The CTIA Messaging Principles and Best Practices is the industry rulebook for text messaging in the United States. Published by CTIA, the trade association representing the US wireless industry, it defines how consumer consent should be obtained, how opt-outs must work, what content is unacceptable, and how the messaging ecosystem's players, carriers, aggregators, platforms, and senders, are expected to behave. US carriers adopt these principles into their own policies and enforce them on every application-to-person (A2P) program.

Almost everyone in messaging cites this document; far fewer have read it. This reference summarizes what it actually says and why it binds you even though it is not law.

What the Document Is

The Messaging Principles and Best Practices is a voluntary industry framework, first issued years ago and revised periodically, most recently to address evolving spam patterns and number types. Its stated goal is protecting consumers from unwanted messages so that messaging remains a trusted, high-engagement channel. It covers SMS and MMS across the number types used for A2P traffic: short codes, 10DLC, and toll-free.

Three characteristics define its legal status:

  1. It is not a statute. No one is fined by a court for violating CTIA guidelines.
  2. It is incorporated by contract. Carriers and aggregators bake the principles into their acceptable-use policies, so your platform agreement obligates you to follow them.
  3. It is enforced by the network. Filtering, campaign suspension, and number blocking are the remedies, applied by carriers without litigation.

The result is a rulebook that often binds more tightly than law: legal compliance arguments do not restore a blocked number.

Consent: The Central Principle

The principles organize messaging by the consent appropriate to it, an approach that parallels but is not identical to the TCPA framework:

  • Conversational messaging. A consumer texts first; the response is implicit in the conversation they started. No separate opt-in required for replying in kind.
  • Informational messaging. The consumer gives their number for a purpose, appointment reminders, account alerts, and messages serve that purpose. Consent is the provision of the number for that use.
  • Promotional messaging. Marketing content requires express written agreement before sending, the industry analog of the FCC's prior express written consent tier at 47 CFR 64.1200(f).

Around consent, the principles specify the expected mechanics: clear calls-to-action that identify the program, disclose message frequency and any rate implications, link privacy policies, and confirmation messages that restate the essentials. They also expect consent to be program-specific and not transferable between brands or use cases, which is why purchased-list traffic violates the framework regardless of what a legal analysis might conclude.

Opt-Out and Sender Identification

The principles require every A2P program to support and honor opt-outs:

  • STOP must work by reply, along with recognized variants, and processing should be immediate at the platform level.
  • HELP must return identification of the program and contact or support information.
  • Senders must be identifiable. Recipients should always know which organization is messaging them, which in practice means branding messages with your name.
  • Opt-out confirmations are expected: a single message confirming unsubscription, matching the structure federal rules now codify.

These mechanics overlap with the FCC's revocation rules, and the program-level build-out is covered in our SMS compliance checklist.

Content Rules

The principles prohibit or restrict content categories summarized by the industry acronym SHAFT (Sex, Hate, Alcohol, Firearms, Tobacco) plus related categories: illegal substances including federally scheduled cannabis, deceptive or fraudulent content, phishing, and malicious links. Restricted-but-permitted categories such as alcohol require age verification. They also address mechanics that correlate with abuse: shared public URL shorteners, snowshoeing (spreading traffic across numbers to evade filtering), and dynamic routing designed to dodge review. The category-by-category breakdown is in our SHAFT compliance guide.

Ecosystem Duties: It Is Not Just Senders

A distinctive feature of the document is that it assigns responsibilities across the whole chain:

PlayerExpected role
CarriersPublish policies, filter abuse, provide redress paths
Aggregators and platformsVet customers, enforce consent and content rules downstream, act on violations
Senders (brands)Obtain proper consent, honor opt-outs, send wanted content, register accurately
Registries and vetting partnersVerify brand identity and campaign claims

This is why your messaging platform asks intrusive questions about list sources and opt-in flows: the principles make platforms accountable for their customers' behavior, and campaign reviews test the answers. Registration mechanics and the rejections that follow inaccurate ones are detailed in our guide to 10DLC campaign rejections.

Why Carriers Enforce Voluntary Guidelines Aggressively

Carriers protect messaging because its value depends on trust: text remains the channel people actually read precisely because it is not yet drowned in spam. Every unwanted message erodes that, raises complaint rates, and invites regulatory attention. Enforcement through filtering and suspension is cheaper and faster than any legal process, and the contractual chain, carrier to aggregator to platform to sender, gives carriers leverage at every link. For senders, the practical takeaway is that carrier trust is an asset you build through clean traffic and lose through complaints, and it transfers poorly between numbers.

Reading the Principles Against the Law

A useful way to understand the guidelines is to map where they parallel legal requirements and where they exceed them:

TopicLegal requirementCTIA principles
Marketing consentPrior express written consent, 47 CFR 64.1200(f)Express written agreement: parallel
Informational consentPrior express consent under TCPA interpretationNumber provided for the purpose: parallel
Opt-outAny reasonable manner, ten business days, FCC 2024 orderSTOP support with immediate processing: stricter in practice
Purchased listsContested legal territory, fact-dependentEffectively prohibited: consent is not transferable
Content categoriesScattered statutes (controlled substances, etc.)SHAFT and related restrictions: broader
Sender identificationRequired for telemarketing contextsExpected on all messages: broader

The pattern is consistent: where law and guidelines address the same topic, the guidelines match or exceed the legal floor. That is why building to the principles, rather than to the minimum lawful position, produces programs that satisfy both regimes at once, and why legal review alone is not a delivery strategy. Carriers enforce their standard; courts enforce theirs; senders answer to both.

The Guidelines as a Living Document

Treat the principles as versioned software rather than settled law. CTIA revises the document as the ecosystem changes, and past revisions tracked the big shifts: the rise of 10DLC registration, the retirement of shared short codes, evolving guidance on consent presentation, and sharpening language around abuse patterns like snowshoeing and public URL shorteners. Carriers then update their own policies on their own schedules, sometimes ahead of the document, sometimes behind it, and aggregators translate both into the enforcement senders actually feel.

Operationally, that means two things. First, compliance positions have dates: a program reviewed against the principles three years ago was reviewed against a different document, and periodic re-reads, or a platform that tracks revisions for you, keep the position current. Second, when your platform relays a new requirement that the published document does not yet contain, that is normal, not arbitrary: the contractual chain lets carriers enforce policy changes immediately, and the document catches up in the next revision. Senders who follow the spirit, consent, wanted content, easy exit, identifiable sender, find that revisions rarely require more from them than a configuration check.

Frequently Asked Questions

Are the CTIA guidelines legally binding?

Not as law. They bind through contract: carrier and platform acceptable-use policies incorporate them, and violations are enforced with filtering, suspension, and termination rather than fines. Some of their requirements parallel legal duties under the TCPA and FCC rules, which are separately enforceable.

Where can I read the actual document?

CTIA publishes the Messaging Principles and Best Practices on its website, ctia.org, along with related resources on short codes and messaging security. Reading the primary document is worthwhile for anyone operating a large program.

Do the guidelines apply to nonprofits and government agencies?

Yes. The principles apply to A2P traffic by sender behavior, not sender tax status. Carve-outs that exist in statutes for nonprofits or political senders do not exist in carrier policy: consent, opt-out, and content rules apply to everyone.

How do the guidelines relate to 10DLC registration?

Registration through The Campaign Registry is the enforcement gateway that operationalizes the principles for long-code traffic: brands verify identity, campaigns declare use cases, and vetting screens claims against the rules. The principles are the standard; registration is the checkpoint.

What happens if my program violates the guidelines?

Typically: increased filtering first, then campaign suspension or number blocking, communicated through your platform. Remediation involves fixing the violation, documenting the fix, and re-review. Repeat violations can end aggregator relationships, which is much harder to recover from than a single suspension.

Run the Program Carriers Want to Deliver

FRANSiS builds every program to the CTIA principles by default: documented consent, instant opt-outs, clean content, and accurate registration, so carriers treat your traffic as trusted. Contact us to get your messaging aligned, and see our security page for the full compliance picture.