10DLC for small business compliance is where most of this quietly goes wrong. You’ve sent a follow-up text to a US customer and never heard back. If it wasn’t because they went quiet, the message may never have reached them at all.
Every leap in how far a message could travel has been followed by a leap in how hard it became to prove who sent it. A royal messenger on the Persian Royal Road carried a physical token, checked against a known pattern, before a recipient would trust a word of what he said; losing that token meant no one downstream believed him, however urgent the message. Every such system eventually gets forged cheaply enough that trust has to move somewhere new: token to signature, signature to letterhead, and now letterhead to a filter that decides, silently, whether a stranger’s business is who it claims to be before a single word gets read.

US carriers have spent the past few years tightening what reaches a phone as SMS, specifically to cut down on spam and fraud. The mechanism is called 10DLC, short for ten-digit long code. It governs application-to-person messaging: texts a business sends to a customer, as distinct from a text one person sends another. It requires a business to register its sending number, verify its brand, and get its messaging campaign approved before carriers will reliably deliver its texts. Unregistered senders don’t get a bounce message or an error. Their texts get filtered silently. The sender has no way of knowing from their own side that anything went wrong. The closest analogy is what happened to email: once a channel gets cheap enough for spammers, the gatekeepers stop trusting senders by default, and the burden of proof moves from the network to the business.
What 10DLC for small business registration actually requires
Registration runs in three layers, and skipping any one of them is enough to get a business filtered.
The first is brand verification: proving the business sending the texts is a real, identifiable company, not a burner operation running spam through a rented number. For a US-registered business, this usually means matching the company’s legal name against its own tax ID. For an operator incorporated outside the US, the process assumes a US business by default. The Campaign Registry, which runs this check, accepts a home-country tax ID instead: a VAT number, or a corporation registration number where VAT doesn’t apply. No US subsidiary is required. The catch: by the registry’s own documentation, that first submission often isn’t enough to reach “Verified” status. The business then has to file a formal appeal with supporting paperwork to clear it. That’s the gap that touches a meaningful share of the international relocation and freight-forwarding businesses reading this.
The second is campaign registration: the business declares what it’s going to send (quote follow-ups, appointment reminders, marketing offers) and picks a use case from a defined list that has to match. Standard categories run from Customer Care and Account Notification through Marketing and Mixed, with a separate, harder-vetted tier for anything sensitive like political messaging or charity appeals. That step also requires a sample message on file, something close to “Hi Sarah, this is Ben with [Business] following up on your moving quote to Austin. Reply STOP to opt out,” so a reviewer can see the actual wording next to the declared use case. A campaign registered under a generic “customer care” label doesn’t automatically cover a marketing sequence. A mismatch between the registered use case and the actual message content is one of the more common reasons a legitimate business still gets throttled: carriers can suspend a sender’s traffic at their own discretion. CTIA’s own messaging guidelines give the sender no guarantee of a warning first.
The third is throughput: even an approved campaign is capped in how many messages it can send per number per day. Carriers set that cap differently from each other. AT&T assigns it per campaign, tied to a message class linked to the campaign’s vetting score: roughly 240 messages a minute at the lowest standard tier, 4,500 at the highest. T-Mobile assigns it as a single daily allowance shared across every campaign under the same brand: as low as 2,000 messages a day at entry level, up to 200,000 at the top.
None of the three layers is optional, and none of them happens automatically just because a business signs up with a texting platform. The platform provisions the number and sends the message. Registration keeps the message from being filtered before it ever reaches a phone.
Deliverability is one half of a working follow-up sequence. Planned follow-up is the other, and neither works without the other.
TCPA compliance is a different concern entirely, separate from carrier registration. The Telephone Consumer Protection Act governs whether a business has legal grounds to text a customer at all: proper consent on file, do-not-call handling. Violations carry statutory damages of $500 per text, or $1,500 if willful, per message and per recipient. A newer wrinkle worth getting right, not assuming: the FCC’s 2023 “one-to-one consent” rule would have required a customer’s consent to name each business individually, invalidating consent collected through shared comparison forms. But a federal appeals court vacated the rule in early 2025, before it took effect, and the FCC has since formally abandoned it. A shared form’s consent can still legally cover multiple sellers under the standard that governs today. Carrier registration doesn’t replace TCPA compliance, and TCPA compliance doesn’t automatically satisfy what a carrier checks for at registration. A business can be fully within its legal rights to text a customer and still get filtered because its privacy policy doesn’t carry the specific language a carrier’s review process is looking for. The two systems check different things, and passing one says nothing about the other.
The part that catches operators off guard
Registration isn’t just a form. Carriers review the stated use case for each campaign and check it against the business’s own privacy policy. They look for specific language: how a customer’s phone number will be used, and confirmation that the customer agreed to receive messages. CTIA, the wireless trade association whose members run the actual filtering, spells out what that language needs to cover: a description of the program, the number the texts will come from, the business’s specific identity, opt-in terms including any fees, and how to opt out. Something like “by submitting this form, you agree to receive text messages about your quote, message frequency varies, reply STOP to opt out” clears that bar. A clause written for data-protection compliance in general, and never revisited for SMS specifically, usually doesn’t. Neither does a STOP-only opt-out system: CTIA expects plain-language variants (end, unsubscribe, cancel, quit) to work too, regardless of capitalization. If a privacy policy doesn’t carry that language in the terms carriers expect, carriers can reject or throttle the campaign, even when the business itself is completely legitimate.
For an operator moving people internationally, or fulfilling work that sends quote follow-ups to US-based customers, this shows up as a quiet, invisible leak in exactly the part of the sales process that matters most: the follow-up. A quote gets sent, a text goes out to check in a few days later, and it evaporates. No delivery failure, no bounce, nothing in the CRM that flags a problem. The customer just never replies, and it looks like they lost interest.
What a filtered message looks like from the operator’s side
Picture a mid-sized operator running 150 US-bound quotes a month, each one triggering a three-text follow-up sequence: a same-day confirmation, a day-three check-in, a day-seven nudge before the lead goes cold. That’s on the order of 450 texts a month riding on one sending number.
The platform sending those texts often has no better visibility into what happened than the operator does. Carrier behavior here isn’t fully documented in public, and it isn’t consistent. A fully unregistered sender’s texts get marked outright “Undelivered” by the major carriers. SMS deliverability vendors who track this report a murkier picture for registered senders caught by a spam filter: a “delivered” receipt sometimes comes back on a message the carrier actually discarded. That’s what makes this specific failure mode so hard to catch. Either way, what shows up in the CRM is a sent text with no reply. Not a bounce. Not an error code. Just silence, on exactly the messages meant to catch someone while the quote is still fresh in their mind.
At any filter rate above zero, the shape of the problem stays the same: a share of that 450-text monthly sequence never reaches a phone, the sales team reads the resulting silence as lost interest, and nobody on the operator’s side has a way to tell “this customer went cold” apart from “this customer’s phone was never enrolled in the first place.” That’s the entire mechanism. It isn’t a sales problem wearing a deliverability costume. It’s a deliverability problem that looks exactly like a sales problem from every angle available to the person running the pipeline.
Non-compliant and compliant, side by side
Lined up next to each other, the gap between the two setups is mechanical, not mysterious.
A non-compliant setup looks like this: a standard long-code number provisioned through a messaging platform, no brand verification completed, a campaign registered under a generic or mismatched use case, or not registered at all, and a privacy policy written for data protection generally with no SMS-specific consent language anywhere in it. Texts sent from that setup default to the lowest trust tier a carrier offers. That means low throughput limits and a real chance of silent filtering the moment volume looks even slightly unusual to a spam model that has no way of knowing the sender is a real moving company running real customer follow-ups.
A compliant setup looks like this: a verified brand matched to the business’s actual legal identity, a campaign registered under the specific use case the business is running (quote follow-ups, appointment confirmations, whatever it genuinely is) with sample messages on file that match what customers receive, and a privacy policy carrying the exact consent and opt-out language carriers expect. Throughput doesn’t quietly climb on its own as a reward for clean sending history, though. The Campaign Registry fixes a trust score at initial vetting. That score holds until the brand actively requests another vetting pass. A compliant business chasing a higher cap has to go ask for it, not wait to be noticed for good behavior.
The gap between the two setups shows up in timing too, not just in whether a message arrives at all. A throttled campaign doesn’t just drop messages. It can also queue them behind a daily cap. An operator running that 450-text monthly sequence on a capped number might find the day-three and day-seven follow-ups for later quotes going out hours or even a day later than intended, stacked up behind earlier sends. A slow, inconsistent follow-up reads to a customer as a disorganized business. That compounds the original problem: on top of texts that may never arrive at all, the ones that do arrive stop showing up on the schedule the sales process was designed around.
The difference between the two setups isn’t the quality of the message. It’s whether the business did the paperwork before it started sending. Carriers aren’t grading copywriting. They’re grading whether the sender proved, in advance, that it is who it says it is and sends what it said it would send. That’s a structural bar, not a skill contest.
Compliance is now a deliverability problem
This isn’t a Movaros-specific issue. Every business moving or communicating with US customers by text is quietly running into this as carriers keep tightening enforcement. This is the rare kind of advantage that behaves like infrastructure rather than effort: the operators who’ve gone through registration properly hold a channel their unregistered competitors can’t use at all, not because the competitor writes worse texts, but because carriers won’t let the message through. Better copywriting doesn’t close that gap. Only the paperwork does.
The natural pushback here is “our texting platform already handles this for us.” Most platforms handle the sending infrastructure: provisioning the number, formatting the message, logging the send. Fewer of them complete brand verification and campaign registration on a business’s behalf without being asked to. Work backward from the platform’s incentives and that gap stops being surprising. A platform gets paid when messages get sent, not when they arrive; registration is a cost center that slows onboarding, and onboarding speed is what platforms compete on. Nobody in the chain is being negligent. The economics just don’t reward anyone but the business itself for owning deliverability. Almost none of them will flag that a business’s privacy policy is missing the consent language a carrier is checking for. That isn’t infrastructure. It’s the business’s own legal content. A platform can hand a business a working number and still leave it sitting on an unverified brand and a mismatched campaign. The business won’t find out until its send performance looks worse than it should for no visible reason.
Fixing this means treating SMS compliance as part of the sales pipeline, not an afterthought handled once and forgotten. That means a privacy policy with the specific consent language carriers expect, a registered sending number tied to a verified brand, and campaigns approved for the actual use case being run, not a generic one filed at setup and never revisited.
Ask your platform three questions
Before writing off a cold pipeline as a sales problem, try a shorter path than guessing: ask whoever manages your texting platform three direct questions. Is our brand verified, and does the legal name on file match our actual registered business? Is our campaign approved for the specific use case we run, not a generic default picked at setup? And does our privacy policy carry the SMS consent language carriers check for, not just general data-protection language written for something else?
A “yes, we think so” to any of those isn’t an answer. Get the actual status, in writing, from whoever manages the sending number. If any one of the three comes back uncertain, that’s the leak. Getting 10DLC for small business right is exactly this kind of unglamorous, easy-to-defer checklist, and it’s exactly the kind that costs the most when it’s skipped.
Movaros already runs compliant, structured follow-up.
A 30-minute call covers how building on shared infrastructure keeps every follow-up message actually reaching a customer’s phone.
