The Complete A2P 10DLC Compliance Checklist (2026)

10DLC compliance isn’t one big requirement. It is thirty small ones scattered across your website, your forms, your registration, and your sending behavior. This checklist collects all of them in review order. Work through it before you submit and campaign approval becomes a formality; each section links to a deep dive.

1. Website (what reviewers open first)

  • Privacy policy exists, is linked in the footer, and loads. Not a template stub but a live page. Requirements
  • Privacy policy addresses SMS/text data explicitly: what you collect and how it is used.
  • Privacy policy states that SMS opt-in data is not shared with third parties for marketing. The single most-cited rejection sentence in 10DLC.
  • Terms of service exist and cover the messaging program (or a dedicated SMS terms page does).
  • Opt-in language is visible wherever phone numbers are collected. Patterns
  • The website matches the registered business, meaning the same legal entity is discoverable, domain matches registration, site is finished (no lorem ipsum, no “coming soon”).

These six items cause the majority of all rejections, and they are exactly what our free scanner audits. Paste your URL and get a PASS/WARN/FAIL report in ~30 seconds before a human reviewer does the same with a two-week turnaround.

2. Consent collection

  • Affirmative opt-in: unchecked checkbox, button, or keyword; never pre-checked, never implied. Rules
  • Full disclosure at collection covering sender name, message types, frequency, “msg & data rates may apply”, STOP instructions, privacy policy link.
  • Marketing consent is optional, never a condition of purchase or service.
  • Consent records kept: timestamp, source, disclosure version, IP where applicable.
  • No purchased, rented, or transferred lists. Consent does not transfer between organizations.

3. Registration accuracy

  • Legal name and EIN exactly match IRS records. Brand guide
  • Use case honestly matches planned traffic. Choosing one
  • Description answers who / to whom / what / consent. Formula + examples
  • Samples include brand name and STOP language; no public link shorteners. Examples
  • Message flags (links, phone numbers) declared truthfully.

Will your website pass carrier review?

Paste your URL into our free AI scanner and get an instant PASS / WARN / FAIL compliance report. No signup needed.

Run a free compliance scan

4. Message content

  • No SHAFT content: sex, hate, alcohol (without age-gating), firearms, tobacco/cannabis. Cannabis/CBD are prohibited on 10DLC regardless of state law. Details
  • No prohibited categories such as payday loans and high-risk lending, gambling where restricted, and debt relief scams. Restricted industries
  • Sender identifies itself in message text.
  • Links are full-domain (or a branded shortener you own) and match your registered site.

5. Operations

  • STOP processed immediately and confirmed once; HELP returns program info. Opt-out guide
  • Quiet hours respected. 8 AM–9 PM recipient local time is the safe window (some states are stricter).
  • Volume within your tier. Know your carrier limits and segment math.
  • Traffic matches your declared use case on an ongoing basis; carriers audit after approval too.
  • List hygiene. Prune non-responders and invalid numbers; high complaint rates get campaigns suspended independently of registration status.

Print it, run it, then submit

If every box checks, your review outcome is close to deterministic. If you want the website section verified in seconds instead of by hand, run the free scanner; if you have already been rejected, jump straight to the rejection fix guide.

Frequently asked questions

Is 10DLC compliance a one-time thing?

No. Registration is one-time (per brand/campaign), but content rules, opt-out handling, quiet hours, and use-case consistency are ongoing obligations. Carriers audit live traffic and suspend campaigns that drift from their declarations.

What is the most commonly failed item?

The privacy policy, which is either missing entirely or missing the statement that SMS opt-in data is not shared with third parties for marketing. It is a two-sentence fix that prevents the single most common rejection.

Does compliance guarantee delivery?

It guarantees a sanctioned route. Content-based spam filtering still applies to registered traffic, so compliant registration plus spammy content still gets filtered (see error 30007).

Check your compliance before you submit

Most 10DLC rejections trace back to the sender's website: a missing SMS clause in the privacy policy, no visible opt-in language, mismatched business details. Our free AI scanner reads your site the way a carrier reviewer does and tells you what to fix.

Scan my website free No signup required  ·  Results in ~30 seconds

Related to this topic: