Compliance

What is CTIA, and what are its messaging principles?

CTIA is the trade association for the United States wireless industry. Its Messaging Principles and Best Practices is the document that sets out how business messaging on US carrier networks is expected to behave, and it is the reference the messaging ecosystem points at when it talks about "the CTIA guidelines".

This page describes what that document asks of senders. It is not legal advice, and CTIA guidance is not law in any case; the legal layer for US messaging is the TCPA and the state statutes alongside it.

A note on sourcing. CTIA publishes the Principles only as a PDF, and this page therefore describes its requirements rather than quoting them. It is written against the edition CTIA published in May 2023. An earlier edition is still served at its own URL and is what a good many inbound links point at, so check the date on the copy you are reading. Whether a newer edition has appeared since is not something this page can tell you: ctia.org renders in the browser and serves almost no text to a fetch, so the two links above are the documents, not a claim about which is current.

Is this a law?

No, and the distinction matters in both directions.

CTIA is a trade association. Nothing in the Principles carries a penalty, no regulator enforces it, and the document itself disclaims giving legal guidance. What gives it teeth is that carriers and the aggregators between you and them apply it as an operating standard: a sender who ignores it does not get fined, they get filtered.

That produces the situation senders find confusing. A campaign can satisfy every legal requirement and still be blocked, because the filtering layer is enforcing an industry practice rather than a statute. It is also why "we have consent" is not a complete answer to a delivery problem. Why SMS messages get filtered by carriers covers what that looks like from the API side.

What does it ask of a sender?

Three things about consent, and a short list of practices it rules out.

A clear and conspicuous call to action. The invitation to opt in has to tell the person what they are signing up for: what the programme is, which number or short code messages will come from, who is actually sending them, the opt-in terms and any fees, and how often to expect messages. The point is that consent is informed, so an opt-in buried in terms of service does not qualify.

Opt-in before the first message. Messages should be sent only after the person has opted in, and the document lists the mechanisms that demonstrate it: entering a number on a website, tapping a button on a mobile page, texting a keyword to a short code, or starting the conversation themselves. Recurring programmes are expected to confirm the opt-in, and an opt-in is per campaign rather than a general permission.

Opt-out that works, in more than one way. People should be able to stop messages at any time, and senders are expected to support several routes, including phone, email and text. Each message should say how to stop it, and an opt-out should get exactly one confirmation message and then silence.

The practices ruled out are as informative as the requirements:

PracticeWhy it is called out
Rented, sold, or shared opt-in listsConsent is not transferable; senders are expected to build their own
SnowshoeingSpreading a campaign across many numbers to dilute per-number signals
Grey routesSending over paths carriers have not authorised for business messaging
Ignoring deactivation filesNumbers change hands, so consent expires with the subscriber

That last one is worth pausing on. The document asks senders to process telephone number deactivation data regularly and remove deactivated numbers, which is a maintenance obligation rather than a consent one, and the one most often skipped. A number reassigned to somebody new turns yesterday's consented recipient into today's complaint.

How does this relate to 10DLC registration?

Registration is the mechanism the ecosystem built to make this enforceable.

The Principles describe how a sender should behave. Registration is how a carrier knows who you are before deciding whether to carry your traffic: your organisation and each campaign are registered, with the call to action and opt-out language among the details submitted. So the two fit together, with the Principles as the standard and registration as the identity layer that lets carriers apply it per sender rather than per message.

That is also why unregistered traffic on a long code is filtered so aggressively. 10DLC registration covers the process on Bird.

What should I take from it?

Treat it as the delivery layer of compliance rather than the legal one.

The practical shape of a US messaging programme is three requirements stacked on each other, and satisfying one says nothing about the others:

  • The law, which decides whether you may send at all. Consent, timing and revocation, from the TCPA.
  • The industry standard, which decides whether carriers will carry it. The Principles, plus registration.
  • The platform's own rules, which decide whether your provider will accept it. Bird's are in abuse and compliance.

The full document is short enough to read in one sitting, and worth reading in full if you are building a messaging programme, because the parts that catch senders out are the operational ones rather than the consent ones.

Bouw op hetzelfde netwerk.

Een test-API-key is direct beschikbaar. Productietoegang wordt ontgrendeld zodra u een betaalmethode toevoegt en een afzender verifieert.

Begin met één kanaal.
Voeg de rest toe wanneer je er klaar voor bent.

Een test-API-key is direct beschikbaar. Productietoegang wordt ontgrendeld zodra je een betaalmethode toevoegt en een afzender verifieert.

Gebruik je Claude Code, Cursor of Codex? Kopieer een setup-prompt en je agent installeert de Bird CLI en skills voor je. Kies de jouwe:

Cursor