> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Omnichannel fallback compliance matrix — TCPA vs DNC vs registration per channel

> The one-page matrix for weighing the three compliance planes — voice dialing windows, sender registration, and opt-in regime — across SMS, voice, WhatsApp, email, and RCS before you pick a primary or fallback channel.

# Omnichannel fallback compliance matrix

Choosing a primary channel is not only a reach and cost decision. Each
channel carries a different compliance burden, and a fallback chain only
works when the next channel in the chain is one your tenant is actually
permitted to use. This page consolidates the compliance comparison that
otherwise lives scattered across
[Country Compliance Requirements](/compliance/country-requirements),
[STIR/SHAKEN Attestation Posture](/compliance/attestation), and
[Outbound send gating](/concepts/send-gating-and-quiet-hours). Read it
once before you assemble a fallback chain; then dive into the deep page
for the one or two planes your traffic actually touches.

<Warning>
  Every control described here is tenant-owned. Orbit carries the settings
  and enforces what you set; which laws apply to your traffic and what
  posture is adequate is your call. This page is **not legal advice** — the
  sole exception is the federal TCPA voice dialing window for US recipients,
  which is a platform guard you cannot toggle.
</Warning>

## 1. The three planes you weigh per channel

Before you pick a primary or fallback channel, weigh three independent
planes. A channel can clear one plane and fail another — the matrix below
scores each channel on all three.

* **Registration plane** — what you must register before the first send:
  US 10DLC brand and campaign, DLT (India), per-country Sender-ID
  registration, toll-free verification, or nothing. Until registration
  clears, the channel is either blocked (fail-closed, as with Sender-ID
  countries) or degraded (unregistered 10DLC traffic gets filtered upstream).
* **Window plane** — when you may send, recipient-local: the federal TCPA
  voice window plus state mini-TCPA overlays on US voice, or the per-channel
  quiet-hours windows you configure yourself everywhere else.
* **Consent plane** — the opt-in regime the traffic must satisfy: TCPA
  opt-in for US SMS marketing, GDPR prior-consent in the EU, CAN-SPAM and
  CASL for email, Meta's opt-in plus template rules on WhatsApp.

Registration is lead time, windows are a send-time gate, and consent is
the posture you must be able to evidence. All three are your responsibility
to set; Orbit enforces the configuration, it does not decide for you.

## 2. The per-channel matrix

One row per channel: the registration burden, the window constraints, the
opt-in regime, and any attestation layer.

| Channel      | Registration plane                                                                                                                                                                                                       | Window plane                                                                                                                                                                                                                                                                            | Consent plane                                                                                                                                                                      | Attestation                                                                                                                                                                                               |
| ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **SMS**      | US: 10DLC brand + campaign. India: DLT. Elsewhere: per-country [Sender-ID registration](/compliance/sender-id-registration) where required (fail-closed until `approved`). Toll-free US numbers: toll-free verification. | Your per-channel quiet hours (default off). No federal SMS window.                                                                                                                                                                                                                      | TCPA opt-in for US marketing; country rules per [Country Compliance Requirements](/compliance/country-requirements) elsewhere.                                                     | None.                                                                                                                                                                                                     |
| **Voice**    | None for the number itself; ownership determines your attestation level.                                                                                                                                                 | **Hard platform guard:** the federal TCPA window on campaign/dialer voice to US recipients, intersected with state mini-TCPA overlays (FL, MS, OK, LA, AL, AR, WV). No tenant toggle, fail-closed on an unresolvable recipient timezone. Your own per-channel quiet hours stack on top. | DNC posture per your scrub settings ([DNC Scrubbing](/compliance/dnc-scrub)) plus consent for autodialed/prerecorded calls.                                                        | STIR/SHAKEN: owned DIDs attest A, leased pool numbers B, anything else C. See [Attestation Posture](/compliance/attestation); [branded calling](/compliance/branded-calling) is an optional layer on top. |
| **WhatsApp** | Meta Business verification, approved display name, approved message templates per category.                                                                                                                              | Your per-channel quiet hours only.                                                                                                                                                                                                                                                      | Meta opt-in; business-initiated sends outside the 24-hour session window must use an approved template.                                                                            | None.                                                                                                                                                                                                     |
| **Email**    | DNS-based, not carrier-based: SPF, DKIM, and DMARC verified per sending identity.                                                                                                                                        | Your per-channel quiet hours only.                                                                                                                                                                                                                                                      | [CAN-SPAM](/compliance/can-spam) (US), [CASL](/compliance/casl-canada-anti-spam) (Canada), GDPR prior-consent (EU) — see the [GDPR posture guide](/compliance/gdpr-posture-guide). | None.                                                                                                                                                                                                     |
| **RCS**      | Verified agent profile per brand; carrier-by-carrier enablement.                                                                                                                                                         | Your per-channel quiet hours only.                                                                                                                                                                                                                                                      | Opt-in, with a per-recipient capability check at send time.                                                                                                                        | Brand verification is the attestation analogue: a verified agent renders with your brand identity.                                                                                                        |

The per-country rows behind the SMS column come from
`GET /api/v1/compliance/country-rules`, which is the read-only reference
the send-time gates consult — query it per market before you commit a
channel plan.

## 3. The fallback decision table

A fallback hop is legal to configure only when the destination channel
clears all three planes for that recipient. Run these checks in order;
the first no stops the chain.

| Situation                                                                                 | Candidate fallback | Checks before the hop                                                                                                                                                                                                                                                                                                                                                  |
| ----------------------------------------------------------------------------------------- | ------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SMS blocked for registration (Sender-ID country pending, 10DLC campaign not yet approved) | Voice              | Is the recipient in a TCPA-window jurisdiction? For US recipients the federal window applies — the hop is refused outside the window regardless of tenant settings. What attestation level will the call carry? A voice fallback from an unowned caller ID attests C and lands in robocall screening; weigh the owned-DID (A) versus lease (B) trade before you route. |
| Email bouncing (hard bounce, suppressed domain)                                           | SMS pick-up        | Is there an SMS opt-in on the contact? TCPA opt-in status is per contact — query it through [Consent Management](/compliance/consent-management) before the hop, and expect the [opt-out suppression](/compliance/opt-out-suppression) list to drop the send anyway if the phone number is suppressed. An email relationship never implies SMS consent.                |
| WhatsApp template rejected or not yet approved                                            | SMS                | Registration plane only: does an approved 10DLC campaign / registered Sender ID cover the destination? The same opt-in posture carries if the contact opted into your program; the channel shift re-runs the destination channel's gates.                                                                                                                              |
| RCS capability check says not-capable                                                     | SMS                | The capability check is per recipient; the SMS hop re-runs SMS registration and opt-in checks. Chain heads that fail capability should move the whole send, not retry RCS.                                                                                                                                                                                             |

Two rules hold on every hop:

1. **Consent is per channel.** Opting into email does not opt the contact
   into SMS; a fallback hop re-runs the destination channel's opt-out,
   suppression, and quiet-hours gates — the same chain documented in
   [Outbound send gating](/concepts/send-gating-and-quiet-hours).
2. **The voice window cannot be configured away.** Any chain that ends in
   US voice is bounded by the federal TCPA window. Plan chains that
   degrade to SMS or email rather than assuming voice is always available.

## 4. Where each control lives

Per channel, per plane — the surface where you set the posture:

* **Quiet hours per channel** — `settings → quiet_hours.<channel>.enabled`
  via `PUT /api/v1/settings/general`; the full gate order is on
  [Outbound send gating](/concepts/send-gating-and-quiet-hours) and the
  window mechanics on [Send Gates](/compliance/send-gates).
* **Opt-out and suppression** — STOP keywords, the Consent API, and bulk
  import; scope decides breadth (`all`-scope entries gate voice too).
  Details on [Opt-Out & Suppression Lists](/compliance/opt-out-suppression).
* **Sender registration** — `POST /api/v1/compliance/sender-id-registrations`
  per country; the per-market rules it enforces are readable through
  `GET /api/v1/compliance/country-rules`.
* **Attestation target and reporting** — Settings → Compliance →
  Attestation; fields and semantics on
  [Attestation Posture](/compliance/attestation).
* **DNC scrub** — org setting `dnc_sync_enabled`, queried through
  `GET /api/v1/compliance/dnc/check`;
  [DNC Scrubbing](/compliance/dnc-scrub) covers the fail-open posture.

The toggle map across all of these — defaults, fail-open versus
fail-closed per surface — is the
[tenant compliance posture overview](/compliance/posture-overview).

## 5. Two worked channel-selection examples

**US mixed traffic — 10DLC SMS primary, owned-DID voice fallback.** A
tenant ships order-status notifications to US recipients and wants a voice
fallback for "delivery exception" alerts. Primary is SMS on an approved
10DLC campaign; the fallback chain ends in voice from DIDs the tenant
owns, so originations attest A and clear the branded-calling screen when
enabled. Every hop into voice is still bounded by the federal window — an
exception alert at 22:30 recipient-local holds until the window opens;
the chain falls back to holding the SMS rather than dialing. Setup order:
register the 10DLC brand and campaign first (lead time), then set
per-channel quiet hours, then attach the owned DIDs and declare the
attestation target.

**EU traffic — Sender-ID SMS, email with GDPR prior-consent.** A tenant
runs lifecycle notifications across France and Germany. SMS rides
registered alphanumeric Sender IDs where the corridor recommends them
(FR per the country-rules reference), email handles long-form drift
(templates, invoices) under GDPR prior-consent evidenced through the
Consent API. The fallback email→SMS hop only runs for contacts whose
consent record carries the SMS channel — otherwise the hop is refused and
the send waits for the email retry window. Registration lead time is
days per Sender-ID country; the DNS identity (SPF/DKIM/DMARC) clears the
same week, so email opens first and SMS joins as registrations land.

## See also

* [Country Compliance Requirements](/compliance/country-requirements) — the per-country sender-type and registration reference
* [STIR/SHAKEN Attestation Posture](/compliance/attestation) — target levels, downgrade reporting, delegate certificates
* [Outbound send gating](/concepts/send-gating-and-quiet-hours) — the ordered gate chain every send walks
* [Cross-channel fallback](/concepts/cross-channel-fallback) — the chain model this matrix feeds
* [Fallback and cascade planes](/concepts/fallback-and-cascade-planes) — where fallback chains execute
* [Tenant compliance posture overview](/compliance/posture-overview) — the toggle map across every compliance surface
* [Consent Management](/compliance/consent-management) — per-contact, per-channel consent records
* [Send Gates](/compliance/send-gates) — quiet-hours windows and the emergency stop
