ServicesHow It WorksIndustriesResultsInsightsBuild My Plan
Consent for Text Messaging

How do you know if consent has been given?

Back to InsightsHow do you know if consent has been given?

How do you know if consent has been given?

Key Facts

The cost of guessing about consent just got real. A single text message sent without proper consent can trigger TCPA statutory damages of $500 to $1,500 per violation, with no aggregate cap — meaning a campaign of just 100 messages could exceed $150,000 in exposure. TCPA lawsuits are up nearly 95% year-over-year through mid-2025, and as of February 2025, all major US carriers block unregistered A2P business SMS entirely, making compliance not just a legal necessity but a operational one.

Most businesses can’t actually prove consent when asked, and relying on “the lead generator said it was fine” is no longer a defense. Under the FCC’s one-to-one consent rule, each brand must obtain its own consent directly from the consumer — lead buyers are now responsible for maintaining their own records and cannot rely on documentation kept by third parties. This means verifying consent per lead before scaling outreach isn’t optional; it’s the only way to avoid costly liability.

To confirm consent is valid, businesses need three things: the right type of consent, proper disclosures shown before opt-in, and a documented, auditable record of the opt-in event. For marketing texts, prior express written consent is required — an affirmative consumer action with clear disclosures about automated messaging, sender identity, and that consent isn’t a condition of purchase. Transactional messages need prior express consent, but adding a discount or upsell reclassifies them as marketing, triggering the higher standard.

Here’s how to verify consent before sending any text:

  • Confirm the opt-in was an affirmative action — no pre-ticked boxes — and that the consumer saw clear disclosure of what they were agreeing to, including message frequency and opt-out method.
  • Keep a timestamped, auditable record of the opt-in: method, exact language presented, timestamp, and source — this is required for 10DLC campaign registration and protects against disputes.
  • Use double opt-in to verify identity: a second confirmation text asking the consumer to reply YES ensures the number belongs to the intended recipient and guards against fraudulent entries.

Never assume consent transferred from a lead generator. Ask for per-lead proof, confirm the scope of consent matches your outreach (e.g., policy renewal reminders vs. promotional offers), and watch for gaps like missing disclosures or unclear sourcing. Honor opt-outs immediately — as of April 2025, businesses must accept opt-out requests through any reasonable method within 10 business days, and a single opt-out revokes consent for all marketing messages from your company.

For CallMyLeads clients, compliance is built into the flow: every lead response includes explicit consent collection during booking, with opt-out honored automatically and immediately. This ensures your team stays focused on closing jobs, not defending against avoidable fines.

Most businesses don't realize their "consent" doesn't hold up until a demand letter arrives. Under the TCPA, marketing texts require prior express written consent — an affirmative action with specific disclosures — while transactional messages only need prior express consent when the number was shared in a directly related context. Adding a discount or upsell to a transactional text reclassifies it as marketing, triggering the higher standard. TCPA violations carry $500–$1,500 per message with no aggregate cap, and litigation has increased nearly 95% year-over-year through mid-2025.

A valid opt-in isn't a pre-ticked box or a buried terms link. It requires five verifiable components: an affirmative consumer action (unchecked-by-default checkbox or text-to-join keyword), clear disclosure of automated messaging, sender identification, a statement that consent isn't a condition of purchase, and a documented record of when, where, and how it was captured. The recipient must know the business name, purpose, frequency, message rates, terms, privacy policy, and opt-out method before agreeing. CTIA requires opt-in checkboxes to remain unchecked by default.

  • Affirmative action — no pre-ticked boxes, no assumed consent
  • Clear disclosure of autodialed/pre-recorded messages
  • Sender identification and business name
  • Consent is not a condition of purchase
  • Timestamped record of the exact opt-in experience

The FCC's one-to-one consent rule means each brand must obtain its own consent directly — lead buyers can't rely on a generator's records. Carriers enforce this operationally: A2P 10DLC registration requires documented consent including the exact opt-in form language or keyword, and unregistered traffic has been blocked entirely since February 2025. Double opt-in — a confirmation text asking the consumer to reply YES — verifies the recipient's identity and protects against fraudulent number entry. CallMyLeads builds this verification into every booking flow, collecting explicit consent before any outreach begins.

The fastest way to lose $500 per text is to assume consent exists. With TCPA litigation up nearly 95% year-over-year through mid-2025 and statutory damages of $500 to $1,500 per message with no aggregate cap, verification isn't paperwork — it's survival (industry analysis confirms both figures).

Start with double opt-in. After someone submits a form or texts a keyword, send a confirmation asking them to reply YES. This verifies the recipient actually subscribed and protects against third parties fraudulently entering someone else's number, according to SMS compliance guidance. CTIA also recommends an immediate auto-confirmation containing your business name, message rates, and opt-out instructions.

Next, check that your opt-in language matches what you actually send. The FCC requires consent to be "logically and topically related" to the context where it was given and advises companies to err on the side of limiting consent to what consumers would clearly expect (attorney analysis of the FCC Order). If someone opted in for appointment reminders and you send promotional offers, you've exceeded the scope.

Never assume third-party lead consent transfers to you. Under the FCC's one-to-one consent rule, each seller must obtain its own consent directly — but note the legal wrinkle: some sources describe the rule as taking effect January 2026, while others report it was vacated. Either way, carriers and reviewers still expect consent documented per brand, so treat per-brand consent as the operating standard. As one compliance expert puts it: "Don't assume consent. Verify before you scale."

Finally, keep timestamped records of exactly what the consumer saw:

  • The opt-in method — form, keyword, or verbal — and the exact timestamp
  • The precise disclosure language presented, including sender identification and the statement that consent isn't a condition of purchase
  • The traffic source that generated the opt-in

This documentation isn't optional. A2P 10DLC campaign registration requires you to describe your exact opt-in form language or keywords, and as of February 2025, all major US carriers block unregistered traffic entirely (carrier registration guidance). A campaign description like "renewal reminders to policyholders who opted in at binding" passes review; "insurance leads marketing texts" does not.

At CallMyLeads, every booking flow collects explicit consent before automated outreach begins, so the record exists before the first text goes out. Build the same habit into your process — verify first, text second, and document everything.

Build a Consent Record You Can Prove — Automatically

Knowing consent was given starts with how it was captured. CallMyLeads collects explicit consent during the booking flow, ensuring every lead has taken an affirmative action before any message is sent — no pre-ticked boxes, no assumptions. This aligns with TCPA requirements that valid opt-in requires clear disclosure of automated messaging, sender identification, and a statement that consent isn’t a condition of purchase.

Once consent is given, the system creates a timestamped, auditable record of exactly what the consumer saw, when they agreed, and how they opted in — meeting A2P 10DLC registration requirements that demand documented opt-in language and method. Carriers now block unregistered traffic entirely, making this documentation not just compliant but essential for message delivery.

The system also honors opt-outs immediately and automatically, processing requests through any reasonable method within the FCC’s 10-business-day window — and revoking consent for all marketing messages from the company upon a single opt-out text. Quiet-hours compliance is built in, preventing messages between 9 p.m. and 8 a.m. in the recipient’s timezone.

By embedding consent capture, verification, and honoring into the lead response workflow, CallMyLeads turns compliance into a competitive advantage — ensuring speed-to-lead never comes at the cost of legal risk.

Stop paying for leads you never get to talk to — every new lead answered in seconds, 24/7/365.

Frequently Asked Questions

How much can a single text message without proper consent cost me under TCPA?
A single text message sent without proper consent can trigger TCPA statutory damages of $500 to $1,500 per violation, with no aggregate cap — meaning a campaign of just 100 messages could exceed $150,000 in exposure. TCPA litigation has increased nearly 95% year-over-year through mid-2025, making compliance critical.
What does valid consent for marketing texts actually require?
For marketing texts, prior express written consent is required — an affirmative consumer action with clear disclosures about automated messaging, sender identity, and that consent isn’t a condition of purchase. It must include a timestamped, auditable record of the opt-in event, such as the exact language presented and method used. Valid opt-in requires affirmative action, clear disclosure of autodialed messages, sender identification, and a statement that consent isn’t a condition of purchase.
Can I rely on consent collected by a lead generator or third party?
No. Under the FCC’s one-to-one consent rule, each brand must obtain its own consent directly from the consumer — lead buyers cannot rely on documentation kept by third parties. You must verify consent per lead before scaling outreach, as assuming consent transferred from a lead generator is no longer a defense. Lead buyers are responsible for maintaining their own records and should ask for per-lead proof.
What is double opt-in and why should I use it?
Double opt-in involves sending a confirmation text after an initial opt-in, asking the consumer to reply YES to verify their identity and intent. This protects against fraudulent entries and confirms the number belongs to the intended recipient. CTIA recommends double opt-in as a best practice to verify identity and prevent third-party fraud.
What happens if someone opts out — does it stop all messages from my business?
Yes. A single opt-out request revokes consent for all marketing messages from your company, regardless of campaign or message type. As of April 2025, businesses must accept opt-out requests through any reasonable method within 10 business days. The FCC does not allow consent to be bifurcated across programs, so one opt-out ends all marketing outreach.
How do I know if my transactional message accidentally becomes marketing?
If you add a discount, upsell, or promotional content to a transactional message, it is reclassified as marketing and triggers the higher prior express written consent standard. Consent must be logically and topically related to the context where it was given — opting in for appointment reminders doesn’t cover promotional offers. Adding a discount or upsell to a transactional text reclassifies it as marketing, requiring full written consent compliance.

Verify First, Text Second — and Never Guess Again

Consent isn't a box you hope got ticked somewhere — it's a record you can produce on demand. The rules are now clear: marketing texts need prior express written consent with an affirmative opt-in, full disclosures, and a timestamped audit trail. Lead generator assurances don't transfer, a single opt-out revokes consent for all your marketing messages, and carriers block unregistered traffic outright. With TCPA litigation up nearly 95% year-over-year and statutory damages of $500–$1,500 per message with no cap, compliance experts agree that guessing is the most expensive strategy available. Your next step: audit every lead source for per-lead consent proof, confirm your opt-in language matches what you actually send, and document everything — method, timestamp, exact wording. If that sounds like work you'd rather not do by hand, CallMyLeads builds consent collection, verification, and instant opt-out handling into every booking flow, so speed-to-lead never comes at the cost of legal risk. Stop paying for leads you never get to talk to — every new lead answered in seconds, 24/7/365.

Build My Lead Response Plan

Get lead response tips that actually work