A2P Compliance Guidelines
Last updated: February 2026
A2P 10DLC registration is a process used by U.S. cellular carriers (e.g. Verizon, AT&T, T-Mobile) to verify who is sending SMS messages and what is being sent to their customers. This helps ensure your contacts receive messages they actually want to receive. Follow these guidelines to avoid A2P rejections, save time, and stay compliant when using Kova AI's messaging features.
Overview of A2P Registration
A2P 10DLC registration is a mandatory carrier requirement for businesses sending application-to-person (A2P) SMS traffic in the United States. Registration is enforced by U.S. cellular carriers to verify sender legitimacy, consent integrity, and message transparency. Follow the guidelines below to get approved and stay approved.
Opt-In Form Requirements
Whether a phone number field is mandatory or optional in a form, survey, quiz, web chat widget, or calendar booking — users cannot be forced to agree to SMS messaging in order to submit. The phone field and consent choices are separate decisions.
Strict Separation: Marketing vs. Non-Marketing Messages
Consent checkboxes must be distinct for marketing and non-marketing messages so subscribers can opt into one, both, or neither. Your forms must include two separate checkboxes with the following exact language:
"I consent to receive marketing text messages, about special offers, discounts, and service updates, from [BUSINESS NAME] at the phone number provided. Message frequency may vary. Message & data rates may apply. Text HELP for assistance, reply STOP to opt out."
"I consent to receive non-marketing text messages from [BUSINESS NAME] about [USE_CASE_FROM_CAMPAIGN_DESCRIPTION]. Message frequency may vary, message & data rates may apply. Text HELP for assistance, reply STOP to opt out."
[BUSINESS NAME] should match what's on your CP 575/147C document.
No Pre-Selection of Checkboxes
Consent checkboxes cannot be pre-selected by default. Users must manually select each checkbox they wish to agree to.
Consent Checkboxes Are Always Optional
Even if the phone number field is required, checking the consent box must remain optional for form submission. Submitting a form cannot be conditional on marketing consent. After submission, only execute communication based on the user's actual checkbox selections.
Footer Links
Privacy Policy and Terms & Conditions links are mandatory in the footer of all forms. See the sections below for what must be included in each document.
Campaign Use Case Descriptions
Campaign descriptions must directly align with the consent checkbox language. The message use cases described in the campaign must be explicitly reflected in the opt-in checkbox wording.
- Non-marketing example: If a campaign includes appointment reminders, order updates, or service notifications, the checkbox must reference those same message types — not generic language like "non-marketing messages."
- Promotional example: If a campaign includes special offers or discounts, the checkbox must reference those same message types — not generic language like "marketing messages."
- Business alignment: The campaign description must match your business niche. Carriers review whether the website supports the stated use case.
Privacy Policy Essentials
Your Privacy Policy must be linked in the footer of every form and must never mention affiliation, selling, or buying of leads.
Strict Prohibition
The policy must never mention affiliation, selling, or buying of leads.
Required Non-Sharing Clause
Your Privacy Policy must include the following exact language regarding third-party data sharing:
"No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties."
Terms of Service Clauses
Your Terms of Service must identify the sender, provide opt-out and support instructions, disclose message frequency, and reference your Privacy Policy. The following clauses are required:
Business Identity Clause
Clearly state your business name and a brief description of the messages users can expect. This gives users an understanding of who is contacting them and why.
Opt-Out & Support Mechanisms
"You can cancel the SMS service at any time. Just text "STOP" to the [Phone Number]. After you send the SMS message "STOP" to us, we will send you an SMS message to confirm that you have been unsubscribed. After this, you will no longer receive SMS messages from us. If you want to join again, just sign up as you did the first time and we will start sending SMS messages to you again. If you are experiencing issues with the messaging program you can reply with the keyword HELP for more assistance, or you can get help directly at [support email address or toll-free number]."
Carrier Liability Clause
"Carriers are not liable for delayed or undelivered messages."
Message Frequency Clause
"As always, message and data rates may apply for any messages sent to you from us and to us from you. You will receive [message frequency]. If you have any questions about your text plan or data plan, it is best to contact your wireless provider."
Privacy Policy Link Clause
"If you have any questions regarding privacy, please read our privacy policy: [link to privacy policy]"
Sample Privacy Policy & Terms of Service
Kova AI recommends building a Privacy Policy and Terms & Conditions page that includes all of the required language outlined above. The following serves as a reference — always consult with your own legal counsel before publishing to ensure it meets the needs of your business and jurisdiction.
At a minimum, your pages must include the non-sharing clause from the Privacy Policy section and all four clauses listed in the Terms of Service section above, with your business name, phone number, support email, and website filled in where indicated.
Doing Business As (DBA) Requirements
If you have an EIN for your company but want to use a different brand name for your messages, add this sentence to the Campaign Use Case Description: "We are doing DBA as [Business_Name]."
The rest of your submission — including the website, Privacy Policy, T&C, and the business name shown in opt-in form checkboxes — must match the declared [Legal Business Name] DBA [DBA Name].
- The DBA relationship must be clearly stated on the website — in the footer and/or header. If it cannot be found, the campaign can be rejected.
- Logos on the website can represent the DBA branding.
Using a Subdomain for A2P Registration
Phone carriers allow subdomains (e.g. form.yourdomain.com) for A2P registration, but they need to understand two things:
- How the subdomain relates to the primary brand. If the subdomain and main domain present very different brands, campaigns will be blocked unless the relationship is made very clear.
- How users get to the opt-in page. Simply stating that a subdomain is where opt-in happens — without showing how people find that page — creates a risk of rejection. If the path is clearly shown (email, social posts, paid ads, or navigation from the main site), subdomains are fine.
Subdomain Readiness Checklist
- ✓Brand Match: Does the subdomain generally match your overall brand (name, logo, look, feel)?
- ✓Discovery Path: Is it obvious how users get to the subdomain (email, social, ads, or navigation)?
- ✓CTIA & Use-Case: Does the page have all the required CTIA disclosures and an appropriate use case?
If all three answers are Yes, you're good to proceed with A2P registration using the subdomain.
How to Get Support
If you have questions about A2P compliance or need help getting your number registered, reach out to the Kova AI support team. Our team is on standby to review your setup and help guide you through the registration process.