Skip to main content

Baseline compliance posture for US SMS traffic

Most tenants run the same everyday traffic: order updates, support replies, marketing promotions — in short, garden-variety application-to-person (A2P) messaging. For that traffic class, US carriers demand one thing above all else: your 10DLC campaign must be approved as MARKETING or MIXED, and your consent, opt-out, and quiet-hours controls must be wired before you send. This page is the baseline posture for exactly that sender. It does not touch HIPAA or PCI-DSS; it is the every-day posture the healthcare and payments verticals layer on top of.
Everything on this page is tenant-owned. Orbit supplies the controls and defaults them open — you set them, you file the registrations, and the go-live decision stays yours. This page is not legal advice. Confirm your TCPA, CTIA, and state-law obligations with qualified counsel.

The two lanes: marketing vs. transactional

Carriers evaluate your traffic by use case, and every campaign submission declares one. The two you actually send fall into two lanes, and mixing them is the most common cause of rejection:
  • Transactional — account notifications, delivery updates, customer care, two-factor auth. Recipients expect the message; consent posture is usually informational; quiet-hours carve-outs are broader.
  • Marketing — promotions, offers, sales outreach. Recipients gave you prior express written consent; opt-out and quiet-hours posture is the strictest; carriers vet the opt-in flow hardest.
A MARKETING campaign on a brand whose traffic is actually CUSTOMER_CARE samples is the classic use-case mismatch rejection — file it under MARKETING from the first submission and the mismatch vanishes. The 10DLC rejections and re-vet guide decodes the exact codes when a filing comes back, and the wizard enforces the distinction between the lanes on the summary step.

1. HIPAA and PCI transaction patterns (when your traffic is not garden-variety)

If your recipient set includes patients or cardholders, this page is the layer under your vertical controls, not a replacement for them:
  • HIPAA-covered traffic layers a per-organization toggle, BAA tracking, PHI access logging, and data-retention enforcement on top of these controls — see HIPAA compliance controls. Toggle HIPAA mode before you put PHI in a message body; the 10DLC posture below stays the same.
  • PCI-adjacent traffic never puts a full PAN or card data in a message body. The pre-send policy scanner blocks a full credit-card number or Social Security number in the body before dispatch — see Pre-Send Policy Scanner & DLP. Use a secure link instead of inline card data; the DLP specifics section names the exact rules.
For the everyday sender — retail promotions, order updates, appointment reminders — the rest of this page is the complete baseline.

2. 10DLC rules on US SMS

US A2P traffic on standard 10-digit numbers runs through The Campaign Registry (TCR). The registration, rejection, and re-vet surfaces are the same for every sender; the wizard is the recommended path.
  • Register a brand — the legal entity TCR anchors the campaign to. For sole proprietors the anchor is a verified phone number by OTP; every other entity type files an EIN. See the 10DLC registration guide.
  • File the campaign as MARKETING — when your traffic is promotions, do not file CUSTOMER_CARE; file MARKETING (or MIXED only when the same sender genuinely serves both lanes). The wizard and the single-shot campaign endpoint validate the use case before submission; the 10DLC registration wizard guide names the full flow, and the preflight linter scores your samples for SHAFT-C wording, shortener links, and missing STOP wording before the filing fee is charged.
  • Keep throughput ahead of volume — the tier your vetting score grants caps your daily message count per number. When your volume approaches the cap, re-vet the brand; read the 10DLC rejections and re-vet guide for the re-vet and throughput endpoints and the per-carrier class map.

3. Suppression and quiet-hours gates

These two are the hard send-side controls. Both are tenant-owned; both default off; for the baseline posture you turn them on before go-live.

Suppression — never message an opted-out address

Suppression is the legal-duty list: STOP, unsubscribed, bounced, complained. Orbit treats it as a hard send-gate that halts the send before dispatch — no campaign, contact import, or API call bypasses it.
  • Seed the list before the first send — if you migrated from another platform, bulk-import the legacy suppression list once. The Opt-Out & Suppression Lists page spells out the import endpoint and per-row results.
  • Scope it correctly — scope all suppresses a phone number across every channel, including voice; email addresses scope to email. Use scope all for a phone STOP signal unless you intentionally want to keep the contact on voice.
  • Custom keywords on top of defaults — when a branded STOP alias (another language, another brand) should trigger suppression, add it to an opt-out list on the matching messaging service; the platform defaults (STOP, CANCEL, UNSUBSCRIBE and their help/start complements) are mandatory and always present — see Custom Opt-Out Keyword Lists.

Quiet hours — hold the send until it is allowed

Marketing to a sleeping recipient is the single most common TCPA complaint on US SMS. Orbit’s quiet-hours gate is a tenant-owned, per-channel toggle; the only hard platform rule is the federal voice window, which does not apply to SMS. For SMS, the gate is yours:
  • Set an org-wide window — enable the sms channel on the org gate and accept the platform window 08:00–21:00 recipient-local, or narrow it to your own regime. The Quiet hours: org-wide channel gates page maps the per-channel surface and the fallback window drip campaigns inherit.
  • Pass the recipient timezone when you have it — gate resolution is recipient-local; for +1 numbers the NANP area code resolves the timezone, and an explicit hint from your CRM beats the fallback. Read the same guide for the unknown_timezone_policy choice when a timezone cannot be resolved.
  • Keep transactional traffic exempt — the transactional carve-out means an OTP or account notice does not pause at the gate. A marketing lane without the carve-out never helps anyone; keep the distinction when you tag sends.

Run this once per sending brand before go-live, then again on each new campaign. Assign an owner to every checkbox; the sign-off means the named owner confirmed it.
  • Opt-in captured and provable. The opt-in moment is recorded per contact with the source (web form, keyword, point-of-sale). When the opt-in is a handshake, a confirmed double opt-in row exists for the (contact, channel) pair. Owner: Compliance.
  • Suppression list seeded and honoured. Legacy opt-outs imported once; every send passes the suppression gate; STOP replies land on the list in real time. Owner: Operations.
  • Quiet hours enabled on the marketing lane. The sms channel gate is on, with a recipient-local window and the transactional carve-out preserved. Owner: Operations.
  • Pre-send policy scanner mode chosen. The organization runs warn (default, findings recorded) or strict (blocking verdicts reject the send); SHAFT, shortener, spam-score, and DLP findings are wired to your review queue. Owner: Compliance/Engineering.
  • 10DLC campaign registered as the right use case. Brand approved, campaign filed as MARKETING (or MIXED only where both lanes genuinely coexist), sample messages match the actual traffic, and the per-day throughput tier covers your volume. Owner: Operations.
  • Evidence retained. Opt-in records, suppression additions, and DLRs are exportable for audit; retention is set per your Data Retention Policy. Owner: Compliance.
Compliance posture is your organization’s decision, and the go-live call is yours. This checklist is the baseline posture, never a substitute for legal review of your TCPA, CTIA, or state obligations.