Effective Date: September 10, 2026 | Last Updated: September 10, 2026
COMEXCEL 10DLC & Business Messaging Policy defines mandatory operational rules, carrier compliance requirements, and consent verification standards governing business text messaging across our Business VoIP Phone Service & Cloud PBX Solutions, 2-way SMS/MMS software endpoints, developer APIs, and CRM automations. COMEXCEL requires all subscribers using business SMS and MMS channels to obtain verifiable recipient consent, maintain immutable opt-in records, honor automated opt-out requests, accurately register brand campaigns with The Campaign Registry (TCR), and strictly adhere to CTIA Messaging Principles, Tier-1 mobile carrier guidelines, and federal statutory regulations. This policy forms an integral public safety and regulatory addendum administered under our master Legal & Compliance Hub.
10DLC Messaging at a Glance
- Core Permitted Traffic: Direct, opt-in business-to-consumer (B2C) and business-to-business (B2B) messaging for customer support, transactional alerts, and consent-verified marketing aligned with our centralized COMEXCEL Legal & Compliance Hub standards.
- Mandatory Registration: All 10-digit long code (10DLC) traffic must be registered with The Campaign Registry (TCR) before sending outbound texts.
- Strict Consent Mandates: Prior express consent for transactional alerts; prior express written consent (PEWC) for commercial marketing. Purchased or scraped contact lists are 100% prohibited.
- Automated Keyword Engine: Immediate system-level suppression upon receiving STOP, END, CANCEL, QUIT, or UNSUBSCRIBE, with automated response routing for HELP and START.
- Carrier Surcharges & Penalties: Upstream carrier pass-through fees and non-compliance fines ($500–$10,000 per violation) resulting from unregistered traffic, phishing, or SHAFT violations are billed directly to the customer.
Purpose, Scope & Governing Ecosystem
This policy governs all SMS, MMS, and A2P messaging sent over COMEXCEL telephone numbers, SIP gateways, mobile applications, desktop softphones, CRM integrations, and developer REST APIs. Compliance with this policy is mandatory and constitutes a legally binding addendum to the COMEXCEL Terms of Service. It enforces statutory compliance under:
- The Telephone Consumer Protection Act (TCPA) and FCC regulatory rulings.
- CTIA Short Code and Commercial Messaging Best Practices.
- Major Tier-1 Mobile Network Operator (MNO) policies (AT&T, Verizon, T-Mobile).
- The Campaign Registry (TCR) brand and campaign standards.
Contextual Link: Comexcel Terms of Service
Targeting URL: https://comexcel.com/legal/terms-of-service/
Understanding A2P 10DLC Architecture
Application-to-Person 10-Digit Long Code (A2P 10DLC) refers to business messaging sent across standard local phone numbers to mobile subscribers. To protect consumers from spam and ensure high delivery rates, wireless carriers require all business traffic to route through verified identity registries:
[Business Entity] ➔ [COMEXCEL Platform] ➔ [The Campaign Registry (TCR)] ➔ [Carrier Gateway] ➔ [Recipient Device]
Unregistered traffic is subject to severe carrier throttling, aggressive content filtering, message blocking, and punitive per-message non-registration surcharges.

10DLC Brand & Campaign Registration Requirements
Customers must register their legal corporate brand and individual messaging campaigns prior to sending production traffic:
- Brand Verification: Submission of legal corporate name, Employer Identification Number (EIN) or Tax ID, Dun & Bradstreet data, corporate address, entity type, and executive contact details.
- Campaign Description & Use Case: Explicitly detailing the purpose of the campaign (e.g., Customer Care, Account Alerts, 2FA/Security, Marketing).
- Call-to-Action (CTA) / Opt-In Workflow: Documenting the exact mechanism used to obtain consumer consent, including live website URLs, registration screenshots, and disclosure wording.
- Sample Messages: Providing representative message templates showing exact sender branding, message copy, and required opt-out disclosures (Reply STOP to cancel).
- Privacy Policy & Terms Compliance: Maintaining an accessible COMEXCEL Privacy Policy-compliant website disclosure containing an explicit non-sharing clause for mobile data.
Consent Framework: Conversational, Informational & Promotional
Customers must obtain the requisite tier of consent before initiating SMS/MMS communications:
| Messaging Category | Operational Use Case | Required Consent Standard |
|---|---|---|
| Conversational | One-on-one two-way support initiated directly by the consumer. | Implied Consent: Limited strictly to answering the customer’s specific inquiry. |
| Informational / Transactional | Appointment reminders, order updates, dispatch notices, 2FA alerts. | Prior Express Consent: Collected via web form, physical agreement, or verbal consent. |
| Promotional / Marketing | Sales offers, discount alerts, product announcements, newsletters. | Prior Express Written Consent (PEWC): Documented, affirmative legal agreement. |
Compliant Web Forms, Point-of-Sale & Opt-In Capture
When capturing mobile consent through digital web forms, checkout portals, or paper intake forms:
- Unchecked Checkboxes: The SMS consent checkbox must be separate from general terms of service and unchecked by default. Pre-checked boxes are strictly invalid under CTIA rules.
- Required Legal Disclosures: The opt-in form must visibly display the business brand name, expected message frequency, carrier rate disclaimers, and direct links to your Privacy Policy and Terms.
Compliant Web Form Disclosure Text:
“By checking this box and providing your phone number, you agree to receive recurring automated promotional and informational text messages from [Business Name] at the number provided. Consent is not a condition of purchase. Msg frequency varies. Msg & data rates may apply. Reply STOP to cancel or HELP for help. View Privacy Policy and Terms.”
Verifiable Opt-In Recordkeeping & Non-Transferability
Customers must maintain complete, audit-ready records of consumer consent for a minimum of 4 years. Records must document:
- Recipient phone number and exact timestamp.
- Opt-in source URL, physical intake form, or point-of-sale receipt.
- Exact version of the disclosure text presented to the consumer.
- Non-Transferability: Opt-in consent applies solely to the specific brand and use case for which it was collected; consent cannot be shared, assigned, rented, or transferred to subsidiary brands or third parties, consistent with our COMEXCEL Privacy Policy non-disclosure standards.
Zero Tolerance for Purchased, Rented & Scraped Lists
COMEXCEL strictly prohibits transmitting messages to contact lists that have been purchased, rented, co-registered, web-scraped, or acquired from third-party lead brokers. Having a consumer’s phone number does not establish consent; messages sent without direct, first-party authorization violate carrier policies and result in immediate route termination.
Sender Transparency & Initial Welcome Messages
Every message sent across the COMEXCEL network must clearly identify the originating business within the body copy. The first message sent in any automated or marketing campaign must include:
- Business/Brand Name.
- Purpose of the messaging program.
- Message frequency disclaimer (“Msg frequency varies”).
- Carrier rate disclaimer (“Msg & data rates may apply”).
- Clear instructions for assistance (“Reply HELP for help”) and opt-out (“Reply STOP to cancel”).
Automated Opt-Out (STOP), HELP & Universal Keyword Handling
The COMEXCEL network enforces automated keyword processing at the carrier gateway layer:
- Universal Opt-Out Keywords: Inbound messages containing STOP, END, CANCEL, QUIT, UNSUBSCRIBE, or ARRET trigger immediate automated suppression across the campaign.
- FCC Revocation Standard: In compliance with FCC rulings, opt-outs submitted by any other reasonable method (email, phone call, customer portal) must be manually suppressed in your CRM within 24 hours.
- HELP Keyword Workflow: Inbound messages containing HELP or INFO return an automated support message detailing brand name, customer support contact details, and opt-out instructions.

Opt-Out Confirmation & Affirmative Re-Opt-In (START)
- Single Confirmation Text: Upon receiving a valid opt-out keyword, the platform returns a single neutral receipt: “[Business Name]: You have been unsubscribed and will receive no further messages. Reply START to resubscribe.” No promotional copy or survey links may appear in this text.
- Handset-Initiated Re-Opt-In: A previously unsubscribed contact can only re-join a campaign by sending START, YES, or UNSTOP directly from their mobile handset. Businesses cannot manually clear suppression flags on behalf of a contact.
CRM Integrations, Webhooks & Automated Workflow Safeguards
When linking COMEXCEL with CRM platforms (Salesforce, HubSpot, Zoho), webhooks, or custom REST APIs:
- Pre-Send Consent Check: Automated workflows must check customer consent records and active suppression lists prior to dispatching SMS payloads.
- Rate-Limit Safeguards: Automated triggers must respect per-second throughput quotas to avoid carrier flood filters.
- Human Hand-Off: Automated conversational AI agents must provide a clear path for recipients to request live human agent assistance. Security requirements governing API endpoints are detailed in our Security & Trust Center.
Production Message Templates & Content Formatting
All message templates must adhere to standard character constraints and clear business formatting:
- Transactional / Appointment Reminder Template:
[Business Name]: Hi [First Name], your appointment is confirmed for [Date] at [Time]. Reply C to confirm or call [Phone Number] to reschedule. Reply STOP to cancel.
- Customer Support Follow-Up Template:
[Business Name]: Hi [First Name], this is [Agent Name] following up on support ticket #[Ticket Number]. Let us know if you need further help! Reply STOP to opt out.
- Promotional / Marketing Offer Template:
[Business Name]: Enjoy [Discount Offer] on your next order with code [CODE] at [Branded URL]. Msg frequency varies. Msg & data rates may apply. Reply STOP to cancel.
Prohibited Content, CTIA SHAFT & High-Risk Niches
All message transmissions are subject to the prohibited traffic and anti-abuse standards outlined in the COMEXCEL Acceptable Use Policy. Carrier firewalls strictly block:
- CTIA SHAFT Topics: Sexually explicit material, Hate speech, Alcohol (unless registered under strict carrier-approved age-gating programs), Firearms, and Tobacco/Vapor/Cannabis/CBD/Delta-8 products.
- High-Risk Financial Services: Payday loans, cash advances, debt consolidation, debt relief, credit repair, cryptocurrency schemes, and deceptive lead generation.
- Deceptive Practices: Phishing, smishing, social engineering, impersonation, sweepstakes, and unverified multi-level marketing (MLM) programs.
URL Shorteners, Branded Domains & Hyperlink Integrity
- Public Link Shorteners Prohibited: Generic, shared link shorteners (e.g., bit.ly, tinyurl, rb.gy) are heavily blocked by Tier-1 carrier filters.
- Dedicated Branded Domains: Senders must use full URLs or dedicated, branded custom domain shorteners (e.g., [link.yourbrand.com/offer](https://link.yourbrand.com/offer)) where the domain matches the verified 10DLC brand registration.
- No Redirect Chains: Links must direct immediately to the destination landing page without multi-hop affiliate redirect chains.
Throughput Limits, Volume Tiers & Anti-Snowshoeing Rules
- Throughput Allocations: Campaign throughput (Messages Per Second / Daily Volume) is determined dynamically by The Campaign Registry (TCR) vetting scores and carrier trust tiers.
- Anti-Snowshoeing Ban: Distributing identical messaging volume across dozens of unregistered or rotational phone numbers to evade carrier throughput caps or spam filters is strictly prohibited. Senders must use designated high-throughput 10DLC or Toll-Free campaign routes backed by automated Failover & Disaster Recovery path management.
Carrier Filtering, Message Delivery & Downstream Liability
Customers acknowledge that mobile carriers (AT&T, Verizon, T-Mobile) operate dynamic, proprietary spam-filtering firewalls. COMEXCEL is not liable for messages throttled, filtered, or blocked by downstream carriers due to non-compliant templates, high opt-out ratios, or unverified campaign traffic.
Carrier Fines, Pass-Through Surcharges & Enforcement
Standard carrier network access surcharges for outbound and inbound SMS/MMS are billed directly to customer accounts. Severe compliance breaches carry direct pass-through fines assessed by Tier-1 carriers:
| Carrier Violation Tier | Specific Non-Compliance Trigger | Upstream Carrier Pass-Through Penalty |
|---|---|---|
| Tier 1: Unregistered Traffic | Sending commercial A2P traffic over unregistered 10DLC numbers. | $10 per message non-registration surcharge |
| Tier 2: Messaging Content Violation | Transmitting prohibited financial schemes, affiliate marketing, or spam. | $1,000 – $5,000 per confirmed carrier audit |
| Tier 3: SHAFT & Cannabis Violations | Promoting firearms, vaping, CBD, delta-8, cannabis, or adult content. | $5,000 – $10,000 per confirmed violation |
| Tier 4: Phishing, Smishing & Spoofing | Social engineering attacks or unauthenticated caller ID spoofing. | Immediate Suspension + $10,000 fine |
Frequently Asked Questions (FAQ) & Compliance Support
What is 10DLC, and why is registration required?
10-Digit Long Code (10DLC) is the North American carrier standard for business-to-consumer text messaging over standard local numbers. Registration authenticates your business identity with The Campaign Registry (TCR) to prevent spam, protect consumers, and ensure optimal delivery rates.
How long does 10DLC Brand and Campaign approval take?
Brand verification typically completes within a few minutes to 24 hours. Campaign vetting by downstream carrier review boards generally takes between 3 to 10 business days depending on the selected use case.
Can I purchase a contact list and send introductory text messages?
No. Carrier regulations and TCPA statutes strictly forbid cold texting. Consent must be gathered directly by your business from the recipient. Purchased, rented, or third-party lists violate this policy and will result in service termination.
What happens if a recipient texts “STOP”?
COMEXCEL’s system immediately registers the opt-out keyword, sends a standard confirmation message, and blocks further outbound messages to that number for that campaign. Outbound attempts to an unsubscribed number will return a delivery failure.
Why are public URL shorteners prohibited in business SMS?
Public shorteners like Bitly or TinyURL are frequently exploited by bad actors to conceal malicious destinations. Carrier network filters automatically flag and block SMS content containing shared public shortener domains. You must use dedicated, branded custom domain shorteners.
Can healthcare providers send patient notifications via COMEXCEL SMS?
Yes, provided the messages comply with HIPAA regulations and TCPA standards. Healthcare alerts must contain minimal Protected Health Information (PHI), focus on appointment or prescription updates, include easy opt-out mechanisms, and originate from an approved healthcare campaign. Review our HIPAA Compliance Statement for full requirements[cite: 6].
What are the consequences of non-compliance with this Messaging Policy?
Non-compliant traffic is subject to carrier filtering, per-message pass-through carrier fines ($500 to $10,000), suspension of messaging capabilities, or permanent termination of the associated COMEXCEL account.
How do I collect valid opt-in consent through my website?
Ensure your web form includes explicit disclosure text stating that the user agrees to receive SMS from your company, clearly notes that consent is not a condition of purchase, provides links to your Privacy Policy and Terms, and includes an unchecked checkbox if capturing marketing consent.
Need Help Registering Your 10DLC Brand & Campaigns?
Our messaging compliance team can guide your organization through TCR brand registration, campaign use-case approval, and automated opt-out verification.
