
DNC Scrubbing Practices · October 4, 2026 · GrowthPros
Can I call someone on a DNC list?
No — calling a DNC-listed number violates federal law, with fines up to $50,120 per call. Learn the narrow legal exceptions and how to keep your outreac...

Key Facts
- Calling a number on the National Do Not Call Registry for telemarketing violates federal law with no exceptions beyond documented consent or existing business relationships per FTC enforcement policy
- Regulatory fines reach up to $50,120 per illegal call, rising annually with inflation according to legal analysis
- Consumers can sue privately for $500–$1,500 per call under the TCPA, with the higher amount for knowing violations per statutory damages framework
- The FTC has recovered over $178 million in civil penalties across 151 enforcement actions, including actions against lead generators and VoIP providers per official enforcement records
- The National DNC Registry held 258.5 million active registrations as of September 2025, with 4.7 million new numbers added in FY 2025 alone per FTC Data Book
- The Eleventh Circuit's 2025 ruling vacating FCC one-to-one consent rules explicitly left DNC Registry consent requirements untouched per legal analysis
- Class action settlements for ignored internal opt-outs averaged $6.6 million in 2024–2025, making opt-out compliance as critical as federal registry scrubbing per compliance experts
The Short Answer: No — and the Fines Prove It
No. Calling a number on the National Do Not Call Registry for telemarketing purposes is a violation of federal law, full stop — with only a handful of narrow exceptions. And the federal government doesn't treat it as a paperwork error. The FTC states plainly that it "takes aggressive legal action to make sure telemarketers abide by the Do Not Call Registry," and the record backs that up.
The penalty math is what makes this question worth asking before you dial, not after. Regulatory fines can reach up to $50,120 per call, a figure that rises yearly with inflation, according to legal analysis of DNC violations. And that's only the government's side of the ledger.
Consumers hold enforcement power too. Under the TCPA, individuals can sue privately for $500 to $1,500 per call — the higher amount applying when a violation is knowing or willful. A single calling session to a few dozen DNC-listed numbers can therefore generate six figures in combined exposure before a single sale is ever made.
The FTC's enforcement history shows these aren't idle threats:
- 151 total enforcement actions brought to date, with 147 already resolved, according to the FTC's Do Not Call enforcement record
- More than $178 million recovered in civil penalties, plus $112 million in restitution and disgorgement
- Recent actions like the $1 million settlement with Citizens Disability over "tens of millions of illegal and misleading calls" in September 2025
- Liability that extends upstream to companies that merely enable illegal calling — including lead generators and VoIP providers pursued for "assisting and facilitating" violations
That last point matters more than most businesses realize. The FTC has pursued not just the callers themselves but the platforms and lead sources behind them, meaning a company that buys non-compliant leads can inherit someone else's violation. It's one reason consent documentation — disclosure text, timestamp, IP address, and the named contacting party attached to every lead — has become standard practice among compliant lead providers like GrowthPros.
The registry itself keeps growing, which shrinks the margin for error every year. As of September 30, 2025, it held approximately 258.5 million active registrations, with more than 4.7 million new numbers added in fiscal year 2025 alone. Odds are increasingly good that any cold-calling list contains registered numbers.
So the short answer is no — and the honest follow-up is that the exceptions (existing customers within the past 12 months, consumer-requested calls, documented prior express written consent naming a specific seller) are the only safe paths, and each one requires proof, not assumptions.
The Legal Exceptions That Let You Call Anyway
The Do Not Call Registry blocks most telemarketing calls, but the law carves out narrow pathways that let you dial a listed number legally. With the FTC's 151 enforcement actions recovering more than $178 million in civil penalties, knowing exactly which exception applies to your call is not optional — it is your defense.
Prior express written consent is the gold standard. The FTC interprets the Telemarketing Sales Rule to require a written agreement identifying the single "specific seller" authorized to call — and per that legal analysis, the authorization does not extend to affiliates, marketing partners, or anyone else. Even after the Eleventh Circuit's Insurance Marketing Coalition ruling loosened TCPA robocall consent rules, it left DNC Registry rules untouched, and practitioners advise assuming regulators will still enforce one-to-one consent.
That means blanket or shared consent does not transfer. A lead generated for one seller cannot legally be worked by a different company, no matter what the lead vendor claims. This is why GrowthPros attaches a consent record — disclosure text, timestamp, IP address, and the named contacting party — to every lead it delivers, so the buyer inherits a defensible audit trail rather than a liability.
The other recognized exceptions include:
- Established business relationships — existing customers or anyone who did business with you within the past 12 months, per the Pennsylvania Attorney General's guidance.
- Consumer-requested calls — the person asked to be contacted, for up to three months after the request.
- Exempt categories — debt collection, charities, veterans organizations, and political calls remain permitted.
The established business relationship exception matters for reactivation campaigns. Reviving a dormant CRM list is legal only when every contact opted in and has a genuine prior relationship with the caller — never a cold list. With federal fines reaching up to $50,120 per call, and the FTC pursuing "assisting and facilitating" claims against lead generators themselves, liability flows upstream to whoever supplied the numbers.
Consent documentation remains the strongest shield. As compliance experts note, capturing and proving prior express written consent turns a potential violation into a verifiable audit trail — and contracts with lead vendors should explicitly require one-to-one permission. If your lead source cannot produce seller-specific consent records, treat the list as untouchable.
Why Compliance Is a Patchwork, Not a Single Registry
Most callers assume the National Do Not Call Registry is the only list they need to worry about. In reality, it's just one layer of a compliance stack that stacks federal rules, state registries, calling-hour limits, and internal opt-out obligations on top of each other.
The federal layer is the baseline. The National DNC Registry held roughly 258.5 million active registrations as of September 2025, and telemarketers must scrub their lists against it every 31 days. Miss that cadence and a single illegal call can cost up to $50,120 in regulatory fines, with consumers able to sue privately for $500–$1,500 per call.
State rules add a second, harsher layer. Several states maintain their own DNC lists with penalties that dwarf the federal baseline:
- New York: up to $20,000 per violation
- New Jersey: $10,000 for a first offense, $20,000 for subsequent violations
- Indiana and Florida: up to $10,000 per call
- Pennsylvania: up to $3,000 per violation if the contact is age 60 or older, per the state Attorney General's FAQ
Calling hours fragment the map further. The federal window is 8am–9pm local time, but state restrictions vary: Florida cuts off at 8pm, Michigan starts at 9am, and Oregon (as of September 2025) permits calls only from 9am–7pm. A dialing campaign that's compliant in Texas can be illegal by dinnertime in Portland.
The layer most businesses underestimate is the internal opt-out list. When a consumer asks you to stop calling, that request carries equal legal weight to the federal registry — and ignoring it triggers TCPA penalties of $500–$1,500 per violation. Class action settlements for ignored opt-outs averaged $6.6 million in 2024–2025.
This patchwork is why GrowthPros scrubs every list against the DNC Registry before any outbound contact and honors opt-outs immediately and permanently across SMS, voice, and email — treating internal requests with the same seriousness as federal ones. The FTC also pursues "assisting and facilitating" liability against lead generators and VoIP providers that enable illegal calls, so compliance responsibility flows upstream to whoever sources the leads, not just whoever dials them.
Given the complexity, legal practitioners advise businesses to audit their lead sources contractually and seek counsel on state-specific rules before dialing across state lines.
Liability Flows Upstream: Lead Buyers and Sellers Both Burn
If you buy leads, here's the uncomfortable truth: the FTC doesn't stop at the caller. It chases everyone who made the calls possible — and that includes the companies that supplied the numbers.
The FTC's DNC enforcement record shows a deliberate strategy of pursuing "assisting and facilitating" violations against the infrastructure behind illegal telemarketing. VoIP providers like XCast Labs and VOIP Terminator, and lead generators like Response Tree, have all faced enforcement actions — not for dialing, but for enabling the dialing. Across 151 enforcement actions, the agency has recovered more than $178 million in civil penalties.
Liability flows upstream. If your lead vendor scraped numbers without valid consent and you call a DNC-listed consumer, both of you sit in the blast radius. Regulatory fines run up to $50,120 per call, and consumers can sue privately for $500–$1,500 per call on top of that.
On January 24, 2025, the Eleventh Circuit vacated the FCC's 2023 one-to-one consent order for TCPA robocall rules in Insurance Marketing Coalition Ltd. v. FCC. Some lead sellers celebrated. They shouldn't have.
The court's decision explicitly left DNC Registry rules untouched — it "did not address the rules governing telephone solicitations to numbers on the federal and state Do Not Call Registries." The FTC separately interprets the Telemarketing Sales Rule to require that written consent identify the single "specific seller" authorized to call; authorization does not extend to affiliates or marketing partners.
Legal practitioners' guidance is blunt: assume the FCC, FTC, and plaintiffs' attorneys will continue arguing one-to-one consent is required for calls to DNC numbers even after the ruling. Their practical recommendations for lead buyers include:
- Revise lead vendor contracts to contractually require one-to-one permission and consent
- Audit lead sellers for compliance rather than trusting their assurances
- Demand documented consent records — disclosure text, timestamp, IP address, and the named contacting party
- Scrub against the National DNC Registry every 31 days, per federal telemarketing rules, plus applicable state lists
That last point about documentation matters more than ever. With roughly 258.5 million numbers now on the registry, the odds that a "shared" lead from an aggregator touches a DNC-listed consumer are not trivial — they're near-certain at volume.
This is why GrowthPros attaches a full consent record — disclosure text, timestamp, IP address, and the named contacting party — to every lead it delivers, and scrubs lists before any outbound contact. When the FTC comes asking who facilitated a call, the answer should be an audit trail, not a shrug.
The takeaway for lead buyers: your vendor's compliance posture is your compliance posture. If they can't produce seller-specific consent for every record, you're not buying leads — you're buying someone else's liability.
A Compliant Outreach Checklist for Lead-Driven Businesses
Knowing the rules is one thing — operationalizing them before every dial is another. The good news: a compliant outreach program reduces to five repeatable habits, and each one maps directly to the penalties regulators actually enforce.
1. Scrub every list against federal and state DNC registries every 31 days. Federal rules require telemarketers to check the National DNC Registry at least every 31 days, and states like Pennsylvania layer on their own quarterly list requirements with a 30-day removal window. With roughly 258.5 million numbers now on the federal registry — and 4.7 million added in FY 2025 alone — a list scrubbed last quarter is already stale.
2. Honor opt-outs immediately, permanently, and across every channel. An internal DNC request carries the same legal weight as the federal registry. Ignoring one triggers TCPA penalties of $500–$1,500 per violation, and class action settlements over exactly this failure averaged $6.6 million in 2024–2025. "Stop" must mean stop — on SMS, voice, and email alike.
3. Restrict reactivation to pre-existing, opted-in relationships. The established business relationship exception — existing customers or anyone who did business with you in the past 12 months — is one of the few legal pathways to a DNC-listed number, per the Pennsylvania Attorney General's DNC guidance. Cold-list "reactivation" isn't reactivation at all; it's unconsented telemarketing with fines up to $50,120 per call.
4. Demand a complete consent record from every lead source. Documented, seller-specific consent is the strongest legal defense a business can hold. For every lead you buy, require four data points before a single dial:
- The exact disclosure text the consumer agreed to
- A timestamp proving when consent was given
- The IP address captured at submission
- The named seller authorized to make contact
That last item matters more than ever. The FTC interprets its Telemarketing Sales Rule to require that consent identify a single "specific seller" — not affiliates or marketing partners — and legal practitioners advise assuming regulators will keep enforcing that standard.
5. Audit your vendors, because liability flows upstream. The FTC doesn't just pursue the business making the calls — it has taken "assisting and facilitating" actions against lead generators and VoIP providers that enable illegal telemarketing, part of 151 enforcement actions recovering more than $178 million. If your lead seller can't produce consent records on demand, that gap is your risk.
This checklist is exactly how GrowthPros builds every lead it delivers. Each lead arrives DNC-scrubbed with its full consent trail attached — disclosure text, timestamp, IP address, and named contacting party — and reactivation campaigns touch only pre-existing, opted-in relationships, never cold lists. Opt-outs are honored immediately and permanently across SMS, voice, and email.
Compliance shouldn't be a second job. If you'd rather inherit this process than build it, book a free 15-minute qualification call — it's honest about fit, commits you to nothing, and tells you exactly what consent-recorded leads in your niche would look like.
Frequently Asked Questions
Can I legally call someone who's on the Do Not Call Registry?
No — calling a DNC-listed number for telemarketing is a violation of federal law unless a narrow exception applies, such as an established business relationship within the past 12 months, a consumer-requested call, or documented prior express written consent. The FTC has brought 151 enforcement actions recovering more than $178 million in civil penalties, so this isn't a rule it treats lightly.
How much can I actually be fined for calling a number on the DNC list?
Federal regulatory fines can reach up to $50,120 per call, a figure that rises yearly with inflation. On top of that, consumers can sue privately for $500–$1,500 per call, so a single session dialing a few dozen listed numbers can generate six figures in exposure before you make a single sale.
What are the exceptions that let me call a DNC-listed number anyway?
The recognized exceptions are an established business relationship (existing customers or anyone who did business with you in the past 12 months), consumer-requested calls for up to three months after the request, and documented prior express written consent naming a specific seller — plus exempt categories like debt collection, charities, and political calls, per the Pennsylvania Attorney General's guidance. Each exception requires proof, not assumptions.
Does shared or blanket consent from a lead vendor let me call DNC-listed numbers?
No — the FTC interprets the Telemarketing Sales Rule to require that written consent identify a single "specific seller," and authorization does not extend to affiliates or marketing partners. Even after the Eleventh Circuit's Insurance Marketing Coalition ruling loosened TCPA robocall consent rules, it explicitly left DNC Registry rules untouched, so assume one-to-one consent still applies.
If I just buy the leads and someone else dials them, am I still on the hook?
Yes — the FTC pursues "assisting and facilitating" violations against lead generators and VoIP providers that enable illegal calling, not just the callers themselves, as its enforcement record against companies like XCast Labs and Response Tree shows. If your lead seller can't produce seller-specific consent records, you're not buying leads — you're buying someone else's liability.
How often do I need to scrub my call lists against the DNC Registry?
Federal rules require scrubbing against the National DNC Registry at least every 31 days, and with roughly 258.5 million active registrations — plus 4.7 million new numbers added in FY 2025 alone — a list scrubbed last quarter is already stale. States like Pennsylvania layer on their own quarterly requirements, and internal opt-out requests carry equal legal weight to the federal registry.
The Only Safe Call Is a Documented One
So — can you call someone on a DNC list? Only with proof, never with assumptions. The narrow exceptions (an established business relationship, a consumer-initiated request, or prior express written consent naming your specific company) are the entire legal playing field, and each one demands documentation you can produce on demand. With fines reaching up to $50,120 per call, private lawsuits stacked on top, and liability flowing upstream to whoever supplied the numbers, the real question isn't whether you can dial — it's whether you can defend the dial. Your next steps are straightforward: scrub every list against federal and state registries every 31 days, honor opt-outs instantly across every channel, and refuse any lead that arrives without a complete consent record. If that sounds like a second job, it's exactly the process GrowthPros builds into every lead it delivers — DNC-scrubbed, consent-recorded, and followed up within minutes. Book a free 15-minute qualification call to see what compliant, audit-ready leads in your niche actually look like. No commitment, no pressure — just an honest answer on fit.
This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.