 10-digit long code numbers to be registered. Brands and campaigns must register through The Campaign Registry, following requirements set by CTIA (the wireless industry association) in its Messaging Principles and Best Practices. Traffic sent from unregistered numbers is commonly filtered or blocked by carriers, so 10DLC registration is a practical prerequisite for compliant SMS at scale in the US, even though it comes from carriers and industry bodies rather than a statute.

Tips for SMS Opt-in and Opt-out Compliance

Obtaining valid consent can be done in multiple ways, such as using a keyword query (e.g., texting "START" to a specific number) or including a checkbox for customers when they sign up online. Here are a few essentials to include in your consent form:

  • A link to your privacy policy.
  • Clear instructions on how to opt-out.
  • Details on how many messages customers can expect.
  • Information on how to get help.

For example, your consent form could read, "Subscribe to receive text messages from [Company Name]" with a link to relevant disclosures. For companies selling personal data, a separate opt-in checkbox is required.

SMS Opt-in Example

ValueText, a Salesforce native messaging app, allows businesses to create an automated consent process using keywords like "START" to initiate Opt-in. A typical call-to-action might say, "Text [KEYWORD] to [NUMBER] for updates on [Product Name]."

You can enhance the process with a double Opt-in by sending a confirmation message like, "We'd like to send you helpful updates. Is that okay? Reply YES or NO." This approach ensures explicit consent and can be automated using tools like ValueText.

How to Handle SMS Opt-outs

To make the opt-out process easy, customers should be able to text keywords like "STOP," "UNSUBSCRIBE," "OPT-OUT," or "CANCEL." ValueText offers a Salesforce-based opt-out automation process, ensuring customers are instantly removed from marketing lists.

Fig 01 · SMS consentDrawn
01 · Opt-inKeyword or checkboxPolicy, frequency and help all stated.
→
02 · Double opt-inReply YES to confirmThe confirmation is recorded on the record.
→
03 · Opt-outSTOP, UNSUBSCRIBE, CANCELHonoured automatically, sends stop.
Fig 01 · Consent in, confirmation, and a way out that needs no one to action it.

If you are interested in more details regarding the topic check here.

WhatsApp Opt-in

When using WhatsApp for business messaging, conversations must be initiated with pre-approved templates. Once a customer replies, consent is considered given, and a 24-hour communication window opens. If the customer sends the first message, consent is automatically assumed.

Fig 02 · WhatsApp consentDrawn
01 · TemplatePre-approved message outConversations start no other way.
→
02 · ReplyConsent givenThe customer's answer is the opt-in.
→
03 · Session24 hoursFree-form messaging until it expires.
Fig 02 · WhatsApp conversations start on a template, and the reply is what opens the session.

Summary: Best Practices for SMS Opt-in and Opt-out Compliance

Complying with US laws for SMS Opt-in and Opt-out may seem complex, but following these steps can simplify the process:

  • Obtain consent using a keyword query.
  • Double Opt-in to confirm permission using automated tools like ValueText.
  • Make it easy to opt-out by providing clear instructions.
  • Ensure compliance with regulations such as CAN-SPAM, TCPA (FCC, 47 U.S.C. § 227), and CCPA.
  • Avoid selling or sharing personal data without consent.

Once you've established your SMS Opt-in and Opt-out processes, it's essential to continually monitor compliance and make adjustments as needed. You can learn more about SMS marketing best practices with Salesforce to stay ahead of the curve.

Key Takeaway About SMS Opt-in and Opt-out

It's important to remember that sending unsolicited text messages is illegal. Penalties range from $500 to $1,500 per violation. Stay compliant with US laws by ensuring that all SMS communications follow the proper Opt-in and Opt-out procedures.

Navigating the complexities of SMS marketing compliance can be overwhelming, but at ValueText, we're here to help. You can BOOK A DEMO with our team to go over your use cases or you can start a free trial. You don't need to do this alone.

Questions about this guide? Write to us. Talk to us→

Keep reading

All posts→
Compliance WhatsApp pricing changes, October 2026 Meta begins charging for service and session messages on 1 October, including messages sent from the WhatsApp Business app. What changes, what does not, and what it means for your spend. 4 Sep 2026 · 6 min read Compliance ContactPointConsent in Salesforce Best Practices Guide Unlock the power of ContactPointConsent in Salesforce to streamline messaging consent and ensure compliance with your automation. 23 Dec 2025 · 7 min read Compliance Salesforce SMS Compliance: ValueText's AI Solutions Navigate SMS compliance in Salesforce with ValueText's AI-driven tools: stay ahead of regulations effortlessly. 23 Jun 2025 · 4 min read
Compliance·22 Jul 2022·7 min read

US Laws for SMS Opt-in and Opt-out

Learn about US laws for SMS Opt-in and Opt-out, including CAN-SPAM, TCPA, and CCPA regulations, with tips for compliance and best practices.

Are you wondering what the US laws for SMS Opt-in and Opt-out are when sending business-related text messages? Understanding these regulations is essential to ensure your business stays compliant and avoids hefty fines.

In 2023, the number of scam reports in the U.S. reached 2.6 million, with financial losses exceeding $10 billion, which was a 14% increase from 2022. Most of the reported scams involved investment and imposter scams, with investment scams alone accounting for $4.6 billion in losses. The FBI's Internet Crime Complaint Center (IC3) also reported a record number of 880,418 complaints in 2023, with total losses exceeding $12.5 billion, reflecting a 22% increase from 2022.

This rise in scam-related complaints highlights the growing threat to both individuals and businesses, making it more crucial than ever for companies to adhere to privacy and consent regulations when conducting SMS marketing campaigns.

Privacy is more important to consumers than ever before, and businesses must comply with privacy laws to build trust. This article outlines key US SMS Opt-in and Opt-out laws, compliance tips, and best practices to help your business navigate these regulations.

Before exploring the legal specifics, it's essential to understand the basics of gaining consent for SMS communication. For consent to be valid, individuals must be fully informed about how their information will be processed. Any consent obtained through vague terms or coercion is considered invalid.

What is SMS Opt-in?

SMS Opt-in is the process where a customer or website visitor gives explicit permission for a company to send them text messages. Without Opt-in consent, it is illegal for a business to collect and process personal data, including sending marketing text messages.

What is SMS Opt-out?

SMS Opt-out allows customers to revoke their consent to receive further messages. Under the CAN-SPAM Act, businesses must offer recipients an easy way to opt-out after they have opted-in.

Top 3 US Laws for SMS Opt-in and Opt-out

1. The CAN-SPAM Act.

The CAN-SPAM Act protects consumers from unwanted marketing and advertising messages. Companies cannot send promotional text messages without the recipient's consent, although transactional messages (e.g., order confirmations) are allowed without prior Opt-in.

Key requirements of the CAN-SPAM Act:

  • Accurate header information: Must clearly identify the sender.
  • Clear subject lines: Must not be deceptive.
  • Labeling of advertisements: The message must be marked as an ad.
  • Valid postal address: Every message must include the company's postal address.
  • Easy opt-out mechanism: Recipients must have a clear way to opt-out of future messages.

CAN-SPAM is primarily an email marketing law. Its reach into text messaging is narrow: it mainly covers "mobile service commercial messages" sent to a wireless subscriber's email-to-text address, which the FCC regulates separately. Most standalone SMS marketing in the US is governed primarily by the TCPA, not CAN-SPAM.

2. The Telephone Consumer Protection Act (TCPA)

The Telephone Consumer Protection Act (TCPA), enforced by the Federal Communications Commission (FCC) under 47 U.S.C. § 227, was passed in 1991 to limit telemarketing calls and messages, and it restricts the use of automated dialing systems, SMS, and pre-recorded messages without express consent. Companies must have written consent before sending text messages, and even if a business relationship exists, explicit permission is still required.

Consumers who receive unsolicited messages can sue for TCPA violations, with penalties ranging from $500 to $1,500 per violation, depending on whether the violation was intentional.

2025 TCPA Updates

As of this update (2026), two TCPA developments from 2025 are worth flagging:

  • The FCC's "one-to-one consent" rule was vacated. This rule would have required businesses to get separate consent from each individual seller before sending autodialed or prerecorded marketing calls and texts. In January 2025, the Eleventh Circuit Court of Appeals vacated the rule before it took effect, so it is not current law.
  • New revocation-of-consent rules took effect in April 2025. Under these FCC rules, a consumer can revoke consent through any reasonable means, and the sender must honor that revocation within 10 business days.

This area of TCPA regulation has moved quickly: confirm the current status of both points with the FCC or legal counsel before relying on them.

3. The California Consumer Privacy Act (CCPA)

The CCPA grants California residents greater control over their personal data and requires businesses to disclose what information they collect and how it's used. Businesses must allow customers to opt-out of data collection and delete personal information upon request.

Key CCPA provisions:

  • Right to know what personal data is collected.
  • Right to opt-out from data sharing with third parties.
  • Right to request data deletion.
  • Right to non-discrimination for exercising privacy rights.

Businesses that fail to comply with CCPA can be fined up to $7,500 per violation.

Also Required: A2P 10DLC Registration

Beyond these laws, US carriers require application-to-person (A2P) text messages sent over standard 10-digit long code numbers to be registered. Brands and campaigns must register through The Campaign Registry, following requirements set by CTIA (the wireless industry association) in its Messaging Principles and Best Practices. Traffic sent from unregistered numbers is commonly filtered or blocked by carriers, so 10DLC registration is a practical prerequisite for compliant SMS at scale in the US, even though it comes from carriers and industry bodies rather than a statute.

Tips for SMS Opt-in and Opt-out Compliance

Obtaining valid consent can be done in multiple ways, such as using a keyword query (e.g., texting "START" to a specific number) or including a checkbox for customers when they sign up online. Here are a few essentials to include in your consent form:

  • A link to your privacy policy.
  • Clear instructions on how to opt-out.
  • Details on how many messages customers can expect.
  • Information on how to get help.

For example, your consent form could read, "Subscribe to receive text messages from [Company Name]" with a link to relevant disclosures. For companies selling personal data, a separate opt-in checkbox is required.

SMS Opt-in Example

ValueText, a Salesforce native messaging app, allows businesses to create an automated consent process using keywords like "START" to initiate Opt-in. A typical call-to-action might say, "Text [KEYWORD] to [NUMBER] for updates on [Product Name]."

You can enhance the process with a double Opt-in by sending a confirmation message like, "We'd like to send you helpful updates. Is that okay? Reply YES or NO." This approach ensures explicit consent and can be automated using tools like ValueText.

How to Handle SMS Opt-outs

To make the opt-out process easy, customers should be able to text keywords like "STOP," "UNSUBSCRIBE," "OPT-OUT," or "CANCEL." ValueText offers a Salesforce-based opt-out automation process, ensuring customers are instantly removed from marketing lists.

Fig 01 · SMS consentDrawn
01 · Opt-inKeyword or checkboxPolicy, frequency and help all stated.
→
02 · Double opt-inReply YES to confirmThe confirmation is recorded on the record.
→
03 · Opt-outSTOP, UNSUBSCRIBE, CANCELHonoured automatically, sends stop.
Fig 01 · Consent in, confirmation, and a way out that needs no one to action it.

If you are interested in more details regarding the topic check here.

WhatsApp Opt-in

When using WhatsApp for business messaging, conversations must be initiated with pre-approved templates. Once a customer replies, consent is considered given, and a 24-hour communication window opens. If the customer sends the first message, consent is automatically assumed.

Fig 02 · WhatsApp consentDrawn
01 · TemplatePre-approved message outConversations start no other way.
→
02 · ReplyConsent givenThe customer's answer is the opt-in.
→
03 · Session24 hoursFree-form messaging until it expires.
Fig 02 · WhatsApp conversations start on a template, and the reply is what opens the session.

Summary: Best Practices for SMS Opt-in and Opt-out Compliance

Complying with US laws for SMS Opt-in and Opt-out may seem complex, but following these steps can simplify the process:

  • Obtain consent using a keyword query.
  • Double Opt-in to confirm permission using automated tools like ValueText.
  • Make it easy to opt-out by providing clear instructions.
  • Ensure compliance with regulations such as CAN-SPAM, TCPA (FCC, 47 U.S.C. § 227), and CCPA.
  • Avoid selling or sharing personal data without consent.

Once you've established your SMS Opt-in and Opt-out processes, it's essential to continually monitor compliance and make adjustments as needed. You can learn more about SMS marketing best practices with Salesforce to stay ahead of the curve.

Key Takeaway About SMS Opt-in and Opt-out

It's important to remember that sending unsolicited text messages is illegal. Penalties range from $500 to $1,500 per violation. Stay compliant with US laws by ensuring that all SMS communications follow the proper Opt-in and Opt-out procedures.

Navigating the complexities of SMS marketing compliance can be overwhelming, but at ValueText, we're here to help. You can BOOK A DEMO with our team to go over your use cases or you can start a free trial. You don't need to do this alone.

Questions about this guide? Write to us. Talk to us→

Keep reading

All posts→
Compliance WhatsApp pricing changes, October 2026 Meta begins charging for service and session messages on 1 October, including messages sent from the WhatsApp Business app. What changes, what does not, and what it means for your spend. 4 Sep 2026 · 6 min read Compliance ContactPointConsent in Salesforce Best Practices Guide Unlock the power of ContactPointConsent in Salesforce to streamline messaging consent and ensure compliance with your automation. 23 Dec 2025 · 7 min read Compliance Salesforce SMS Compliance: ValueText's AI Solutions Navigate SMS compliance in Salesforce with ValueText's AI-driven tools: stay ahead of regulations effortlessly. 23 Jun 2025 · 4 min read