Text message marketing to advertisers: what the TCPA actually requires before you send

Somewhere in your operator dashboard there is a button that sends a text to every advertiser whose listing expires this week, or to every advertiser who canceled last quarter and might come back for twenty percent off. Pressing it feels like ordinary marketing, the same nudge a gym or a software company sends its own customers. It is also, under a federal law that has nothing to do with adult content or high-risk merchant categories, one of the easiest ways to turn a mailing list into a lawsuit.
The Telephone Consumer Protection Act does not read your message before deciding whether it applies. It reads the delivery mechanism: an automated system sending a text without the right kind of consent on file. A renewal reminder for an escort listing and a renewal reminder for a gym membership are the same violation under the same statute, priced the same way. What follows is the shape of that statute after two rule changes that landed within the past two years, one of which reversed a rule before it ever took effect. None of this is legal advice, and a lawyer who handles TCPA defense is worth the retainer the day a demand letter arrives, not the day after.
Why a text message is worth more attention than an email
An email sent without permission gets marked as spam and, at worst, damages a sender's domain reputation. A text message sent without the right consent under the TCPA carries a fixed price tag: five hundred dollars per message, tripled to fifteen hundred dollars if a court finds the violation willful or knowing. Neither figure depends on the recipient proving they were harmed, annoyed, or even that they read the message. The price attaches to the act of sending.
That fixed price turns a marketing list into a litigation risk instead of an ordinary operating expense. A single text to one advertiser is a five-hundred-dollar problem, easy to absorb if it ever surfaces. The same text sent by an automated platform to four thousand lapsed advertisers, exactly what a win-back campaign is for, is an exposure that starts at two million dollars before any court finds anything willful. Lawyers who bring these cases as class actions know the arithmetic works the same regardless of what the advertisers were advertising, which is why a badly configured SMS platform reads to the plaintiffs' bar as a commodity target.
There is no carve-out in the statute or in the FCC's rules for adult content, high-risk merchant categories, or any other vertical. The consent rules that apply to a text promoting a listing upgrade are the same rules that apply to a dentist's appointment reminder. That absence of a special rule cuts against the operator, not for them: nobody reviewing a TCPA complaint against a classifieds directory applies a more forgiving standard because the underlying business is already used to scrutiny elsewhere. If anything, a plaintiff's lawyer reads high-risk merchant and hears a defendant unlikely to fight a settlement demand all the way to trial.
What triggers the statute is narrower than most operators assume, and worth naming precisely because the rest of this article depends on it: an automated telephone dialing system, in practice any platform that sends texts from a list rather than one at a time by a human typing a number, contacting a phone without the consent that message's category requires. A single manual text from a support agent's own phone to one advertiser who called with a question sits outside the statute's core target. A batch send from the platform that manages renewal reminders sits squarely inside it.
The consent tier you are already crossing without noticing
The TCPA and the FCC's rules split consent into two tiers, and the distance between them is the distance between a formality and a real liability. A transactional or informational text, an ad went live, a payment failed, a message came in from a viewer, needs only prior express consent, meaning the advertiser gave you the number for that kind of purpose. A marketing or promotional text, a renewal discount, a feature upgrade, a win-back offer, needs prior express written consent: a documented opt-in, tied to your named business specifically, stating in writing that agreeing to receive texts is not a condition of buying anything from you.
The most common way operators cross that line without meaning to is reusing a number collected for one purpose to serve the other. An advertiser gives a mobile number to receive a one-time code during account verification. Months later, marketing imports every verified advertiser's number into a win-back campaign because the number is sitting right there in the database. The consent captured at verification covered a code, not a discount offer, and importing the number does not import consent along with it.
The second trap is bundling a promotional line into a transactional text, because it feels efficient to add and don't forget to upgrade to a message already going out to confirm a listing is live. Under the FCC's own guidance, a message cannot count as informational at all if it carries any advertising content, which means one added sentence pulls the entire message, and the consent standard governing it, into the marketing tier. A confirmation text sent under transactional consent that also pitches an upgrade is not a transactional text with a bonus. It is a marketing text sent without the consent marketing requires.
Both traps share a root cause: treating a phone number as a single field in a database rather than as a record that carries a specific promise about what it will be used for. The same channel already costs money in a different way, through toll fraud dressed up as failed login attempts on verification forms, so most directories already track SMS spend closely. Consent failures on the marketing side of that channel do not show up on a monthly invoice. They show up, months later, as a demand letter that treats every text in the campaign as a separate violation.
What changed in 2025, and what did not
For most of 2024, operators buying leads or renting marketing lists were told to prepare for a rule requiring consent to name one specific business rather than a vague list of marketing partners. The FCC adopted that one-to-one consent rule, set to take effect on January 27, 2025, and the Eleventh Circuit Court of Appeals vacated it on January 24, 2025, three days early, ruling the FCC had exceeded its statutory authority. The FCC has since formally removed the rule from its own regulations. As of today, consent shared among a named list of partners is not illegal specifically because of that rule, for the simple reason that the rule does not exist.
That is not the same as a green light for vague consent language. Courts deciding ordinary TCPA cases, with no special rule to lean on, still ask whether a reasonable person reading the opt-in text would have understood which business would be texting them. A checkbox agreeing to hear from our marketing partners was weak evidence of consent before the one-to-one rule existed, survived the rule's short life without ever being tested against it, and remains weak evidence today for the same reason it always was: it does not tell anyone, including a judge, that your directory specifically was the one authorized to send the text.
A separate set of rules, adopted in February 2024 and effective April 11, 2025, did survive and did change how a business must handle an advertiser asking to stop. Consent can now be revoked by any reasonable means, not only through a channel the business designates. If a platform only recognizes the word stop typed back to the sending number, and an advertiser instead tells an account manager on a phone call to stop texting them, that request still counts, and a court can treat it as a valid revocation regardless of what the system logged.
The same rules gave businesses a backstop rather than a target on timing: a revocation must be honored within ten business days at the outside, with the FCC explicit that a business should act as soon as practicable rather than treating ten days as the goal. A single follow-up text confirming the opt-out is allowed, provided it carries no promotional content, and a reply sent within about five minutes is presumptively reasonable. Sitting on a stop request for a week because it technically falls inside the legal window reads very badly in front of a jury.
The vendor's mistake becomes your bill
Most directories that run SMS marketing at any scale use a platform or an outside vendor rather than building the sending infrastructure themselves, and some run affiliate or referral programs where a partner texts prospects using material the directory supplied. An FCC ruling from 2013, arising out of complaints against a satellite television company's outside telemarketers, established that a business can be held liable for a vendor's TCPA violations under ordinary federal agency law, even though the business never personally sent a single message. The theory is not that hiring a vendor is inherently risky. It is that a business which gives a vendor access to its customer data, lets the vendor use its brand name, approves the vendor's scripts, or learns the vendor is breaking the rules and does nothing about it, has made that vendor's conduct its own.
That ruling is FCC guidance rather than a statute Congress wrote, and a later court challenge established that it does not bind judges the way a law does. In practice the distinction has mattered less than it sounds: courts facing TCPA claims against a company for a vendor's conduct have repeatedly applied the same factors the FCC listed, and have declined to dismiss cases where a company handed over its customer list and its name and then claimed it had nothing to do with what the vendor sent. Treating the ruling as non-binding and therefore irrelevant is the kind of reading a company's lawyer regrets giving it the week before losing a motion.
The underlying question is the same one that already decides how much you answer for traffic a partner brings in without your direct oversight: who actually controlled the message, not whose finger was on the send button. A vendor who can pull an advertiser list, write copy under your name, and text on a schedule nobody at the directory reviewed is functioning as your agent whether or not the contract calls it that.
The practical fix does not require building an in-house SMS platform. It requires a contract naming the specific opt-in language a vendor will use, giving the directory the right to see the consent record behind any number the vendor contacts, and letting the directory shut down a campaign the moment the vendor cannot produce that record. A vendor that resists putting any of this in writing is telling an operator, in advance, exactly what will happen the first time a recipient complains.
The number that is not your advertiser's anymore
Advertisers churn, and the mobile number tied to a canceled account does not stay reserved for them. Carriers must let a disconnected number sit unused for at least forty-five days before reassigning it, which sounds protective until the arithmetic runs the other way: an advertiser who stopped renewing eight months ago has quite plausibly had that number handed to a stranger with no relationship to the directory, who has never consented to anything and is now receiving a win-back offer addressed to someone else.
The FCC operates a paid Reassigned Numbers Database, live since November 2021, that lets a business check whether a number has been permanently disconnected since the date it collected consent. A safe harbor exists for a business that queried the database within the thirty days before contacting a number and received an incorrect no, meaning the database itself was wrong, not the business's timing. It does not protect a business that never queried at all, and the burden of proving the query happened sits with the business being sued, not the advertiser who complained.
Subscribing to a federal database is worth it once a marketing list reaches a scale where checking manually stops being practical, and not before. Below that scale, the cheaper discipline is removing a number from every marketing list the day an account lapses rather than the day someone remembers to clean the list, and treating any number that has not produced a click, a reply, or a login in several months as unverified before it goes into the next campaign, rather than assuming silence means the same person is still on the other end.
None of this requires giving up text as a channel, and the operators who get hurt by it are rarely the ones who decided texting advertisers was too risky to try. They are the ones who never separated a transactional opt-in from a marketing one in their own database, never wrote down what a vendor may send on their behalf, and never noticed that a phone number is a promise with an expiration date rather than a permanent field. Start this quarter by splitting consent records into those two tiers with a timestamp and the exact disclosure text each advertiser saw, put a written opt-in requirement and an audit right into the next vendor contract signed, and prune lapsed advertisers out of every marketing list before the next campaign ships rather than after a complaint arrives.
One more thing worth checking before assuming a compliant text is a delivered text: carriers apply their own content filters when a business registers a messaging number, grouping sexual content with hate speech, alcohol, firearms and tobacco under an industry shorthand carriers call SHAFT, and a message can clear every consent requirement here and still get silently throttled or blocked before it reaches a phone. That is a carrier policy question, not a TCPA one, and it belongs on the same pre-launch checklist rather than showing up as a surprise after a campaign has already shipped.


