
How do I know if someone is on the DNC list?
Key Facts
- You can't look up a number on the DNC Registry — businesses must subscribe and scrub their lists per DNC compliance guidance.
- The National DNC Registry held 253+ million active registrations in FY 2024 per the FTC's data book.
- FTC penalties hit up to $53,088 per violation as of January 2025 per compliance analysts.
- TCPA damages run $500 per call, trebled to $1,500 for willful violations with no cap per M&S Law Group.
- 11 states maintain their own DNC registries, with state penalties from $100 to $25,000 per call per Aloware.
- Telemarketers must re-scrub calling lists against the Registry at least every 31 days per DNC.com.
- A clean registry scrub is no defense to a TCPA consent claim per Aloware's compliance analysis.
Why You Can't Just 'Look Someone Up' on the DNC List
Here's the good news and the bad news: you can't type a phone number into a search box and find out if it's on the National Do Not Call Registry. The Registry isn't a public lookup tool — it's a database that businesses must subscribe to and scrub their calling lists against, not one long list anyone can browse.
To access it legally, you subscribe at telemarketing.donotcall.gov and obtain a Subscription Account Number (SAN). As the FTC puts it, every seller should subscribe, pay the appropriate fee, and agree to certification requirements to receive one. The Registry contains phone numbers only — no names, no other identifying details, and no indication of whether a number is a landline or cell phone.
The scale of this database is enormous. The FTC's FY 2024 data book reports 253+ million active registrations, and consumers filed over 2 million DNC complaints that same year. If you call or text someone on the list without a valid exemption, the stakes are steep:
- FTC penalties of up to $53,088 per violation as of January 2025
- TCPA statutory damages of $500 per call — trebled to $1,500 for willful violations, with no cap
- State-level penalties ranging from $100 to $25,000 per call
And here's the part that catches even careful businesses off guard: a clean DNC scrub alone doesn't protect you. As compliance analysts note, "a clean registry scrub is no defense to a TCPA consent claim." The two obligations are separate, and you must satisfy both. Since December 2023, the FCC has also extended DNC protections to marketing text messages, so this isn't just a phone-call problem.
The registry also doesn't tell the whole story. Beyond the federal list, 11 states maintain their own DNC registries, and every company must maintain an internal opt-out list of people who asked not to be contacted. Verification means checking all three layers — which is why any legitimate response system, including what we run at CallMyLeads, treats DNC screening as a built-in compliance step rather than an afterthought.
So the real question isn't "how do I look someone up?" It's "how do I verify my entire calling list the right way?" — with a SAN, a documented scrub cycle, and proof you can point to if a regulator ever asks.
The Three Layers You Actually Have to Check
Checking one list isn't checking at all. Businesses that get hit with DNC violations almost always scrubbed something — just not everything the law requires.
The National Do Not Call Registry is not a public lookup tool you can search one number at a time. As DNC.com explains, it's a database marketers must subscribe to and scrub their calling lists against before making calls. You access it at telemarketing.donotcall.gov after obtaining a Subscription Account Number (SAN), and the FTC requires you to re-scrub at least every 31 days. With 253+ million active registrations in FY 2024, this layer catches the bulk of protected numbers — but only the bulk.
Here's where a federal-only scrub quietly fails you. Eleven states maintain their own DNC registries — Colorado, Florida, Indiana, Louisiana, Massachusetts, Missouri, Oklahoma, Pennsylvania, Tennessee, Texas, and Wyoming. A number can sit on a state list without appearing in the federal database, and state penalties run from $100 to $25,000 per call. If you call into any of those states, a clean federal scrub is not a defense.
The third layer is the one you build yourself. Companies are required to maintain an internal DNC list of every consumer who has asked not to be contacted — and regulators have said opt-outs must be honored through any reasonable means, not just "magic words" like "stop" or "unsubscribe." Since April 2025, the processing window is 10 business days. That's why services like CallMyLeads honor opt-outs immediately and automatically across every channel, rather than waiting for a manual list update.
Real verification means checking all three layers on a documented cycle:
- Federal registry — scrub at least every 31 days, ideally every 28 for a safety margin
- State lists — all 11 state registries, every time you scrub
- Internal opt-outs — your own suppression list, updated the moment someone asks
The good news: you don't have to run three separate checks. Commercial scrubbing services can process Federal, State, and Internal DNC lists in a single pass, often alongside reassigned-number and TCPA litigator checks. Whatever tool you use, log every scrub with a timestamp — as Aloware puts it, "a scrub you cannot date is a scrub you cannot defend."
Scrub on a Cycle — and Prove It
The 31-day scrub rule is the legal floor, not a best practice. Federal law requires telemarketers to scrub their calling lists against the National DNC Registry at least every 31 days — and meeting that cycle is also a condition of the DNC safe harbor for inadvertent violations. Miss the window and your defense starts to crumble.
That's why many compliance practitioners recommend a tighter cadence: scrub every 28 days, or every 14 days for extra precaution, with automated re-screening workflows that flag new registrations between cycles (see guidance). The registry is a moving target — it held 253+ million active registrations in FY 2024 and grew to 258+ million by the end of FY2025. A number that was clean last month may not be clean today.
Here's the part that trips up growing businesses: a scrub you cannot date is a scrub you cannot defend. If an auditor or plaintiff's attorney asks when you last checked a number, "we scrub regularly" won't cut it. You need proof, and that proof has three parts:
- A timestamp for every scrub, so you can show exactly when each list was checked
- Download receipts from the registry, proving you pulled current data
- Output files showing which numbers were screened and what was suppressed
The gap between "we scrub our lists" and "we can prove we scrubbed this number" is where outbound teams get hit, as compliance analysts put it. FTC penalties now run up to $53,088 per violation (effective January 2025), and state penalties range from $100 to $25,000 per call. Documentation is what turns a good process into a defensible one.
There's also a newer deadline to know: as of April 11, 2025, opt-out requests must be processed within 10 business days, down from the previous 30-day window (read the rule change). Regulators also say consumers can opt out by "any reasonable means" — not just magic words like "stop" or "unsubscribe" — and the suppression should apply across all channels, not just the one phone number they texted from (see the FCC guidance summary).
For a service like CallMyLeads that handles lead response and follow-up across calls and texts on behalf of clients, this is why scrubbing runs on a fixed, logged cycle rather than an ad-hoc check. When every response, nurture message, and reminder touches a contact's number, the scrub record and the opt-out log are the paper trail that keeps the whole follow-up machine safe to run.
Scrub on a cycle tighter than the law requires, date every scrub, and honor opt-outs in days — not weeks. That's the difference between a compliance program and a liability waiting to surface.
A Clean Scrub Isn't Enough: Consent Is a Separate Gate
Picture this: your team scrubs every list, gets a clean result, and calls the lead anyway. Months later, a TCPA claim lands anyway — because the scrub and consent are two completely separate gates, and you only cleared one.
As compliance guidance for outbound teams puts it bluntly, "a clean registry scrub is no defense to a TCPA consent claim." The DNC Registry tells you who doesn't want marketing calls. It says nothing about whether the person on the other end agreed to hear from you. Those are two different legal questions, and passing one doesn't pass the other.
Under the TCPA, calling someone on the national registry or your internal opt-out list is only allowed with prior express written consent or an established business relationship. Michele Shuster, managing partner at M&S Law Group and former Chief of the Ohio AG's Consumer Protection Section, calls the "TCPA-compliant lead" a myth. Her point: leads don't carry compliance with them — businesses create it through audits, scrubs, and documented consent.
The established business relationship (EBR) exemption is real, but narrow. Live calls are permitted up to 18 months after a transaction or 90 days after an inquiry, according to DNC.com's TCPA overview. Critically, the EBR exemption does not cover automated calls, prerecorded messages, or texts. And the window only holds if you can prove when the transaction or inquiry actually happened.
Texts are now squarely in scope too. The FCC's December 2023 order extends DNC Registry protections to marketing text messages, meaning you can only text a DNC-listed consumer with their prior express invitation or permission. If your follow-up strategy leans on text — as most fast lead-response programs do — consent applies there just like it does on the phone.
So what does defensible consent look like? At minimum:
- Written consent tied to the specific phone number the consumer provided
- Clear identification of who will be calling or texting, and for what purpose
- A timestamped record showing when and how consent was captured
- Documentation of any EBR you're relying on — the transaction date or inquiry date
That last point matters more than most teams realize. The gap between "we scrub our lists" and "we can prove we scrubbed this number" is where outbound teams get hit, as Aloware's compliance analysis warns. The same logic applies to consent: a form fill with no record of what the consumer agreed to is worth almost nothing in a dispute.
The stakes are steep. TCPA statutory damages run $500 per violation, trebled to $1,500 for willful violations, with no cap, per M&S Law Group — and that's on top of FTC penalties of up to $53,088 per violation effective January 2025.
This is why CallMyLeads builds consent capture directly into the booking flow and follows quiet-hours and telemarketing rules on every call and text. When every lead gets an instant, documented response, speed and compliance stop being competing priorities — they run on the same record.
How CallMyLeads Handles DNC and Consent For You
Speed-to-lead only pays off if every follow-up is legal. A text sent at 9:47 p.m. or to a DNC-registered number can cost far more than the job it was chasing — FTC penalties now run up to $53,088 per violation, and TCPA damages add $500 to $1,500 per message with no cap.
That is why compliance is built into every CallMyLeads plan, not bolted on. When your leads come in from a form, an ad, a chat, or a missed call, the system responds in seconds — but only within rules that keep home services, dental, legal, and other clients protected.
Here is what that looks like in practice:
- DNC scrubbing before outreach. Calling lists are checked against the National Do Not Call Registry — a database businesses must subscribe to and scrub against, not a public lookup, according to DNC compliance guidance. The law requires re-scrubbing at least every 31 days, and every scrub is logged so it can be defended later.
- Opt-outs honored immediately and automatically. Federal rules give businesses 10 business days to process opt-outs; CallMyLeads does it instantly. Regulators expect opt-outs accepted by "any reasonable means," not just magic words like "stop," per compliance documentation from Clay.
- Explicit consent collected in the booking flow. A clean DNC scrub is no defense to a TCPA consent claim, as Aloware's compliance analysis makes clear — so consent is captured up front, before any automated follow-up begins.
- Quiet-hours rules followed. Outreach stays within the legal calling window of 8 a.m. to 9 p.m. in the recipient's local time — even though calls are answered 24/7/365.
- Registered business texting. All messaging runs under A2P 10DLC, the US carrier registration regime for application-to-person texting.
The consent piece matters more every year. The FCC's December 2023 order extended DNC Registry protections to marketing text messages, meaning texting a registered number now requires the consumer's prior express invitation or permission, according to Cooley LLP's legal analysis. With more than 253 million numbers on the Registry and over 2 million complaints filed in FY 2024 alone, the odds of hitting a protected number are high.
The stakes are real, but so is the upside of doing this right. Michele Shuster, a former Chief of the Ohio AG's Consumer Protection Section, calls the "TCPA-compliant lead" a myth and recommends regular scrubs against federal, state, and company-specific lists plus frequent training, in her analysis for M&S Law Group. That is exactly the discipline a done-for-you system should carry for you.
CallMyLeads handles the scrubbing, consent capture, opt-outs, quiet hours, and carrier registration — so your team gets sub-10-second follow-up without the compliance risk. For dental and medical clients, HIPAA-aligned configurations use approved scripts only.
If slow or risky follow-up is costing you jobs, book a free 15-minute scoping call. We will map your lead sources, show you how compliant speed-to-lead works for your business, and quote a flat setup fee upfront — no contract, cancel anytime.
Frequently Asked Questions
Can I just type a phone number into the Do Not Call Registry to check if it's listed?
How often do I legally have to scrub my calling list against the DNC Registry?
Is checking the national DNC list enough, or are there other lists I need to check?
If my list comes back clean after a DNC scrub, am I safe to call or text?
What are the penalties if I call someone on the DNC list by accident?
How quickly do I have to honor an opt-out request?
The Real Answer: Stop Looking People Up, Start Scrubbing Everything
So, how do you know if someone is on the DNC list? You don't look them up — you scrub your entire list, on a cycle, and you can prove it. That means a SAN from telemarketing.donotcall.gov, re-scrubbing at least every 31 days (28 is safer), checking all three layers — federal, the 11 state registries, and your own internal opt-out list — and remembering that a clean scrub never replaces documented consent. With over 253 million registered numbers and FTC penalties reaching $53,088 per violation, a single unchecked call can erase the profit from a whole campaign. Your next steps: subscribe to the Registry, tighten your scrub cadence, timestamp every scrub, and capture consent in writing before any call or text goes out. Or let someone carry that weight for you — CallMyLeads builds DNC scrubbing, instant opt-out handling, consent capture, and quiet-hours rules into every plan, so your leads get answered in seconds without the liability. Book a free 15-minute scoping call and see how compliant speed-to-lead works for your business.