> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# TCPA Reasonable Revocation (2025): One-to-One Consent Vacatur and the Reasonable-Revocation Era

> What the two seismic 2024-2025 TCPA shifts are in plain language: the FCC one-to-one consent order vacated by the Eleventh Circuit before its effective date, and the revocation order that made any reasonable expression a valid revocation on a 10-business-day clock. Maps each change to the exact Orbit controls a US A2P tenant must configure.

# TCPA Reasonable Revocation (2025): One-to-One Consent Vacatur and the Reasonable-Revocation Era

Two changes define the rule set every US SMS and voice sender operates under as of this page's publish date. The FCC's one-to-one consent order was vacated by the Eleventh Circuit in January 2025, before it ever took effect. The FCC's revocation-of-consent order took effect in April 2025 and replaced the old assumption that a consumer must opt out the way you told them to: any reasonable expression now revokes, across channels, on a 10-business-day clock. This page states both changes in plain language and maps each one to the Orbit control you configure in response.

<Warning>
  This page is a plain-language guide to two FCC orders and one court
  decision, not legal advice. TCPA doctrine moves; the statuses stated here
  are those of October 2026. Verify the current status of each order and
  what it requires of your specific traffic with qualified counsel.
</Warning>

***

## Section 1 — The 2024-2025 TCPA landscape in plain language

Both orders came out of the FCC's standing TCPA rulemaking (CG Docket No. 23-301). Their fates diverged:

| Order | Adopted / released | Effective date | Status at publish date (October 2026) |
| - | - | - | - |
| **One-to-one consent order** (the "lead-generator loophole" closure) | Adopted December 2023, released January 2024 | Was set for January 2025 | **Vacated** by the US Court of Appeals for the Eleventh Circuit in January 2025, before that effective date |
| **Revocation-of-consent order** (the "reasonable means" order) | Adopted and released April 2024 | April 2025, twelve months after release | **In effect** on its core provisions; a partial deferral of some provisions to October 2025 was lifted in part, which is why April 2025 governs |

**One-to-one consent, vacated.** The 2023 order targeted comparison-shopping and lead-generation forms: one consumer signature on a form that listed dozens of "sellers" would no longer have delivered prior express written consent to each of them. The order required consent to be one-to-one, a single signed written agreement naming the one seller that may contact the consumer. The Eleventh Circuit vacated the rule on petition for review in January 2025, before its effective date, so it never governed anyone. The pre-order landscape is what applies at publish date: consent scope is still judged by the consent language you captured and the case law on it, not by an FCC one-to-one rule. Treat the vacatur as a reason to keep doing the disciplined thing, not to stop: consent captured per seller, per purpose, still defends better in litigation than umbrella consent harvested across a seller list. See [Consent Management & Receipts](/compliance/consent-management) for recording basis and source per contact and channel.

**Reasonable revocation, in effect.** The April 2024 order codified that a consumer may revoke consent using any reasonable means, not only the mechanism you designated in your opt-in copy. A texted `unsubscribe`, a `leave me alone` reply, an emoji, or words spoken on a call are presumptively valid revocations. Two corollaries carry the operational weight:

* **The 10-business-day window.** Once a revocation is communicated, you have at most 10 business days to honor it. There is no "we process opt-outs on Fridays" defense inside that window.
* **Cross-channel scope.** The FCC rejected the argument that a revocation is channel-bound. A consumer who revokes by text has revoked for the relationship, which reaches your calls as well as your texts, and a revocation stated on a call reaches your texts.

Verify both statuses and their consequences for your traffic with qualified counsel before you rely on this section.

***

## Section 2 — What "reasonable revocation" means in practice

The old model assumed the consumer opts out the way your consent copy instructed. The 2025 model assumes the consumer picks the form and you interpret it. Concretely, these inbound expressions are presumptively revocations now:

* `unsubscribe`, `stop`, `cancel`, `remove` — standard vocabulary.
* `leave me alone`, `stop contacting me`, `take me off your list` — free-text requests that match no keyword.
* An emoji or shorthand reply sent in apparent response to your message.
* Words spoken on a call: "don't call me again" is a revocation the agent hears, not a keyword any system can match.

How Orbit splits that surface today, stated plainly:

**Inside the keyword vocabulary, Orbit fails closed.** The inbound matcher applies the canonical STOP alias vocabulary (English `STOP`, `STOPALL`, `UNSUBSCRIBE`, `QUIT`, `OPT OUT`, `CANCEL`, `END`, `REMOVE`, `BLOCK`, plus the localised sets) on every inbound reply, before any of your rules run. A match writes a suppression entry immediately, with no human in the loop. That vocabulary, and the synonyms you add to it, is documented in [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table), and adding your own synonyms is additive and tenant-owned: **Messages → SMS → Opt-out Rules**, or `POST /api/v1/settings/opt-out-rules` over the API.

**Outside the vocabulary, Orbit records but does not auto-suppress.** Orbit does not run free-text intent classification on inbound messages that miss the alias vocabulary, and nothing on the platform converts `leave me alone` into a suppression entry on your behalf. The reply arrives in your inbox as an ordinary inbound message, verbatim, in the conversation history. Under the reasonable-revocation rule that reply is a revocation you are on the hook to honor; the configuration that closes the gap is yours:

1. **Widen the alias vocabulary** with the expressions your audience actually uses, through the Opt-out Rules editor. Every synonym you add moves an expression from human review into automatic, instant suppression.
2. **Run a review pass over inbound replies** that ask to be left alone without matching. The conversation history is your record that the request arrived; a written operating procedure is what turns it into a suppression entry inside your honor window.
3. **Treat voice as a revocation channel with no keywords.** An agent who hears "don't call me again" must record it before the call closes, through the Consent API (`POST /api/v1/compliance/consent` with `opt_in: false`) so the number lands on the suppression list the voice and dialer gates read.

That split is the honest posture: fail-closed automation for the alias vocabulary, recorded-for-review for everything else. Do not assume the platform parses free text it does not parse.

Confirm with qualified counsel which expressions count as "reasonable" for your traffic, and whether your review pass meets the standard the order sets.

***

## Section 3 — Cross-channel scope of revocation

An SMS STOP in Orbit is already broader than SMS. When the inbound matcher fires, the suppression entry it writes is scoped `all` on the reply-capable phone number: the same entry gates SMS, WhatsApp, RCS, and, because the voice and dialer gates read the suppression list, your calls. See [Opt-Out & Suppression Lists](/compliance/opt-out-suppression) for the scope model. That default is what the FCC's cross-channel rule expects of the SMS entry point: the consumer's `STOP` ends the relationship reachable on that number, not just the SMS thread.

The entry points differ, and the differences are exactly where a 2025 tenant gets caught:

| Entry point | Scope written | Cross-channel result |
| - | - | - |
| STOP keyword on SMS/WhatsApp | `all` | Gates every channel on the number, including voice and dialer |
| Consent API (`opt_in: false`) | `all` | Same as above, regardless of identifier type |
| Preference Center opt-out | `all` | Same as above |
| Bulk CSV import, phone row | `all` by default | Same as above; a `channel` column overrides per row |
| Bulk CSV import, email row | `email` by default | Email only; a `channel` column overrides per row |

What you must configure for revocations that arrive **by phone call or by email**, where no keyword fires:

* **Phone-call revocations.** Record them through the Consent API with `opt_in: false`, or through the Preference Center, so the entry carries scope `all` and the voice gate stops dialing the number too. A note in the CRM that "customer asked to stop" is not a suppression entry and gates nothing.
* **Email-stated revocations.** A reply to your email saying "stop contacting me" is a revocation of the relationship under the order, not only of the email channel. The Consent API and the Preference Center write scope `all`; if you import such rows by CSV instead, the email default scope is `email`, so set the `channel` column explicitly to cover the channels the consumer revoked. Decide with counsel whether a channel-limited request (a true *partial* revocation, "no more texts but the statement emails are fine") is what the consumer asked for, and record the scope that matches their words.

The suppression list is where all of it lands and where every send gate reads; [Opt-Out & Suppression Lists](/compliance/opt-out-suppression) documents the ledger, the bulk import, and the export you use to prove it.

Confirm with qualified counsel how the cross-channel and partial-revocation rules apply to your consent relationships.

***

## Section 4 — The 10-business-day honor window and Orbit's timing

The order gives you at most 10 business days from the moment a revocation is communicated to the moment it is honored. Orbit's two paths measure very differently against that window, and you should know which of your revocations runs on which clock.

**The alias path honors immediately.** A STOP-alias match writes the suppression entry as part of handling the inbound message, and every send gate reads the same ledger before dispatch, dropping the suppressed address regardless of campaign, import, or API call. There is no batch window between the reply and the gate: the next send attempt after the entry exists is blocked. Revocations on this path comply with the 10-business-day window by a margin of days.

**The review path runs on your clock, and that clock is the one the order watches.** Every revocation a human handles, a non-alias text, a call, an email, starts a 10-business-day countdown at the moment the consumer communicated it, not at the moment your team got around to it. Configure the path so the countdown cannot be lost:

1. **Set an internal SLA well inside 10 business days.** A 48-hour target leaves margin for weekends, holidays, and a missed queue; a 9-day target does not.
2. **Name an owner for the review queue.** The inbox pass from Section 2 needs a responsible role and a documented procedure, or it silently becomes a 12-day queue.
3. **Use the Consent API for individual recordings, not the CSV import.** `POST /api/v1/compliance/consent` with `opt_in: false` writes the entry in one call the moment the revocation is spotted. The CSV import is the migration and bulk tool, not the daily path.
4. **Reconcile weekly.** Compare the revocation requests visible in your inbox and call logs against the suppression ledger's export, and chase every request with no ledger row. [Export Consent & Suppression Records](/compliance/consent-suppression-export) gives you the ledger side of that comparison.

The window is a floor the order enforces, not a target to aim at. Confirm with qualified counsel that your honor-window procedure, and its SLA, satisfy the rule as applied to your program.

***

## Section 5 — Evidence capture: what a 2025-era revocation record looks like

Revocation litigation in the reasonable-revocation era starts from the consumer's claim "I told them to stop on this date." Your defense is a record that answers five questions, and Orbit's record-keeping surfaces hold four of the five directly:

1. **Timestamp of the revocation as communicated.** The inbound message's arrival time in the conversation history; for a call, the call record. If your team records the revocation later, keep both timestamps: when the consumer said it, and when the suppression entry was written.
2. **Channel of the revocation.** SMS, WhatsApp, voice, or email; the channel the request arrived on is part of the story the cross-channel rule makes relevant.
3. **Verbatim text or utterance.** The conversation history preserves inbound replies verbatim; for voice, the call recording or written log your process keeps, subject to your recording-consent posture ([Recording Consent](/compliance/recording-consent)).
4. **Scope applied.** The suppression ledger entry carries its channel scope; scope `all` on the number is the entry that answers the cross-channel rule.
5. **Propagation lag.** The difference between (1) and the moment the entry took effect. On the alias path this is effectively zero; on the review path it is the number your SLA and your weekly reconciliation exist to keep inside 10 business days.

The two surfaces that assemble this into a defensible pack:

* [Consent Record Defense](/compliance/tcpa-consent-record-defense) — the consent ledger with basis, source, and per-event history, and how to build the evidentiary chain for one number when discovery arrives.
* [TCPA Evidence Pack in the Binder](/compliance/tcpa-evidence-binder) — the export surface that bundles your outbound posture evidence, quiet hours, DNC, send gates, suppression, for production.

Record revocations at the scope and timestamp the consumer's words carried, not the ones that were convenient to enter, because the record you keep is the record you produce. Confirm with qualified counsel what your revocation records must contain and how long to retain them.

***

## Related pages

* [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table) — the exact vocabulary the inbound matcher fails closed on, and how to add synonyms.
* [Opt-Out & Suppression Lists](/compliance/opt-out-suppression) — the scope model (`all` vs per-channel), the ledger, bulk import, and export.
* [Consent Management & Receipts](/compliance/consent-management) — recording consent and revocation per contact and channel, `opt_in: false` included.
* [TCPA Posture Guide](/compliance/tcpa-posture-guide) — assembling the full US marketing-SMS posture this page's controls slot into.
* [Consent Record Defense](/compliance/tcpa-consent-record-defense) and [TCPA Evidence Binder](/compliance/tcpa-evidence-binder) — the record-keeping surfaces a 2025 revocation record lands in.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.