Text messaging is the only marketing channel where getting one thing wrong can cost you the channel itself. Carriers filter numbers that generate complaints. The TCPA carries statutory damages of $500 per message, trebled if the violation is wilful, and it is enforced largely by private plaintiffs who aggregate claims across a whole list. A campaign to ten thousand people that should not have gone out is not a marketing mistake. It is a five-million-dollar theoretical exposure.

The good news is that the rules are not complicated, and most of the mechanical parts can be automated. This post covers what opt-out compliance actually requires, what smskick handles for you, and what stays yours no matter which platform you use.

Consent comes first, and it is not automatic

Opt-out is the second half of the story. The first half is that you needed permission before the first message, not just a way out after it.

For marketing texts, US law requires prior express written consent. In practice that means the person actively agreed - ticked an unticked box, submitted a form, texted a keyword to you - and that the agreement said, in terms they could see, that they would receive marketing text messages from your business. A few things that are not consent, however common they are:

  • A phone number given for a different purpose. Someone who gave you their mobile to get a delivery notification did not agree to your promotions.
  • A pre-ticked box, or consent buried in terms nobody opened.
  • A purchased, rented, scraped or appended list. Consent given to another business is not transferable to yours, whatever the seller's paperwork claims.
  • A list you inherited in an acquisition, unless the original opt-in language covered a change of ownership.

The uncomfortable part is that consent is not just something you need to have. It is something you need to be able to prove, months or years later, for one specific phone number, on request.

Keep the evidence, not just the promise

When a complaint arrives, the question is never "does your company have a consent policy?" It is "show me consent for +1-555-0142." A policy document does not answer that. A record does.

That is why smskick asks you to attest to each list at the moment you import it, rather than once at signup. Every import records who confirmed it, when, from where, and the exact wording they were shown - stored verbatim, because wording changes and an attestation is only evidence if you can show what was actually agreed to. If your CSV carries consent_source and consent_date columns, those are read and stored per contact, which is stronger still: it answers the question for that individual number rather than for the batch.

None of this is enforced against your data. A list with no consent columns still imports, because refusing would break every business with an older export and would mostly teach people to invent values. What smskick does instead is make the gap visible, so you know where you stand before somebody else asks.

What happens when someone opts out

Under the CTIA guidelines that carriers enforce, you must honour opt-out requests immediately and without requiring anything further from the recipient. The recognised keywords are STOP, STOPALL, UNSUBSCRIBE, CANCEL, END and QUIT.

Real replies are messier than that list. People send "STOP.", "Please stop", "stop texting me", "unsubscribe me". A platform that only matches the exact keyword misses all of those - and each miss means continuing to text somebody who asked you to stop, which is precisely the behaviour that generates complaints and gets numbers filtered.

smskick handles this in two passes. It strips punctuation and spacing, so "STOP ALL" and "stop-all" both collapse to a recognised keyword; and it checks each word of the reply on its own, so "please stop" and "stop texting me" are caught too. Both passes are deliberately generous. Over-recognising an opt-out costs you one message. Under-recognising one costs you the number.

Once detected, the number goes on a suppression list scoped to your account. It is checked again at the moment of delivery, not only at campaign build time - so somebody who opts out while a campaign is mid-flight is dropped from the rest of it rather than finishing the run.

Quiet hours

The TCPA restricts marketing calls and texts to between 8am and 9pm in the recipient's local time, and several states are stricter. This trips people up because the sender's timezone is irrelevant and a national list spans four or more of them.

smskick infers the recipient's timezone from their area code and holds campaign messages outside the window, releasing them when it opens. It is not perfect - people keep their numbers when they move - but it is far better than sending everything at once from your own timezone and hoping.

Where our responsibility ends and yours begins

We will be plain about this line, because platforms are sometimes vague about it in a way that is convenient for them and dangerous for you.

smskick handles: STOP and opt-out detection, permanent per-account suppression, re-checking suppression at delivery, quiet-hour enforcement by recipient timezone, carrier registration for your number, and keeping the consent records you give us.

You remain responsible for: actually obtaining consent before you upload anyone, the truthfulness of what you attest to at import, identifying your business in your messages, the content being lawful and not misleading, and honouring opt-out requests that arrive by other routes - a phone call, an email, a conversation in your shop. Legally, you are the sender. The FCC treats the party that chooses the recipients, the timing and the content as the one that initiated the message, and on a self-serve platform that is you.

A practical checklist

  1. Collect consent in writing, with clear language. Say who is texting, that it is marketing, and that message rates may apply. Do not pre-tick the box.
  2. Record where and when each person opted in. A consent_source and consent_date column in your CSV takes ten minutes to add and answers the only question that ever gets asked.
  3. Identify yourself in the first message. "Hi, it's [business]" - a recipient who cannot tell who is texting them reports it as spam.
  4. Include opt-out instructions, at minimum on the first message of a campaign and periodically thereafter.
  5. Never re-add a suppressed number. If someone opts out and later opts back in through your website, that is fine - but the record needs to show the new opt-in.
  6. Honour opt-outs from every channel, not just replies to your texts.
  7. Watch your opt-out rate. A sharp rise is almost always a list problem, and it is a signal you get before the carrier acts on it, not after.

The takeaway

Opt-out compliance comes down to two things: real consent on the way in, and instant, reliable opt-out on the way out. The second one can be automated, and on smskick it is. The first one cannot be, because it happens on your website, at your counter, in your shop - somewhere no platform can witness.

What a platform can do is make sure that when the question arrives, you have an answer. That is worth setting up before you need it.