Skip to content
iMessage APIs

Ground rules

Permission is the part you cannot outsource

Your provider handles the infrastructure. Consent, opt-outs and record keeping stay with you — and in the US the penalties are assessed per message, which is how a small mistake becomes a large number.

This is a plain-English overview, not legal advice

Messaging law varies by country and, in the US, by state — several states have their own statutes that are stricter than the federal baseline. If you are sending at volume or in a regulated industry, have a lawyer review your consent flow. What follows is the shape of the problem, not a compliance program.

Skipping 10DLC is not skipping the rules

The most common misunderstanding in this category: because iMessage does not travel over carrier messaging rails, providers can skip A2P 10DLC registration. That is genuinely convenient — it removes a multi-week approval process before you can send your first message.

But 10DLC is a carrier requirement, and consent law is a legal requirement. They are separate systems that happen to overlap. In the US, the Telephone Consumer Protection Act governs the message regardless of which pipe carries it. Removing the carrier gatekeeper removes a check that was, in practice, also stopping some people from making expensive mistakes.

What counts as consent

The bar is that the person knowingly agreed to receive messages from you at that number. Practically:

  • They gave you the number for this purpose. A phone number collected for a delivery is not consent to send promotions.
  • The agreement was affirmative. A pre-ticked box is not consent. Buried terms are not consent.
  • It was clear who would be messaging. Consent given to you does not transfer to a partner, an affiliate, or a business that buys your list.
  • Promotional messages need a higher bar than transactional ones. “Your appointment is confirmed” and “20% off this weekend” are not the same category and should not rely on the same permission.

A purchased list is never consent. Neither is a number scraped from a public listing, nor one a customer gave your business six years ago for something unrelated.

Opt-outs have to actually work

Every provider will honor STOP. That is table stakes and not sufficient, because customers do not reliably type STOP. In a real conversation thread they type “please stop texting me”, or “take me off this”, or just “no”. If a human reading the thread would understand it as a request to stop, treat it as one.

This matters more on iMessage than on SMS precisely because the channel is conversational. You have invited a two-way exchange; you cannot then require a specific keyword to end it.

  • Suppress immediately, not on the next batch sync.
  • Suppress across every system you own — the provider’s suppression list does not update your CRM.
  • Never send a confirmation that reads as one more message.
  • Keep the opt-out permanently, including after a data migration.

Keep records that would survive a complaint

If someone complains, the question is what you can show. For every contact you message you want to be able to produce: when consent was given, through what mechanism, what wording they agreed to, and every message you sent since. Store it in your own system. A provider account you might cancel is not a records-retention strategy.

Quiet hours and cadence

The federal baseline is no calls or texts before 8am or after 9pm in the recipient’s local time. Several states are stricter. In practice, the conservative window — 9am to 8pm — is also better for response rates, so there is no tension between compliance and results.

Store the customer’s timezone explicitly. Inferring it from the area code has been unreliable since number portability, and a 6am text is both a violation and the fastest way to get blocked.

The other risk

Platform dependency, and how to hold it sensibly

Apple does not sell this capability. Every provider in this category therefore operates in a space Apple has not sanctioned, and that is worth planning around rather than ignoring.

Own your customer data

Contacts, consent records and conversation history should live in a system you control. If a provider relationship ends, you should lose a channel, not a customer list.

Keep a second path

Email or SMS as a fallback for anything that genuinely has to arrive. Use iMessage for the relationship, not for the messages you cannot afford to lose.

Do not build the business on it

A channel that improves your numbers is a good investment. A channel that your operations cannot function without is a dependency you did not price correctly.

Get the permission right and the channel takes care of itself

Businesses that message people who genuinely want to hear from them rarely have a compliance problem, because they rarely generate a complaint. The rules and good practice point the same direction.

Still unsure whether this fits your business? Ask us.