Before you text a borrower, get prior express written consent for marketing messages, capture it separately from transactional consent, register your A2P/10DLC campaign, and log proof in your CRM. Skip any one of these and you risk carrier blocking, regulatory exposure, or both. Every requirement below ties back to one federal statute and a fast-moving carrier registration system, and mortgage teams need to treat both as day-one setup, not an afterthought.
TL;DR:
- Mortgage lenders must obtain separate, written consent for marketing texts, clearly specifying the message purpose, frequency, and rates to stay compliant.
- All consent records must include the exact language, timestamp, IP address, and be tied to the specific loan or lead, stored securely in the CRM for years.
- Registration of A2P/10DLC campaigns with the Campaign Registry and accurate carrier attributes are essential to prevent message rejection or throttling.
- Revocation of consent must be honored promptly through any reasonable means, with internal processes to process opt-outs within 10 business days or less.
- Avoid bundling consent for loan disclosures and marketing, and never send urgency or superlative language to reduce spam filters and regulatory risks.
Table of Contents
- Your quick-start checklist for compliant mortgage texting
- How the TCPA applies to text messages sent by mortgage lenders
- Designing consent capture that survives an audit
- What happens when a borrower revokes consent
- Registering your campaign with carriers and avoiding rejection
- What your consent records need to look like in practice
- Compliant message examples and content to avoid
- Where state laws add restrictions beyond federal rules
- What enforcement and penalties actually look like
- A practical sequence for rolling out your compliance program
- What most broker teams get wrong about texting compliance
- How 1 Solution helps you operationalize this checklist
- Sources
- FAQ
Your quick-start checklist for compliant mortgage texting
Loan officers and compliance leads can act on this list today, without waiting on a full policy rewrite.
- Add a separate, unchecked checkbox for marketing text consent, distinct from any transactional or loan-status consent language.
- Write consent language that names your brand, the message purpose, frequency expectations, and includes "message and data rates may apply."
- Include HELP and STOP instructions in your first outbound message and honor STOP requests immediately across every channel.
- Register your A2P/10DLC brand and campaign with The Campaign Registry before sending any production traffic, using the correct lending content attribute.
- Store consent proof (exact text shown, timestamp, IP address, form ID, and the associated loan or lead record) in your CRM, not in email inboxes or spreadsheets.
Every item here maps to a legal or carrier requirement covered in detail below.
How the TCPA applies to text messages sent by mortgage lenders
The federal law governing this entire area is 47 U.S.C. §227, the Telephone Consumer Protection Act. The statute restricts autodialed calls and texts to U.S. phone numbers without prior consent, and it defines covered communications broadly enough to include SMS and MMS messages, not just voice calls. If your loan origination system or CRM sends texts through any automated platform, the TCPA applies to your mortgage business the same way it applies to a retailer or a debt collector.
The consent standard depends on message purpose. Marketing texts, meaning anything promoting your services, rates, or referral programs, require prior express written consent, often shortened to PEWC. That consent must be in writing, must clearly disclose that the borrower agrees to receive automated marketing messages, and cannot be a condition of getting the loan. Transactional or informational messages, such as a status update on an existing application, generally fall under a lower consent bar because they relate to a transaction the borrower already initiated. The distinction matters enormously for how you build your opt-in forms, and conflating the two is one of the most common mistakes mortgage shops make.
What counts as an autodialer has been a moving target in federal courts for years, but the practical takeaway for mortgage teams is simpler than the case law: if your platform can send texts to a list without a human manually typing and sending each one, treat it as covered equipment and apply full TCPA consent rules. Waiting for a definitive court ruling on your specific software before building compliant consent flows is not a strategy, it is a liability.

Designing consent capture that survives an audit
Consent that cannot be reproduced during a dispute is functionally no consent at all. Build your intake forms, borrower portal, and call center scripts around a few non-negotiables.
- Use a separate, unchecked checkbox for marketing text consent, never bundled with a general terms-of-service or loan disclosure checkbox.
- Capture the exact consent language the borrower saw, along with a timestamp, IP address, device type, and the form or page ID where consent was given.
- Tie every consent record to the specific loan or lead ID in your CRM so it is retrievable in seconds, not buried in a shared inbox.
- If your team collects consent verbally at a call center, record the disclosure language read and log it with the same rigor as a web form submission.
Multi-channel capture is normal in mortgage lending. A borrower might opt in through your loan application, then again through your borrower portal, then a third time on a call with a loan officer. Sync all three to a single CRM record rather than three disconnected logs, or you will not be able to prove which consent covers which message when a dispute arises.
Pro Tip: Treat every consent checkbox like a legal document, because in a TCPA dispute, it is one.
What happens when a borrower revokes consent
The FCC's TCPA Consent Order clarified that consumers can revoke consent by any reasonable means, not just by replying STOP to a text. A borrower who tells a loan officer on a phone call "stop texting me" has revoked consent just as effectively as one who texts STOP, and that revocation applies across robocalls and robotexts alike. Lenders must honor these requests promptly, and "I didn't see it in the system" is not a defense once a request has been made through any documented channel.
The FCC has also issued a limited waiver delaying certain revocation rule elements until April 11, 2026, giving callers more time to build the systems needed to honor revocation requests across every business unit and vendor. That delay is a planning window, not a pass. Use it to build the infrastructure now.
Set an internal service level agreement, such as honoring revocation within 10 business days at the outside, though same-day processing is safer given the FCC's "any reasonable means" standard. If you use third-party texting vendors, your contract needs language requiring them to process opt-outs on the same timeline and to sync suppression lists back to your CRM automatically.
Registering your campaign with carriers and avoiding rejection
Legal consent and carrier registration are two separate compliance tracks, and mortgage teams frequently satisfy one while failing the other. Campaign Registry guidance requires brands, including lenders, to register A2P/10DLC campaigns with accurate brand attributes, sample messages, and documented opt-in workflows before sending production traffic.
Carrier-facing registration typically requires your legal brand name, an NMLS or lender identifier, a live privacy policy link, sample messages representative of what you actually send, and a description of how you collect opt-in consent. Registration guidance for vertical lenders flags bundled consent and missing privacy policy links as the most common reasons carriers reject or throttle mortgage campaigns. Selecting the wrong content attribute, such as registering as general marketing when you are actually a direct lender, is another frequent rejection cause.
Work with your campaign service provider (CSP) to review sample messages before submission rather than after a rejection. Registration review can take anywhere from a few days to a couple of weeks depending on carrier queue volume, so build that lead time into any product launch or campaign refresh.
What your consent records need to look like in practice
Proof of consent is only useful if it is complete and retrievable. At minimum, your system should store the exact consent text the borrower saw, a timestamp, the source (web form, portal, call center), the IP address or session ID, the associated loan or lead record, and a sample of the actual message sent.
Retention matters as much as capture. Keep these records for the life of the loan relationship and beyond, since TCPA disputes can surface years after the original text was sent. Store proofs in your CRM or a secure log system, not in email threads that get purged on a rolling schedule. Our guide on secure borrower messaging walks through a 10-step framework for building this kind of audit-ready system.
If you use a third-party SMS vendor, your contract should specify an SLA for opt-out processing time, grant you audit access to their consent logs, and include indemnity language covering violations caused by the vendor's own system failures.
Compliant message examples and content to avoid
A transactional message like "Your loan application status has been updated. Log in to your portal to view details: [secure link]" generally requires a lower consent bar than a marketing message like "Rates just dropped! Reply YES to see if you qualify for a lower payment." The second example needs prior express written consent captured through that separate, unchecked checkbox described earlier.
- Avoid superlative or urgency-driven language like "act fast" or "guaranteed approval," both of which raise carrier spam filters and regulatory scrutiny.
- Never send repeated links or multiple messages in quick succession, a pattern carriers flag as bulk spam behavior.
- Keep sensitive borrower data, such as Social Security numbers or full loan amounts, out of SMS entirely and route borrowers to a secure portal instead.
Pro Tip: If a message would embarrass you read aloud in front of a regulator, rewrite it before you send it.
Where state laws add restrictions beyond federal rules
The TCPA sets the federal floor, not the ceiling. Some states extend Do Not Call protections to text messages or add their own consent and disclosure requirements on top of federal law, and state attorneys general have brought their own enforcement actions independent of the FCC. Our overview of mortgage regulatory compliance covers how state and federal rules interact for brokers operating across multiple markets.
If you originate loans in more than one state, build a state-policy matrix mapping each state's texting and DNC rules against your standard consent flow, and flag any state that requires stricter language or additional registries. Consult counsel on edge cases rather than assuming your federal-level compliance automatically satisfies every state.
What enforcement and penalties actually look like
The TCPA allows private lawsuits with statutory damages, and courts can multiply those damages for willful violations, which makes a single bad campaign expensive at scale. The FCC has also increased its rulemaking activity around consent and revocation, signaling more enforcement attention ahead. If you discover a violation, prioritize triage in this order: pull consent proof for the affected borrowers, pause the offending campaign immediately, and remediate the underlying process before resuming.
A practical sequence for rolling out your compliance program
Mortgage teams that get this right tend to follow the same rollout order. Design your consent flows and separate marketing checkbox first, then register your brand and campaign with carriers, then integrate consent capture with your CRM so nothing lives in a spreadsheet. Test your opt-out handling end to end before launch, and schedule recurring audits, quarterly at minimum, to catch drift.

An integrated platform helps because it keeps consent capture, message templates, and audit logs in one place instead of scattered across a loan origination system, a separate CRM, and a texting vendor's dashboard. That single-source approach is what makes a revocation request processed in one system actually stick everywhere else.
What most broker teams get wrong about texting compliance
The biggest failure I see is bundled consent: one checkbox covering loan disclosures, marketing, and terms of service all at once. That single shortcut invalidates otherwise solid consent language. Fix your capture flow and your vendor SLAs before you worry about anything else.
— Omar Khamisa
How 1 Solution helps you operationalize this checklist
1 Solution was built by mortgage professionals who dealt with fragmented consent tracking firsthand, and the platform brings consent capture, CRM, and messaging into one connected system instead of three disconnected tools.
- Capture and store consent records tied directly to each loan file.
- Send SMS through a system with built-in audit logs, with per-message charges as detailed on the provider's pricing page.
- Sync opt-outs across your CRM and messaging tools in real time.
See how the 1 Solution platform fits your compliance workflow.
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Sources
- 47 U.S. Code § 227 - Restrictions on use of telephone equipment | LII / Legal Information Institute
- FCC TCPA Consent Order (clarifying revocation, opt-out rules) — DOC-400039A1
- TCR introduction and 10DLC guidance (Campaign Registry)
- AWS: Registration help for vertical lenders (10DLC guidance)
FAQ
What are the new TCPA rules for 2026?
The FCC issued a limited waiver delaying certain revocation rule elements until April 11, 2026, giving callers more time to implement systems that honor revocation "by any reasonable means" across every channel. Lenders should use this window to build centralized opt-out processing rather than waiting for the deadline.
Does the TCPA apply to text messages?
Yes. 47 U.S.C. §227 defines covered communications to include SMS and MMS messages, so autodialed texts to a borrower's phone require the same consent standards as calls.
What is the Truth in Lending Act (TILA)?
TILA is a federal law requiring lenders to disclose loan terms, costs, and annual percentage rates clearly to borrowers before they commit to credit. It governs disclosure content rather than texting itself, though lenders sometimes use compliant SMS to deliver TILA-related status updates through secure portal links.
Is texting HIPAA compliant?
HIPAA governs protected health information, not mortgage lending communications, so standard SMS about loan status or rates does not trigger HIPAA rules. Mortgage texts should still avoid sensitive personal data like Social Security numbers and route borrowers to a secure portal instead.
Does a mortgage company need separate consent for marketing texts?
Yes. Marketing texts require prior express written consent captured through a separate, unchecked checkbox, distinct from any transactional or loan-status consent, according to carrier and TCPA guidance for lenders. Bundling marketing consent with other disclosures is one of the most common reasons consent gets invalidated in disputes.

