Ground rules
Permission is the part you cannot outsource
Your provider handles the infrastructure. Consent, opt-outs and record keeping stay with you — and in the US the penalties are assessed per message, which is how a small mistake becomes a large number.
This is a plain-English overview, not legal advice
Messaging law varies by country and, in the US, by state — several states have their own statutes that are stricter than the federal baseline. If you are sending at volume or in a regulated industry, have a lawyer review your consent flow. What follows is the shape of the problem, not a compliance program.
Skipping 10DLC is not skipping the rules
The most common misunderstanding in this category: because iMessage does not travel over carrier messaging rails, providers can skip A2P 10DLC registration. That is genuinely convenient — it removes a multi-week approval process before you can send your first message.
But 10DLC is a carrier requirement, and consent law is a legal requirement. They are separate systems that happen to overlap. In the US, the Telephone Consumer Protection Act governs the message regardless of which pipe carries it. Removing the carrier gatekeeper removes a check that was, in practice, also stopping some people from making expensive mistakes.
What counts as consent
The bar is that the person knowingly agreed to receive messages from you at that number. Practically:
- They gave you the number for this purpose. A phone number collected for a delivery is not consent to send promotions.
- The agreement was affirmative. A pre-ticked box is not consent. Buried terms are not consent.
- It was clear who would be messaging. Consent given to you does not transfer to a partner, an affiliate, or a business that buys your list.
- Promotional messages need a higher bar than transactional ones. “Your appointment is confirmed” and “20% off this weekend” are not the same category and should not rely on the same permission.
A purchased list is never consent. Neither is a number scraped from a public listing, nor one a customer gave your business six years ago for something unrelated.
Opt-outs have to actually work
Every provider will honor STOP. That is table stakes and not sufficient, because customers do not reliably type STOP. In a real conversation thread they type “please stop texting me”, or “take me off this”, or just “no”. If a human reading the thread would understand it as a request to stop, treat it as one.
This matters more on iMessage than on SMS precisely because the channel is conversational. You have invited a two-way exchange; you cannot then require a specific keyword to end it.
- Suppress immediately, not on the next batch sync.
- Suppress across every system you own — the provider’s suppression list does not update your CRM.
- Never send a confirmation that reads as one more message.
- Keep the opt-out permanently, including after a data migration.
Keep records that would survive a complaint
If someone complains, the question is what you can show. For every contact you message you want to be able to produce: when consent was given, through what mechanism, what wording they agreed to, and every message you sent since. Store it in your own system. A provider account you might cancel is not a records-retention strategy.
Quiet hours and cadence
The federal baseline is no calls or texts before 8am or after 9pm in the recipient’s local time. Several states are stricter. In practice, the conservative window — 9am to 8pm — is also better for response rates, so there is no tension between compliance and results.
Store the customer’s timezone explicitly. Inferring it from the area code has been unreliable since number portability, and a 6am text is both a violation and the fastest way to get blocked.
The other risk
Platform dependency, and how to hold it sensibly
Apple does not sell this capability. Every provider in this category therefore operates in a space Apple has not sanctioned, and that is worth planning around rather than ignoring.
Own your customer data
Contacts, consent records and conversation history should live in a system you control. If a provider relationship ends, you should lose a channel, not a customer list.
Keep a second path
Email or SMS as a fallback for anything that genuinely has to arrive. Use iMessage for the relationship, not for the messages you cannot afford to lose.
Do not build the business on it
A channel that improves your numbers is a good investment. A channel that your operations cannot function without is a dependency you did not price correctly.
Get the permission right and the channel takes care of itself
Businesses that message people who genuinely want to hear from them rarely have a compliance problem, because they rarely generate a complaint. The rules and good practice point the same direction.
Still unsure whether this fits your business? Ask us.
Further reading
Consent in practice
Opt-ins that hold up
The consent you collect is the consent you can prove. Here is what a defensible opt-in looks like at each place a small business touches a customer.
8 min readOperationsIs business iMessage legal?
Sending business messages is legal and routine. What binds you is consent law, and it applies regardless of which channel carries the message.
7 min readOperationsWhy numbers get flagged
Lines go quiet for reasons that are mostly predictable and mostly preventable. Here is what triggers it and what to do while it is happening.
7 min readIndustry playbooksIndependent pharmacies
Refill and pickup reminders are among the most useful messages any business sends. They are also the ones where you can say the least.
7 min readIndustry playbooksChildcare and preschools
Parents want to know their child is fine and to be told immediately when they are not. Everything else you might send is a distraction from that.
6 min readIndustry playbooksNonprofits and churches
Volunteer shifts, event reminders and donor thanks work beautifully by message. Fundraising appeals mostly do not, and sending them costs more than they raise.
6 min read