Skip to content
Compliance

10DLC registration guide for cold SMS (US carriers in 2026)

Registration is an identity check, not a content approval — and the throughput numbers that govern you are published by your provider, never by the carriers.

28 Mar 2026 13 min readBy Autocloz Editorial, Compliance team
10DLC registration guide for cold SMS (US carriers in 2026)

To send application-to-person SMS to US mobile numbers on a 10-digit long code, two records have to exist in The Campaign Registry: a Brand, which is your legal entity, and at least one Campaign, which is a specific messaging programme with a declared opt-in. You cannot file either yourself — TCR's own site says direct registration is not available for Brands — so your messaging provider files them as your Campaign Service Provider. Approval is an identity and consent-evidence check. It is not permission to text people who never asked.

What you are actually registering, and why you cannot file it yourself

The Campaign Registry describes itself as "the backbone support for the 10DLC messaging ecosystem" and states that "Brands and Campaign Service Providers (CSPs) are verified prior to being allowed to send messages". The verification chain has three links and each one constrains the next.

The Campaign Service Provider is your messaging platform. It holds the registry account. TCR's site is explicit that "direct registration with TCR is not available for Brands", so whatever console you use to submit a brand belongs to your provider, and the fields you can fill are the fields that provider chose to expose.

The Brand is your company, keyed to a tax identity. Twilio's documentation states that a tax ID may register up to five Standard or Low Volume Standard Brands, and Telnyx's documentation describes one brand per EIN as the working rule. The name, address, EIN and website you submit are checked against third-party business records, which is why a brand fails on a mismatched registered address far more often than on anything to do with messaging.

The Campaign is one messaging programme — a use case, a description of how people opt in, sample messages, and the opt-out and help behaviour. Telnyx's documentation puts the ceiling at five campaigns per brand, and adds the constraint that catches people out later: "A Number can only be used in one Campaign and its parent Brand."

That last rule is the one worth internalising before you buy anything. Numbers are not a pool you draw from. Each number is attached to exactly one campaign, and moving it means re-associating it rather than reconfiguring a sender.

Registration is an identity check, not a content approval

It helps to know what problem this framework was built to solve, because that explains which of its rules bend and which do not.

CTIA published a Messaging Security Best Practices document in October 2025 — a separate, shorter document from the Messaging Principles and Best Practices most guides quote. Section 3.2.4 is titled "Know Your Customer" and asks that "Communications Platform as a Service (CPaaS) providers, Connection Aggregators, and other parties should undertake reasonable efforts to 'know their customer' by obtaining sufficient identifying information to verify or authenticate a Message Sender's identity before the Message Sender sends a message."

Section 3.1 then lists what a Service Provider may treat as evidence when deciding to block a message, including "Fraud or other malfeasance", "Utilization of grey routes", "Lack of authentication", and "A pattern of abuse of industry best practices". Section 5 describes the abuse the framework is aimed at in concrete terms — SIM boxes, SIM farms, and "'disposable,' 'rental,' or temporary telephone numbers" used to originate large volumes.

Read those together and 10DLC stops looking arbitrary. It is a know-your-customer regime for telephone numbers. The registry exists so that when unwanted traffic appears, a carrier can name the legal entity behind it within minutes rather than tracing a chain of resellers. Everything the submission form asks you for serves that purpose.

The two rejections you will actually meet, and the fields that cause them

Campaign rejections are not mysterious, and they are almost never about your product. Twilio publishes both of the common ones as documented error codes, which makes them checkable rather than folkloric.

Error 30896 — campaign vetting rejection, opt-in error. Twilio's description: "your campaign submission was rejected during review because the opt-in details you provided don't adequately show how end users consent to receive messages". The listed causes are worth reading as a checklist of your own form. The message_flow field "does not clearly explain who is opting in, where opt-in happens, or how consent is collected". Multiple opt-in routes exist but only one was declared. The web opt-in flow is "missing a public website link, a privacy policy link, terms of service, or hosted screenshots". The privacy policy "lacks required mobile-number non-sharing statement or rate disclosures". A keyword opt-in was claimed without supplying opt_in_keywords or a compliant opt_in_message. Consent "appears shared rather than campaign-specific".

Error 30909 — message flow or call to action incomplete or unverified. Twilio: the rejection happens when "the Message Flow or Call to Action does not give reviewers enough information to verify how end users consent to receive messages", including where "opt-in evidence cannot be verified due to inaccessible, private, or incomplete website content".

Three practical consequences fall out of those two lists.

  • Your privacy policy is part of the submission. The mobile-number non-sharing statement — a sentence saying that phone numbers collected for SMS are not sold or shared with third parties for marketing — is a genuine, frequently-missing requirement, and it lives on a page most sales teams have never read.
  • A login wall fails the review. If a reviewer cannot reach the form, the opt-in is unverified regardless of how real it is. Hosted screenshots exist for exactly this case.
  • Every opt-in route has to be declared, not just the main one. A web form plus a keyword plus a verbal opt-in at an event is three routes, and describing only the first is the single most common shape of a 30896.

Why "cold SMS" has no use case on the form

The registration form has a field that quietly settles the question. message_flow asks you to describe, end to end, how a person came to consent to these messages. There is no wording of that field that honestly describes a purchased list or a scraped set of mobile numbers, and reviewers check the described flow against a live page.

That is a carrier standard rather than a legal one, and the legal layer says something separate and stricter. The TCPA requires prior express written consent for marketing messages delivered by an automatic telephone dialing system or an artificial or prerecorded voice, defined at 47 CFR 64.1200(f)(9), and the statutory damages at 47 U.S.C. 227(b)(3) are assessed per message. A registry approval is not a defence to any of that, and the two regimes reach different conclusions in different cases. If you are building a US text programme, the consent, opt-out and classification rules that decide whether a message is even permitted matter more than the registration paperwork, and the equivalent analysis for outbound calling is a different regime again.

The workable framing is that US SMS is a warm channel. Inbound leads, trial signups, existing customers, event registrants and people who texted a keyword are all describable in message_flow. A list you bought is not. Nothing about this description is legal advice, and a lawyer should advise on what your own programme needs.

Throughput is assigned per carrier, and the numbers are published by your provider

Here is the part of 10DLC that surprises people who assumed registration was a formality: it also decides how fast you may send, and the numbers are not published by the carriers who set them. They reach you through messaging-provider documentation, which is why two vendors' pages agreeing is worth more than one vendor's page asserting.

T-Mobile applies a daily cap at the Brand level, shared across every campaign under that brand, banded by the brand's vetting score. Telnyx and Infobip publish the same bands: a score of 1 to 24 gives roughly 2,000 messages a day, 25 to 49 gives 10,000, 50 to 74 gives 40,000, and 75 to 100 gives 200,000. Infobip additionally maps a Russell 3000 listing to the top band. Twilio describes the same structure from the other direction, listing a Low-Volume Standard brand at up to 2,000 SMS segments and MMS a day and a Standard brand as "From 2,000 and up to unlimited".

AT&T applies a per-minute rate at the campaign level, banded by campaign class and vetting score. Infobip's reference lists a Class A standard campaign at 4,500 SMS messages a minute and a Class E standard campaign at 240, with a trial class down at 6.

Verizon publishes no throughput guidance. Telnyx's 10DLC FAQ states that Verizon had not declared any throughput guidance as of September 2023, and no provider has published a Verizon band since. Planning a Verizon-specific rate is planning against a number nobody has stated.

Sole Proprietor brands sit outside the scoring entirely. Twilio's documentation puts a Sole Proprietor brand at 1,000 SMS segments and MMS a day to T-Mobile and one campaign only. Messaging-provider help documentation adds that these campaigns carry no trust score, a fixed rate of 15 messages a minute at AT&T, and a single telephone number per campaign. Check the current figures against your own provider's page before you plan against them.

Two operational notes matter more than the exact figures, which move. First, exceeding a limit queues rather than rejects — Infobip states that AT&T queues over-rate messages to the next interval and that T-Mobile queues over-cap messages for delivery at 8 a.m. the next day. Second, because the T-Mobile cap is per brand and the AT&T rate is per campaign, splitting one programme across several campaigns changes your AT&T behaviour and does nothing at all for your T-Mobile ceiling.

Buying more numbers is the failure mode the rules were written to catch

The obvious response to a throughput ceiling is to buy more numbers and spread the traffic. That pattern has a name, and it is named in the guidance as something not to do.

CTIA's Messaging Principles and Best Practices defines snowshoe messaging at section 5.5.2 and asks senders not to engage in it. The October 2025 Messaging Security Best Practices reinforces it at section 5.2 — "Consistent with Section 5.5.2 of the Messaging Principles and Best Practices (Snowshoe Messaging), Message Senders should not engage in Wireless Messaging Abuse" — and then tells providers what to watch for, including "Monitoring and establishing reasonable limits for activation of multiple (e.g., 10 or more) SIM cards or telephone numbers likely associated with a Message Sender within a short period of time and specific location".

Ten numbers in a short window is a documented detection trigger. The registry structure works against the tactic independently, since a number belongs to exactly one campaign under one brand and the T-Mobile cap is applied at brand level anyway. The honest conclusion is that SMS does not scale the way email does. Adding mailboxes genuinely adds email capacity; adding numbers mostly adds registration overhead and detection surface.

Autocloz's free plan covers 5 users and 10 mailboxes, and it treats SMS as one channel among email, calling, LinkedIn and WhatsApp rather than as the volume channel — start free if you would rather put the volume where it belongs and keep SMS for people who already replied. The number itself stays yours: the Twilio SMS integration and its equivalents connect a number registered under your own brand.

SHAFT is defined, but not in the document everyone cites

A small correction that saves an argument with a reviewer. The acronym SHAFT is quoted constantly as though it came from CTIA's Messaging Principles and Best Practices. It does not appear there. It appears in the October 2025 Messaging Security Best Practices, at footnote 5, which reads: "'SHAFT' refers to content related to sex, hate, alcohol, firearms, or tobacco."

Five letters, not six. There is no C for cannabis in CTIA's own definition, which is worth knowing because cannabis messaging is restricted anyway — by individual carrier and provider acceptable-use policies rather than by that acronym. The operational instruction is unchanged and slightly more annoying than the acronym suggests: the authoritative list of restricted content for your traffic is your messaging provider's AUP and your carrier's policy, and those documents differ from one another and from CTIA.

What registration does not buy you, and what Autocloz does not do

The gaps are more useful than another paragraph of reassurance, and these are the gaps.

An approved campaign is not consent. It is a carrier's acceptance of your description of your consent. If the description and the reality diverge, the campaign can be suspended after approval, and the TCPA analysis was never touched by the approval either way.

Autocloz does not register your brand or campaign, and cannot verify that you did. Registration happens with The Campaign Registry through your messaging provider, against your legal entity and your EIN. What the product carries is the operational surface around it: an SMS template row holds a dlt_template_id and a carrier_campaign_id so you can pin the registration you obtained, and campaign preflight raises a no_sms_templates warning when a workspace has SMS steps and no active template. Be precise about what that enforcement is — the sender refuses to dispatch when a step's linked SMS template is missing or is not in active status, and it does not check the pinned registration id against any registry or carrier. It is a pin for your records, not a validation.

Autocloz does not scrub against the National Do Not Call Registry. The suppression list it enforces is the one your workspace maintains, from manual entries and captured opt-outs. Registry access is a subscription your organisation holds in its own name, and the FCC and FTC safe harbours are conditioned on using a version obtained no more than 31 days before the contact.

Suppression is keyed to the identifier, not to the person. A STOP recorded against a mobile number blocks that number. It does not, on its own, suppress that human being's email address or LinkedIn profile, because the product has no way to know they are the same person unless the records are linked. If a cross-channel block is what you want, write the suppression against the wildcard channel so one list gates every channel rather than one.

Quiet hours in the send gate use the sending account's time zone. The per-lead time zone is honoured by the campaign sending window; the account-level gate is a separate check and reads the account's zone. For a US list spanning four time zones, set the account to the strictest zone you send into or segment by region, and do not assume one setting governs both behaviours.

No product can tell you whether a specific message is lawful. Whether your call-to-action captured prior express written consent, whether a state statute reads differently on your facts, and whether a given message is marketing or transactional are questions decided on evidence a product cannot see. Treat everything here as a description of published material — TCR's own documentation, CTIA's Messaging Principles and Best Practices and its October 2025 Messaging Security Best Practices, Twilio's and Telnyx's and Infobip's provider documentation, and the FCC's rules at 47 CFR 64.1200 — then take advice for your own situation. If you are weighing whether the channel earns its registration overhead at all, the case for SMS against email on a cold list is the question to settle first, and the SMS channel's own pre-send gate only ever enforces what you configured it to enforce.

Frequently asked

Can I register a 10DLC brand directly with The Campaign Registry?

No. The Campaign Registry states on its own site that direct registration is not available for Brands, and that Brands must work through a registered Campaign Service Provider. In practice your messaging provider — Twilio, Telnyx, Bandwidth, Sinch, Infobip and others — is the CSP, and it submits the Brand and Campaign records on your behalf against your legal entity and your EIN. That also means the record you can see and edit is the one your provider exposes to you, not a login of your own at the registry.

What is a 10DLC trust score and what does it change?

A trust score is a vetting number in the range 1 to 100 assigned to a registered Brand, and it decides the throughput band the carriers apply to that Brand's traffic. Telnyx and Infobip both publish the same T-Mobile bands as of their current documentation - roughly 2,000 messages a day for a score of 1 to 24, 10,000 for 25 to 49, 40,000 for 50 to 74, and 200,000 for 75 to 100, counted across every campaign under the Brand. The score is produced by a third-party vetting provider rather than by your messaging platform, and raising it is a re-vetting request, not a settings change.

Does an approved 10DLC campaign mean I am allowed to send cold SMS?

No. Registration is a carrier deliverability framework and it is separate from the law. Every campaign submission asks how recipients opted in, and Twilio's rejection code 30909 exists precisely for a message flow that reviewers cannot verify. Separately, the TCPA requires prior express written consent for marketing messages delivered by an automatic telephone dialing system or an artificial or prerecorded voice, and that consent question is decided by a court on evidence, not by a registry approval. Take advice on your own programme from a lawyer.

What happens to my messages when a carrier throughput limit is reached?

The behaviour differs by carrier and it is not a rejection. Infobip's 10DLC throughput reference states that messages exceeding AT&T's per-minute limits are queued and forwarded at the next interval, while messages over the T-Mobile daily cap are queued for delivery at 8 a.m. the next day. Queued rather than dropped is better than it sounds and worse than it looks - a time-sensitive message that arrives tomorrow morning has usually missed its moment, so the daily cap is a scheduling constraint rather than a purely commercial one.

Is buying extra phone numbers a legitimate way to raise SMS throughput?

Spreading traffic across many originating numbers to work around a cap is snowshoeing, which CTIA's Messaging Principles and Best Practices asks senders not to do at section 5.5.2, and which the October 2025 Messaging Security Best Practices reinforces at section 5.2. The registry structure works against it too, because a number belongs to exactly one campaign under one brand. Adding numbers does not scale SMS the way adding mailboxes scales email.

What are the 10DLC sole proprietor limits?

A Sole Proprietor brand is the registration path for a sender without an EIN. Twilio's documentation puts a Sole Proprietor brand at 1,000 SMS segments and MMS a day to T-Mobile and one Campaign only, and provider documentation additionally describes a fixed AT&T rate of 15 messages a minute per campaign and a single telephone number per campaign, with no trust score assigned. It is a path for an individual sending low volumes, not a shortcut around Standard Brand vetting.

Share
Free to start

Stop reading. Start sending.

Every tactic in this article is implemented behind the Autocloz dashboard.