CTIA Messaging Principles and Best Practices: The Plain-English Guide (2026)

CTIA Messaging Principles and Best Practices: The Plain-English Guide (2026)

Quick answer: what the CTIA Messaging Principles and Best Practices require

The CTIA Messaging Principles and Best Practices (current edition May 2023, with a companion Messaging Security Best Practices document updated in October 2025) are the US wireless industry's voluntary rulebook for business-to-consumer texting. They are not a law, but the carriers write them into 10DLC, toll-free and short code approval, so in practice they decide whether your messages are delivered. The core requirements are: get consent that matches the message type (implied for conversational replies, express for informational, express written for promotional); identify your business, the programme, the message frequency and any charges in the first message; honour STOP and any plain-language opt-out with one confirmation; answer HELP with your name and a contact; publish an accessible privacy policy; keep out SHAFT and other prohibited content; use links on your own domain; and never spread one programme across many numbers to dodge filtering. Everything below is a plain-English walk through those rules and what they look like in a real campaign.

What the document is, and why it matters more than "voluntary" suggests

CTIA is the trade association of the US wireless carriers. Its Messaging Principles were first published in 2019, rewritten in May 2023 to replace the old P2P and A2P vocabulary with Consumer (an individual person who subscribes to a wireless messaging service) and Non-Consumer (a business, organisation or entity that uses messaging to communicate with Consumers, including agents acting on its behalf), and supplemented in October 2025 by a security document aimed at CPaaS providers and aggregators. The principles say on their face that they are best practices, not legal requirements, and that senders must still comply with the TCPA, CAN-SPAM and FCC rules. The reason they carry weight is enforcement by contract: The Campaign Registry vets 10DLC campaigns against them, toll-free verification asks the same questions, the short code programme audits against the CTIA Short Code Monitoring Handbook, and carrier spam filters are tuned to the behaviours the document prohibits. A programme that breaks the principles does not get a fine; it gets filtered.

If you want the legal layer alongside this one, the US telecom regulations hub covers the TCPA, state mini-TCPAs and the 2025 and 2026 rule changes, and the compliance page summarises how Signalmash applies both.

The three consent tiers

The principles sort Non-Consumer messages into three types and attach a consent standard to each. Registering a campaign under the wrong tier, or sending a higher-tier message on a lower-tier consent, is the single most common reason for filtering after approval.

  • Conversational. The Consumer texts first and the business only replies with relevant information. Consent is implied by the Consumer's message; no verbal or written permission is expected, as long as the reply stays on the topic the Consumer raised.
  • Informational. Appointment reminders, order updates, account alerts, welcome texts. The Consumer should give express permission before receiving them: a ticked box, a keyword, a verbal yes recorded at the point of sale. The permission must be for text messages specifically, not buried in general terms.
  • Promotional. Sales, offers, marketing. The Consumer should give express written permission before the first message, and the disclosure they agreed to must describe the programme they are joining. This mirrors the TCPA's prior-express-written-consent standard for automated marketing texts.

Two practical corollaries: consent for one brand does not transfer to another, and a mixed programme (say, order updates that occasionally carry a coupon) must be registered and consented at the promotional level.

The first-message and ongoing disclosure checklist

For any recurring programme the principles expect the Consumer to see, in the initial or confirmation message, who is sending, what the programme is, how often messages will arrive, whether message and data rates or other charges apply, how to get help and how to stop. In practice that produces a confirmation message shaped like this: brand name, programme name, "Msg frequency varies" or "up to 4 msgs/month", "Msg & data rates may apply", "Reply HELP for help, STOP to cancel". Beyond the first message, the principles ask for:

  • Sender identification in every message, so a recipient can tell who is texting without a lookup.
  • A privacy policy that is conspicuously displayed and easily accessed, for example through clearly labelled links at the point of opt-in. Reviewers look for a statement that mobile numbers and consent are not shared with third parties for their marketing.
  • Links on your own domain. If a shortener is used it should be one with a web address and IP addresses dedicated to the exclusive use of the Message Sender. Public shorteners are treated as a phishing signal.
  • Terms and conditions for the programme, published where the Consumer opted in.

Opt-out and HELP: the two keywords carriers test

The principles standardise on STOP for opt-out instructions but are explicit that requests written in normal language, such as stop, end, unsubscribe, cancel, quit or "please opt me out", should also be read and acted on. Senders should acknowledge and honour every opt-out by sending one final confirmation message per campaign, and nothing after it. Since April 2025 the FCC's revocation rules make the same point as a matter of law, with a ten-business-day deadline to honour the request.

HELP must return customer-care contact information: a toll-free or ten-digit number, an email address or web page, together with the programme name, so a Consumer who does not recognise a message can find out who sent it. Carriers and registries test both keywords during vetting and periodically afterwards; a HELP response that names a CPaaS platform rather than your brand is a recurring rejection reason.

Prohibited content

Message Senders are expected to prevent content that is unlawful, harmful, abusive, malicious, misleading, harassing, excessively violent, obscene or illicit, or defamatory, together with deceptive or phishing content, threats, invasions of privacy, malware and incitement to discrimination. The carriers' shorthand for the categories most often caught is SHAFT: sex, hate, alcohol, firearms and tobacco (the October 2025 security document spells the acronym out that way), with cannabis, gambling, high-risk lending and debt collection treated as restricted or carrier-specific. Restricted does not always mean banned: age-gated alcohol programmes and licensed gambling in permitted states can be registered with the right evidence, but they cannot ride on a general marketing campaign.

Snowshoeing, shared numbers and number rotation

Snowshoe messaging, defined as spreading messages across many sending phone numbers or short codes to evade volume-based controls, is prohibited outright, and rotating numbers to escape a filtered one is treated as the same offence. Shared numbers are allowed only under documented arrangements in which every sender behind the number is identified. The practical rule for a growing programme is to increase throughput by registering the campaign properly, requesting higher trust vetting or moving to toll-free or a short code, rather than by adding long codes.

Toll-free and short code specifics

Only toll-free numbers that are reserved or in working status for a voice subscriber may be enabled for messaging, and where a toll-free number is shared the toll-free voice provider is treated as the subscriber responsible for it. Toll-free messaging also has its own verification programme, which asks for the same opt-in evidence and sample messages as 10DLC. Short codes are governed by the Common Short Code registry, campaign pre-approval and ongoing audits under the CTIA Short Code Monitoring Handbook; the monitoring programme sends test messages and issues violation notices, and repeated findings can suspend the code.

What the October 2025 security best practices add

The security companion document is written mainly for CPaaS providers, aggregators and carriers, but three obligations reach the sender. Providers must run know-your-customer checks that obtain sufficient identifying information to verify a Message Sender's identity, which is why onboarding now asks for an EIN, a website and a named contact. Providers must monitor traffic, detect volumetric anomalies and shut down a Message Sender's compromised account as soon as reasonably possible, so leaked API credentials will take your programme offline. And senders are asked to protect their own credentials, avoid SIM boxes, SIM farms and disposable numbers, and use email authentication (DKIM, SPF) where email is part of the flow. The document also defines wireless messaging abuse as the use of SIM cards or temporary numbers to send large volumes of unwanted or illegal texts.

How the principles fit with the TCPA and 10DLC

Three layers, three enforcers. The TCPA and state laws are enforced in court and by the FCC and state attorneys general, with statutory damages per message. The CTIA principles are enforced by carriers and registries through vetting, filtering and suspension. 10DLC, toll-free verification and short code approval are the mechanisms that turn the principles into checkboxes. A compliant programme satisfies all three at once, and the cheapest way to get there is to build the consent record, the disclosures and the keyword handling once and reuse them across every number type. The 10DLC readiness checker scores a programme against the same criteria a reviewer applies; the A2P 10DLC requirements guide lists the documents to gather.

A ten-point self-audit

  1. Every number on the list has a consent record with source, wording, timestamp and channel.
  2. The consent wording matches the message type actually sent (conversational, informational, promotional).
  3. The first or confirmation message names the brand, the programme, frequency, charges, HELP and STOP.
  4. Every message identifies the sender.
  5. STOP, QUIT, END, CANCEL, UNSUBSCRIBE and plain-language equivalents all trigger an opt-out, with one confirmation and then silence.
  6. HELP returns the brand name and a real contact.
  7. The privacy policy is linked at opt-in and says numbers are not shared for third-party marketing.
  8. Links use your own domain or a dedicated shortener.
  9. No SHAFT or restricted content rides on a general campaign; restricted programmes are registered as such with age gating.
  10. Throughput comes from registration and vetting tiers, not from adding numbers.

Signalmash runs this audit with every customer during onboarding, writes the campaign brief and sample messages, and handles resubmissions. Book a 15-minute call and we will tell you which of the ten points your programme would fail today.

People also ask

What are the CTIA Messaging Principles and Best Practices?

A voluntary set of rules published by CTIA, the US wireless carriers' trade association, that describe how businesses should text consumers: consent by message type, sender identification, opt-out and HELP handling, privacy policy, prohibited content and anti-spam behaviour such as the ban on snowshoeing. The current edition is dated May 2023, with a separate Messaging Security Best Practices document updated in October 2025.

Are the CTIA messaging guidelines legally binding?

No. They are industry best practices and say so explicitly, and senders remain bound separately by the TCPA, CAN-SPAM and FCC rules. In practice they are binding through contract: carriers, The Campaign Registry, the toll-free verification programme and the short code registry all enforce them by vetting, filtering and suspending traffic that breaks them.

What consent do I need to send marketing texts under the CTIA principles?

Express written consent before the first promotional message, given in response to a disclosure that names the brand and describes the programme, and that is not a condition of purchase. Informational messages need express consent, and conversational replies to a consumer-initiated text need no separate permission as long as they stay on topic.

What is SHAFT in SMS compliance?

Sex, hate, alcohol, firearms and tobacco, the content categories carriers treat as prohibited or restricted on standard messaging programmes. Some restricted categories, such as age-gated alcohol promotions, can be registered with the right controls, but they cannot be sent on a general-purpose campaign.

What is snowshoeing in text messaging?

Spreading one messaging programme across many phone numbers or short codes to stay under per-number volume thresholds and evade spam filtering. The CTIA principles prohibit it, treat number rotation the same way, and expect senders to increase throughput by registering campaigns, improving vetting scores or moving to toll-free or short code numbers instead.