Panoramic enterprise cybersecurity and telecommunications visual illustrating COMEXCEL 10DLC SMS verification, carrier brand registration, and automated opt-out compliance shields.

COMEXCEL 10DLC & Business Messaging Policy

Carrier-grade SMS/MMS compliance standards, TCPA consent frameworks, and automated opt-out governance for business communications.

A2P 10DLC REGISTERED • TCPA COMPLIANT • VERIFIED OPT-IN • CTIA ALIGNED

Effective Date: August 25, 2026 | Last Updated: August 25, 2026

COMEXCEL requires all customers using business SMS and MMS services to obtain appropriate recipient consent, maintain verifiable opt-in records, honor automated opt-out requests, accurately register messaging campaigns, and comply with Tier-1 carrier requirements, CTIA Messaging Principles, and federal statutory regulations.

This policy applies across our Business VoIP Phone Service & Cloud PBX Solutions, 2-way business SMS/MMS channels, developer APIs, and CRM automations. It governs messaging operations for small businesses, medium businesses, enterprises, remote offices, contact centers, marketing teams, healthcare organizations, CRM administrators, developers, resellers, and anyone using COMEXCEL SMS/MMS infrastructure. This policy forms an integral part of the COMEXCEL Legal & Compliance Hub and establishes binding standards for all messaging accounts.

10DLC Messaging at a Glance

  • Core Permitted Traffic: Direct, opt-in business-to-consumer (B2C) and business-to-business (B2B) messaging for customer support, transactional alerts, and consent-verified marketing.
  • Mandatory Registration: All 10-digit long code (10DLC) traffic must be registered with The Campaign Registry (TCR) before sending outbound texts.
  • Strict Consent Mandates: Prior express consent for transactional alerts; prior express written consent (PEWC) for commercial marketing. Purchased or scraped contact lists are 100% prohibited.
  • Automated Keyword Engine: Immediate system-level suppression upon receiving STOP, END, CANCEL, QUIT, or UNSUBSCRIBE, with automated response routing for HELP and START.
  • Carrier Surcharges & Penalties: Upstream carrier pass-through fees and non-compliance fines ($500–$10,000 per violation) resulting from unregistered traffic, phishing, or SHAFT violations are billed directly to the customer.

Purpose, Scope & Governing Ecosystem

This policy governs all SMS, MMS, and A2P messaging sent over COMEXCEL telephone numbers, SIP gateways, mobile applications, desktop softphones, CRM integrations, and developer REST APIs. Compliance with this policy is mandatory and constitutes a legally binding addendum to the COMEXCEL Terms of Service. It establishes operational compliance under:

  • The Telephone Consumer Protection Act (TCPA) and FCC regulatory rulings.
  • CTIA Short Code and Commercial Messaging Best Practices.
  • Major Tier-1 Mobile Network Operator (MNO) policies (AT&T, Verizon, T-Mobile).
  • The Campaign Registry (TCR) brand and campaign standards.

Understanding A2P 10DLC Architecture

Application-to-Person 10-Digit Long Code (A2P 10DLC) refers to business messaging sent across standard local phone numbers to mobile subscribers. To protect consumers from spam and ensure high delivery rates, wireless carriers require all business traffic to route through verified identity registries:

Plaintext

[Business Entity] ➔ [COMEXCEL Platform] ➔ [The Campaign Registry (TCR)] ➔ [Carrier Gateway] ➔ [Recipient Device]

Unregistered traffic is subject to severe carrier throttling, aggressive content filtering, message blocking, and punitive per-message non-registration surcharges.

Technical architecture flowchart demonstrating how business SMS messages route from COMEXCEL cloud PBX through The Campaign Registry and carrier filters to mobile handsets.

10DLC Brand & Campaign Registration Requirements

Customers must register their legal corporate brand and individual messaging campaigns prior to sending production traffic:

  • Brand Verification: Submission of legal corporate name, Employer Identification Number (EIN) or Tax ID, Dun & Bradstreet data, corporate address, entity type, and executive contact details.
  • Campaign Description & Use Case: Explicitly detailing the purpose of the campaign (e.g., Customer Care, Account Alerts, 2FA/Security, Marketing).
  • Call-to-Action (CTA) / Opt-In Workflow: Documenting the exact mechanism used to obtain consumer consent, including live website URLs, registration screenshots, and disclosure wording.
  • Sample Messages: Providing representative message templates showing exact sender branding, message copy, and required opt-out disclosures (Reply STOP to cancel).
  • Privacy Policy & Terms Compliance: Maintaining a public, accessible website Privacy Policy containing an explicit non-sharing clause for mobile data.

Compliant Web Forms, Point-of-Sale & Opt-In Capture

When capturing mobile consent through digital web forms, checkout portals, or paper intake forms:

  • Unchecked Checkboxes: The SMS consent checkbox must be separate from general terms of service and unchecked by default. Pre-checked boxes are strictly invalid under CTIA rules.
  • Required Legal Disclosures: The opt-in form must visibly display the business brand name, expected message frequency, carrier rate disclaimers, and direct links to your Privacy Policy and Terms.

Plaintext

Compliant Web Form Disclosure:

“By checking this box and providing your phone number, you agree to receive recurring

automated promotional and informational text messages from [Business Name] at the number

provided. Consent is not a condition of purchase. Msg frequency varies. Msg & data rates

may apply. Reply STOP to cancel or HELP for help. View Privacy Policy and Terms.”

Verifiable Opt-In Recordkeeping & Non-Transferability

Customers must maintain complete, audit-ready records of consumer consent for a minimum of 4 years. Records must document:

  • Recipient phone number and exact timestamp.
  • Opt-in source URL, physical intake form, or point-of-sale receipt.
  • Exact version of the disclosure text presented to the consumer.
  • Non-Transferability: Opt-in consent applies solely to the specific brand and use case for which it was collected; consent cannot be shared, assigned, rented, or transferred to subsidiary brands or third parties.

Zero Tolerance for Purchased, Rented & Scraped Lists

COMEXCEL strictly prohibits transmitting messages to contact lists that have been purchased, rented, co-registered, web-scraped, or acquired from third-party lead brokers. Having a consumer’s phone number does not establish consent; messages sent without direct, first-party authorization violate carrier policies and result in immediate route termination.

Sender Transparency & Initial Welcome Messages

Every message sent across the COMEXCEL network must clearly identify the originating business within the body copy.

Initial Message Standard: The first message sent in any automated or marketing campaign must include:

  • Business/Brand Name.
  • Purpose of the messaging program.
  • Message frequency disclaimer (“Msg frequency varies”).
  • Carrier rate disclaimer (“Msg & data rates may apply”).
  • Clear instructions for assistance (“Reply HELP for help”) and opt-out (“Reply STOP to cancel”).

Automated Opt-Out (STOP), HELP & Universal Keyword Handling

The COMEXCEL network enforces automated keyword processing at the carrier gateway layer:

  • Universal Opt-Out Keywords: Inbound messages containing STOP, END, CANCEL, QUIT, UNSUBSCRIBE, or ARRET trigger immediate automated suppression across the campaign.
  • FCC Revocation Standard: In compliance with FCC rulings, opt-outs submitted by any other reasonable method (email, phone call, customer portal) must be manually suppressed in your CRM within 24 hours.
  • HELP Keyword Workflow: Inbound messages containing HELP or INFO return an automated support message detailing brand name, customer support contact details, and opt-out instructions.
Technical flowchart illustrating automated keyword parsing for STOP, HELP, and START commands with immediate carrier suppression and confirmation receipts.

Opt-Out Confirmation & Affirmative Re-Opt-In (START)

  • Single Confirmation Text: Upon receiving a valid opt-out keyword, the platform returns a single neutral receipt: “[Business Name]: You have been unsubscribed and will receive no further messages. Reply START to resubscribe.” No promotional copy or survey links may appear in this text.
  • Handset-Initiated Re-Opt-In: A previously unsubscribed contact can only re-join a campaign by sending START, YES, or UNSTOP directly from their mobile handset. Businesses cannot manually clear suppression flags on behalf of a contact.

CRM Integrations, Webhooks & Automated Workflow Safeguards

When linking COMEXCEL with CRM platforms (Salesforce, HubSpot, Zoho), webhooks, or custom REST APIs:

  • Pre-Send Consent Check: Automated workflows must check customer consent records and active suppression lists prior to dispatching SMS payloads.
  • Rate-Limit Safeguards: Automated triggers must respect per-second throughput quotas to avoid carrier flood filters.
  • Human Hand-Off: Automated conversational AI agents must provide a clear path for recipients to request live human agent assistance.

Production Message Templates & Content Formatting

All message templates must adhere to standard character constraints and clear business formatting:

  • Transactional / Appointment Reminder Template:

[Business Name]: Hi [First Name], your appointment is confirmed for [Date] at [Time]. Reply C to confirm or call [Phone Number] to reschedule. Reply STOP to cancel.

  • Customer Support Follow-Up Template:

[Business Name]: Hi [First Name], this is [Agent Name] following up on support ticket #[Ticket Number]. Let us know if you need further help! Reply STOP to opt out.

  • Promotional / Marketing Offer Template:

[Business Name]: Enjoy [Discount Offer] on your next order with code [CODE] at [Branded URL]. Msg frequency varies. Msg & data rates may apply. Reply STOP to cancel.

Prohibited Content, CTIA SHAFT & High-Risk Niches

All message transmissions are subject to the prohibited traffic and anti-abuse standards outlined in the COMEXCEL Acceptable Use Policy. Carrier network firewalls strictly block the following categories:

  • CTIA SHAFT Topics: Sexually explicit material, Hate speech, Alcohol (unless registered under strict carrier-approved age-gating programs), Firearms, and Tobacco/Vapor/Cannabis/CBD/Delta-8 products.
  • High-Risk Financial Services: Payday loans, cash advances, debt consolidation, debt relief, credit repair, cryptocurrency schemes, and deceptive lead generation.
  • Deceptive Practices: Phishing, smishing, social engineering, impersonation, sweepstakes, and unverified multi-level marketing (MLM) programs.

Throughput Limits, Volume Tiers & Anti-Snowshoeing Rules

  • Throughput Allocations: Campaign throughput (Messages Per Second / Daily Volume) is determined dynamically by The Campaign Registry (TCR) vetting scores and carrier trust tiers.
  • Anti-Snowshoeing Ban: Distributing identical messaging volume across dozens of unregistered or rotational phone numbers to evade carrier throughput caps or spam filters is strictly prohibited. Senders must use designated high-throughput 10DLC or Toll-Free campaign routes.

Carrier Filtering, Message Delivery & Downstream Liability

Customers acknowledge that mobile carriers (AT&T, Verizon, T-Mobile) operate dynamic, proprietary spam-filtering firewalls. COMEXCEL is not liable for messages throttled, filtered, or blocked by downstream carriers due to non-compliant templates, high opt-out ratios, or unverified campaign traffic.

Carrier Fines, Pass-Through Surcharges & Enforcement

  • Pass-Through Surcharges: Standard carrier-assessed network access surcharges for outbound and inbound SMS/MMS are billed directly to customer accounts.
  • Non-Compliance Fines: Severe compliance breaches—including unregistered SHAFT content, spam outbreaks, phishing, or evasive snowshoeing—carry direct pass-through fines assessed by Tier-1 carriers ($500 to $10,000 per violation) which will be charged directly to the responsible customer.
  • Compliance Audits: Upon carrier inquiry, customers must provide verifiable proof of opt-in within 24 hours. Failure to provide records will result in immediate suspension of messaging capabilities.

Frequently Asked Questions (FAQ) & Compliance Support

What is 10DLC, and why is registration required?

10-Digit Long Code (10DLC) is the North American carrier standard for business-to-consumer text messaging over standard local numbers. Registration authenticates your business identity with The Campaign Registry (TCR) to prevent spam, protect consumers, and ensure optimal delivery rates.

How long does 10DLC Brand and Campaign approval take?

Brand verification typically completes within a few minutes to 24 hours. Campaign vetting by downstream carrier review boards generally takes between 3 to 10 business days depending on the selected use case.

Can I purchase a contact list and send introductory text messages?

No. Carrier regulations and TCPA statutes strictly forbid cold texting. Consent must be gathered directly by your business from the recipient. Purchased, rented, or third-party lists violate this policy and will result in service termination.

What happens if a recipient texts “STOP”?

COMEXCEL’s system immediately registers the opt-out keyword, sends a standard confirmation message, and blocks further outbound messages to that number for that campaign. Outbound attempts to an unsubscribed number will return a delivery failure.

Why are public URL shorteners prohibited in business SMS?

Public shorteners like Bitly or TinyURL are frequently exploited by bad actors to conceal malicious destinations. Carrier network filters automatically flag and block SMS content containing shared public shortener domains. You must use dedicated, branded custom domain shorteners.

Can healthcare providers send patient notifications via COMEXCEL SMS?

Yes, provided the messages comply with HIPAA regulations and TCPA standards. Healthcare alerts must contain minimal Protected Health Information (PHI), focus on appointment or prescription updates, include easy opt-out mechanisms, and originate from an approved healthcare campaign.

What are the consequences of non-compliance with this Messaging Policy?

Non-compliant traffic is subject to carrier filtering, per-message pass-through carrier fines ($500 to $10,000), suspension of messaging capabilities, or permanent termination of the associated COMEXCEL account.

How do I collect valid opt-in consent through my website?

Ensure your web form includes explicit disclosure text stating that the user agrees to receive SMS from your company, clearly notes that consent is not a condition of purchase, provides links to your Privacy Policy and Terms, and includes an unchecked checkbox if capturing marketing consent.

Need Help Registering Your 10DLC Brand & Campaigns?

Our messaging compliance team can guide your organization through TCR brand registration, campaign use-case approval, and automated opt-out verification.