Not legal advice
This is the shape of the problem in plain English. Messaging law varies by country and by US state, and several states are stricter than the federal baseline. If you are sending at volume or in a regulated industry, have a lawyer review your consent flow.
The short answer
Sending business text messages to customers is legal and completely routine. Millions of businesses do it every day. What the law regulates is not the channel — it is whether the person agreed to hear from you.
What actually binds you
In the US, the Telephone Consumer Protection Act governs commercial messaging to mobile numbers. It applies to the message regardless of which pipe carries it, which means an iMessage is subject to the same consent rules as an SMS. Several states have their own statutes that go further.
In practice that means four obligations:
- Get consent before you message. The person knowingly agreed to receive messages from you at that number.
- Keep promotional and transactional consent separate. Agreeing to appointment reminders is not agreeing to a Black Friday promotion.
- Honor opt-outs immediately. Including plain-English ones, not just the word STOP.
- Keep records. When consent was given, how, and to what wording.
The penalties are assessed per message, which is how a small mistake becomes a large number. The practical detail of getting this right is in collecting opt-ins that hold up.
The 10DLC confusion
Providers advertise that iMessage needs no A2P 10DLC registration, and that is true — 10DLC is a US carrier requirement for SMS traffic, and an iMessage never touches the carrier messaging rails. It is a genuine convenience: you can launch in an afternoon instead of waiting weeks for campaign approval.
Convenience is not permission
Skipping carrier registration removes a gatekeeper, not an obligation. Consent law applies exactly as before. If anything the risk is higher, because the check that used to slow people down is gone.
The other half: Apple's terms
This is the part that deserves a straight answer rather than a dodge. Apple does not sell this capability and has not sanctioned it. Every provider in this category operates infrastructure Apple did not design for commercial messaging.
That is a risk between the provider and Apple, not between you and law enforcement — you are not breaking a law by buying a messaging service. But it is a genuine platform dependency, and the consequence lands on you: a line can be flagged and stop delivering with no appeal process available to you.
The sensible response is not to avoid the category. It is to hold it correctly: keep a fallback channel, keep customer records in your own systems, and do not build operations that cannot function if the line goes quiet. More on that in the API gap page.
Industry-specific rules stack on top
- Healthcare: messages referencing a condition or treatment may constitute protected health information. Sendblue lists HIPAA at its enterprise tier; most providers list nothing. Keep outbound copy generic.
- Financial services: communications retention requirements may apply to the whole thread, not just what you sent.
- Legal: privilege and confidentiality considerations around anything discussed in a message.
- Debt collection: a separate and much stricter regime. Do not improvise here.
The test that keeps you safe
Could you show, in five minutes, exactly when this person agreed to hear from you and what they agreed to?
Businesses that can answer that almost never have a legal problem, because they almost never generate a complaint. The rules and good practice point the same direction — which is convenient, because the good-practice version is also the one that works better commercially.