Skip to content
AI Dialer

Compliance

A2P 10DLC registration: why your business texts aren't arriving

  • 7 min read

By Last updated

The short answer

A2P 10DLC is the US framework for sending application-to-person text messages over ordinary 10-digit numbers. Businesses register a brand and each messaging campaign with the carriers; unregistered traffic is filtered aggressively and usually silently, so messages report as sent but never arrive.

The symptom is distinctive and maddening: your platform reports messages as sent, delivery receipts look fine or arrive as ambiguous statuses, and recipients tell you they got nothing. No bounce, no error, no explanation. That is carrier-level filtering, and in the US it almost always traces back to 10DLC registration.

What 10DLC is and why it exists

A 10-digit long code is an ordinary phone number. For years businesses sent bulk messages over them because they were cheap and looked personal, which is exactly why spammers did the same. Carriers had no way to tell a dental practice's appointment reminders from a phishing run over identical infrastructure.

A2P 10DLC is the answer: application-to-person traffic over long codes must be registered. You declare who you are (the brand) and what you send (the campaign), the carriers assign a trust score, and that score governs your throughput and how aggressively your messages are filtered.

Message routes in the US
RouteWhat it isRegistration
A2P 10DLCBusiness messaging over an ordinary local numberBrand + campaign, required
Toll-free messagingMessaging over an 800/833/844 numberToll-free verification, required
Short codeDedicated 5–6 digit numberFull carrier programme approval
P2PA person texting from their own handsetNone

Brand and campaign, and why both exist

Registration has two layers, and conflating them is the most common source of rejection.

The brand

Who you legally are: registered business name, tax identifier, address, website, and a contact. This is verified against public records, so the details must match exactly. A trading name that differs from the registered entity, or an EIN with a typo, fails verification, and the failure message rarely says which field was wrong.

The campaign

What you actually send: the use case (marketing, two-factor codes, account notifications, appointment reminders), sample messages, and the part most rejections hinge on: how consumers opt in.

The opt-in description is where campaigns get rejected

Reviewers want to see the exact mechanism: where the form is, what the checkbox says, what the consumer sees before they agree. “Customers opt in on our website” is not enough. A URL to the live form and the verbatim disclosure text is.

Your sample messages must also match the use case, include your brand name, and (for marketing campaigns) show the opt-out instruction. A sample that says “Hi {name}, your appointment is confirmed” filed under a marketing use case gets rejected for inconsistency, not for content.

Trust score and throughput

Registration produces a trust score that determines how many messages per second you can send and your daily ceiling to each carrier. Sending above it does not produce an error; it produces queuing and then silent drops.

  • Verified business details raise it. A properly verified brand with matching public records scores materially better than a sole proprietorship with sparse data.
  • Clean opt-in practice raises it over time. Low complaint rates and healthy opt-out handling feed back into the score.
  • Complaints and spam reports lower it, and the effect persists.
  • Message content matters. Public URL shorteners are heavily penalised because they are what phishing uses. Use a branded domain or none.

What gets filtered even when you are registered

Registration is necessary, not sufficient. Content filters run on every message regardless of score, and they are blunt.

  1. Public URL shorteners. bit.ly and its peers are treated as high risk. This is the single most common cause of filtering among registered senders.
  2. Restricted categories. Cannabis, firearms, high-interest lending, gambling, and adult content are blocked or heavily restricted on 10DLC, whatever your score.
  3. Phishing-shaped language. “Verify your account”, “click here immediately”, urgency plus a link. Filters cannot distinguish your legitimate version from the fraudulent one.
  4. Volume spikes. A sender averaging two hundred messages a day that suddenly sends twenty thousand looks compromised.
  5. Missing opt-out on marketing. Both a compliance failure and a filtering trigger.

Getting registered without three rounds of rejection

  1. 1

    Gather the legal details first

    Registered entity name exactly as filed, tax ID, registered address, and a website that is live and describes the business. Mismatches here cause most brand failures.
  2. 2

    Fix your opt-in before you register

    A live form with a clear, unticked consent checkbox, disclosure that message and data rates apply, and a link to your terms and privacy policy. Reviewers will look at the page.
  3. 3

    Write samples that match the use case

    Real messages, brand name included, opt-out language on marketing samples. One use case per campaign: mixing reminders and promotions in one campaign is a rejection.
  4. 4

    Register the brand, then the campaign

    Brand verification typically clears quickly; campaign vetting takes longer and is where the review happens.
  5. 5

    Warm up rather than launching at full volume

    Ramp over the first fortnight. A brand-new registration sending its daily ceiling on day one looks exactly like an abused one.

10DLC is a carrier delivery framework. It is not a legal permission slip. The TCPA still governs whether you may send at all, and marketing texts to mobiles need prior express written consent regardless of how well registered you are.

The two systems interact usefully, though: the opt-in flow that satisfies a 10DLC reviewer is largely the same one that produces a defensible TCPA consent record. Build it once, properly, and both problems are handled.

STOP handling is non-negotiable on both counts. Honour STOP, END, QUIT, UNSUBSCRIBE and their variants immediately and permanently, across every campaign rather than only the one they replied to.

Outside the US

10DLC is a US framework. Other markets impose their own: sender ID registration in India, Singapore, and much of the Gulf; content pre-approval in several Asian markets; and in the EU, GDPR consent obligations that are stricter than the TCPA's in some respects and looser in others.

The generalisable rule is the same everywhere: register your identity with whoever the local gatekeeper is, keep opt-in provable, and do not use public link shorteners.

Reading delivery reports honestly

Delivery reporting on 10DLC is genuinely confusing, and the confusion hides most filtering problems. The statuses do not mean what their names suggest.

What each status actually tells you
StatusWhat it meansWhat it does not mean
Sent / AcceptedYour provider accepted the messageNothing about whether a carrier took it
DeliveredThe carrier acknowledged receiptNot always that a handset displayed it
Undelivered / FailedA carrier rejected it, sometimes with a codeRarely explains why in plain language
No final statusThe carrier never reported backFrequently the signature of silent filtering

The pattern to watch for is a high proportion of messages that reach “sent” and then never resolve. That is not a reporting delay; it is usually filtering. Compare delivery rates by carrier; filtering is rarely uniform, and one carrier lagging far behind the others points straight at a registration or content problem rather than a platform fault.

Writing messages that get through

Content filtering runs on every message regardless of registration, and a handful of habits account for most avoidable failures.

  1. Identify yourself in the first message of any conversation. Filters and recipients both treat an unattributed message as suspicious.
  2. Use a branded link domain, or no link at all. Public shorteners are the single most common cause of filtering among properly registered senders.
  3. Avoid urgency stacked with a link. “Act now, click here to verify” is indistinguishable from phishing to a classifier, however legitimate your intent.
  4. Include opt-out language on marketing messages. Required for compliance and treated as a positive signal by filters.
  5. Keep formatting plain. Heavy punctuation, all-caps, and unusual character substitutions are classic evasion signals.
  6. Send at a human pace. A steady daily volume looks like a business; a nightly burst at the daily ceiling looks like a compromised account.

Frequently asked questions

What is A2P 10DLC?
The US framework for sending application-to-person messages over ordinary 10-digit long codes. Businesses register a brand and each messaging campaign with the carriers, which assigns a trust score governing message throughput and how aggressively messages are filtered.
Why are my business texts not being delivered?
In the US, almost always unregistered or under-registered 10DLC traffic. Filtering is silent; messages report as sent and never arrive. Among registered senders, the most common remaining cause is public URL shorteners like bit.ly, which are treated as high risk because phishing uses them.
How long does 10DLC registration take?
Brand verification usually clears quickly. Campaign vetting takes longer because a reviewer checks your opt-in flow and sample messages, and a rejection restarts that clock, which is why fixing the opt-in page before submitting is worth the delay.
Do I need 10DLC for two-factor authentication codes?
Yes. Any application-originated message over a long code needs registration, including one-time passcodes. There is a specific use case for it, and it typically receives favourable throughput because the traffic is expected and rarely complained about.
Does 10DLC registration mean I comply with the TCPA?
No. They are separate. 10DLC is a carrier delivery framework; the TCPA is law governing whether you may send at all. Marketing texts to mobiles need prior express written consent whether or not you are registered.
Can I use a toll-free number for business texting instead?
Yes, and toll-free messaging has its own verification process rather than 10DLC. It suits national brands and support lines; local numbers generally perform better for regional businesses. Either way, unverified traffic is filtered.

Sources

  1. Combating Spoofed Robocalls with Caller ID AuthenticationFederal Communications CommissionThe STIR/SHAKEN framework, the attestation levels carriers sign calls with, and the mandate requiring providers to authenticate caller ID.
  2. 47 U.S.C. § 227 — Restrictions on the use of telephone equipmentCornell Legal Information InstituteThe Telephone Consumer Protection Act itself — the consent requirements, calling-hours limits, and private right of action.
  3. Telemarketing Sales RuleFederal Trade CommissionDo-not-call obligations, abandonment-rate limits for predictive dialing, and required call disclosures.

See it working: business sms

Business SMS lets your team send and receive texts from the same numbers you call from, in one shared inbox. In the US, application-to-person texting requires 10DLC brand and campaign registration. Without it, carriers filter your messages before anyone sees them.

  • No subscription
  • Numbers in 100+ countries
  • Compliance built in