SMS opt out requirements obligate every organization that texts to honor STOP requests and other reasonable revocations, while opt-in requirements demand the right tier of consent, with specific disclosures, before the first message is sent. Together they form the consent rulebook that the TCPA, FCC regulations, and wireless carriers all enforce. This guide lays out both sides as working checklists: what a compliant opt-in flow contains, how opt-out handling must work, and what records prove you did it right.

This article is general information, not legal advice. Consult an attorney for guidance on your specific program.

Key takeaways:

  • Informational texts require prior express consent; marketing and fundraising texts require prior express written consent with specific disclosure language.
  • A compliant opt-in discloses the program name, message frequency, "message and data rates may apply," and HELP/STOP instructions.
  • Under the FCC rule effective in 2025, recipients can revoke consent by any reasonable means, and revocations must be honored within 10 business days.
  • One confirmation message clarifying scope is permitted after an opt-out, but nothing promotional.
  • Carriers and 10DLC registration enforce consent standards independently of the law, so weak flows get filtered even when nobody sues.

The consent types and what each permits

Consent is not one thing. United States texting rules recognize tiers, and the tier you collect determines what you may send.

Consent tierHow it is grantedWhat you may send
Prior express consentPerson knowingly provides their number for a purpose, such as an intake or registration formInformational messages related to that purpose: reminders, alerts, service updates
Prior express written consentSigned written or electronic agreement with clear automated-marketing disclosureMarketing, promotional, and fundraising messages, plus informational ones

Three rules of thumb keep organizations on the right side of the line:

  • Consent is purpose-bound. A number given for appointment reminders is not consent for fundraising appeals. Fundraising and promotional content sits in the stricter written-consent tier.
  • Consent is party-bound. Consent given to a partner organization, an event host, or a list vendor does not transfer to you.
  • Written consent must be affirmative. Pre-checked boxes do not count, and the disclosure must state that consent is not a condition of purchase or service.

If your program will ever send anything promotional, collect prior express written consent at the start. It covers both tiers and spares you from segmenting by consent scope later, though tagging scope per contact remains a best practice.

What a compliant opt-in flow looks like

Whether the opt-in happens on a web form, a paper form, or by texting a keyword to your number, the disclosure shown at the moment of consent should contain every element on this checklist:

  1. Your organization or program name, so the person knows exactly who will be texting them.
  2. A description of what they will receive, such as appointment reminders, volunteer updates, or fundraising news.
  3. Message frequency, either a specific cadence ("up to 4 msgs/month") or "message frequency varies."
  4. The phrase "message and data rates may apply." Carriers expect this exact disclosure.
  5. Opt-out instructions: "Reply STOP to cancel."
  6. Help instructions: "Reply HELP for help."
  7. A link to your privacy policy and terms, with the privacy policy stating that mobile opt-in data is not shared with third parties for marketing.
  8. For written consent: an affirmative unchecked checkbox or signature, plus the statement that consent to receive automated marketing texts is not a condition of purchase or service.

After the opt-in, send a single welcome or confirmation message that repeats the program name, frequency, "message and data rates may apply," and STOP/HELP instructions. That message closes the loop and creates one more record of the disclosure.

For healthcare programs, consent capture carries additional privacy considerations; see our guide on how to collect and document HIPAA texting consent for the health-specific layer.

Double opt-in: when to use it

Double opt-in adds a verification step: after someone submits a form or texts a keyword, you send a message asking them to reply YES to confirm. Only confirmed contacts join the list.

Double opt-in is not legally required in most cases, but it is worth using when:

  • Numbers are collected on paper or verbally, where typos and misheard digits are common.
  • A third party or field team collects numbers on your behalf.
  • You operate in a sensitive vertical, such as healthcare or services for vulnerable populations, where texting the wrong person has consequences beyond compliance.
  • You want the strongest possible consent evidence, since the confirmation reply proves the phone's actual owner agreed.

The cost is some drop-off between step one and step two. The benefit is a list where every number verifiably belongs to a person who said yes twice. For mission-driven organizations, that trade is usually worth it on high-stakes programs and optional on low-risk informational ones.

Opt-out requirements: the rules that changed

Opt-out handling is where regulators have been most active recently, and where the requirements are most concrete.

Honor STOP and its variants

Recipients can opt out by replying STOP, and you must also treat common variants as revocations: STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, and natural-language equivalents like "please stop texting me." Keyword-only matching that ignores a plain-English refusal is exactly the gap the FCC has moved to close.

Revocation by any reasonable means

Under the FCC rule effective in 2025, consumers may revoke consent through any reasonable means, not just your designated keyword. That includes replies in other wording, messages through other channels, phone calls, and emails. You cannot require a specific method or make people navigate a process to leave. Revocations must be honored within 10 business days at the latest, and the practical standard for texting platforms is immediate suppression. The FCC's consumer materials on unwanted texts are at https://www.fcc.gov/consumers.

The confirmation message rule

After an opt-out, you may send one final confirmation message acknowledging the request. The rules around it are tight:

  • It must be sent promptly after the opt-out.
  • It may confirm the opt-out and, where you run multiple message programs, ask the person to clarify scope.
  • It may not contain marketing, promotion, or attempts to win the person back.
  • If the person does not respond to a scope question, treat the revocation as applying to everything.

Suppression must be global and permanent

An opt-out applies across your campaigns, not per campaign. The suppressed number stays suppressed through vendor migrations, list rebuilds, and staff turnover. Losing a suppression list during a platform switch is one of the most common ways organizations end up facing claims, since re-texting a documented opt-out is easy to frame as willful.

Consent records: your proof

Every requirement above generates a documentation duty. For each contact, your records should capture:

  • Date and time of opt-in, and the channel (web form URL, keyword, paper form, event).
  • The exact disclosure language displayed at consent, versioned over time as your forms change.
  • Consent scope: informational, marketing and fundraising, or both.
  • The welcome message and its timestamp.
  • Every opt-out or revocation event, its channel, and when suppression took effect.

Retain all of it for at least four years, matching the federal statute of limitations for TCPA claims. A platform should do this automatically; FRANSiS logs consent sources, message history, and opt-out events per contact, so the audit trail exists whether or not anyone remembered to keep one. FRANSiS also processes STOP and its variants instantly and suppresses contacts across all campaigns, which satisfies the strictest reading of the revocation rules without staff involvement.

Carrier and 10DLC expectations

Even if no regulator ever looked at your program, the carriers would. To send application-to-person texts over local numbers in the United States, organizations register their brand and campaigns through the 10DLC system, and registration reviews look specifically at consent:

  • Your campaign registration must describe how you collect opt-in, and reviewers check that your stated flow includes the standard disclosures.
  • Your website's privacy policy and terms are checked for the mobile-data-sharing language.
  • Carriers monitor complaint rates, and programs generating STOP and spam reports get filtered or suspended regardless of legal compliance.
  • Keyword responses for HELP and STOP must work correctly, and carriers test them.

This means opt-in and opt-out hygiene is not just liability protection; it is deliverability. A program with clean consent gets its messages delivered, while a sloppy one watches messages silently disappear. Work through our full SMS compliance checklist to cover the legal and carrier layers together.

Frequently asked questions

What are the legal requirements for SMS opt-out?

You must honor STOP requests and any other reasonable form of revocation, including plain-language replies and requests made through other channels. Under the FCC rule effective in 2025, revocations must be honored within 10 business days, suppression must apply across all your campaigns, and only a single non-promotional confirmation message may follow.

What must an SMS opt-in disclosure include?

The program or organization name, the type of messages, message frequency, "message and data rates may apply," STOP and HELP instructions, and a link to your privacy policy. For marketing and fundraising texts, you also need an affirmative signature or checkbox and a statement that consent is not a condition of purchase or service.

Is double opt-in required for SMS?

Generally no, it is a best practice rather than a legal requirement in most United States contexts. It is strongly recommended when numbers are collected on paper or verbally, when third parties collect on your behalf, or when texting the wrong person carries privacy consequences, because the confirmation reply proves the actual phone owner consented.

Can we send a message after someone texts STOP?

Yes, exactly one: a prompt confirmation acknowledging the opt-out, which may ask the person to clarify scope if you run multiple programs. It cannot include any marketing or retention pitch, and if the person does not reply to a scope question, the opt-out applies to all your messaging.

How long should we keep SMS consent records?

At least four years, matching the federal statute of limitations for TCPA claims, and many organizations keep five to cover filing lag. Records should include the opt-in timestamp and source, the exact disclosure shown, consent scope, and every opt-out event with the date suppression took effect.

Conclusion

Opt-in and opt-out rules are two halves of one promise: people hear from you because they asked to, and they stop hearing from you the moment they ask to stop. Get the disclosure elements right at capture, honor every reasonable revocation instantly, send nothing but a clean confirmation afterward, and keep records long enough to prove all of it. Organizations that treat the consent rulebook as product design rather than legal overhead end up with lists that are smaller on paper and far more valuable in practice.

Ready to run consent-first texting without the manual overhead? Contact the FRANSiS team to see how built-in opt-in capture, automatic STOP handling, and durable consent records keep your program compliant from the first message.