Compliance
A2P 10DLC registration: why your business texts aren't arriving
- 7 min read
By Sujan ThapaliyaLast updated
The short answer
The symptom is distinctive and maddening: your platform reports messages as sent, delivery receipts look fine or arrive as ambiguous statuses, and recipients tell you they got nothing. No bounce, no error, no explanation. That is carrier-level filtering, and in the US it almost always traces back to 10DLC registration.
What 10DLC is and why it exists
A 10-digit long code is an ordinary phone number. For years businesses sent bulk messages over them because they were cheap and looked personal, which is exactly why spammers did the same. Carriers had no way to tell a dental practice's appointment reminders from a phishing run over identical infrastructure.
A2P 10DLC is the answer: application-to-person traffic over long codes must be registered. You declare who you are (the brand) and what you send (the campaign), the carriers assign a trust score, and that score governs your throughput and how aggressively your messages are filtered.
| Route | What it is | Registration |
|---|---|---|
| A2P 10DLC | Business messaging over an ordinary local number | Brand + campaign, required |
| Toll-free messaging | Messaging over an 800/833/844 number | Toll-free verification, required |
| Short code | Dedicated 5–6 digit number | Full carrier programme approval |
| P2P | A person texting from their own handset | None |
Brand and campaign, and why both exist
Registration has two layers, and conflating them is the most common source of rejection.
The brand
Who you legally are: registered business name, tax identifier, address, website, and a contact. This is verified against public records, so the details must match exactly. A trading name that differs from the registered entity, or an EIN with a typo, fails verification, and the failure message rarely says which field was wrong.
The campaign
What you actually send: the use case (marketing, two-factor codes, account notifications, appointment reminders), sample messages, and the part most rejections hinge on: how consumers opt in.
The opt-in description is where campaigns get rejected
Your sample messages must also match the use case, include your brand name, and (for marketing campaigns) show the opt-out instruction. A sample that says “Hi {name}, your appointment is confirmed” filed under a marketing use case gets rejected for inconsistency, not for content.
Trust score and throughput
Registration produces a trust score that determines how many messages per second you can send and your daily ceiling to each carrier. Sending above it does not produce an error; it produces queuing and then silent drops.
- Verified business details raise it. A properly verified brand with matching public records scores materially better than a sole proprietorship with sparse data.
- Clean opt-in practice raises it over time. Low complaint rates and healthy opt-out handling feed back into the score.
- Complaints and spam reports lower it, and the effect persists.
- Message content matters. Public URL shorteners are heavily penalised because they are what phishing uses. Use a branded domain or none.
What gets filtered even when you are registered
Registration is necessary, not sufficient. Content filters run on every message regardless of score, and they are blunt.
- Public URL shorteners. bit.ly and its peers are treated as high risk. This is the single most common cause of filtering among registered senders.
- Restricted categories. Cannabis, firearms, high-interest lending, gambling, and adult content are blocked or heavily restricted on 10DLC, whatever your score.
- Phishing-shaped language. “Verify your account”, “click here immediately”, urgency plus a link. Filters cannot distinguish your legitimate version from the fraudulent one.
- Volume spikes. A sender averaging two hundred messages a day that suddenly sends twenty thousand looks compromised.
- Missing opt-out on marketing. Both a compliance failure and a filtering trigger.
Getting registered without three rounds of rejection
- 1
Gather the legal details first
Registered entity name exactly as filed, tax ID, registered address, and a website that is live and describes the business. Mismatches here cause most brand failures. - 2
Fix your opt-in before you register
A live form with a clear, unticked consent checkbox, disclosure that message and data rates apply, and a link to your terms and privacy policy. Reviewers will look at the page. - 3
Write samples that match the use case
Real messages, brand name included, opt-out language on marketing samples. One use case per campaign: mixing reminders and promotions in one campaign is a rejection. - 4
Register the brand, then the campaign
Brand verification typically clears quickly; campaign vetting takes longer and is where the review happens. - 5
Warm up rather than launching at full volume
Ramp over the first fortnight. A brand-new registration sending its daily ceiling on day one looks exactly like an abused one.
Consent is a separate obligation
10DLC is a carrier delivery framework. It is not a legal permission slip. The TCPA still governs whether you may send at all, and marketing texts to mobiles need prior express written consent regardless of how well registered you are.
The two systems interact usefully, though: the opt-in flow that satisfies a 10DLC reviewer is largely the same one that produces a defensible TCPA consent record. Build it once, properly, and both problems are handled.
STOP handling is non-negotiable on both counts. Honour STOP, END, QUIT, UNSUBSCRIBE and their variants immediately and permanently, across every campaign rather than only the one they replied to.
Outside the US
10DLC is a US framework. Other markets impose their own: sender ID registration in India, Singapore, and much of the Gulf; content pre-approval in several Asian markets; and in the EU, GDPR consent obligations that are stricter than the TCPA's in some respects and looser in others.
The generalisable rule is the same everywhere: register your identity with whoever the local gatekeeper is, keep opt-in provable, and do not use public link shorteners.
Reading delivery reports honestly
Delivery reporting on 10DLC is genuinely confusing, and the confusion hides most filtering problems. The statuses do not mean what their names suggest.
| Status | What it means | What it does not mean |
|---|---|---|
| Sent / Accepted | Your provider accepted the message | Nothing about whether a carrier took it |
| Delivered | The carrier acknowledged receipt | Not always that a handset displayed it |
| Undelivered / Failed | A carrier rejected it, sometimes with a code | Rarely explains why in plain language |
| No final status | The carrier never reported back | Frequently the signature of silent filtering |
The pattern to watch for is a high proportion of messages that reach “sent” and then never resolve. That is not a reporting delay; it is usually filtering. Compare delivery rates by carrier; filtering is rarely uniform, and one carrier lagging far behind the others points straight at a registration or content problem rather than a platform fault.
Writing messages that get through
Content filtering runs on every message regardless of registration, and a handful of habits account for most avoidable failures.
- Identify yourself in the first message of any conversation. Filters and recipients both treat an unattributed message as suspicious.
- Use a branded link domain, or no link at all. Public shorteners are the single most common cause of filtering among properly registered senders.
- Avoid urgency stacked with a link. “Act now, click here to verify” is indistinguishable from phishing to a classifier, however legitimate your intent.
- Include opt-out language on marketing messages. Required for compliance and treated as a positive signal by filters.
- Keep formatting plain. Heavy punctuation, all-caps, and unusual character substitutions are classic evasion signals.
- Send at a human pace. A steady daily volume looks like a business; a nightly burst at the daily ceiling looks like a compromised account.
Frequently asked questions
What is A2P 10DLC?
Why are my business texts not being delivered?
How long does 10DLC registration take?
Do I need 10DLC for two-factor authentication codes?
Does 10DLC registration mean I comply with the TCPA?
Can I use a toll-free number for business texting instead?
Sources
- Combating Spoofed Robocalls with Caller ID Authentication — Federal Communications CommissionThe STIR/SHAKEN framework, the attestation levels carriers sign calls with, and the mandate requiring providers to authenticate caller ID.
- 47 U.S.C. § 227 — Restrictions on the use of telephone equipment — Cornell Legal Information InstituteThe Telephone Consumer Protection Act itself — the consent requirements, calling-hours limits, and private right of action.
- Telemarketing Sales Rule — Federal Trade CommissionDo-not-call obligations, abandonment-rate limits for predictive dialing, and required call disclosures.
See it working: business sms
Business SMS lets your team send and receive texts from the same numbers you call from, in one shared inbox. In the US, application-to-person texting requires 10DLC brand and campaign registration. Without it, carriers filter your messages before anyone sees them.
- No subscription
- Numbers in 100+ countries
- Compliance built in