The deliverable first: a pre-send checklist for an SMS journey, every control tied to the published carrier code, registry policy, or federal rule that makes it necessary. What follows explains why the checklist has a Gate column, and why most rows say Carrier.
A lawful SMS program and a delivered SMS program are two different programs. The law asks whether the recipient consented and whether they can revoke. The carrier asks whether you are registered and vetted, whether your traffic matches your registration, and whether your content sits on its private allow list. You can answer the first question perfectly and fail all three parts of the second, which is where this paper spends its words.
Two gates, two rulebooks
The CTIA Messaging Principles and Best Practices call themselves "a set of voluntary best practices developed by CTIA's member companies" that "do not constitute or convey legal advice." They also authorize the second gate: "All Service Providers may filter or block Unwanted Messages before they reach Consumers," and providers "may notify the Message Sender" when they block, "to the extent practical." CTIA expects carriers to layer their own pre-approval, vetting, audits, and filtering on top (CTIA MPBP, May 2023, §1, §2.3, §5.1, §7.1, §7.2.3).
They do. AT&T can downgrade your service class, suspend your campaign, or terminate you "at AT&T's sole discretion… without prior notice," and its Message Classes "may be adjusted by AT&T without notice." Its code is marked "AT&T Proprietary," does not appear on att.com, and reaches the public through aggregator documentation sites, including the copy linked here; it also binds advertising to guidelines the advertiser "agrees to treat… as confidential information of AT&T" (AT&T CoC, March 1, 2021). T-Mobile's ladder runs from suspended sending rights to "Suspension of all network services," under what it calls "a living document" it may update "at any time, in T-Mobile's sole and absolute discretion" (T-Mobile CoC v2.2, November 2020, §1.3, §1.4).
A court or a regulator adjudicates the statutory gate after the fact, in public, against a rule you can look up. Your counterparty adjudicates the carrier gate in real time, in private, against a rulebook it rewrites without telling you.
The rulebook most people cite is not the one filtering them
Myth: the CTIA Messaging Principles were updated in October 2025. Vendor explainers circulating in 2026 describe an October 2025 update tightening URL handling and opt-in language (cited as the misconception, never as authority: messageiq.io, 10dlccheck.com).
No such edition exists. The current Messaging Principles is dated May 2023 and says on its face that it "replaces the 2019 CTIA Messaging Principles and Best Practices" (§2.1). CTIA's October 2025 publication is a different, shorter document, the Messaging Security Best Practices, carrying no URL-shortener rule and no opt-in language rule. The Campaign Registry's April 2026 guide still sends registrants to the May 2023 file, by URL.
Myth: SHAFT is the CTIA rule governing what you can text.
The words "SHAFT," "alcohol," "firearms," "tobacco," "cannabis," "gambling," and "lending" appear nowhere in the May 2023 Messaging Principles. SHAFT is defined in the Short Code Monitoring Program Handbook v1.9, scoped to short code programs. The Messaging Principles' content rule (§5.3.1) is behavioral: it bars content that is unlawful, deceptive, privacy-invading, threatening, malware-bearing, or age-gate-failing. No product categories at all.
The categorical bans live in the carrier codes. T-Mobile's Disallowed Content list, barred "regardless of any prior approval," covers payday loans, non-direct lenders, debt collection, debt consolidation, credit repair, cannabis, work-from-home programs, "Job Alerts from 3rd Party Recruiting Firms," gambling, and third-party lead generation (T-Mobile CoC §5.2). AT&T's overlapping list adds debt relief and affiliate lead generation. Every category there is a lawful business somewhere in the United States. Two more AT&T bullets, verbatim: "Messaging resulting in excessive complaints or opt-out requests," and "Messaging that, in AT&T's sole discretion, abuses or harms its Customers or is otherwise inappropriate" (AT&T CoC).
The first makes a metric a prohibited content category. The second is unbounded. No statute reads like either one. People credit a voluntary industry document with rules that are private contract terms, then assume clearing the document clears the contract.
The registry does not approve your campaign
The Campaign Registry disclaims the approval role in its own guide: "TCR does not review, approve, or reject campaigns. This is done by your CNP and their upstream CNP or DCA partner," and "TCR is not a compliance house" (TCR CSP User Guide, April 2026, pp. 24, 26). CTIA concedes messages die in transit, offering redress to a sender who can show they were "blocked between message submission and receipt by the intended recipient's device" (CTIA MPBP §7.2.8).
When a lawful message is not arriving, work the second gate in the order the chain enforces it: registration truth, number type and sharing, content category, the link, volume against your class or tier, then your own opt-out rate.
Gate two throttles before it blocks
Registration is a precondition to delivery: entities "must be registered before their campaign messages will be approved for delivery on our network" (T-Mobile support). It moves you off the grey route and out of the consumer spam filter, and onto a different enforcement regime.
Throughput follows a vetting score assigned before you send anything. A Standard Vet returns a 0-100 score, and "A score of 75 or above grants a brand the highest throughput terms." Skip it and you take the floor: brands off the Russell 3000 list "automatically have access to the entry level throughput for both AT&T (Class: E or F) and T-Mobile (Tier: LOW)." T-Mobile's published daily cap runs from 2,000 messages per day at Tier LOW to 200,000 at Tier TOP; AT&T's SMS rate from 240 per minute at Class E/F to 4,500 at Class A/B, both "subject to change by MNOs at any time" (TCR CSP User Guide, pp. 27–28).
Vetting is not retroactive: scores apply "to any campaign registered after the vet was completed," so earlier campaigns need a resubmit. The carriers meter different objects: AT&T "provides throughput based on each campaign," unshared across a brand's other campaigns, while T-Mobile allocates a daily allowance "to each brand and tied to the brand's EIN," shared across every campaign that brand runs (same, "MNO Terms"). Splitting a program into more campaigns buys AT&T headroom and nothing on T-Mobile, where one allowance divides more ways. Settle that in journey design, not in a post-launch review. And the filing has to keep matching the traffic (T-Mobile CoC §3.12).
The link is where journeys die
One practice, four authorities, four different strengths, and no way to obey all four.
CTIA asks senders to use a shortener "dedicated to the exclusive use of the Message Sender" and to make the destination "unambiguously identify the website owner" (CTIA MPBP §5.3.2). TCR refuses them at the registration form: "public URL shorteners (bitly, tinyurl) are not accepted" (TCR CSP User Guide). T-Mobile calls the practice "highly discouraged" and prohibits using more than one (T-Mobile CoC §4.7). AT&T bans them outright: "The practice of using public URL shorteners in bulk Messaging is prohibited" (AT&T CoC), an upgrade from the "highly discouraged" wording in its own 2020 edition.
You do not pick which of the four adjudicates your message, so build to the strictest. Own the domain and drop public shorteners. T-Mobile's affirmative rule already points there: one business web domain per program, with "a branded short URL" allowed for custom links (§3.3).
Redirect chains "may result in immediate suspension of services" (same, §4.8), and AT&T requires the landing page to name its owner and, where it collects personal information, carry "a published, conspicuously-accessible privacy policy."
What the carriers disagree about on opt-out
Myth: every outbound message must carry an opt-out line. The primary sources disagree. CTIA wants opt-out instructions in the opt-in confirmation for recurring programs. T-Mobile requires them at opt-in and "at least once per month," then recommends the first message and "at least every 5th message… if not on every message." AT&T is strictest: informational and promotional messaging "must contain a notice" of how to opt out (T-Mobile CoC §2.8, §2.10; AT&T CoC).
The correction does not license dropping the line. Same rule as the link: build to the strictest carrier in your route.
The harder half of AT&T's rule: senders must honor equivalents they never advertised, "such as 'Quit' or 'Wrong Number'," and stop "regardless of whether the Messages include an opt out notice." T-Mobile's floor set is STOP, END, CANCEL, UNSUBSCRIBE, and QUIT, tolerant of punctuation, case, and surrounding text (T-Mobile CoC §2.8, §2.11). That opt-out rate is itself a filtering input, and T-Mobile's published numbers are written as guidance rather than as automatic consequences. T-Mobile assigns the first one to the DCA in your route rather than to itself: the "DCA should monitor STOP and HELP responses on a campaign basis and should be flagged for monitoring and/or conduct a consent audit shall opt-out rates exceed .5% per messaging campaign blast." For the second, "it is suggested" that rates above "4% opt-out within 24 hours" bring immediate suspension of the campaign, a root cause analysis, and a consent audit. The unhedged clause is the one that follows: "At T-Mobile's discretion, any campaign found to have a 'high' volume or percentage of opt-out messages and or complaints may result in suspension or termination of a specific messaging campaign and/or blocking of sending numbers" (T-Mobile CoC v2.2, November 2020, §2.15). Treat 0.5% and 4% as the published thresholds your route partner is told to watch, and measure per send. A monthly average hides the 24-hour spike they are written around.
Where the two gates meet on consent
47 CFR § 64.1200(a)(10) lets a called party revoke consent "by using any reasonable method." Replying "stop," "quit," "end," "revoke," "opt out," "cancel," or "unsubscribe" is a "reasonable means per se"; other words count if "a reasonable person would understand those words to have conveyed a request to revoke consent." Revocations must be honored within "ten business days," senders "may not designate an exclusive means" of revoking, and one confirmation message carrying no marketing content is permitted (FCC 24-24, Appendix A). Those rules took effect April 11, 2025 (FCC DA 26-12, ¶3).
One requirement inside them sits under a waiver. The FCC's Consumer and Governmental Affairs Bureau waived § 64.1200(a)(10) only to the extent it requires treating a revocation "in response to one type of message as applicable to all future robocalls and robotexts from that caller on unrelated matters" (DA 25-312, ¶1), then on January 6, 2026 extended that waiver to January 31, 2027 while the Commission takes comment "on ways we can modify the requirement" (DA 26-12, ¶¶5, 12). Stated plainly, as of August 30, 2026: the revocation rules are in force, and only the stops-everything-from-this-sender piece is waived.
The carrier gate sets its own consent conditions. T-Mobile already accepts revocation by "phone call, email, or text" and requires per-campaign consent that "must not" be treated as blanket consent across brands (T-Mobile CoC §2.4). AT&T states that "Customer consent may not be bought, sold, rented, or shared," a rule about how you acquired consent, enforced as a condition of delivery.
With a rule in force, a waiver that expires, and a proceeding that could move it, the cheap and reversible choice is to capture revocation scope in the consent record now: which campaign, which sender, what the recipient said, and whether they asked for everything to stop. That costs a field. What policy to apply to it is a question for your counsel, not for me.
The pre-send checklist
Each control exists because a published document says so, linked in the last column. Legal means a federal rule requires it; Carrier, a carrier code, as a condition of delivery; Registry, the registration system; Both, a federal rule and a carrier code independently require it.
| # | Control | Gate | Why |
|---|---|---|---|
| 1 | CTA names the program, originating number, sending entity, fees, and opt-out; consent logged with timestamp, medium, exact language, campaign, number | Both | CTIA §5.1.1, §5.1.2 |
| 2 | No bought, rented, shared, or affiliate-sourced consent, whatever its legality | Carrier | AT&T consent rule; T-Mobile §4.1 |
| 3 | Consent scoped per campaign and per sender, never blanket | Both | CTIA §5.1.2.2; T-Mobile §2.4 |
| 4 | First message within 30 days of consent, or double opt-in again | Carrier | T-Mobile CoC v2.2, November 2020, §2.4 |
| 5 | STOP, END, CANCEL, UNSUBSCRIBE, QUIT honored, plus in-sentence and mixed-case variants, plus phone and email | Both | T-Mobile §2.4, §2.8, §2.11; AT&T "reasonable equivalent"; §64.1200(a)(10) |
| 6 | No exclusive revocation channel; any reasonable method honored within 10 business days; one confirmation text, no marketing | Legal | §64.1200(a)(10), (a)(12) |
| 7 | Opt-out instructions at opt-in and monthly, and per message where AT&T is in your route | Carrier | T-Mobile §2.8, §2.10; AT&T notice rule |
| 8 | HELP answered for anyone, subscribed or not; carrier deactivation files processed daily | Both | HELP: CTIA Short Code Handbook §3.4, TCR mandatory HELP fields · deactivation: CTIA §5.1.5, T-Mobile §2.13, AT&T |
| 9 | Own the link. One branded domain per program, no public shorteners, no redirect chains, landing page names its owner | Carrier / Registry | AT&T "prohibited"; TCR "not accepted"; T-Mobile §3.3, §4.7, §4.8; CTIA §5.3.2 |
| 10 | One dedicated number per program, never shared or sub-aggregated, pools declared at 50+; no cycling, snowshoeing, dynamic routing, or swapping blocked numbers | Carrier / Registry | T-Mobile §3.1, §4.6; TCR "Number Pooling," 50+; T-Mobile §4.9, §4.3, §4.5, §4.4; AT&T prohibited techniques |
| 11 | Brand identity Verified, then vetted: 75+ is the top tier, and vetting is not retroactive | Registry / Carrier | TCR "Vetting and Appeals" |
| 12 | Model the ceiling first: AT&T meters per campaign, T-Mobile per brand EIN; registration kept true to live traffic | Carrier / Registry | TCR "MNO Terms"; T-Mobile §3.12 |
| 13 | Opt-out rate measured per send against the published thresholds: at 0.5% the DCA should flag monitoring or a consent audit, and 4% in 24 hours is the suggested suspension line (both worded as guidance in the source; suspension is at T-Mobile's discretion) | Carrier | T-Mobile CoC v2.2, November 2020, §2.15 |
| 14 | Content checked against the carrier disallowed lists, not only the law; age gate by date of birth at opt-in | Carrier | T-Mobile §5.2, §5.7; AT&T prohibited messages |
| 15 | Escalation path ready: your connectivity partner's contact, and evidence you can produce | Carrier | CTIA §7.2.8 |
| 16 | Carrier codes re-read and diffed on a schedule | Carrier | AT&T "without notice"; T-Mobile §1.4 |
Row 16 keeps the other fifteen honest. Both codes reserve the right to change silently, and AT&T's already did, on the rule behind row 9.
What the checklist does not cover
United States only, and SMS and MMS on 10DLC, not RCS. It names AT&T and T-Mobile because those two publish codes you can read, and asserts nothing about any other carrier: I could not obtain a comparable primary document, and an unsourced claim about a carrier's filtering is what this paper argues against.
It does not teach consent architecture; it inherits it. Editions matter too. The T-Mobile code cited is v2.2, dated November 2020, still what T-Mobile's support page links to today, so its published figures (0.5%, 4% in 24 hours, 30 days) are five years old. The AT&T code is the March 1, 2021 edition, the newest I could locate. Check both editions before you rely on a number.
The operating principle
Compliance is a floor you can read. Deliverability is a contract you mostly cannot: private, revisable without notice, decided in real time by your counterparty, and able to bar a lawful industry by category.
Put both gates on one checklist, with every row naming which gate it answers to. That is the cheapest way to stop a team from reading a legal review as a delivery guarantee.
Every quotation here was verified against the linked primary document on August 30, 2026. Carrier codes change without notice and the FCC waiver expires January 31, 2027, so confirm any rule against its source before you rely on it. The checklist and the framing are mine; the quoted behavior belongs to the carriers, the registry, and the regulator.
The views here are mine and do not represent any employer or client, past or present.
Drafted with AI assistance; researched, edited, and verified by Jennifer Gallo LeBlanc.
Sources
Every primary source is the standards body's, the registry's, the carrier's, or the regulator's own document. Accessed 2026-08-30.
- CTIA — "Messaging Principles and Best Practices," May 2023. Voluntary and not-legal-advice scope; call-to-action and consent-record requirements; opt-in confirmation elements; per-campaign consent; opt-out handling; deactivation files; the nine-item content rule (§5.3.1); URL shortener and owner-identification rules (§5.3.2); "may filter or block," discretionary notice, and suspension (§7.1–§7.2.4); redress for blocking between submission and handset (§7.2.8). https://api.ctia.org/wp-content/uploads/2023/05/230523-CTIA-Messaging-Principles-and-Best-Practices-FINAL.pdf
- CTIA — "Messaging Security Best Practices," October 2025. The actual October 2025 CTIA publication: monitoring and blocking, forensic cooperation, email-to-SMS authentication, SIM-farm abuse, CPaaS credential compromise. https://api.ctia.org/wp-content/uploads/2025/10/Messaging-Security-Best-Practices-_October-2025.pdf
- CTIA — "Short Code Monitoring Program Handbook," v1.9, effective August 2, 2023. The definition of SHAFT Content; §3.5 program content rules; §3.4 HELP response obligation regardless of subscription. https://api.ctia.org/wp-content/uploads/2024/01/CTIA-Short-Code-Monitoring-Handbook-v1.9-FINAL.pdf
- The Campaign Registry — "CSP User Guide," April 2026. Ecosystem role definitions; brand identity verification; class and tier assignment and the Russell 3000 default; vetting, the 0–100 score, the 75+ threshold, and non-retroactivity; mandatory opt-out and HELP fields; "public URL shorteners (bitly, tinyurl) are not accepted"; number pooling at 50+; "TCR does not review, approve, or reject campaigns"; "TCR is not a compliance house"; the AT&T and T-Mobile throughput matrices. https://www.campaignregistry.com/wp-content/uploads/CSP-User-Guide_Apr_2026-v2_comp.pdf
- T-Mobile — "Code of Conduct," v2.2, November 2020, retrieved from T-Mobile's support site. Enforcement ladder (§1.3); "living document… sole and absolute discretion" (§1.4); consent, 30-day staleness, no blanket consent (§2.4); opt-out keywords and cadence (§2.8, §2.10, §2.11); daily deactivation files (§2.13); opt-out thresholds (§2.15); one recognizable number (§3.1); one branded domain (§3.3); campaign accuracy (§3.12); no bought or shared consent (§4.1); snowshoe (§4.3); filter evasion (§4.4); dynamic routing (§4.5); shared numbers prohibited (§4.6); public shorteners (§4.7); redirect chains (§4.8); number cycling (§4.9); the Disallowed Content table (§5.2); age gating with date-of-birth verification (§5.7). https://www.t-mobile.com/support/public-files/attachments/T-Mobile%20Code%20of%20Conduct.pdf
- AT&T — "Code of Conduct for AT&T Short Code and 10-Digit A2P SMS Messages," March 1, 2021. Marked "AT&T Proprietary"; not published on att.com; retrieved from an aggregator's public documentation site. Code enforcement without prior notice; message classes adjusted "without notice"; unregistered A2P rate limiting; the no-bought-or-shared-consent rule; opt-out notice, "reasonable equivalent" responses, and cessation regardless of notice; confidential advertising guidelines; the Prohibited Messages list; prohibited messaging techniques including the ban on public URL shorteners; landing-page owner-identification and privacy-policy requirements. https://docs.intelepeer.com/atmosphere/Content/Resources/Files/att_bulk_messaging_code_of_conduct_re_10dlc_a2p_messages__03.2.pdf
- AT&T — same document, prior edition, 06/01/2020. Cited only where the editions differ: the withdrawn "15 SMS messages or segments thereof, per sending number per minute" figure, and the "highly discouraged" wording on public URL shorteners that the 2021 edition upgraded to "prohibited." https://sinch.github.io/docs/sms/sms-other/downloads/ATT_Code_of_Conduct_062020.pdf
- T-Mobile — "Consumer versus Non-Consumer Text Messaging" (support page). Registration required before campaign messages are approved for delivery; sanctioned routes versus grey routes. https://www.t-mobile.com/support/plans-features/consumer-versus-non-consumer-text-messaging
- FCC — TCPA Consent Order, FCC 24-24, released February 16, 2024, Appendix A (Final Rules). The adopted text of 47 CFR § 64.1200(a)(10) and (a)(12): any-reasonable-method revocation; the seven per se words; the reasonable-person test; the ten-business-day deadline; no exclusive revocation channel; the one-time confirmation text and five-minute presumption. https://docs.fcc.gov/public/attachments/FCC-24-24A1.pdf
- FCC — Order, DA 25-312, released April 7, 2025 (CG Docket No. 02-278). The original limited waiver of § 64.1200(a)(10) as to cross-matter revocation. https://docs.fcc.gov/public/attachments/DA-25-312A1.pdf
- FCC — Order, DA 26-12, released January 6, 2026 (CG Docket No. 02-278). Extension of the § 64.1200(a)(10) waiver to January 31, 2027; confirmation that the TCPA Consent Order amendments took effect April 11, 2025; the October 29, 2025 proceeding seeking comment on modifying the cross-matter revocation requirement. https://docs.fcc.gov/public/attachments/DA-26-12A1.pdf
- messageiq.io and 10dlccheck.com — vendor explainers, cited only as evidence of the "October 2025 CTIA update" misconception, never as authority. https://messageiq.io/blogs/ctia-messaging-principles-and-best-practices/ · https://10dlccheck.com/learn/ctia-guidelines-explained
```