Home/Guides/How to Build a Website Consent Form That Survives Audit

How to Build a Website Consent Form That Survives Audit

By , Founder of Full Percent Updated 10DLCSMS consentOpt-in formsTCPA
Short answer

A website SMS consent form passes 10DLC review when it has a separate, unchecked, optional SMS checkbox and disclosure text naming the brand, message type, frequency, data rates, and HELP and STOP. It also needs live Privacy Policy and Terms links, with the policy saying mobile information is not shared for marketing. Keep a record of each consent.

What do reviewers check in your SMS consent form?

Reviewers check that consent is clear, specific, optional, and documented. They want an unchecked SMS checkbox, disclosure text that names your brand, and working links to a Privacy Policy and Terms that cover SMS.

A quick correction to a common misunderstanding: TCR stands for The Campaign Registry, the industry database where 10DLC brands and campaigns are registered. TCR does not review forms itself. Your messaging provider, such as Twilio, Bandwidth, Telnyx, or a platform built on them, submits your campaign, and the provider and carrier-appointed vetting partners review it. Whoever reviews it, the checks are consistent:

ElementWhat reviewers look for
SMS checkboxUnchecked by default, separate from other consents, and not required to submit the form
Disclosure textBrand name, message type, frequency, "Msg and data rates may apply," HELP and STOP instructions
Privacy PolicyLive link near the checkbox; states that mobile information is not shared with third parties for marketing
TermsLive link; describes the SMS program, opt-out, help, and charges
WebsiteA real business site with contact details that matches the registered brand
ConsistencyForm wording matches the opt-in description and sample messages in your campaign

If an element is missing, expect a rejection. Twilio's error 30925, for example, rejects campaigns whose opt-in checkbox is pre-selected or bundled with Terms acceptance.

How should the form be structured?

Put the standard contact fields first, then a clearly labeled, optional SMS consent checkbox with its disclosure, then the policy links and the submit button. Reviewers should find the consent in seconds.

Step 1: Contact fields

Name, email, and phone number. The phone field feeds your SMS program, but the form must still submit when the SMS box is left unchecked.

Step 2: SMS consent checkbox

Place a separate checkbox directly beside its label. It must be unchecked by default, and checking it must not be a condition of submitting the form or buying anything. Under FCC rules, prior express written consent must disclose that it is not a condition of purchase.

Step 3: Disclosure text

Use the checkbox label or text right next to it:

I agree to receive recurring marketing text messages from [Brand] about [offer] at the number provided. Consent is not a condition of purchase. Msg frequency varies. Msg and data rates may apply. Reply HELP for help and STOP to opt out. See our Privacy Policy and Terms.

Our SMS opt-in language guide has variations by use case.

Step 4: Privacy Policy and Terms links

Link both from the consent area. Reviewers open them, so they must load without errors, and both must mention SMS specifically.

Step 5: Submit and record

When the form is submitted with the box checked, store the consent record. CTIA lists the data to retain: timestamp, capture method, the exact language and page shown, the campaign, IP address, phone number, and the identity of the person who consented.

Which form mistakes get campaigns rejected?

Most rejections come from a handful of mistakes: pre-checked or required boxes, bundled consent, vague labels, and broken or generic policies.

Pre-checked or required SMS box

A pre-selected box is not affirmative consent, and a required box makes consent a condition of submitting the form. Both fail.

Bundled consent

Bad: "I agree to the Terms, Privacy Policy, and to receive emails and texts." Good: a separate box for SMS, a separate box for email, and Terms acceptance handled on its own.

Vague label

Bad: "Marketing communications." Good: "Text messages from XYZ Lending about business funding options." Name the channel, the brand, and the topic.

Privacy Policy that permits sharing

If your policy says you may share contact data with partners or affiliates for marketing, add a clear carve-out: mobile numbers and SMS consent are not shared with third parties for marketing purposes.

Unreadable disclosure

Disclosure in faint gray micro-type, or hidden behind a link, does not look like clear and conspicuous consent. Make it the same size and contrast as the form's body text.

Page that does not match the brand

A landing page with no business identity, or a domain that does not match the registered brand, looks like a lead-generation front and invites rejection.

What design choices help a form pass?

Keep the consent block visible, readable on a phone, and word-for-word identical to what you registered. Design should make consent obvious, not persuasive.

  • Visible placement: above the submit button, not below the fold or in a footer.
  • Grouping: set the SMS checkbox and disclosure apart with spacing or a light border so reviewers can find them in a screenshot.
  • Exact match: the form text, the campaign's opt-in description, and your confirmation message should use the same brand name and program description.
  • Mobile first: test on a phone. The checkbox must be easy to tap and the disclosure readable without zooming.
  • Accessible labels: connect the label to the checkbox so tapping the text toggles it and screen readers announce it.

What happens during 10DLC campaign review?

Your provider submits the campaign with your opt-in description, sample messages, and website. Reviewers then compare what you described against the live site and the screenshots you supplied. Timelines vary by provider and by queue, and a rejection adds a resubmission cycle.

Reviewers typically:

  1. Open the website and confirm it is a real, live business that matches the registered brand
  2. Find the opt-in form and check the checkbox, disclosure, and links
  3. Open the Privacy Policy and Terms and look for SMS-specific language and the non-sharing statement
  4. Compare sample messages with the declared use case, and check that they include the brand name and opt-out language
  5. Approve, or reject with a reason code you can fix and resubmit against

Twilio advises editing and resubmitting a rejected campaign rather than creating a new one. Check your provider's current guidance.

How do you submit your form with a 10DLC application?

Give reviewers a live URL and a clear screenshot, and describe the opt-in flow exactly as a consumer experiences it.

  1. Publish the form on your live domain with working policy links.
  2. Take a full-page screenshot on desktop and one on mobile showing the unchecked box and disclosure.
  3. Host the screenshot at a public URL if your provider asks for one.
  4. In the opt-in or message flow field, describe where the form lives, what the disclosure says, and that consent is optional. Link the Privacy Policy and Terms.
  5. Paste sample messages that match the confirmation and marketing texts you will send.
  6. Submit, and keep copies of everything you provided.

How can you check your form before you submit?

Run the page through a checklist before a reviewer sees it. Our free Landing Page QA tool scans a URL for 10DLC and TCPA consent signals. If you would rather start clean, our 10DLC-compliant website includes a custom-branded site, Privacy Policy, Terms, and SMS consent pages, plus contact forms with compliant consent language. It is ready to submit to a carrier or messaging platform for 10DLC review.

Frequently asked questions

Does the SMS consent checkbox have to be optional?

Yes. The checkbox must be unchecked by default, and the form must submit without it. FCC rules say prior express written consent cannot be a condition of purchase, and messaging providers commonly reject campaigns where SMS consent is pre-selected, required, or bundled with accepting the Terms of Service.

Who reviews my SMS opt-in form for 10DLC?

Your messaging provider and carrier-appointed vetting partners review it, not The Campaign Registry itself. TCR is the database where brands and campaigns are registered. Reviewers visit your live site, check the consent form and policies, and compare them with the opt-in description and sample messages you submitted.

What should an SMS privacy policy say for 10DLC?

It should explain how you collect and use mobile numbers, state that mobile information and SMS consent are not shared with third parties or affiliates for marketing purposes, and describe how to opt out. It must be live, linked near the consent checkbox, and consistent with how you actually handle the data.

Can one checkbox cover both email and SMS consent?

No. Use separate checkboxes for SMS and email marketing, and keep both separate from Terms acceptance. Reviewers treat a combined email-and-SMS box as bundled consent, and a consumer may want one channel but not the other. Each checkbox should have its own clear label and disclosure.

What consent records should I keep for SMS opt-ins?

CTIA recommends keeping the timestamp, capture method, the exact language and experience shown, the specific campaign, IP address, phone number, and the identity of the person who consented. Store a copy of the form version too, so you can prove what a consumer saw on the day they opted in.

Sources

Related

Need this done for you?

Full Percent builds compliant websites in 1 business day and sets up SMS, email and AI agent systems.

See the $350 compliant website
Stephen Ventura

Stephen Ventura founded Full Percent in Boca Raton, Florida. He has built email systems since 1997 and SMS platforms since before the iPhone. stephenventura.com