Short answer: replying to someone who just called you is about the most defensible text message there is. Adding an offer to the bottom of that reply is a different message with a different standard, and that is the line most businesses cross without noticing.

That distinction — responsive versus promotional — does more work than any other single idea in messaging compliance. Get it right and most of the rest follows.

The distinction that decides everything

Regulators, carriers and the registries all draw a version of the same line.

A responsive message answers the thing the person contacted you about. They called about a leaking water heater; you text back about the leaking water heater. They filled in a quote form; you text to arrange the quote. Their number arrived in a context directly related to what you are now saying to them, and consent to be contacted about it is reasonably implied by the fact that they contacted you.

A promotional message sells. New offers, seasonal availability, a discount, a nudge to book something they did not ask about. This needs consent that was actually given, in advance, and that you can produce a record of.

The trap is that these blend. A perfectly good responsive text — "Sorry we missed you, what can we help with?" — becomes a promotional one the moment you append "and ask about our spring service plan". One sentence changed the category of the whole message and the standard it has to meet.

If you only take one thing from this: do not staple offers to service messages. Keep them as separate messages with separate consent, and the question of which rules apply never becomes ambiguous.

Why "they called us first" is not a complete answer

It is a good argument for a reply. It is not a permanent licence.

Someone calling about a repair in March has not agreed to hear about your maintenance plan in September. The context that made your reply reasonable was the repair, and it expires with it. Businesses get into trouble by treating an inbound call as an opt-in to the marketing list, because operationally that is the easy thing to do — the number is right there in the CRM.

The other half of it is that consent is not the only thing being checked. Carriers apply their own rules on top of the law, and they are the ones who can switch your number off. A campaign can be entirely lawful and still get filtered into oblivion for looking like unsolicited marketing.

What actually gets a campaign rejected

To send business messaging in the US you register the campaign, and that registration is reviewed. Ours is registered the same way our clients' are, so this list is from the review process rather than from a summary of it.

The rejections cluster:

  • A vague consent string. "I agree to receive communications from us" is not enough. The wording has to name the brand, say what kind of messages, state the frequency, note that message and data rates may apply, and give the opt-out and help keywords.
  • Consent disclosures that contradict each other. The checkbox on the form, the terms page and the brand record all get compared. If the form says one thing and the terms say another, that is a rejection — not because either is wrong, but because they disagree.
  • A missing privacy clause. There is specific carrier-required language about not sharing mobile information with third parties for marketing. It has to appear on the privacy policy essentially verbatim. Paraphrasing it is one of the most common single causes of rejection.
  • An opt-in form buried among other things. The consent form is expected to be reachable and unambiguous, which in practice means it gets a page of its own rather than being a checkbox at the bottom of a long contact form.
  • A brand name that does not match. The name in the messages, on the website, and on the registration all have to be the same string.

How we set ours up

Concretely, because the abstract version is easy to nod along to and hard to act on. Ours lives at our opt-in page and the wording is quoted back on our terms and privacy policy.

Marketing and non-marketing consent are two separate checkboxes. They are different permissions and blending them means you cannot prove which one you have. Someone can agree to appointment reminders and decline offers, which is a perfectly normal thing to want.

Both start unchecked, and neither is required to submit. A pre-ticked box is not consent, and making consent a condition of doing business is the thing the disclosure language explicitly disclaims.

Each consent string stands on its own. It names the brand, the category of message, the frequency, the rates disclaimer, and both STOP and HELP — so that a reviewer reading only that sentence has everything.

Submitting without ticking anything is a valid outcome. Those records get messaging suppressed at the contact level, so no future automation can accidentally text someone who did not agree. The system does not rely on anyone remembering.

One source of truth for the strings. The consent wording is defined once in code and rendered everywhere it appears. That is not tidiness — it is what makes it structurally impossible for the form and the terms to drift apart, which is the second rejection reason above.

The state-law layer people miss

Federal rules are not the whole picture. States add their own requirements, and they are not uniform — several have their own mini-TCPA statutes with tighter rules on timing, frequency and what counts as consent.

The one that catches operators out most often is call recording, because it is not a messaging rule and so nobody thinks to check it. A number of states, Maryland among them, require every party to consent to a recorded call rather than just one. If you are recording calls for quality, or running any kind of AI system that transcribes them, that is a real constraint with real penalties and it applies at the point the call connects.

A workable default

If you want a rule of thumb that keeps you out of most trouble:

  1. Reply freely to people who contacted you, about the thing they contacted you about.
  2. Never attach an offer to a service message.
  3. Collect explicit, separate, unticked consent before anything promotional.
  4. Log when and how each consent was given, in a form you could show someone.
  5. Honour STOP instantly and permanently, across every record for that number.
  6. Keep the wording identical everywhere it appears.

None of that is expensive. It is mostly decisions made once, at setup, and encoded so that the system enforces them rather than relying on discipline. The businesses that get into difficulty are almost never the ones who read the rules and made a judgement call — they are the ones who never drew the line between a reply and an advert.

Related: the five ways missed-call text-back breaks, where assumed consent is the fifth.

Can we text someone who filled in a form on our website?

To reply about what they asked, yes. To market to them, only if the form captured consent for marketing specifically, with wording that named it. A form submission is not automatically a marketing opt-in.

Does a customer who has bought from us count as opted in?

Not automatically for marketing. An existing relationship supports messages about their job, their appointment or their account. Promotional messaging is a separate permission and is worth collecting explicitly.

What has changed in the rules recently?

The regulatory picture has moved more than once — the FCC's one-to-one consent rule was vacated in early 2025, and a federal appeals court rejected another consent rule in 2026. The underlying responsive-versus-promotional distinction has been stable throughout, which is why it is a better thing to build on than any particular rule.

Do these rules apply to email too?

Different regime, and generally a lighter one — email requires accurate headers, a working unsubscribe, and a postal address. The reason to treat them similarly is practical rather than legal: the same discipline about separating service from promotion keeps you out of spam folders.

More in lead generation.