Limited offer · on the snapshot· Closing in00d00h00m00sClaim now →
Blog

The SMS Opt-In Script Every Agency Needs in 2026 (TCPA, CAN-SPAM and FTC Consent Copy You Can Steal)

Texting on behalf of clients? Here's the exact TCPA-compliant SMS opt-in language, consent copy and STOP/HELP replies agencies can steal, plus the 2026 rules that actually apply.

September 20, 2026 · 17 min read · by

  • #Tier 4
  • #Compliance
  • #sms
  • #tcpa
  • #opt-in
  • #consent
  • #ghl
  • #all-sizes

The fastest way to compliant client SMS is to steal a consent script that already works: an unchecked opt-in box that says who is texting and why, a confirmation text with STOP and HELP baked in, and auto-replies that handle opt-outs on their own. Get those three pieces right and you satisfy the TCPA, CAN-SPAM, the FTC and the carriers in one move. The wording is below, ready to paste. What most agencies get wrong is not the automation, it’s the sentence next to the phone-number field, and that sentence is what a plaintiff’s lawyer reads first.

If you send texts on behalf of clients, the legal exposure sits on you as the sender as much as on the client. This is the operator’s version of consent: the exact copy, the rules that apply in 2026, where it breaks, and how the answer changes by agency size.

Flow diagram titled The Compliant SMS Consent Path showing four numbered steps: 1. Opt-in box (unchecked), consent is not a condition of purchase; 2. Confirmation text, reply HELP for help, STOP to cancel; 3. STOP/HELP auto-reply, honor opt-outs within 10 business days; 4. Compliant delivery across TCPA, CAN-SPAM, FTC and carriers. Source: TCPA 47 U.S.C. 227, FTC Reviews Rule, CTIA Messaging Principles.

Table of contents

Why the opt-in sentence matters more than the automation

It’s a Tuesday and you’re onboarding a dentist with a list of 4,000 patients in a spreadsheet. They want appointment reminders and a review push. You wire it up in GoHighLevel in an afternoon: reminders, missed-call text-back, a review request two hours after the visit. Clean work. Then you go to import the 4,000 numbers.

Stop there. That spreadsheet is where agencies get sued. Not because the automation is wrong, but because nobody can point to the moment each of those 4,000 people agreed, in writing, to receive texts from that dentist. The workflow is fine. The consent record behind it does not exist.

The compliant part of SMS is not the send, it’s the sign-up. Every rule below comes back to one question: can you prove this specific person agreed, in clear language, to get these specific messages from this specific business? If yes, you are almost entirely covered. If no, the best-built automation in the world is a liability you scaled.

The numbers are per-message, which makes texting different.

$500–1,500
TCPA damages per text
$53,088
Max FTC penalty per violation
10 biz
Days to honor an opt-out
86%
Consumers who opt in when asked

The Telephone Consumer Protection Act sets statutory damages at $500 for every non-compliant text, trebled to as much as $1,500 for a willful violation, with no cap (47 U.S.C. § 227). Text messages count as “calls” under the statute. Do the arithmetic on a single 5,000-number blast and you are looking at $2.5 million in bare statutory exposure. TCPA class actions are a cottage industry because the math is that ugly.

The FTC stacks on top. Its Rule on the Use of Consumer Reviews and Testimonials, in effect since October 21, 2024, bans fake and incentivized reviews with penalties up to $53,088 per violation (FTC). That matters because so much agency SMS is a review request. The same $53,088 figure applies to CAN-SPAM violations on email (FTC).

013,27226,54439,81653,0881,500TCPA (per willful text)53,088CAN-SPAM (per email)53,088FTC Reviews Rule (per violation)

Maximum statutory penalty per violation by regime. Sources: 47 U.S.C. § 227 and the FTC 2025 penalty adjustment.

Now the upside. Per EZ Texting’s 2025 Consumer Texting Behavior Report, a survey of 1,074 US mobile owners, 86% of consumers now opt in to receive texts from businesses (EZ Texting). People will say yes; they just want to know who is texting and how to stop. Ask cleanly and you get a list that is large and legally solid. Skip the ask and you get a lawsuit that converts badly.

The rules that apply in 2026 (and the one that does not)

Four regimes to satisfy, plus the carrier layer. Here is the whole map on one screen.

Regime Covers The consent bar What it costs to miss
TCPA Marketing texts and calls to US numbers Prior express written consent for marketing; honor opt-out in 10 business days $500–$1,500 per text, uncapped
CAN-SPAM Commercial email Clear opt-out, valid physical address, honest headers Up to $53,088 per email
FTC Reviews Rule Review and testimonial requests No fake, incentivized or gated reviews Up to $53,088 per violation
GDPR Any EU resident’s data Freely given, specific, informed, unambiguous opt-in Up to 4% of global turnover
A2P 10DLC / CTIA The carrier delivery layer Documented opt-in per campaign; STOP and HELP supported Traffic blocked, campaign shut down

Three specifics worth pinning down.

Quiet hours. Automated marketing texts may only go out between 8 a.m. and 9 p.m. in the recipient’s local time (47 CFR § 64.1200). Build the client’s time zone into the send window, not your own.

The opt-out rule got teeth in 2025. Since April 11, 2025, a consumer can revoke consent through any reasonable means, not just the exact keyword STOP, and you must honor it within 10 business days (Nixon Peabody). Honor “stop,” “unsubscribe,” “cancel,” “quit” and plain-English requests the same way.

Reviews. The FTC Reviews Rule is simple: you cannot buy reviews, write them, or ask only happy customers (FTC). If your agency sells a review service, this governs your SMS copy directly. More on doing it cleanly in our Google review automation playbook.

The carrier layer sits underneath all of this. Before a single text delivers, each client campaign has to be registered under A2P 10DLC, and registration requires documented opt-in plus working STOP and HELP keywords per the CTIA Messaging Principles and Best Practices. We cover that in the A2P 10DLC registration playbook; this post is the consent language it demands.

Here is the part to bookmark. Every block below satisfies the TCPA, the carriers and the FTC at once. Swap [Business Name], [phone] and [link] for the client’s real details and keep the rest close to verbatim. The phrasing is doing legal work, so resist the urge to “clean it up.”

Save that library as a snippet in your onboarding doc, fill in the client’s details on day one, and you have a defensible consent record before the first automation fires. If you’d rather not rebuild these blocks in every account, they ship pre-wired in our SMS automation feature.

Consent-first SMS, pre-built for every client

The DM Snapshot installs opt-in capture, STOP/HELP handling and the exact consent copy above into your GoHighLevel account, white-labeled and live in 24 hours.

Setting it up right is half the battle. Here is how it quietly goes wrong.

Comparison slide titled SMS Consent: Don't vs Do. The Don't column (how agencies get sued): import a 4,000-row spreadsheet and blast it, pre-checked opt-in box, one send window in the agency's time zone, route only happy clients to the review link. The Do column (compliant, still converts): re-permission and import only confirmed opt-ins, unchecked box with full consent copy, send in the recipient's local time zone, same public honest-feedback link for everyone. Source: TCPA 47 U.S.C. 227, FTC Reviews Rule.

The imported list with no paper trail. A client hands you thousands of contacts and swears “they’re all customers.” Customer status is not consent to text marketing. If you cannot show when and how each person agreed to SMS specifically, do not blast them. Run a re-permission pass: email the list, ask them to opt in to texts, and import only the ones who do. You will lose numbers, and keep the ones who won’t sue you.

The pre-checked box. Someone sets the opt-in checkbox to checked “to boost sign-ups.” That is not consent under the TCPA or GDPR, both of which require a clear affirmative action. Audit every form on day one and after any redesign.

Quiet-hours drift. Your agency is in California, the client is in Boston, your send window is set to your time zone. A 6:30 p.m. Pacific send lands at 9:30 p.m. Eastern, past the cutoff. Set the window to the recipient’s local time, per client.

STOP that goes nowhere. A workflow gets rebuilt, native STOP handling detaches, and opt-outs stop registering. Now you’re texting people who told you to stop, the single most common TCPA claim. Send a test STOP after any change and confirm the contact is marked unsubscribed.

The review request that gates on happiness. An “are you happy? yes goes to the review link, no goes to a private form” flow feels smart and is now an explicit target of the FTC Reviews Rule. Route everyone to the same public page and ask for honest feedback. Consent, too, is specific to the business that collected it, so keep lists walled off per sub-account rather than letting a template bleed across clients.

Before

Import the client's 4,000-row spreadsheet and blast itPre-checked opt-in box to lift conversionsOne send window in the agency's time zoneReview flow that routes only happy clients to GoogleSTOP handling assumed, never tested

After

Re-permission the list, import only confirmed opt-insUnchecked box with full TCPA consent copyPer-client send window in the recipient's local timeEveryone gets the same public, honest-feedback linkTest STOP after every workflow change

Same rules, three agency sizes

The law is identical at any size. What changes is how you run it.

Solo operator or freelancer (everything manual). You are the compliance department. The risk is doing it ad hoc, differently for each client, with no saved record. The fix is one reusable onboarding checklist: the consent copy above saved as snippets, plus a folder where you screenshot each client’s live opt-in form the day it goes up. That screenshot is your evidence. Ten minutes now versus a deposition later.

Small agency, 1 to 10 people (multiple sub-accounts). Now the danger is inconsistency: one person uses the good opt-in copy, another hand-types a version that drops the frequency line. Make the consent library a locked template in your onboarding SOP, and add one QA step before any campaign goes live to confirm the opt-in language, the STOP/HELP replies, and the send window. This is also the band where A2P 10DLC registration becomes a documented step, not an afterthought.

Growing agency, 11 to 20+ (real book of clients). At this size you are effectively a messaging reseller, and you want a reseller ID on your A2P registrations so campaigns filed for clients are attributed correctly. Assign an owner for messaging compliance, keep a per-client consent log recording the source and date of every opt-in, and audit live campaigns quarterly. One TCPA class action dwarfs the cost of the person who runs this, and the attribution discipline feeds cleaner reporting too, covered in lead attribution that proves ROI.

Objections agency owners actually raise

“Won’t a double opt-in tank my conversion rate?” Marginally, and it’s worth it. A smaller clean list outperforms a big dirty one on deliverability because carriers reward low spam complaints. You are trading a little top-of-funnel for a list that actually delivers.

“The client already has a customer list, can’t we just use it?” Being a customer is not the same as consenting to marketing texts, and courts have been clear on that. Re-permission the list. It feels like throwing away contacts, but you are throwing away liabilities and keeping the people who want to hear from the business anyway.

“Isn’t consent the client’s legal problem, not mine?” No. As the party building and sending the campaign, your agency can be named in a TCPA action alongside the client, and “we were just running the software” is not a defense. This is why you want the consent copy standardized and the opt-in screenshots on file. Your process is your protection.

“Do I need a lawyer for all this?” For the templates, no, the copy above reflects standard TCPA and carrier requirements. For anything unusual, a client in a regulated vertical, a big imported list, or EU data at scale, spend an hour with a TCPA attorney. When in doubt, talk to us first.

Back to that dentist and their 4,000-row spreadsheet. You didn’t import it. You built a re-permission email, got 1,900 confirmed opt-ins in a week, and wired the reminders and review requests to that clean list with the consent copy above. Smaller list, zero exposure, and the texts actually deliver because the carriers trust the sending pattern. That’s the whole trade: a little friction at sign-up buys a channel you can run at scale without looking over your shoulder.

FAQ

What does TCPA-compliant SMS opt-in language need to include?

An unchecked consent box (or an affirmative action like texting a keyword) with copy that names the business sending the messages, states consent is not a condition of purchase, discloses that message frequency varies and rates may apply, tells the user to reply STOP to cancel and HELP for help, and links to a privacy policy. Consent must be captured before any marketing text is sent, with a record of when and how it was given.

Is the FCC one-to-one consent rule still in effect in 2026?

No. The Eleventh Circuit vacated it on January 24, 2025 in Insurance Marketing Coalition Ltd. v. FCC, one business day before it was due to take effect, finding the FCC had exceeded its authority. The rule never became enforceable and the FCC removed it. Any tool telling you that you need separate consent for every individual seller is working from outdated information.

Can an agency get sued under the TCPA for a client's texts?

Yes. The agency that builds and sends a text campaign can be named in a TCPA lawsuit alongside the client, and 'we just ran the software' is not a defense. Standardize compliant opt-in language, store consent records per client, and test STOP handling before every campaign goes live. Statutory damages are $500 per text, up to $1,500 for willful violations, with no cap.

Can I text a client's existing customer list?

Not automatically. Being a customer is not the same as giving prior express written consent to receive marketing texts. Run a re-permission campaign first: contact the list through a channel you have consent for, ask them to opt in to SMS specifically, and only text those who confirm. Texting an old list with no SMS consent record is a common source of TCPA claims.

How fast do I have to honor an SMS opt-out?

Since April 11, 2025, you must honor a revocation of consent within a reasonable time not to exceed 10 business days. Consumers can opt out by any reasonable means, not just the keyword STOP, so honor 'stop,' 'unsubscribe,' 'cancel,' 'quit' and plain-language requests the same way. Automated STOP handling processes opt-outs instantly, well inside the requirement.

How should agencies word an SMS review request to stay FTC-compliant?

Ask for honest feedback, route every recipient to the same public review page regardless of how they feel, and never offer anything in exchange for a positive rating. Do not send only happy customers to a public review site and unhappy ones to a private form. The FTC's Reviews Rule, effective October 21, 2024, bans incentivized and gated reviews, with penalties up to $53,088 per violation.

Sources

47 U.S.C. § 227 (TCPA) · 47 CFR § 64.1200 (quiet hours) · Wiley: 11th Circuit vacates one-to-one consent · Nixon Peabody: consent-revocation rules · FTC Reviews Rule Q&A · FTC 2025 penalty adjustment · FTC CAN-SPAM guide · CTIA Messaging Principles (May 2023) · GDPR consent · EZ Texting 2025 report

Ready to put this to work?

Install the DM Snapshot in 24 Hours

Every workflow above — already built, refined across 80+ U.S. marketing agencies, installed for you for $997 one-time.