TCPA Reasonable Revocation (2025): One-to-One Consent Vacatur and the Reasonable-Revocation Era
Two changes define the rule set every US SMS and voice sender operates under as of this page’s publish date. The FCC’s one-to-one consent order was vacated by the Eleventh Circuit in January 2025, before it ever took effect. The FCC’s revocation-of-consent order took effect in April 2025 and replaced the old assumption that a consumer must opt out the way you told them to: any reasonable expression now revokes, across channels, on a 10-business-day clock. This page states both changes in plain language and maps each one to the Orbit control you configure in response.Section 1 — The 2024-2025 TCPA landscape in plain language
Both orders came out of the FCC’s standing TCPA rulemaking (CG Docket No. 23-301). Their fates diverged:
One-to-one consent, vacated. The 2023 order targeted comparison-shopping and lead-generation forms: one consumer signature on a form that listed dozens of “sellers” would no longer have delivered prior express written consent to each of them. The order required consent to be one-to-one, a single signed written agreement naming the one seller that may contact the consumer. The Eleventh Circuit vacated the rule on petition for review in January 2025, before its effective date, so it never governed anyone. The pre-order landscape is what applies at publish date: consent scope is still judged by the consent language you captured and the case law on it, not by an FCC one-to-one rule. Treat the vacatur as a reason to keep doing the disciplined thing, not to stop: consent captured per seller, per purpose, still defends better in litigation than umbrella consent harvested across a seller list. See Consent Management & Receipts for recording basis and source per contact and channel.
Reasonable revocation, in effect. The April 2024 order codified that a consumer may revoke consent using any reasonable means, not only the mechanism you designated in your opt-in copy. A texted
unsubscribe, a leave me alone reply, an emoji, or words spoken on a call are presumptively valid revocations. Two corollaries carry the operational weight:
- The 10-business-day window. Once a revocation is communicated, you have at most 10 business days to honor it. There is no “we process opt-outs on Fridays” defense inside that window.
- Cross-channel scope. The FCC rejected the argument that a revocation is channel-bound. A consumer who revokes by text has revoked for the relationship, which reaches your calls as well as your texts, and a revocation stated on a call reaches your texts.
Section 2 — What “reasonable revocation” means in practice
The old model assumed the consumer opts out the way your consent copy instructed. The 2025 model assumes the consumer picks the form and you interpret it. Concretely, these inbound expressions are presumptively revocations now:unsubscribe,stop,cancel,remove— standard vocabulary.leave me alone,stop contacting me,take me off your list— free-text requests that match no keyword.- An emoji or shorthand reply sent in apparent response to your message.
- Words spoken on a call: “don’t call me again” is a revocation the agent hears, not a keyword any system can match.
STOP, STOPALL, UNSUBSCRIBE, QUIT, OPT OUT, CANCEL, END, REMOVE, BLOCK, plus the localised sets) on every inbound reply, before any of your rules run. A match writes a suppression entry immediately, with no human in the loop. That vocabulary, and the synonyms you add to it, is documented in Opt-Out Keyword Alias Table, and adding your own synonyms is additive and tenant-owned: Messages → SMS → Opt-out Rules, or POST /api/v1/settings/opt-out-rules over the API.
Outside the vocabulary, Orbit records but does not auto-suppress. Orbit does not run free-text intent classification on inbound messages that miss the alias vocabulary, and nothing on the platform converts leave me alone into a suppression entry on your behalf. The reply arrives in your inbox as an ordinary inbound message, verbatim, in the conversation history. Under the reasonable-revocation rule that reply is a revocation you are on the hook to honor; the configuration that closes the gap is yours:
- Widen the alias vocabulary with the expressions your audience actually uses, through the Opt-out Rules editor. Every synonym you add moves an expression from human review into automatic, instant suppression.
- Run a review pass over inbound replies that ask to be left alone without matching. The conversation history is your record that the request arrived; a written operating procedure is what turns it into a suppression entry inside your honor window.
- Treat voice as a revocation channel with no keywords. An agent who hears “don’t call me again” must record it before the call closes, through the Consent API (
POST /api/v1/compliance/consentwithopt_in: false) so the number lands on the suppression list the voice and dialer gates read.
Section 3 — Cross-channel scope of revocation
An SMS STOP in Orbit is already broader than SMS. When the inbound matcher fires, the suppression entry it writes is scopedall on the reply-capable phone number: the same entry gates SMS, WhatsApp, RCS, and, because the voice and dialer gates read the suppression list, your calls. See Opt-Out & Suppression Lists for the scope model. That default is what the FCC’s cross-channel rule expects of the SMS entry point: the consumer’s STOP ends the relationship reachable on that number, not just the SMS thread.
The entry points differ, and the differences are exactly where a 2025 tenant gets caught:
What you must configure for revocations that arrive by phone call or by email, where no keyword fires:
- Phone-call revocations. Record them through the Consent API with
opt_in: false, or through the Preference Center, so the entry carries scopealland the voice gate stops dialing the number too. A note in the CRM that “customer asked to stop” is not a suppression entry and gates nothing. - Email-stated revocations. A reply to your email saying “stop contacting me” is a revocation of the relationship under the order, not only of the email channel. The Consent API and the Preference Center write scope
all; if you import such rows by CSV instead, the email default scope isemail, so set thechannelcolumn explicitly to cover the channels the consumer revoked. Decide with counsel whether a channel-limited request (a true partial revocation, “no more texts but the statement emails are fine”) is what the consumer asked for, and record the scope that matches their words.
Section 4 — The 10-business-day honor window and Orbit’s timing
The order gives you at most 10 business days from the moment a revocation is communicated to the moment it is honored. Orbit’s two paths measure very differently against that window, and you should know which of your revocations runs on which clock. The alias path honors immediately. A STOP-alias match writes the suppression entry as part of handling the inbound message, and every send gate reads the same ledger before dispatch, dropping the suppressed address regardless of campaign, import, or API call. There is no batch window between the reply and the gate: the next send attempt after the entry exists is blocked. Revocations on this path comply with the 10-business-day window by a margin of days. The review path runs on your clock, and that clock is the one the order watches. Every revocation a human handles, a non-alias text, a call, an email, starts a 10-business-day countdown at the moment the consumer communicated it, not at the moment your team got around to it. Configure the path so the countdown cannot be lost:- Set an internal SLA well inside 10 business days. A 48-hour target leaves margin for weekends, holidays, and a missed queue; a 9-day target does not.
- Name an owner for the review queue. The inbox pass from Section 2 needs a responsible role and a documented procedure, or it silently becomes a 12-day queue.
- Use the Consent API for individual recordings, not the CSV import.
POST /api/v1/compliance/consentwithopt_in: falsewrites the entry in one call the moment the revocation is spotted. The CSV import is the migration and bulk tool, not the daily path. - Reconcile weekly. Compare the revocation requests visible in your inbox and call logs against the suppression ledger’s export, and chase every request with no ledger row. Export Consent & Suppression Records gives you the ledger side of that comparison.
Section 5 — Evidence capture: what a 2025-era revocation record looks like
Revocation litigation in the reasonable-revocation era starts from the consumer’s claim “I told them to stop on this date.” Your defense is a record that answers five questions, and Orbit’s record-keeping surfaces hold four of the five directly:- Timestamp of the revocation as communicated. The inbound message’s arrival time in the conversation history; for a call, the call record. If your team records the revocation later, keep both timestamps: when the consumer said it, and when the suppression entry was written.
- Channel of the revocation. SMS, WhatsApp, voice, or email; the channel the request arrived on is part of the story the cross-channel rule makes relevant.
- Verbatim text or utterance. The conversation history preserves inbound replies verbatim; for voice, the call recording or written log your process keeps, subject to your recording-consent posture (Recording Consent).
- Scope applied. The suppression ledger entry carries its channel scope; scope
allon the number is the entry that answers the cross-channel rule. - Propagation lag. The difference between (1) and the moment the entry took effect. On the alias path this is effectively zero; on the review path it is the number your SLA and your weekly reconciliation exist to keep inside 10 business days.
- Consent Record Defense — the consent ledger with basis, source, and per-event history, and how to build the evidentiary chain for one number when discovery arrives.
- TCPA Evidence Pack in the Binder — the export surface that bundles your outbound posture evidence, quiet hours, DNC, send gates, suppression, for production.
Related pages
- Opt-Out Keyword Alias Table — the exact vocabulary the inbound matcher fails closed on, and how to add synonyms.
- Opt-Out & Suppression Lists — the scope model (
allvs per-channel), the ledger, bulk import, and export. - Consent Management & Receipts — recording consent and revocation per contact and channel,
opt_in: falseincluded. - TCPA Posture Guide — assembling the full US marketing-SMS posture this page’s controls slot into.
- Consent Record Defense and TCPA Evidence Binder — the record-keeping surfaces a 2025 revocation record lands in.