Baseline compliance posture for US SMS traffic
Most tenants run the same everyday traffic: order updates, support replies, marketing promotions — in short, garden-variety application-to-person (A2P) messaging. For that traffic class, US carriers demand one thing above all else: your 10DLC campaign must be approved asMARKETING or MIXED, and
your consent, opt-out, and quiet-hours controls must be wired before you
send. This page is the baseline posture for exactly that sender. It does not
touch HIPAA or PCI-DSS; it is the every-day posture the healthcare and payments
verticals layer on top of.
Everything on this page is tenant-owned. Orbit supplies the controls and
defaults them open — you set them, you file the registrations, and the
go-live decision stays yours. This page is not legal advice. Confirm your
TCPA, CTIA, and state-law obligations with qualified counsel.
The two lanes: marketing vs. transactional
Carriers evaluate your traffic by use case, and every campaign submission declares one. The two you actually send fall into two lanes, and mixing them is the most common cause of rejection:- Transactional — account notifications, delivery updates, customer care, two-factor auth. Recipients expect the message; consent posture is usually informational; quiet-hours carve-outs are broader.
- Marketing — promotions, offers, sales outreach. Recipients gave you prior express written consent; opt-out and quiet-hours posture is the strictest; carriers vet the opt-in flow hardest.
MARKETING campaign on a brand whose traffic is actually CUSTOMER_CARE
samples is the classic use-case mismatch rejection — file it under
MARKETING from the first submission and the mismatch vanishes. The
10DLC rejections and re-vet guide decodes
the exact codes when a filing comes back, and the wizard enforces the
distinction between the lanes on the summary step.
1. HIPAA and PCI transaction patterns (when your traffic is not garden-variety)
If your recipient set includes patients or cardholders, this page is the layer under your vertical controls, not a replacement for them:- HIPAA-covered traffic layers a per-organization toggle, BAA tracking, PHI access logging, and data-retention enforcement on top of these controls — see HIPAA compliance controls. Toggle HIPAA mode before you put PHI in a message body; the 10DLC posture below stays the same.
- PCI-adjacent traffic never puts a full PAN or card data in a message body. The pre-send policy scanner blocks a full credit-card number or Social Security number in the body before dispatch — see Pre-Send Policy Scanner & DLP. Use a secure link instead of inline card data; the DLP specifics section names the exact rules.
2. 10DLC rules on US SMS
US A2P traffic on standard 10-digit numbers runs through The Campaign Registry (TCR). The registration, rejection, and re-vet surfaces are the same for every sender; the wizard is the recommended path.- Register a brand — the legal entity TCR anchors the campaign to. For sole proprietors the anchor is a verified phone number by OTP; every other entity type files an EIN. See the 10DLC registration guide.
- File the campaign as
MARKETING— when your traffic is promotions, do not fileCUSTOMER_CARE; fileMARKETING(orMIXEDonly when the same sender genuinely serves both lanes). The wizard and the single-shot campaign endpoint validate the use case before submission; the 10DLC registration wizard guide names the full flow, and the preflight linter scores your samples for SHAFT-C wording, shortener links, and missing STOP wording before the filing fee is charged. - Keep throughput ahead of volume — the tier your vetting score grants caps your daily message count per number. When your volume approaches the cap, re-vet the brand; read the 10DLC rejections and re-vet guide for the re-vet and throughput endpoints and the per-carrier class map.
3. Suppression and quiet-hours gates
These two are the hard send-side controls. Both are tenant-owned; both default off; for the baseline posture you turn them on before go-live.Suppression — never message an opted-out address
Suppression is the legal-duty list: STOP, unsubscribed, bounced, complained. Orbit treats it as a hard send-gate that halts the send before dispatch — no campaign, contact import, or API call bypasses it.- Seed the list before the first send — if you migrated from another platform, bulk-import the legacy suppression list once. The Opt-Out & Suppression Lists page spells out the import endpoint and per-row results.
- Scope it correctly — scope
allsuppresses a phone number across every channel, including voice; email addresses scope toemail. Use scopeallfor a phone STOP signal unless you intentionally want to keep the contact on voice. - Custom keywords on top of defaults — when a branded STOP alias
(another language, another brand) should trigger suppression, add it to an
opt-out list on the matching messaging service; the platform defaults
(
STOP,CANCEL,UNSUBSCRIBEand their help/start complements) are mandatory and always present — see Custom Opt-Out Keyword Lists.
Quiet hours — hold the send until it is allowed
Marketing to a sleeping recipient is the single most common TCPA complaint on US SMS. Orbit’s quiet-hours gate is a tenant-owned, per-channel toggle; the only hard platform rule is the federal voice window, which does not apply to SMS. For SMS, the gate is yours:- Set an org-wide window — enable the
smschannel on the org gate and accept the platform window 08:00–21:00 recipient-local, or narrow it to your own regime. The Quiet hours: org-wide channel gates page maps the per-channel surface and the fallback window drip campaigns inherit. - Pass the recipient timezone when you have it — gate resolution is
recipient-local; for +1 numbers the NANP area code resolves the timezone,
and an explicit hint from your CRM beats the fallback. Read the same guide
for the
unknown_timezone_policychoice when a timezone cannot be resolved. - Keep transactional traffic exempt — the transactional carve-out means an OTP or account notice does not pause at the gate. A marketing lane without the carve-out never helps anyone; keep the distinction when you tag sends.
4. Baseline checklist — tenant-owned, not legal advice
Run this once per sending brand before go-live, then again on each new campaign. Assign an owner to every checkbox; the sign-off means the named owner confirmed it.- Opt-in captured and provable. The opt-in moment is recorded per
contact with the source (web form, keyword, point-of-sale). When the opt-in
is a handshake, a
confirmed double opt-in row exists for the
(contact, channel)pair. Owner: Compliance. - Suppression list seeded and honoured. Legacy opt-outs imported once; every send passes the suppression gate; STOP replies land on the list in real time. Owner: Operations.
- Quiet hours enabled on the marketing lane. The
smschannel gate is on, with a recipient-local window and the transactional carve-out preserved. Owner: Operations. - Pre-send policy scanner mode chosen.
The organization runs
warn(default, findings recorded) orstrict(blocking verdicts reject the send); SHAFT, shortener, spam-score, and DLP findings are wired to your review queue. Owner: Compliance/Engineering. - 10DLC campaign registered as the right use case. Brand approved,
campaign filed as
MARKETING(orMIXEDonly where both lanes genuinely coexist), sample messages match the actual traffic, and the per-day throughput tier covers your volume. Owner: Operations. - Evidence retained. Opt-in records, suppression additions, and DLRs are exportable for audit; retention is set per your Data Retention Policy. Owner: Compliance.
Related references
- Assemble your tenant’s compliance posture — how profiles, country rules, and vertical packs compose (the assembly this page plugs into).
- 10DLC registration — brand and campaign filing, use-case codes, throughput tiers, and the preflight linter.
- 10DLC registration wizard — the recommended save-and-resume operator flow.
- 10DLC rejections and re-vet — decode rejection codes, re-vet the brand, read throughput classes.
- Quiet hours: org-wide channel gates — the per-channel surface, fallbacks, and timezone resolution.
- Opt-Out & Suppression Lists — the import endpoint and how suppression is scoped.
- Pre-Send Policy Scanner & DLP — verdicts, scan mode, and the rules each channel runs.
- HIPAA compliance controls and PCI DSS posture — when a sender carries patient or cardholder data, this page is the layer underneath.