Outbound sales in India — a practical 2026 guide (DLT, WhatsApp, calling)
Four registrations, a ninety-day header expiry, and a one-year cross-operator blacklist. What TRAI's 2025 amendment changed for anyone running Indian outbound.
Running outbound into India means operating inside a registration system, not around one. Four things get registered on an access provider's DLT platform — the sender entity, every header, every content template, and consent where you rely on it — and since TRAI's Second Amendment Regulations of 12 February 2025 that registration includes physical verification and biometric authentication of a named person. Headers expire after ninety days of disuse. Five complaints in ten days triggers action. This is what the machinery looks like from an operator's chair.
The registration chain, and who actually approves each link
The first surprise for a team arriving from a US or European stack is that TRAI approves nothing directly. TRAI writes the regulations; the access providers — the telecom operators — run the DLT platforms, hold the registers, and make the approval decisions. Your counterparty is an operator, and the registers are blockchain-backed, which is why revocations propagate across providers rather than sitting in one operator's database.
Four artefacts get registered, and each one gates the next.
The Principal Entity. Your company, registered as the party on whose behalf commercial communication is sent. Everything else hangs off this record.
The header. The sender identifier a recipient sees. Schedule-I as amended describes it as an 11-character alphanumeric string, and provides that the type of commercial communication be identifiable from the header structure by suffixing -P, -S, -T or -G for promotional, service, transactional and government messages. Header approval is not a formality: the amendment requires an access provider to "designate a separate executive specially for the purpose of carrying out approval of Header registration", scrutinising the sender's justification against the number of headers already allotted and the number previously blacklisted.
The content template. The message body, pre-approved, with variable fields marked. Content-template approval carries the same designated-executive requirement and the same style of scrutiny — how many templates the sender already holds, and how many have been blacklisted.
Consent, where you rely on it. Consent acquisition runs through a short code, which the amendment specifies as 127xxx or such other code as the Authority prescribes, and the consent-seeking message must clearly name the Principal Entity or brand. The confirmation a customer receives must itself carry information about how to revoke.
Two of those four are approved per artefact rather than per company, which is the operational fact that shapes a launch plan. A new campaign with a new message is a new template submission, and template turnaround is the item most likely to sit on the critical path. Which channels can carry a cold first touch in India at all is the strategic question that should be settled before you start filing any of this, and what DLT registration is is the shorter definition.
Registration now includes a person, not just a company
The February 2025 amendment inserted a sub-item into Schedule-I that changes the character of registration. The registration process of Senders and Telemarketers by access providers "shall include — (a) physical verification of the entity; (b) biometric authentication of the authorized person of the entity; (c) linking of the entity with a unique mobile number".
Physical verification. Biometric authentication of a named individual. A unique mobile number tied to the entity. That is a know-your-customer regime, and it exists because the failure it addresses was shell entities cycling through registrations faster than enforcement could follow.
The same amendment attacks the other half of that problem by shortening the chain. TRAI's press release states that the revised regulations "limit the number of intermediaries between the Principal Entity (PE) and the Telemarketer (TM) to ensure full traceability of messages", and separately mandates "strict Principal Entity (PE) - Telemarketer (TM) traceability". If you buy SMS through a reseller who buys from an aggregator who buys from an operator, that chain is now a compliance object rather than a commercial detail, and it is worth knowing exactly how many links sit between your message and the network before you sign anything.
Headers expire after ninety days, and a blacklisted one suspends everything
Two provisions in the amendment produce operational failures that look like outages, and neither is intuitive.
Unused headers are deactivated automatically. Access providers must "temporarily deactivate unused Headers i.e., Headers which have not been used to send Messages through any Access Provider for a period of ninety days, or such period as may be specified by the Authority, through an automated process", reactivating on the sender's request. A header registered for a seasonal campaign and left idle for a quarter is not reliably live when the next season arrives, and discovering that on launch morning is a bad way to discover it.
A blacklisted header suspends the sender, not just the header. The regulation requires access providers to "immediately suspend the traffic from a Sender, when a Header is blacklisted by the OAP for sending commercial communications, in violation of the regulations", with traffic resuming "only after review of all the registered Headers and registered Content Templates of the registered Sender by the respective registrars and findings are recorded, or seven days from suspension, whichever is earlier". Then the sting: "Repeat violations shall result in blacklisting of the Sender across all the Access Providers for a minimum period of one year."
One bad header takes the whole sending identity offline for up to seven days while every other header and template you own is reviewed. That is a strong argument for separating headers by risk — keeping transactional traffic on a header that never carries anything promotional — and an even stronger one against experimenting with borderline content on a header your invoices depend on.
What the February 2025 amendment changed about getting caught
The detection side moved further than the registration side. TRAI's press release of 12 February 2025 sets out the changes, and they compound.
- The complaint window widened. A customer may now complain "within 7 days of receiving spam as compared to earlier 3-day time limit".
- Preference registration is no longer a prerequisite. Consumers can complain about unregistered senders "without the need of first registering their preferences".
- The action threshold dropped and widened at once. From "10 complaints against the sender in last 7 days" to "5 complaints against the sender in last 10 days". Fewer complaints, over a longer window.
- The operator's clock shortened. Time for access providers to act against unsolicited communication from unregistered senders fell "from 30 days to 5 days".
- Complaint filing got easier by design. Operator apps must surface the complaint option prominently, auto-capture call logs and SMS details with permission, and accept screenshots.
- Networks now look for you rather than waiting. Access providers are mandated to analyse call and SMS patterns "based on parameters such as unusually high call volumes, short call durations, and low incoming-to-outgoing call ratios", and to deploy honeypots — dedicated numbers that attract and log spam.
That last pair is the one an outbound team should sit with. A dialler that produces high volume, short durations and almost no inbound is describing the exact shape the network is now instructed to flag. The signature of a badly run calling operation and the signature of a spammer are the same signature.
The money side: disincentives, deposits and a tariff ceiling
Three financial provisions round out the picture, and they point in different directions.
Access providers face graded penalties for misreporting. The press release specifies a financial disincentive of ₹2 lakh for a first instance of misreporting the count of unsolicited communication, ₹5 lakh for a second, and ₹10 lakh per instance thereafter, imposed separately for registered and unregistered senders and on top of penalties for invalid closure of complaints and for failures in header and content-template registration. Those land on your operator, not on you — which means your operator now has a direct financial interest in your traffic being clean.
Senders can be asked for a security deposit. Access providers "have been enabled to prescribe a security deposit for the senders and telemarketers, which can be forfeited in case of violation", and must enter into a legally binding agreement with every registered sender and telemarketer setting out roles, responsibilities and the actions available on non-compliance. Read that agreement. It is where your actual exposure is written down.
And the inter-operator charge now covers transactional traffic. Regulation 35 of the principal regulations governs what a terminating access provider may charge an originating access provider for delivering commercial communication, at up to five paise per promotional SMS and per service SMS. The amendment inserts a third sub-regulation: "Upto Rs. 0.05 (five paisa only) for each Transactional SMS". That is a wholesale charge between operators rather than your price list, but it is one of the inputs your provider's per-message pricing is built on, and it is worth recognising when a quote changes and nobody can explain why.
Autocloz's free plan covers 5 users and 10 mailboxes across email, calling, LinkedIn, SMS and WhatsApp in one workspace, priced in rupees with GST captured at checkout rather than converted from a dollar list price — start free and connect your own Indian sender rather than renting one. The number and the registration stay yours: the MSG91 SMS integration is the common Indian path, and the dispatch gate sits in front of whichever provider you choose.
Costing a WhatsApp programme after per-message pricing
WhatsApp economics changed shape on 1 July 2025, when Meta moved the Business Platform from conversation-based pricing to per-message pricing. You are charged when a template message is delivered. Marketing templates are charged on delivery. Utility and authentication templates are charged outside an open customer service window, and utility templates delivered inside one became free on the same date. Non-template messages inside an open window are free, and everything is free for 72 hours inside an open free entry point window. Meta also introduced volume-based tiers that unlock lower rates for utility and authentication templates.
For India, Meta's documentation records four dated changes: billing localisation with INR as a currency option from 1 January 2026, a requirement that eligible customers migrate every WhatsApp Business Account in their portfolio to INR by 31 December 2026, a higher India marketing rate effective 1 January 2026, and a higher India authentication-international rate effective 1 April 2026.
Rates move, so model the structure rather than a number. As an illustrative worked example with no real rate in it: if your marketing template rate is R per delivered message and you run a three-touch business-initiated sequence to N prospects, the ceiling is 3 × N × R. Every prospect who replies collapses their remaining touches to zero marginal cost, because a reply opens the 24-hour customer service window and free-form messages inside it are not charged. That single property inverts the usual outbound instinct. Broadcasting three marketing templates to a cold list is the most expensive way to use the channel; getting one reply and continuing inside the window is the cheapest. Where WhatsApp genuinely fits in a B2B motion follows directly from that arithmetic, and the WhatsApp channel enforces the template and window rules rather than letting a send fail at Meta.
Where Indian outbound programmes actually break
Five failure modes account for most of the incidents, and none of them is exotic.
Template drift. A template is approved, a rep improves the copy, and the sent body no longer matches the registered one. On the DLT side that is a scrubbing failure; on the WhatsApp side it is a rejected send. Pin the template as the source of the body rather than treating it as a reference copy.
Header surprise. The -P suffix appears on your promotional header whether or not the team expected it, and a recipient who reads the header as promotional treats the message accordingly. Plan the copy for a message that announces its own category.
The idle-header expiry. Ninety days without traffic, and an automated process deactivates it. Calendar it.
The reseller chain. Every intermediary between you and the operator is now a traceability liability as well as a margin. Know how many there are.
Suppression that stops at one channel. A person who opts out of your SMS and then receives your call has been protected by a phone-only list and annoyed anyway. That is an argument for a single suppression store that every channel reads before dispatch, which is what makes one shared do-not-contact list worth building before the first campaign rather than after the first complaint.
What Autocloz does not do for Indian compliance
Precision about the gaps beats another paragraph of reassurance, and these are the gaps.
It does not register your entity, header, content template or consent. All four happen on an access provider's DLT platform against your own legal entity, with physical verification and biometric authentication of your authorised person. The product carries dlt_template_id and carrier_campaign_id fields on an SMS template so you can pin the ids you obtained, and it does not validate them against any registry or operator. They are your record, not a check.
The SMS dispatcher enforces less than the WhatsApp one. For SMS it refuses to send when the step's linked template is missing or is not in active status, and it does not verify the registered id. For WhatsApp it refuses when a step names no template, when the linked template is not found in the workspace, or when its status is anything other than Meta's approved, and it treats the 24-hour customer service window as closed unless it has evidence otherwise. Those are different strengths of gate, and it is worth knowing which one you are relying on.
It does not scrub against any preference register. DLT scrubbing against the National Customer Preference Register happens on the operator's platform when the message is submitted, not inside this product. The suppression list Autocloz enforces is the one your workspace maintains, from manual entries and captured opt-outs.
Quiet hours in the send gate use the sending account's time zone. The per-lead time zone is honoured by the campaign sending window; the account-level gate reads the account's zone. A list mixing Indian and overseas contacts needs segmented campaigns or an account set to the strictest zone you send into.
It does not provision a 140 or 1600 series number. Those come from a telecom provider under your own registration. What the product does is dial through the provider you connected and record what happened.
And no product can tell you whether a specific campaign is lawful. Whether a content template honestly describes your message, whether an inferred consent covers a given contact, whether your auto-dialer use has been pre-declared as the regulation expects, and how the DPDP Act applies to your contact records are decided on evidence software cannot see. Treat this as a description of published material — TRAI's Telecom Commercial Communications Customer Preference (Second Amendment) Regulations, 2025 and the accompanying press release of 12 February 2025, and Meta's own Business Platform pricing documentation — and take advice for your own situation before you scale.
Frequently asked
What has to be registered before you can send commercial SMS in India?
Four things, on an access provider's DLT platform rather than with TRAI directly - the sender entity itself, each SMS header you will send from, each content template you will send, and the consent where you rely on explicit consent rather than an inferred or transactional basis. TRAI's Second Amendment Regulations of 12 February 2025 also require that the registration of Senders and Telemarketers include physical verification of the entity, biometric authentication of its authorised person, and linking the entity to a unique mobile number.
How many complaints does it take to get action against a sender in India?
TRAI's press release of 12 February 2025 states that the trigger was changed from "10 complaints against the sender in last 7 days" to "5 complaints against the sender in last 10 days", which both lowers the threshold and widens the window. The same amendment cut the time an access provider has to act against unsolicited communication from unregistered senders from 30 days to 5 days, and extended the window in which a customer may complain from 3 days to 7.
What happens to a sender that repeatedly violates the Indian SMS rules?
TRAI's February 2025 press release describes a graded response - for a first violation of the regulatory threshold, outgoing services on all of the sender's telecom resources are barred for 15 days, and for subsequent violations all telecom resources including PRI and SIP trunks are disconnected across all access providers for one year and the sender is blacklisted. The regulation text adds that where a header is blacklisted, traffic is suspended until the registrar reviews all of that sender's headers and content templates, or seven days, whichever is earlier.
Do unused SMS headers expire in India?
Yes. The Second Amendment Regulations require access providers to "temporarily deactivate unused Headers i.e., Headers which have not been used to send Messages through any Access Provider for a period of ninety days, or such period as may be specified by the Authority, through an automated process" and to reactivate them on the sender's request. A header parked for a quarter between campaigns is therefore not guaranteed to be live when the next campaign launches.
How does WhatsApp Business pricing work in India now?
Meta moved the WhatsApp Business Platform to per-message pricing on 1 July 2025, charging when a template message is delivered rather than per 24-hour conversation. Marketing templates are charged on delivery; utility and authentication templates are charged outside an open customer service window, and utility templates delivered inside one are free. For India specifically, Meta's documentation records billing localisation in INR from 1 January 2026, a requirement to migrate WhatsApp Business Accounts to INR by 31 December 2026, a higher marketing rate from 1 January 2026 and a higher authentication-international rate from 1 April 2026.
Can I use an ordinary ten-digit mobile number for outbound telemarketing in India?
The February 2025 amendment restricts senders from using normal ten-digit numbers for telemarketing so that commercial communications originate from designated headers or specific number series. TRAI's press release states that the 140 series continues to be used for promotional calls while the newly allocated 1600 series is designated for transactional and service calls. The regulation also expects a sender to pre-declare the use of an auto-dialer or robo-calling rather than deploying it silently.