Opt-In Text Message Compliance: The Complete Guide for Salesforce Teams
As a US-based business that uses text messages to communicate with customers, opt-in compliance is non-negotiable, as it forms the backbone of your messaging initiative.
Each opt-in text message you send out has to have a documented proof of consent that you received from your recipient. It cannot simply be a hypothetical or inferred consent; rather, you must prove that you collected permission to contact the person, including how you did so.
Failure to comply with opt-in requirements can be very costly for you, especially since intentional TCPA violations can cost you up to $1,500 per message under penalty of law. That means that sending out 500 messages to a group of contacts may expose you to $750,000 worth of liability.
In this guide, you’ll learn how to implement an opt-in SMS process that is legally compliant. You’ll also see how MessageBlink streamlines compliance efforts within Salesforce.
Who Regulates SMS in the US?
Before diving into process, it helps to understand who sets the rules:
FCC (Federal Communications Commission) — oversees all electronic communication, including text messaging
TCPA (Telephone Consumer Protection Act) — sets the legal standard for consent, message delivery, and opt-out handling
CTIA & MMA — industry bodies that define best practices around opt-in flows, disclosure language, and opt-out mechanics
Together, these form the compliance framework every US-based SMS program must operate within.
4 Steps to SMS Opt-In Compliance
Step 1: Collect Clear, Verifiable Consent
All opt in text messages that are sent need to be authorized. The authorization needs to:
Be explicit – cannot be implied, grouped with any other agreement or part of TOS
Be informed – consumer is fully aware they are opting into receiving text messages from your company
Be voluntary – consent cannot be used as an obligation in order to use the product/service/offer
Be time-stamped – recorded along with the date when the opt in was submitted
According to TCPA regulations, all evidence of consent must be held for at least 4 years.
Accepted methods for collecting SMS opt-in consent:
| Method | Valid? | Additional Step Needed? | Notes |
| Checkbox on web form | ✅ Yes | Double opt-in recommended | Include clear opt-in language beside the checkbox |
| Keyword text (e.g. JOIN) | ✅ Yes | No | Direct consent from the device owner |
| Paper or event sign-up | ✅ Yes | Double opt-in recommended | Follow up with SMS confirmation to verify device ownership |
| Email or digital form | ✅ Yes | Double opt-in recommended | Send a confirmation text to complete the opt-in |
The MessageBlink platform records each opt-in activity automatically, including the origin, the method used, and the exact time stamp in the Salesforce Contact or Lead record. Should there be any dispute regarding the consent, the relevant record can be retrieved within seconds.
Step 2: Choose the Right Opt-In Flow — Single or Double
Not all opt-ins are equal. The method you use to capture consent determines whether a single or double opt-in is appropriate.
| Opt-In Type | When to Use | What It Looks Like |
| Single opt-in | Consent initiated by the user via SMS | User texts JOIN to your number; consent is assumed from device owner |
| Double opt-in | Consent collected via form, email, or event | You send a follow-up message asking the user to reply YES to confirm |
Single opt-in applies only where the individual contacts you directly via a text message; since only the rightful owner of the device can send such a message.
However, for double opt-in, another step is needed:
“You have requested SMS messages from [Company]. Type YES to confirm subscription. Messages may incur msg & data rates. Text STOP to stop subscription.”
Double opt-in is more significant where:
The permission was acquired using a landing page, form, or event registration
You plan bulk messaging
You are after a verified list of contacts and an audit trail
MessageBlink enables this. It provides the functionality to set up rules whereby the right confirmation message will be triggered by the manner in which the number was captured and each response will be time-stamped in Salesforce.
When in doubt, double opt-in is always the safer choice.
Step 3: Disclose Program Details Before the First Message
Before your recipient commits to your text messages, he or she should know what you expect from them. The guidelines put forth by the CTIA and MMA are clear about this: You can’t hide information in your privacy policy – you have to disclose it upfront. Your disclosure of opt-in should include:
What types of messages they’ll receive (e.g. appointment reminders, promotional offers, account alerts)
How frequently (e.g. “Up to 4 messages per month”)
That message and data rates may apply
Where to find your Terms and Privacy Policy
How to opt out at any time
Example of a compliant opt-in confirmation message:
“Thank you for opting into SMS alerts from [Company]. You will be sent a maximum of 4 texts per month containing information and offers. Message and data rates may apply. To unsubscribe reply STOP or HELP for assistance. Visit our Terms: [link]”
This simple text message incorporates all the necessary information and the five main compliance points in just one message.
With MessageBlink you can create your own templates, including this required text, which automatically sends out as soon as an opt-in event occurs. This could be through keyword subscription, through filling out a web form, or an automated API connection.
Step 4: Honor Every Opt-Out — Immediately
An opt-out is not a preference; rather, under the TCPA, it’s a requirement. An opt-out that is either ignored or even worse, processed with additional communications thereafter, is surefire compliance failure.
What you need to do upon receiving an opt-out:
A. Keep It Simple
While it is not mandatory that each communication include an opt-out option, CTIA recommends doing so no less than once per month, or more often depending on your cadence of messages. Here is what it looks like:
“Reply STOP to unsubscribe.”
Use a simple keyword that works for everyone: STOP is mandatory, while PAUSE or HELP may be included if you desire.
B. Respond Automatically
Upon receipt of the opt-out, send an automated response:
“You have successfully opted out from [Company] alerts. You will receive no additional messages. Reply JOIN if you would like to join again.”
C. Log It, Block It, Stop It
Upon receiving an opt-out request, you should do three specific actions:
Log the opt-out date and time
Block the number from future campaign sends
Prevent any further messages to that individual unless opting back in.
The MessageBlink platform takes care of all three. When the contact responds with “STOP,” or whatever other unsubscribe keyword you have set up, the system processes the unsubscribe, takes the phone number out of your messaging program, and logs the action in Salesforce for that contact.
Easy, automatic, and fully logged.
8 Common SMS Compliance Mistakes to Avoid
Even well-intentioned teams get this wrong. Most violations don’t come from ignoring the rules — they come from process gaps.
rules — they result from process gaps.
Delivering promotional messages without written consent A phone number on a contact form is not consent to be marketed to. Consent for sending promotional messages should be documented, specific, and unrelated to general data collection.
Presuming there is no need for consent when sending transactional messages Message types like order confirmation and appointment reminder usually do not need opt-in consent as long as they are actually transactional messages, yet once any promotion language is used – it is required.
Skipping double opt-in for online submissions Submission of your number on a website form constitutes the first part, and confirmation of the user’s permission to contact – the second part. Double opt-in should always be employed whenever you get consent from anywhere other than keyword reply.
Failing to timestamp when someone has opted in/out “He has opted-in.” – this isn’t enough. You have to be able to prove the exact time of obtaining consent, including all disclosures made then.
Keeping outdated lists active Opt-ins from two years ago do not guarantee current involvement. Contacts that have been inactive for a long time may require being confirmed once more – both for compliance and for deliverability reasons.
Lack of clear opt-out options The law obliges you to provide your recipients with a convenient means of unsubscribing. Failure to do this or making the process difficult is likely to result in complaints.
Putting off processing of opt-outs An opt-out request should be handled right away, without any delay, or even less so the next time you run your batches. Messages sent following the receipt of STOP are considered violations.
Adding opted-out contacts back without permission Opting someone out does not imply that you can send them messages after they filled another form. You require explicit consent for each mailing – preferably a double opt-in.
How MessageBlink Keeps You Compliant by Default
Compliance breaks down at scale. It’s impossible to effectively manage thousands of contacts in different campaigns without a risk of having just one contact who lacks proper consent.
With MessageBlink, you get an integrated solution for building compliant messaging campaigns right inside the Salesforce CRM platform.
Automatic logging of consents All consents are recorded with timestamps, sources, methods of capturing consent, and are tied to the Contact/Led record in Salesforce. No more spreadsheets. Everything logged automatically in Salesforce.
Opt-in types support Set up workflows for handling consents depending on the method of obtaining the phone number. Form submission results in “REPLY YES TO CONFIRM.” Single opt-ins are triggered automatically using keyword texts. All responses saved to Salesforce.
Ready-to-go compliant templates Create message templates where the disclosure language (message types, frequencies, ways of opting out, policies) is pre-written. Activate these message templates automatically when the opt-in events happen.
Automatic opt-out management Whenever a contact uses STOP command, MessageBlink will send a confirmation message and suppress the contact from all other future campaigns. Nothing left for you to clean manually.
Consent verification at campaign level Configure campaigns and automation workflows only to send SMS campaigns to contacts who opted in.
Compliance isn’t a checkbox you tick once. It’s built into how your Salesforce SMS workflows run every day.
Book a meeting with our team today, or download the app directly from the Salesforce AppExchange to get started right away!
