TCPA and Telemarketing Rules · September 28, 2026 · GrowthPros

Is it illegal to send unsolicited texts?

Unsolicited marketing texts can cost $500–$1,500 each under the TCPA. Learn the 2025 rules, real settlements, and five safeguards to text legally.

Flat illustration of a smartphone sending message bubbles marked with dollar signs, representing costly unsolicited texts under TCPA rules.

Key Facts

  • Unsolicited marketing texts can cost $500–$1,500 per message under the TCPA according to legal analysis
  • DSW settled for $4.42 million in 2025 for texting consumers who had already opted out per recent settlements data
  • Uber paid $20 million in 2017 over unsolicited robocalls and texts, including messages sent after opt-out attempts per documented settlements
  • Clover Network paid $15 million in 2024 for more than a million unsolicited texts per recent enforcement actions
  • Continued texting after a STOP request is treated as a willful violation carrying $1,500-per-message penalties per FCC guidance
  • Businesses must retain consent documentation for at least five years from the date of collection per compliance recommendations
  • Approximately 100,000 phone numbers are reassigned every day, creating significant compliance risk per FCC data

The Short Answer: Yes — Unsolicited Marketing Texts Can Cost You $500–$1,500 Each

One text message. That's all it takes to owe a stranger $500 — and if a court decides you knew better, $1,500. Under the Telephone Consumer Protection Act (TCPA), sending marketing texts without prior express written consent isn't a gray area: it's a federal violation, and there's no ceiling on how those per-message penalties stack up.

The math gets ugly fast. A single noncompliant blast to 10,000 numbers carries a theoretical liability of $5 million to $15 million, because the TCPA places no total cap on damages. And this isn't hypothetical risk — courts have forced real settlements out of recognizable brands in recent years:

  • Uber — $20 million (2017) over unsolicited robocalls and texts, including messages sent after opt-out attempts
  • Clover Network — $15 million (2024) for more than a million unsolicited texts
  • Cash App — $12.5 million (2025); Zales — $7.5 million (2025)
  • DSW — $4.42 million (2025) for the simplest failure imaginable: texting people who had already opted out

The DSW case is the one that should keep sales and marketing leaders up at night. These weren't cold texts to strangers — they went to existing customers who simply asked to stop receiving messages. Continued texting after a STOP request is treated as a willful violation, which is what unlocks the $1,500-per-message tier rather than $500.

Here's the tension every business feels: speed-to-lead genuinely matters. Contact a lead within five minutes and you're dramatically more likely to make contact than waiting thirty. But the pressure to respond instantly is exactly what pushes teams toward shortcuts — blasting lists without consent records, ignoring opt-outs, skipping DNC scrubs — and each shortcut converts a growth tactic into per-message statutory liability.

Some courts have recently created procedural confusion about whether texts qualify as "calls" under certain TCPA provisions — the Seventh Circuit ruled they don't for private do-not-call claims — but legal experts consistently recommend treating marketing texts as fully TCPA-regulated regardless, since autodialer and consent claims still apply.

The businesses that scale safely do it by making compliance structural, not aspirational. GrowthPros, for example, attaches a consent record — disclosure text, timestamp, IP address — to every lead before delivery, so the speed-to-lead follow-up happens inside a documented consent trail rather than around it. That's the standard the settlements above implicitly set: fast outreach is only an asset when every message can prove it was invited.

If a court just ruled that texts might not be "calls" under the TCPA, you might assume the compliance pressure is easing. The opposite is true: 2025's rulings have fractured the legal landscape so thoroughly that full compliance is now the only rational strategy.

The confusion started with the Supreme Court's June 20, 2025 decision in McLaughlin Chiropractic Associates v. McKesson Corp., which left district courts split on whether texts qualify as "calls" under the TCPA. The Seventh Circuit then ruled that text messages are not "telephone calls" under Section 227(c)(5), eliminating private do-not-call claims for unwanted marketing texts in Illinois, Indiana, and Wisconsin — but Section 227(b) autodialer and prerecorded voice claims remain fully intact and still apply to SMS programs.

Meanwhile, the Eleventh Circuit vacated the FCC's one-to-one consent rule on January 24, 2025, in Insurance Marketing Coalition v. FCC, meaning businesses now follow the pre-2023 consent definition. But as legal analysts note, the heightened 2012 standard requiring prior express written consent for marketing texts sent via autodialer remains in force. No court has given anyone permission to text without consent.

The bigger trap is state law, which often exceeds federal requirements:

  • Florida and Oklahoma ban automated dialing systems outright and cap you at 3 texts per subject per rolling 24 hours.
  • Connecticut penalties reach $20,000 per unsolicited text infraction.
  • Texas requires a $200 registration fee plus a $10,000 bond unless you text only consumers with clear documented consent.
  • Virginia requires opted-out numbers to stay on a do-not-text list for 10 years.

These states presume recipients with in-state area codes are physically in-state, effectively forcing nationwide compliance with their stricter rules. And the stakes are enormous: TCPA damages carry no aggregate cap, so a single noncompliant blast can mean multimillion-dollar liability. Recent settlements prove it — Clover Network paid $15M for over a million unsolicited texts, and DSW paid $4.42M for texting consumers who had already opted out.

That's why legal experts consistently recommend treating marketing texts as calls and complying fully regardless of the court split. The judicial disagreement gives no safe harbor; it just creates more ways for plaintiffs to shop for a favorable forum. Consent documentation is your only real defense — timestamped logs, exact disclosure language, and immediate opt-out honoring.

This is exactly how GrowthPros operates: every lead arrives with a consent record attached — disclosure text, timestamp, IP address, and the named contacting party — and lists are DNC-scrubbed before any outbound contact. The goal isn't to exploit legal gray areas; it's to make every message defensible before it's ever sent.

What Compliant Consent Actually Looks Like

Compliant consent isn't just a box to check—it's the entire legal defense when marketing by text. Under the TCPA, businesses must obtain prior express written consent that includes specific, verifiable elements to avoid liability of $500 to $1,500 per violation. This means clear checkbox language, an electronic signature, and a disclosure that consent isn't a condition of purchase. Crucially, the consent must authorize no more than one identified seller, a requirement rooted in FCC guidance that remains relevant despite recent legal shifts around one-to-one consent rules. Without this precise documentation, any text campaign assumes TCPA risk by default.

The consent log itself is non-negotiable evidence. Businesses must maintain timestamped records for at least five years, capturing the date, method, exact consent language, IP address, and contact details. This documentation transforms consent from a verbal promise into provable compliance—a point underscored by settlements like DSW Shoe Warehouse's $4.4M payment for texting after opt-out and Uber's $20M resolution for similar violations. GrowthPros builds this standard into every lead, attaching consent records that include disclosure text, timestamp, IP, and the named contacting party to each delivered contact. For businesses buying leads, this shifts liability: purchasing cheap leads without consent trails transfers full TCPA exposure to the buyer, regardless of the seller's claims.

  • Use unambiguous checkbox language that specifies the exact seller and purpose of contact
  • Require an electronic signature or equivalent affirmative action (e.g., typing full name)
  • Explicitly state that consent is not a condition of purchase or service
  • Log timestamp, IP address, and full consent language for every opt-in
  • Retain all consent documentation for a minimum of five years from the date of collection

The lead-generation loophole remains a critical vulnerability. Some vendors sell leads claiming "implied" or "bulk" consent, but TCPA compliance demands written consent tied to a single identified seller. If a lead lacks this specific, traceable consent—especially when resold through multiple layers—the buyer inherits all regulatory risk. GrowthPros avoids this by sourcing only leads with consent-recorded, opt-in relationships, ensuring every contact includes the documented authorization needed to defend against TCPA claims. When consent is proven, the focus shifts to execution: timely follow-up, strict opt-out honoring, and list hygiene. Without it, even a single noncompliant text blast invites multimillion-dollar liability—making consent documentation not just a best practice, but the foundation of legal text marketing.

Knowing the law is one thing; building a program that survives an audit or a class action is another. The difference between the two comes down to five operational safeguards you can put in place this week.

1. Capture compliant consent — and save the exact language. Your checkbox copy matters. Under the FCC's 2012 standard, marketing texts sent via autodialer or prerecorded voice require prior express written consent, and legal experts stress that you must retain the precise consent wording alongside timestamped logs. Keep those records for at least five years — date, method, exact language, and contact details.

2. Honor opt-out keywords immediately. FCC rules recognize "stop," "quit," "end," "cancel," "unsubscribe," "opt out," and "revoke." Send one final confirmation if needed, then stop. Continued texting after a STOP request is treated as a willful violation — the kind that carries $1,500-per-message penalties. DSW learned this the hard way, settling for $4.42 million in 2025 for texting consumers who had opted out.

3. Scrub your lists — repeatedly. Roughly 100,000 phone numbers are reassigned every day, and texting a number whose new owner never consented is a violation. The FCC's Reassigned Numbers Database (152M+ numbers) provides a safe harbor if you query it at least every 45 days, alongside DNC Registry scrubbing before every campaign.

4. Text only 9 a.m. to 8 p.m., recipient's local time. Federal law allows 8 a.m.–9 p.m., but states tighten the window — Florida and Oklahoma cut off at 8 p.m., and Texas starts automated messages at 9 a.m. The safest approach is 9 a.m.–8 p.m. based on the recipient's actual time zone, not their area code.

5. Document everything. In a dispute, the party with the records wins. At minimum, your documentation should include:

  • The exact consent disclosure text and the timestamp it was captured
  • The consumer's IP address and the named contacting party
  • DNC and reassigned-number scrub logs with query dates
  • A permanent opt-out list, retained for years — Virginia requires 10

This is also why buying leads blind from a marketplace is a compliance gamble. A compliant lead provider does this work upstream: GrowthPros, for example, attaches a consent record — disclosure text, timestamp, IP address, and named contacting party — to every lead it delivers, scrubs lists against the DNC Registry before any outbound contact, and honors opt-outs immediately and permanently. When your lead source can prove consent trail by trail, your five safeguards shrink to one vendor conversation instead of five internal projects.

How to Text Fast Without Texting Illegally

Speed is the whole game in lead conversion — but texting fast means nothing if the message itself puts you on the wrong side of the TCPA. The five-minute window that makes contact roughly 100x more likely than waiting thirty minutes only works when the person on the other end actually consented to hear from you.

The math is brutal when you get it wrong. TCPA violations run $500 per message and up to $1,500 for willful ones, with no aggregate cap on damages — a single noncompliant blast can mean multimillion-dollar liability. DSW settled for $4.4M in 2025 for texting consumers who had already opted out.

The fastest way to burn your business isn't slow follow-up — it's fast follow-up to people who never consented. The riskiest practices we see are predictable:

  • Cold lists — purchased databases with no consent trail attached, where you can't prove who agreed to what or when.
  • Shared marketplace leads — leads sold to five or more buyers with murky consent that names no specific seller, the exact "lead generator loophole" regulators targeted when the FCC adopted its one-to-one consent rules.
  • Reactivating old lists without documented opt-in — a dormant file is not the same as a consented file.

Legal experts are blunt on this point: if you market by text, assume TCPA risk unless you can prove compliant consent and proper opt-out handling. Even with recent court splits over whether texts qualify as "calls" under certain TCPA provisions, the consensus is to comply as if they do.

The fix isn't slowing down — it's buying leads that carry their own paper. Every lead should arrive with disclosure text, a timestamp, the IP address, and the named contacting party, with consent logs maintained for at least five years as compliance guidance recommends. Lists should be DNC-scrubbed before any outbound contact, and opt-outs honored immediately and permanently.

That's how GrowthPros builds its pipeline: exclusive and capped-shared leads (hard max of two buyers, never five) that are consent-recorded, time-stamped, and qualified before delivery — then followed up with AI voice, SMS and email inside the five-minute window. Reactivation runs only on pre-existing, opted-in databases you already own, never cold lists.

Speed and compliance aren't in tension. They're the same requirement done right.

Want to see consent-documented leads for your niche? Book the 15-minute qualification call or submit the get-started funnel — exclusive leads by niche, followed up in minutes, including the leads you already paid for.

Why Compliance Isn't the Enemy of Speed—It's the Foundation

Sending unsolicited texts isn't just risky—it's expensive, with penalties stacking up to $1,500 per message and no cap on total liability, as seen in multimillion-dollar settlements from brands like DSW, Uber, and Clover Network. Despite recent court confusion over whether texts qualify as 'calls' under the TCPA, legal experts agree: compliant consent, immediate opt-out honoring, and rigorous list hygiene aren't optional—they're the only defensible path forward. GrowthPros builds this compliance into every lead by attaching timestamped consent records, scrubbing against DNC and reassigned number databases, and ensuring opt-outs are honored permanently—so your speed-to-lead follow-up happens within a protected, documented framework. If you want leads that arrive ready for compliant, five-minute follow-up—complete with consent trails and niche-specific qualification—submit the get-started funnel to begin a free, no-obligation qualification call.

This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.

Start

More booked calls. Not more form fills.

Tell us your niche and your goal. We will show you realistic volume, exclusivity options, and what follow-up looks like on a live call — no pressure, no 40-page deck.