Compliance

What happens when someone replies STOP

Two things happen, and only one of them is yours. Your messaging provider blocks that sender from reaching that handset — instantly, automatically, and only for that sender. The rule is bigger: the request belongs to you, it has to be recorded when it arrives, honored within ten business days, and kept for five years. And on a cold list none of that is the first question, because a skip-traced number never gave you consent to revoke in the first place — the registries and your own do-not-call duty reach you regardless. Everything that goes wrong lives in the gap between those layers, and the fastest way to fall into it is a fresh list import.

Keith PeikerKeith PeikerPublished August 20, 2026 · 19 min read

Key takeaways

  • A cold list has no consent to revoke. The FCC's revocation rules are written around withdrawing consent that already exists. On a skip-traced list it never did — what reaches you is the national Do Not Call registry, whatever state registry covers the number, and the internal do-not-call duty that a request triggers on its own.
  • Two layers, failing in opposite directions. The provider block fails closed — your send is rejected and you find out. Your own suppression list fails open — nothing stops you and nobody tells you.
  • The block is scoped to a sender; the duty is scoped to you. Your provider files the opt-out against the sender that received it — the number itself, or the Messaging Service that number sends through. Stand up a sender outside that scope and the automatic block does not follow. The obligation does.
  • STOP is not the only valid opt-out. The FCC's rule names seven words as reasonable per se, then says any reply a reasonable person would read as a revocation counts too. Those fire no keyword, so a person has to catch them.
  • The re-import is the usual accident. Same human, new row, clean flag. Suppression has to attach to the person rather than to the row that carried them in, live at the account level, and be checked at send time — not at upload.

What actually happens when someone texts STOP?

Two separate systems react, and they are not connected to each other. One is machinery you did not build and cannot turn off. The other is a record you are responsible for keeping, and nothing in the stack will keep it for you. Confusing the first for the second is how careful people end up out of compliance. Before either of them, though, there is a question about your list that decides which rules are in play at all — so start there.

Almost everything written about STOP assumes a fact that is not true of a skip-traced list — that consent existed and is now being withdrawn. Consent under the TCPA runs from a specific person to a specific caller. A number a data vendor pulled out of a public record is not that, and nothing you write in the message creates it. The FCC's revocation rules at § 64.1200(a)(10) through (a)(12) are written in exactly those terms, as revocation of prior express consent. On a cold list there is, strictly, nothing to revoke.

That does not leave you freer. It means the rules that reach you are the ones with no consent element at all, and two of them are registries you have to go and get. The national Do Not Call registry bars telephone solicitations to registered residential subscribers — it applies before anyone has replied to anything, and no reply is required to trigger it. Several states run their own registry on top of it, along with their own telemarketing statutes, some of which reach texts specifically and carry their own private rights of action; which ones apply turns on where the called party is, and sometimes on where you are as well. The third rule is the internal do-not-call duty at § 64.1200(d), which is triggered by the request itself rather than by any consent that preceded it. That third one is what this post is about. The registry side is its own subject: TCPA rules for real estate investors.

Suppressing your own opt-outs is not registry compliance

They are separate obligations and they fail separately. A flawless internal do-not-call list does nothing about a number sitting on the national registry that has never replied to you. And the registry safe harbor at § 64.1200(c)(2) is conditional — written procedures, trained personnel, records, and a version of the registry obtained no more than 31 days before the message goes out. No texting platform scrubs the registry for you, ours included.

Layer one: the block that happens without you

Universal support for STOP is an industry baseline, not a courtesy — CTIA's Messaging Principles and Best Practices treats a working opt-out as a condition of running a messaging program at all, and expects senders to honor plain-language opt-outs regardless of capitalization or punctuation. Providers implement it below your application. Twilio, whose behavior is publicly documented, treats STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, REVOKE and OPTOUT as default opt-out keywords on long codes, and START and UNSTOP as the opt-in keywords that undo it.

Once that fires, the send stops being your decision. Twilio rejects further messages with error 21610, described in its own docs in terms of the sender: the recipient has opted out of messages from your phone number, your Channels sender, or your Messaging Service. You cannot clear it from your side. Only the recipient can, by texting START — which is exactly right, and worth internalizing before you go looking for a way around it.

Layer two: the record you are required to keep

Nothing above satisfies the rule. The FCC's do-not-call requirements at 47 C.F.R. § 64.1200(d) say that when you receive a request not to be contacted, you must record it and put that number on your do-not-call list at the time the request is made — and honor it within a reasonable time not to exceed ten business days from receipt. Paragraph (e) applies both the registry rule and this internal-list rule to solicitations made to wireless numbers, and the FCC has long treated a text as a call for that purpose. Paragraph (d)(1) also asks for a written policy, available on demand, and (d)(2) asks that anyone touching the outreach be trained on the list.

Two different parts of the rule reach list-based texting, and they reach it for different reasons. The revocation rule at § 64.1200(a)(10) governs how consent gets withdrawn — which is the rule that applies when you actually have consent, and the one your provider and your vendors will point at either way. The internal do-not-call machinery at § 64.1200(d) attaches to telemarketing calls and texts, does not turn on how the message was sent, and does not turn on whether consent ever existed. Whether a "we buy houses" text is telemarketing is a question you do not want to be the test case for. Assume both are in play; the engineering is the same either way.

The two layers fail in opposite directions

The provider block fails closed: your message is rejected, an error comes back, and you know. Your own suppression list fails open: if the record is missing, the message sends normally, the delivery receipt looks fine, and the only party who notices is the person you were told to stop texting.

Why an opt-out has to survive your whole account, not one campaign

Here is the whole problem in one sentence: the automatic block is defined in terms of a sender, and your obligation is defined in terms of you. Those are different objects, and they drift apart the moment your account has more than one phone number in it.

Numbers change under you constantly and for ordinary reasons. You buy a second local number to match a new market. A number gets flagged and you replace it. You stand up a separate messaging service for a different kind of campaign. What survives those moves depends entirely on where your provider filed the opt-out, and it files it against the sender that received it: on Twilio that is the number itself, or the Messaging Service the number sends through. So a pool of numbers inside one Messaging Service does carry the block across the pool — that scope is real. Anything you stand up beside it does not. A new standalone number, a second messaging service, a second account: each one starts clean, and the person who told you to stop is reachable again from a number they have never seen. That is a hazard to design against, not a technique — and treating it as a technique is precisely the conduct the rules exist to catch.

The rule has something to say about the corporate version of the same move, and it is worth reading in the direction it actually points. Section 64.1200(d)(5) is a limit on how far a request travels, not an expansion of it: absent a specific request to the contrary, a do-not-call request applies to the particular business entity making the call or on whose behalf it is made, and does not apply to affiliated entities unless the consumer would reasonably expect them to be included, given the identification of the caller and the product advertised. That exception is narrow and fact-bound, and the paragraph is about affiliates — not about your own phone numbers. A second number under the same entity was never outside the request, because paragraph (d) is already written in terms of that person or entity. What § 64.1200(d)(3) does close is the outsourcing door: where a party other than the one on whose behalf the contact is made keeps the records, the party on whose behalf it was made is liable for failures to honor the request. You can hire the list out. You cannot hire the liability out.

The scope test

Ask one question: if I bought a new number tomorrow and loaded my entire list against it, who would get a message who should not? If you cannot answer immediately, your suppression is living somewhere narrower than your account — on a number, on a campaign, or on a spreadsheet somebody keeps by hand.

The replies that mean stop but don't say STOP

The automatic block is keyword matching. The rule is not. That gap is the single most under-appreciated thing in SMS compliance, and it gets wider the colder your list is, because people who never opted in do not answer with tidy keywords.

Read the paragraph below for what it is: a revocation standard, written for consent that exists. Where there was never any consent, the same reply is a do-not-call request under paragraph (d) instead — which starts the same ten-business-day clock and produces the same five-year record. The two rules arrive at the same operational answer from opposite directions, and neither of them is satisfied by keyword matching. What follows is the FCC's own description of how loose the wording is allowed to be.

Section 64.1200(a)(10) says a called party may revoke consent by any reasonable method, and makes seven replies reasonable per se: stop, quit, end, revoke, opt out, cancel, unsubscribe. Then it keeps going.

If a reply to an incoming text message uses words other than "stop," "quit," "end," "revoke," "opt out," "cancel," or "unsubscribe," the caller must treat that reply text as a valid revocation request if a reasonable person would understand those words to have conveyed a request to revoke consent.
47 C.F.R. § 64.1200(a)(10)

None of the following fires a keyword. All of them are the kind of reply a reasonable person reads exactly one way:

  • "take me off your list"
  • "wrong number — quit texting me"
  • "not interested, don't contact me again"
  • "how did you get this number? remove me"
  • "I've asked you people three times already"

The same paragraph adds two more things worth knowing. You may not designate an exclusive means of revoking consent — "reply STOP" cannot be the only door. And § 64.1200(a)(11) says that using some other channel, such as a voicemail or an email to a number or address meant to reach you, creates a rebuttable presumption that consent was revoked once the consumer produces evidence they made the request. A voicemail counts. A reply to your email footer counts. Neither one will ever touch your texting platform unless a person puts it there.

The practical consequence: somebody has to read the replies. Not skim the ones that look like leads — read them. On a cold list this is a daily job, and it is the only place in the whole system where a human is genuinely irreplaceable.

Can you text back to confirm the opt-out?

Yes, once, and carefully. Section 64.1200(a)(12) permits a single confirmation message so long as it merely confirms the request, contains no marketing or promotional content, and is the only additional message sent after the revocation. Send it within five minutes and it is presumed to fall within the consumer's prior express consent; take longer and you have to show the delay was reasonable. If the person had agreed to several categories of messages from you, that confirmation may ask which ones they meant — and until they answer, everything requiring consent stops.

One piece of the 2024 rule is still on hold

The FCC's February 2024 revocation order also included a provision that would require one revocation to apply to all future calls and texts from that sender on unrelated matters. That specific piece has been repeatedly delayed and currently takes effect January 31, 2027; the rest of the order has been in force since April 2025. Build for the broad version now. The narrow reading is a moving compliance date, and the work is identical either way.

The re-import: how people break this by accident

Almost nobody sets out to text someone who opted out. What actually happens is that the list gets refreshed. You pull the county again six months later. You buy the same market from a second vendor. A partner sends over a file. Same human, new row — and the row is clean, because the thing that marked them was attached to the old row, not to the person.

There are four ways this happens, and most tools have at least one of them:

  1. The import creates a second record for the same person. Holding the flag on a contact record is fine as long as a later file can find that record. The failure is when it cannot: the import writes a new contact, the flag stays behind on the old one, and now there are two rows for one human — one suppressed, one not. The one that sends is the new one.
  2. Phone formats drift. (555) 555-0100, 5555550100 and +15555550100 are the same person and three different keys. If the import matches on the raw string, dedupe misses, and so does suppression. Normalizing every number to one canonical shape on every write path is not housekeeping — it is the thing that makes the opt-out findable later.
  3. The opt-out is scoped to a campaign or a list. Some tools record the unsubscribe against the send it came from. Start a new campaign and you have a fresh audience with no memory of the last one.
  4. Suppression is only applied at import. Scrubbing the CSV against your do-not-call file at upload is worth doing and is not sufficient. Anyone who opts out after the upload is already sitting inside the list, looking exactly like everybody else. The check has to run at send time, on every path that sends without a human in the loop.
A do-not-call request must be honored for 5 years from the time the request is made.
47 C.F.R. § 64.1200(d)(6)

Five years is longer than your list

Most lists get replaced far more often than every five years. That is the whole argument in one line: the opt-out has to outlive the list it arrived on. If your suppression cannot survive a full list replacement, it does not meet the standard — no matter how clean today's file looks.

And remember what this looks like from the other side. The person does not know they are in a new import, and they have no idea which of your numbers they replied to. To them there is no campaign and no CRM — there is you, texting them again after they told you not to.

How to keep one suppression list that everything respects

The fix is not complicated, it is just structural. One list, five properties. Whatever software you use, these are the questions to ask it.

  1. Scoped to your whole account, and attached to the person rather than to the row. Not to a campaign, not to a segment, not to the particular import that produced today's copy of them. Whatever object holds the flag, one canonical phone format written by every path that creates a contact is what lets a later file find that object again.
  2. Written by every opt-out route. The keyword webhook, a person marking a reply by hand, a bulk pass after a review session, an imported do-not-call file. All four write to the same place and mean the same thing.
  3. Read at send time by every automated send path. Campaigns, bulk send, auto-replies, AI replies — a gate that only the campaign builder calls is not a gate. Hand-typed one-to-one messages are the one case where reasonable people differ, because a human is making the decision rather than the software; the question to ask there is whether the person typing can see the opt-out before they hit send.
  4. Applied as a filter, not an afterthought. If suppression is applied after the recipient count is calculated, the number you approved and the number you sent are different — and so is the money.
  5. Never cleared by an import, and never cleared by you. Undoing an opt-out is the recipient's decision, expressed by texting START. It is not a data-cleanup task.

Full disclosure: reitexter is ours, so here is the shape with the edges showing. One suppression gate decides whether a contact may be texted, and it reads the union of every suppression signal on that contact record rather than a single flag — a block, a manual unsubscribe, the flag the inbound STOP webhook sets, and membership in the account's unsubscribers group. Any one of them suppresses, so it does not matter which route did the writing. Every automated send path calls it: campaign and bulk sends apply it as a filter on the recipient query, so the count you approve is the count that sends; the per-message worker re-checks each contact on the way out; and the keyword auto-replies, the missed-call auto-text and the AI SMS replies each check before they answer. The one exception is a message you type by hand to one person — a human is making that call, not the software — and it is called out as an exception rather than quietly folded in.

Two edges you should know rather than assume. First, the message you type by hand in the chat window does not pass through that gate — a person is choosing to send that one, with the contact's unsubscribed state visible in the thread — so it is a deliberate exception, not a claim that the software is catching it for you. Second, our inbound handler records an opt-out automatically on a one-word reply of stop or unsubscribe. Twilio blocks a wider keyword set at the sender, so a reply of cancel or quit still stops that sender — but it does not by itself write the record on our side, and neither does any of the sentences above. Those get marked by a person, which is one action, in bulk or one at a time.

What makes an opt-out survive a refresh is the import path rather than the gate. A CSV is normalized to one canonical phone format and matched against the contacts the account already has, so a row for someone who already said stop updates that record instead of creating a second, clean one. And if someone texts STOP from a number you have never imported, the record is created already suppressed, so a later file lands on it too. The limit that follows from the same design is worth stating plainly: the opt-out lives on the contact record, not in a separate number-keyed vault beside it. Delete the contact and you delete the evidence of what they said. Plans start at $99.99/month and every plan includes every feature — the tiers differ by numbers, segments and seats. See pricing.

I am not a lawyer and this is not legal advice — it is a description of how the rules and the plumbing fit together, with the citations attached so you can check every line yourself. If you are texting cold lists at volume, have someone who does this for a living read your setup, and read the registry side before the opt-out side. But the engineering half is not a judgment call. One list, scoped to your account, written by everything, read by everything, that outlives every import. Build that once and the legal question stops being an operational question.

Frequently asked questions

Does replying STOP block my texts automatically?

At the provider level, yes. Messaging providers intercept standard opt-out keywords and block further messages from that sender to that handset — Twilio, for example, rejects them with error 21610 and describes the block in terms of your phone number, Channels sender, or Messaging Service. The scope is that sender, so numbers sending through the same Messaging Service are covered and a sender you set up beside it is not. You cannot clear it from your side; only the recipient can, by texting START. That block does not satisfy your own record-keeping obligation, which is separate.

Is STOP the only way someone can opt out of my texts?

No. Under 47 C.F.R. § 64.1200(a)(10), a consumer may revoke consent by any reasonable method. The words stop, quit, end, revoke, opt out, cancel and unsubscribe are reasonable per se, but any reply a reasonable person would understand as a request to stop is also valid — and you may not designate an exclusive means of revoking. A voicemail or email creates a rebuttable presumption of revocation. On a list that never gave consent there is nothing to revoke, and the same reply is a do-not-call request under paragraph (d) instead — same ten-business-day clock, same five-year record. None of these trigger keyword blocking, so someone has to read the replies.

How fast do I have to honor a text opt-out, and how long does it last?

The FCC's rules require a revocation or do-not-call request to be honored within a reasonable time not to exceed ten business days from receipt, and require the request to be recorded on your do-not-call list at the time it is made. Section 64.1200(d)(6) requires that the request be honored for five years from the time it is made.

If I buy a new phone number, does the old opt-out follow it?

The automatic provider block does not — it is scoped to the sender that received the STOP. Your legal obligation does, because paragraph (d) is written in terms of the person or entity making the contact, and a second number under the same entity was never outside the request. Section 64.1200(d)(5) is about something narrower and points the other way: a request applies to that particular entity and does not extend to affiliated entities unless the consumer would reasonably expect them to be included, given how the caller identified itself and what was advertised. Treat the gap between the block and the duty as a hazard to design against, not as a way to keep sending.

Does importing a fresh list reset someone's opt-out?

It must not, though in practice it is the most common way an opt-out gets lost. A new file creates a new row, and if the suppression flag lived on the old row — or if the phone number is formatted differently in the new file — the person comes back in looking clean. Suppression has to attach to the person rather than to the row that carried them in, live at the account level, and be checked at send time, with one canonical phone format on every write path so a refreshed file matches the record that already says stop.

Does keeping my own do-not-call list cover me for the national registry?

No — they are separate obligations that fail separately. The internal list at 47 C.F.R. § 64.1200(d) is about honoring requests people make to you. The national registry rule at § 64.1200(c) bars telephone solicitations to registered residential subscribers who have never contacted you at all, and its safe harbor is conditional on written procedures, trained personnel, records, and a version of the registry obtained no more than 31 days before the message goes out. Several states also run their own registries and their own telemarketing statutes. Scrubbing against those is a different job from suppression, and texting platforms do not do it for you.

Can I send a confirmation text after someone opts out?

One, and only one. Section 64.1200(a)(12) allows a single confirmation message provided it merely confirms the revocation, carries no marketing or promotional content, and is the only additional message you send. Sent within five minutes of receipt it is presumed to fall within the consumer's prior express consent; later than that, you would have to show the delay was reasonable.

Keith Peiker

Keith Peiker

Founder, reitexter

Founder of reitexter. Grew his own company from zero to $500k+ in 12 months on about $3,600 a year of text messages — then built the software for everyone else working a list of phone numbers.

More about Keith

Keep reading

One opt-out list. Every automated send checks it.

reitexter runs campaigns, bulk sends, auto-replies and AI replies through the same suppression gate before anything leaves, applied as a filter on the recipient query so the count you approve is the count that sends — and a re-imported list lands on the record that already says stop instead of creating a fresh one. Plans start at $99.99/month, and every plan includes every feature; the tiers differ by numbers, segments and seats.

Get started