Theory Road.
← PerspectivesSystems & Integration

A2P 10DLC Registration for Small Businesses, Step by Step.

Every text your business sends from a normal 10-digit number passes through the A2P 10DLC framework. Here is what the brand and campaign registrations ask for, how to get them approved the first time, and what to fix when they bounce back.

By Theory RoadSeptember 21, 20269 min read

A2P 10DLC registration is the process of telling the US carriers who your business is and what it intends to text from a standard 10-digit phone number. You register a Brand (legal business name, EIN, address, website) and one or more Campaigns (use case, sample messages, how people opt in, how they opt out) through your messaging provider, and until that is approved your texts are blocked or heavily filtered. This guide covers what the framework is, who registers it for you, what each form asks for, why applications get rejected, and the consent language that passes review.

We have registered brands and campaigns for our own numbers and walked service businesses through it inside their CRM and call tracking tools. The paperwork is not hard. The failures come from a handful of predictable gaps, and almost all of them are on the website, not in the form.

What A2P 10DLC Is.

Definition: A2P 10DLC is the carrier framework for application-to-person messaging sent from standard 10-digit long codes in the United States. Application-to-person means a system sent the text, whether that is a CRM workflow, an appointment reminder, a missed call auto-reply or a bulk campaign. Person-to-person is one human texting another from a handset, and that is not what this covers.

Before the framework, businesses texted from ordinary local numbers with no registration and the carriers treated all of it with suspicion. Now a registered business gets a known identity and a trust score, and traffic from that identity is delivered with predictable throughput. Traffic from an unregistered number is filtered or blocked outright, and the sending platform will usually still show the message as sent, which is what makes the failure so hard to see.

Two neighbors worth knowing so you do not confuse the processes. Toll-free numbers have their own verification process, separate from 10DLC. Short codes (five or six digits) are a different product with their own approval. If your tool gave you a local number, you are in 10DLC.

Who Registers It for You.

Registration goes through your provider, and there are two kinds. Direct messaging providers such as Twilio, Telnyx and Bandwidth expose the brand and campaign forms in their console; you fill them in and they submit to the registry. Tools that bundle texting, such as GoHighLevel, HubSpot with the SMS add-on and CallRail, register on your behalf: they collect the same information in their own settings screens and file it under their provider relationship.

In both cases you are answering the same questions and the reviewer is applying the same standards. The bundled tools hide some fields and pick sensible defaults, which is convenient until a rejection comes back and the reason is vague. When that happens, go to the tool's registration status page first; the rejection reason is usually there in the registry's own wording.

Sole proprietors without an EIN have a separate low-volume path that registers on a person's name and a verified mobile number instead of a tax ID. It is capped hard on volume and on the number of phone numbers you can attach, but for a one-person business sending confirmations it is the right door, and it avoids a mismatch rejection on a business that has no tax record to match.

Brand Registration: What It Asks For.

  • Legal business name, exactly as it appears on your EIN letter or state filing. Not the DBA, not the website name. Mismatch is the top brand-level rejection.
  • EIN (tax ID). The registry checks it against public records; the name you type and the name on file have to agree.
  • Business address, the one on your tax or state records.
  • Website. A live site with a privacy policy that mentions SMS. A parked page or a social profile will not pass.
  • Business type and vertical. Pick the accurate one; the reviewer will look at the site.
  • A contact person with a business email on the same domain as the website.

Vetting is a second step some providers offer or require, in which a third party scores the brand. A vetted brand gets higher daily message caps and better throughput per number; an unvetted brand gets the minimum tier. If you send more than a trickle, ask your provider how to request vetting and what it costs, because the caps on the lowest tier surprise businesses that run appointment reminders in batches.

Campaign Registration.

The campaign describes what you will send. Each campaign has a use case (customer care, marketing, mixed, account notifications and so on), a description of the message flow, sample messages, a description of how a person opts in, and how opt-out is handled. One brand can hold several campaigns, and a service business usually needs one mixed campaign that covers confirmations, follow-ups and the occasional promotion.

Sample messages are read literally. They should look like what you will actually send, with the business name in them, and at least one should include opt-out language such as "Reply STOP to opt out". The opt-in description has to explain where the number is collected and what the person agreed to, and it has to match what the reviewer will find on your website. Reviewers open the page you name.

The three registration paths and what they are for
PathWho it is forWhat it requiresThroughput and capsTypical timeline
Sole proprietorA one-person business without an EINName, address, verified mobile number, one campaignLowest tier, one numberDays
Standard brand, unvettedMost small businesses with an EINBrand form, website with SMS privacy language, one or more campaignsBase tier caps set by the carriersDays to weeks
Standard brand, vettedBusinesses sending at volume or needing higher capsEverything above plus third-party vettingHigher caps based on the vetting scoreWeeks, with vetting adding time
The reviewer does not read your intentions. They read your website, your form and your sample messages, in that order.
Fix the website first.
Add a privacy policy section that says you collect phone numbers for SMS, what you send, that consent is not a condition of purchase, that message and data rates may apply, how to opt out (STOP) and get help (HELP), and that numbers are not shared with third parties for marketing. Put the consent disclosure on every form that collects a phone number.
Collect the brand facts.
EIN letter, legal name, registered address, website URL, business email on the domain. Confirm the name on the EIN letter matches what you will type, character for character.
Open the registration in your provider.
In Twilio, Telnyx or Bandwidth this is in the messaging or compliance section of the console. In GoHighLevel, HubSpot or CallRail it is under phone or SMS settings with a registration status panel. Submit the brand and wait for it to show approved before starting the campaign.
Write the campaign to match the messages.
Pick the use case that matches what you will send. Write three to five sample messages with the business name and STOP language. Describe opt-in as it happens on your form, and paste the URL of that form.
Attach the numbers.
Associate every number that will send under the campaign. A number that is not attached to an approved campaign is unregistered even if the brand is approved.
Watch the status and read the rejection.
Check the status panel daily. If a rejection comes back, read the reason in the registry's wording, fix the exact thing named, and resubmit. Do not resubmit unchanged.
Test with a real handset.
Send a message from each registered number to a phone on a major carrier and confirm delivery. Then switch the automations on.

Why Registrations Get Rejected.

  • The website's privacy policy does not mention SMS. This is the most common campaign rejection and the easiest fix.
  • The form that collects the number has no opt-in language. A phone field with no disclosure and no checkbox does not support the consent the campaign claims.
  • The business name does not match EIN records. A DBA, an abbreviation or a missing "LLC" is enough.
  • Sample messages have no opt-out language, or do not identify the business.
  • The use case does not match the samples: a customer care campaign with a promotion in the samples.
  • The website is a landing page, a social profile or under construction, so the reviewer cannot verify the business.

Consent has to appear where the number is collected. On a web form, that means a disclosure next to the phone field, and for marketing messages an unchecked checkbox the person ticks. Wording we use, adjusted to the business: "By providing your phone number and checking this box, you agree to receive text messages from [Business] about your inquiry and our services. Message frequency varies. Message and data rates may apply. Reply STOP to opt out, HELP for help. See our Privacy Policy."

On a phone call or in person, consent is recorded in the CRM with the date and the method, and the campaign's opt-in description should say so. On an inbound text, the person's own message is the opt-in for a reply. Our TCPA compliance checklist covers how these tie to the legal side, which is separate from carrier registration but asks for the same evidence.

Timelines and What to Do While You Wait.

Approval times vary from days to weeks and depend on the path, whether vetting is involved, and how many times you resubmit. We do not quote a number because it moves. What is stable: brand approval comes before campaign approval, and campaign approval before the numbers are usable, so start the whole thing well before the day you planned to turn on texting.

While waiting, do not send from the unregistered numbers, even a little; the filtering damages reputation and the carriers remember. Build the automations and the copy. Get the speed to lead call flow working on voice, which needs no registration. Set up the STOP handling and the suppression list so the first opt-out is honored automatically. And keep the confirmation emails from the provider; if a rejection is wrong, the appeal goes faster with the original submission in hand. If texting is part of a wider lead system, sequence the build so registration is the first ticket, not the last.

What Usually Goes Wrong After Approval.

  • A new number is added to the phone system and never attached to the campaign, so it sends unregistered.
  • The website is redesigned and the privacy policy or the form disclosure disappears. Registrations can be re-reviewed.
  • The messages drift from the registered use case, for example a customer care campaign that starts sending promotions.
  • Daily caps on the unvetted tier are hit by a reminder batch and the tail of the batch never delivers.
  • STOP replies are received by the platform but the CRM keeps the contact in a sequence that sends by another route.

How long does A2P 10DLC registration take?

It varies from days to weeks. Brand approval is usually the faster step and campaign review the slower one, with vetting and any resubmission adding time. Start registration as soon as you decide to text, keep the status panel in view, and do not send from the numbers until the campaign shows approved.

Do I need to register if my CRM sends the texts?

Yes. Tools such as GoHighLevel, HubSpot and CallRail register on your behalf, but they still need your legal business name, EIN, address, website and use case, and the same review applies. Look for a registration or compliance status panel in the tool's phone settings and complete it before enabling any texting automation.

Can a sole proprietor register for A2P 10DLC without an EIN?

Yes. There is a separate sole proprietor path that registers on the person's name, address and a verified mobile number instead of a tax ID. It has the lowest throughput and allows only one number, but for a one-person business sending confirmations and replies it is the correct route and avoids a name-to-EIN mismatch rejection.

Why was my 10DLC campaign rejected?

The usual reasons are a privacy policy with no SMS language, a form that collects phone numbers without opt-in wording, a business name that does not match EIN records, and sample messages without opt-out language. Read the rejection reason in the registry's own words on your provider's status page, fix that exact item, and resubmit.

Work with us

Let’s talk about what’s next.

A short note on where the business is and where it needs to go. A senior partner replies within one business day.

t@theoryroad.com

Your briefUnder a minute

Tell us what you need.

Read by a person. Never sold, never added to a list.