A2P SMS compliance requirements¶
A2P SMS Compliance content requirements explain the message content, consent practices, and sending behavior required for A2P SMS using an approved Sender ID.
This information helps users prepare compliant Sender ID applications and understand why an application may be rejected, suspended, or returned for changes during review.
Approval depends on the accuracy of the submitted business and messaging information, the Sender ID, the consent flow, the sample content, and the way messages are sent.
Messages must comply with applicable laws, regulations, and messaging industry requirements in the destination country.
Sender ID application requirements¶
Sender ID applications must clearly identify the sender, use accurate messaging information, and follow valid consent and opt-out practices.
The submitted description, sample messages, opt-in flow, and actual message traffic must describe the same use case.
Use a recognizable domain¶
If an A2P message includes a link, the link should use a recognizable domain associated with the business or service identified in the application.
Avoid generic, unrelated, suspicious, or frequently changing domains. A consistent business domain helps users recognize the sender and understand where the link will take them.
Use clear and natural language¶
Messages should be written in clear, natural language.
Avoid unusual spellings, excessive symbols, misleading formatting, or wording that may make messages look like spam.
Messages should not use intentionally distorted words, random characters, or obfuscated text to bypass filtering or hide the real meaning of the message.
Collect direct consent¶
User consent must be collected directly for the specific messaging campaign described in the application.
Do not use consent obtained from another company, another messaging campaign, purchased lists, rented lists, shared databases, or third-party lead sources.
Consent must apply only to the specific brand, messaging campaign, and message purpose disclosed to the user during opt-in.
Set message frequency expectations¶
Users should be informed about the expected message frequency before or during opt-in, especially for recurring campaigns.
Example:
You may receive up to 5 messages per month.
Identify the business¶
Messages should clearly identify the business, brand, or service that is contacting the user.
Users should not have to guess who sent the message or why they received it.
Example:
Example Brand: Your appointment is confirmed for 10:00 AM. Reply STOP to unsubscribe. Reply HELP for further assistance.
Include STOP and HELP instructions¶
A2P messages should include clear opt-out and help instructions where applicable.
For recurring messaging campaigns, opt-out instructions should be provided during opt-in and repeated regularly in messages.
Note
A Branded Sender ID does not support reply-based opt-out. In this case, the message should include an opt-out link or another clear opt-out method.
Examples:
Reply STOP to unsubscribe.
Reply HELP for help.
Keep application information accurate¶
Application information must accurately reflect the live use case.
The messaging description, sample messages, Sender ID, opt-in method, links, and actual message content must remain consistent.
A Sender ID application may require changes or resubmission if the submitted information does not match the real message traffic. Associated traffic may also be restricted.
Note
contact.center™ may request updates, clarification, or resubmission if the application details do not match the actual message content or sending behavior.
Prohibited messaging practices¶
The following sending practices are not allowed for A2P traffic registered through Sender ID applications.
Filter evasion¶
Messaging campaigns must not use techniques designed to avoid spam controls, filtering systems, or compliance checks.
This includes replacing blocked Sender IDs or domains for the purpose of continuing the same non-compliant traffic.
URL cycling and public URL shorteners¶
Messaging campaigns must not rotate multiple domains, shortened links, or URLs to evade filtering or dilute reputation tracking.
Public URL shorteners should not be used in A2P messages.
Where links are required, use a recognizable domain that belongs to or clearly represents the business or service identified in the application.
URL redirects and forwarding¶
Messages must not contain links that use multiple redirects or obscure the final destination.
Users should be able to understand where a link will take them.
Links that redirect through several domains or hide the final landing page may prevent approval, cause messages to be filtered, or result in messaging restrictions.
Prohibited message content¶
A2P messages must not contain unlawful, misleading, harmful, abusive, or inappropriate content.
The following content is not allowed:
Spam or unsolicited messages.
Fraudulent, deceptive, or misleading messages.
Phishing messages.
Scam messages.
Content that promotes, depicts, or endorses violence.
Inappropriate content.
Profanity, hate speech, harassment, abusive language, or discriminatory content.
Illegal drugs, illegal substances, or illegal prescriptions.
Any content that is illegal in the destination country or otherwise violates applicable laws, regulations, or messaging requirements.
Note
Sender ID applications may be returned for changes or rejected if their traffic includes or promotes prohibited content. Associated traffic may also be blocked.
contact.center™ may also restrict new application submissions, request corrective action, or limit Sender ID availability if prohibited content is detected.
Important
A2P message content must be appropriate for the intended audience and must comply with applicable laws and messaging requirements in the destination country.
Disallowed messaging categories¶
The following A2P messaging categories are not supported:
Category |
Disallowed content |
|---|---|
High-risk financial services |
Payday loans, non-direct lending, and debt collection. |
Debt forgiveness |
Debt consolidation, debt reduction, and credit repair programs. |
Illegal substances |
Cannabis, illegal prescriptions, and other illegal substances. |
Work and investment opportunities |
Work-from-home programs, job alerts from third-party recruiting firms, and high-risk investment opportunities. |
Gambling |
Gambling-related campaigns, betting-related campaigns, or other gambling content. |
Lead generation |
Campaigns where collected user information is shared, sold, rented, or transferred to third parties. |
Other illegal or non-compliant content |
Any campaign type that is prohibited by applicable law, regulation, or messaging industry requirements. |
Note
Applications for these categories may not be approved even if similar content was previously approved or accepted by another provider.
Phishing¶
Phishing is not allowed.
Phishing means sending messages that appear to come from a reputable company, service, or organization in order to trick users into revealing personal information.
Examples of sensitive information include:
Passwords.
Account credentials.
Payment card details.
Banking information.
Verification codes.
Personal identification details.
A2P messages must not impersonate another company, service, government body, or individual.
Fraud or scam¶
Fraudulent or scam messages are not allowed.
This includes messages that use wrongful or criminal deception to obtain financial or personal gain.
Such messages often involve money, payments, account access, prizes, investments, or business transactions.
Examples of prohibited fraud or scam content include:
Fake payment requests.
Fake account alerts.
Fake prize or reward claims.
Messages requesting payment under false pretenses.
Messages designed to trick users into sharing personal or financial information.
Deceptive marketing¶
Marketing messages must be truthful, clear, and not misleading.
A2P messages must not use false claims, deceptive wording, hidden conditions, or misleading calls-to-action.
If a campaign includes promotional content, the user must have provided the required level of consent before receiving those messages.
The following practices are not allowed:
Using false or misleading claims in promotional messages.
Hiding important terms, fees, conditions, or opt-in details.
Using deceptive language in calls-to-action, forms, landing pages, or message content.
Promoting products or services with claims that cannot be verified or substantiated.
Using a misleading or unclear Sender ID.
Making the message purpose unclear.
Compliance audits and notices¶
Sender ID applications and their associated traffic may be reviewed for compliance with applicable messaging requirements.
Traffic that creates consumer harm, generates complaints, or appears to violate messaging requirements may be restricted, blocked, or require corrective action.
A Sender ID application may require review or corrective action if:
The traffic appears to be unwanted or harmful.
The campaign receives excessive complaints.
The message content does not match the registered campaign use case.
The campaign uses prohibited sending practices.
The campaign falls under a prohibited or disallowed content category.
The sender cannot provide valid consent records when required.
The campaign continues sending messages to users who opted out.
Depending on the severity of the issue, corrective actions may include traffic blocking, application rejection, a request for root cause analysis, application updates, or resubmission.
Repeated violations or severe compliance issues may result in long-term or indefinite traffic restrictions or rejection of the application.
Age gating¶
Messaging that includes age-restricted content must comply with applicable laws and must use a valid age verification process.
Age-restricted content may include, but is not limited to:
Sexually explicit or adult content.
Alcohol-related content.
Firearms-related content.
Tobacco-related content.
Other content restricted by age under applicable laws or regulations.
A simple Yes or No confirmation is not considered a sufficient age gate.
Where age verification is required, the opt-in process should include date of birth verification or another appropriate age verification mechanism.
Important
A Sender ID application may be rejected or returned for changes, or its traffic may be restricted, if the submitted use case, message content, consent flow, or sending behavior does not meet applicable messaging requirements.
Consent and opt-out requirements¶
A2P messages may be sent only to users who have agreed to receive messages from the business for the messaging use case and purpose described in the Sender ID application.
Messages sent under the application must meet the following requirements:
Users must understand what types of messages they are agreeing to receive.
Consent must apply only to the business, brand, messaging use case, and purpose explained during opt-in.
Consent records should be retained and provided if requested during review.
Users must be able to opt out at any time.
Opt-out requests must be honored promptly.
After a user opts out, no further messages may be sent except for a final confirmation message.
For Sender IDs that support reply-based opt-out, common opt-out keywords include:
STOP
END
CANCEL
UNSUBSCRIBE
QUIT
Example opt-out confirmation:
You have been unsubscribed and will no longer receive messages from Example Brand.
Reasons an application may require changes¶
A Sender ID application may require changes or may not be approved if:
The campaign content falls under a prohibited or disallowed category.
The campaign description does not match the submitted sample messages.
The Sender ID is unclear or inconsistent.
The opt-in process is missing, unclear, or not specific to the campaign.
The opt-out message is missing or incomplete.
The campaign uses public URL shorteners, suspicious domains, or redirect chains.
The campaign appears to use third-party lead lists or shared consent.
The message samples contain misleading, deceptive, or non-compliant content.
The campaign information is incomplete, inaccurate, or inconsistent with the intended use case.
The campaign uses prohibited sending practices, such as filter evasion or sharing a Sender ID across unrelated brands or services.
Recommended user guidance¶
Before submitting a Sender ID application, make sure that:
The campaign use case is allowed.
The business and sender information are accurate.
The message content clearly identifies the sender.
The opt-in method is clear and specific to the messaging campaign described in the application.
The messaging campaign does not rely on purchased, rented, shared, or third-party consent.
Message samples include required opt-out wording where applicable.
Any URLs use a recognizable business domain.
The campaign description, sample messages, and consent flow all describe the same use case.
The planned traffic does not include prohibited content or prohibited sending practices.