Your messaging provider submitted your 10DLC campaign, and it came back rejected, usually with a terse reason code and a sentence of explanation that assumes you already know the system. Rejections are common, they are almost always fixable, and they nearly always trace to a handful of recurring problems in how the campaign was described rather than anything wrong with your organization.
This walkthrough decodes the rejection reasons reviewers cite most, in plain language, with the concrete fix for each. It assumes you know the basics of the registration system; if not, start with our explainer on The Campaign Registry and come back.
Who Is Actually Rejecting You
Understanding the reviewers explains the fixes. A 10DLC campaign passes through layered review: The Campaign Registry (TCR) platform itself, independent vetting providers, and Direct Connect Aggregators (DCAs), the entities that connect campaigns to carrier networks and review them against carrier rules before activation. A rejection can come from any layer, but the standards are broadly shared, drawn from carrier codes of conduct and CTIA's Messaging Principles and Best Practices. Reviewers are checking one master question: does this campaign clearly describe legitimate, consented messaging that matches what the brand actually does? Every common rejection is a way of answering "not yet."
The Common Rejections, Decoded
1. Inadequate or missing opt-in description
The most frequent failure. Your campaign must describe exactly how recipients consent to your messages: the field asks how opt-in is collected, and reviewers reject vague answers like "customers sign up." They want the mechanism: a web form at a stated URL, a keyword texted to your number, a paper form, a verbal script.
Fix: Describe the mechanism concretely, and make the evidence visible. If opt-in happens on a web form, the form should exist at a public URL you can cite, and it should state what messages the subscriber will receive. If opt-in is verbal or on paper, say so and summarize the script or form language. Screenshots of the opt-in flow, where your provider's submission supports them, are often what resolves this rejection.
2. Missing compliance language in sample messages
Reviewers expect your message program to show the standard courtesies: identification of who is sending, opt-out instructions ("Reply STOP to unsubscribe"), and, in your opt-in confirmation, message frequency and "message and data rates may apply" disclosure.
Fix: Include sender identification in sample messages, add STOP language to at least the first message sample and your stated confirmation message, and confirm HELP is supported. These conventions come straight from CTIA guidance, and their absence signals an unfamiliar sender.
3. Sample messages that do not match the described use case
You registered "appointment notifications" and the samples read like marketing blasts, or the description says donor updates and a sample mentions a sale. Mismatch between use case, description, and samples is an instant flag.
Fix: Make the three elements tell one story. Samples should be real messages you intend to send, representative of the registered use case, with variable fields shown in brackets. If you genuinely run mixed traffic, register the mixed use case or split into multiple campaigns.
4. Website problems: missing, mismatched, or incomplete
Reviewers visit the brand website. Rejections follow when the site is down, under construction, unrelated to the registered brand name, or missing the pages that support the campaign, especially the opt-in page and privacy policy.
Fix: The registered domain should be live, clearly belong to the registered legal entity, and contain a reachable privacy policy. If your organization operates under a recognizable public name that differs from its legal name, register the DBA properly so the reviewer can connect them.
5. Privacy policy gaps, especially the data-sharing sentence
A modern rejection staple: carrier standards expect your privacy policy to address text messaging data, and reviewers increasingly look for language stating that mobile opt-in data is not shared with third parties for marketing purposes.
Fix: Add a short SMS section to your privacy policy covering what data the texting program collects, how it is used, and that opt-in information is not sold or shared with third parties for their marketing. Link the policy from the opt-in form.
6. Brand registration mismatches upstream
Sometimes the campaign is fine and the brand record is the problem: legal name not matching IRS or state records, wrong EIN, or an unverified brand status that caps what campaigns can be approved.
Fix: Verify the brand record against your formation documents and EIN letter, exactly as written, and resubmit or re-vet the brand first. Nonprofits should ensure their charitable status is reflected, which also unlocks favorable campaign classes. Our trust score guide covers how brand standing shapes throughput.
7. Prohibited or restricted content categories
Carrier programs flatly prohibit certain content on 10DLC, the SHAFT categories (sex, hate, alcohol, firearms, tobacco) plus high-risk financial offers like payday lending, debt relief, and cannabis, which remains barred on carrier networks regardless of state law. Campaigns brushing against these areas are rejected or require special handling.
Fix: If your messaging genuinely falls outside these categories but the description accidentally suggests otherwise, rewrite for clarity. If it falls inside them, the answer is not wordsmithing; it is that the use case is not eligible, and pretending otherwise risks brand-level consequences.
8. URL shorteners and suspicious links in samples
Public link shorteners in sample messages draw rejections because shared shortener domains are spam-associated.
Fix: Use full branded URLs on your own domain, or a dedicated branded short domain, in samples and in real sending.
The Resubmission Playbook
- Read the rejection reason as a question. Each code asks "show me X": show me consent, show me the policy, show me the match between story and samples.
- Fix the artifact, not just the form. If the gap is your opt-in page or privacy policy, change the actual page first; reviewers re-check.
- Align every field to one narrative. Brand, website, use case, description, opt-in, and samples should read like chapters of the same book.
- Resubmit through your provider and expect days, not weeks. Reviews commonly turn around within several business days; complex cases and appeals take longer.
- Do not send unregistered in the meantime. Unregistered traffic faces filtering and carrier penalty fees, and a pattern of it damages the brand standing your campaign depends on; our fees breakdown shows how the penalty math works.
This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel or the relevant regulator.
Frequently Asked Questions
Why was my 10DLC campaign rejected?
Most rejections cite one of a few recurring gaps: a vague opt-in description, missing opt-out and disclosure language in sample messages, samples that do not match the registered use case, a website or privacy policy that does not support the campaign, brand record mismatches, or content in a prohibited category. The rejection reason from your provider identifies which, and each has a concrete fix.
How do I fix an opt-in rejection?
Describe the exact consent mechanism, web form URL, keyword, paper form, or verbal script, in the opt-in field, make sure the mechanism visibly exists, and ensure the opt-in point discloses message frequency, data rates, and opt-out. Where supported, attach screenshots of the flow. Vagueness, not wrongdoing, causes most opt-in rejections.
How long does 10DLC campaign approval take after resubmission?
Reviews typically complete within several business days, though timelines vary with vetting layers and appeal queues. Fixing every cited issue before resubmitting matters more than speed; each bounce restarts the cycle.
Can I send messages while my campaign is rejected or pending?
You should not. Unregistered 10DLC traffic is subject to carrier filtering and per-message penalty fees, and sending around a rejection undermines the brand reputation your registration depends on. Wait for activation; a compliant campaign usually clears quickly once the gaps are fixed.
What is the data-sharing language reviewers want in my privacy policy?
A statement addressing text messaging data, commonly to the effect that mobile information and SMS opt-in consent are not shared with or sold to third parties for their marketing purposes. Reviewers check that the policy exists, is reachable from your site and opt-in flow, and covers the texting program specifically.
Registration Handled Right the First Time
FRANSiS prepares and submits 10DLC registration for you, with opt-in flows, policy language, and samples built against reviewer expectations, and an AI Powered Helper answering texts once you are live. Contact us to take the guesswork out of registration.


