Read this first: not legal advice
This page is general information for operators. It is not legal advice, and BlueReacher is not your lawyer. Text messaging law moves through FCC orders and court rulings several times a year, and state rules are often stricter than federal ones. Have counsel review your opt-in language, your message templates, and your opt-out process before you send at volume. No product feature makes you compliant on its own.The TCPA applies to iMessage
The Telephone Consumer Protection Act (47 U.S.C. § 227) regulates calls and texts sent to telephone numbers. The FCC has treated text messages as “calls” under the statute since its 2003 Report and Order, and its TCPA Omnibus Declaratory Ruling and Order of July 10, 2015 extended that reading to internet-to-phone messaging. Nothing in the law turns on which app renders the message. What matters is that you sent a commercial message to a phone number. Whetherchannel is imessage, rcs, or sms, your obligations are the same.
Two things operators get wrong:
“It’s B2B, so the TCPA doesn’t apply.” The federal do-not-call rules at 47 C.F.R. § 64.1200(c) protect residential subscribers, and the FCC presumes wireless numbers are residential. Most mobile numbers on a B2B list are somebody’s personal cell phone. Treat every mobile number as covered.
“We’re not an autodialer, so we’re clear.” Facebook, Inc. v. Duguid, 592 U.S. 395 (April 1, 2021) narrowed the autodialer definition to systems that generate numbers randomly or sequentially, which weakens most § 227(b) claims against list-based texting. It does nothing to § 227(c) do-not-call claims, which require no autodialer. Under § 227(c)(5) a plaintiff needs two messages in a 12-month period to a number on the National Do Not Call Registry or on your internal list. Statutory damages are 1,500 for willful or knowing violations.
No A2P registration required is not the same as no obligation
iMessage sends run on dedicated iMessage lines, managed for you, with no A2P registration required. Carrier registration and legal compliance are separate systems. Not filing a carrier form does not reduce your TCPA exposure by a dollar. Build your consent and opt-out process assuming a plaintiff’s lawyer will read your logs, because that is who reads them.Consent
Capture consent so it survives a deposition. For every opt-in, store the exact disclosure text the person saw, a timestamp, the IP address or event source, the checkbox state, the phone number as submitted, and a screenshot or versioned copy of the form. A CSV column that says
consent: yes proves nothing.
Buying a list is not consent. Consent given to a lead vendor is a factual question about what the disclosure said, and the FCC’s one-to-one consent rule that would have tightened this was vacated by the Eleventh Circuit in Insurance Marketing Coalition Ltd. v. FCC, No. 24-10277 (January 24, 2025). The rule is gone, the litigation risk is not. If you buy leads, get the disclosure text and the consent records in writing before you send.
Revocation: the rules effective April 11, 2025
The FCC’s Report and Order FCC 24-24 (CG Docket No. 02-278, adopted February 15, 2024) rewrote how consent gets revoked. The core provisions took effect April 11, 2025. Again, this is general information, not legal advice, and the operational details below are how BlueReacher implements the rules, not a legal opinion about your program. What changed:- Any reasonable means. A contact can revoke consent by any reasonable method. You cannot designate an exclusive channel for opt-outs.
- Per se reasonable keywords. A reply of stop, quit, end, revoke, opt out, cancel, or unsubscribe is automatically a valid revocation. Other wording is not automatically unreasonable, and the burden is on you to show a request was not a revocation.
- 10 business days. You must honor a revocation as soon as practicable and no later than 10 business days after receipt. The clock starts when your organization receives it, not when it reaches the platform.
- One confirmation message. You may send a single confirmation of the opt-out within five minutes, with no marketing content in it.
STOP detection in BlueReacher
Every inbound message on every channel is scanned before it reaches your inbox. On a keyword match, the platform sets the contactstatus to opted_out, stops any active sequence, blocks future sends to that contact across every line and channel in your workspace, and fires a contact.opted_out webhook. A send to an opted-out contact returns 403 contact_opted_out.
Why keyword matching alone is not enough
Keyword detection catches the per se reasonable list. It does not catch what people actually type in a conversational thread:- “please take me off your list”
- “not interested, don’t message me again”
- “wrong number”
- “who is this? remove me”
- “stpo” and “STOP.” and “Stop pls”
- replies in Spanish, French, or any language your list speaks
- Err toward honoring. An ambiguous reply you honor costs you one lead. An ambiguous reply you ignore costs 1,500 per message afterward.
- Feed in off-platform revocations. Opt-outs arrive by email, phone call, LinkedIn reply, and through your reps. Those count from the moment your company receives them. Push them into the platform the same day.
Recording an off-platform revocation
Purpose: add a phone number to your workspace opt-out list when the revocation arrived somewhere other than an inbound message. Method and path:POST https://api.bluereacher.com/functions/v1/opt-outs
Auth: send Authorization: Bearer bluereacher_your_api_key and Content-Type: application/json.
400 invalid_number for a number that is not valid E.164. 401 invalid_api_key. 409 duplicate_external_id when external_id was already used with different values. 422 invalid_channel for a channel outside the three allowed values. 429 rate_limited with a Retry-After header. A 409 on an identical repeat is safe to treat as success.
List existing opt-outs with GET /functions/v1/opt-outs, filtered by to, channel, or created_after.
Quiet hours
Federal rules at 47 C.F.R. § 64.1200(c)(1) bar telephone solicitations before 8 a.m. or after 9 p.m. in the called party’s local time. Several states are stricter. Florida (Fla. Stat. § 501.059) and Oklahoma both cut the window to 8 a.m. through 8 p.m. Three operational points:- Local time means where the person is, not what their area code says. A number with a New York area code can belong to someone living in Los Angeles. Sending at 8:01 a.m. Eastern hits them at 5:01 a.m. Use the contact’s known location when you have it, and hold the send until the latest safe hour across plausible zones when you do not.
- Courts split in 2025 on whether quiet hours apply to messages sent with consent. Do not build a program that depends on the permissive reading.
- A safe operating default is 9 a.m. to 6 p.m. recipient local time, Monday through Friday. For B2B outreach it also performs better.
Identify yourself in the first message
47 C.F.R. § 64.1200(d)(4) requires a telemarketer to give the caller’s name, the entity on whose behalf the message is sent, and a contact phone number or address. The first message from a new line should name the person, name the company, and say how the recipient can reach you or stop the messages. “Hey, quick question” from an unknown number is both a compliance gap and the worst-performing opener in outbound.Record-keeping
Keep these, per contact, for at least five years. The TCPA statute of limitations is four years (28 U.S.C. § 1658), and internal do-not-call requests carry a five-year retention rule under 47 C.F.R. § 64.1200(d)(6).- Consent record: disclosure text shown, timestamp, source, form version
- Full message history, both directions, with
created_attimestamps - Every revocation: verbatim text, receipt timestamp, timestamp when it was honored
- Your written internal do-not-call policy, available on request under 47 C.F.R. § 64.1200(d)(1)
- Proof of personnel training on that policy
- National Do Not Call Registry scrub logs, refreshed at least every 31 days
Compliance checklist
- Counsel has reviewed your opt-in language and your message templates
- Written internal do-not-call policy exists and is available on request
- Everyone who touches outreach has been trained on it, with a dated record
- Consent evidence stored per contact: disclosure text, timestamp, source
- Purchased lists come with the vendor’s disclosure text and consent records in writing
- National Do Not Call Registry scrub runs at least every 31 days
- Automatic STOP detection is on for every line and every channel
- The non-keyword revocation review queue has a named owner and a same-day service level
- Off-platform opt-outs (email, phone, reps) get pushed in via
POST /opt-outsthe same day - Opt-outs apply across all lines and all channels, not just the line that received them
- Every revocation is honored well inside 10 business days, with both timestamps logged
- Send windows respect the recipient’s actual local time, not their area code
- First message from a new line names the sender, the company, and a way to stop
- State rules checked for every state you send into, starting with Florida and Oklahoma
- Records retained five years
Primary sources
- Telephone Consumer Protection Act of 1991, 47 U.S.C. § 227
- FCC implementing rules, 47 C.F.R. § 64.1200
- FCC Report and Order FCC 24-24, CG Docket No. 02-278, adopted February 15, 2024; revocation rules effective April 11, 2025
- FCC Consumer and Governmental Affairs Bureau waiver orders of April 7, 2025 and January 6, 2026, delaying 47 C.F.R. § 64.1200(a)(10) to January 31, 2027
- FCC TCPA Omnibus Declaratory Ruling and Order, July 10, 2015
- Facebook, Inc. v. Duguid, 592 U.S. 395 (April 1, 2021)
- Insurance Marketing Coalition Ltd. v. FCC, 11th Cir. No. 24-10277 (January 24, 2025)
- Florida Telephone Solicitation Act, Fla. Stat. § 501.059
- Oklahoma Telephone Solicitation Act, effective November 1, 2022