Why a phone number needs registration at all
Until a few years ago, you could connect any regular U.S. phone number (10 digits, "10DLC") to an automated sending system and blast out large volumes of messages with no registration at all. The major U.S. carriers - AT&T, T-Mobile, Verizon - recognized this as an open channel for spam and SMS fraud, and built a mandatory registration process called A2P 10DLC (Application-to-Person, 10-Digit Long Code). Every business sending messages from software - including GoHighLevel, Twilio, and any other CRM - has to go through it before its messages reach anyone.
What registration actually involves
- Brand registration - identifying the business with the central registry (The Campaign Registry) using a legal name, tax ID/EIN, and address.
- Campaign registration - declaring the type of messages actually being sent (appointment reminders, booking confirmations, review requests, etc.) with real sample text.
- Proof of consent - documenting how and when recipients agreed to receive messages, as part of the registry's own approval process.
In GoHighLevel the process is built into the platform (Twilio runs the technical layer behind the scenes), but it doesn't happen on its own - someone has to fill in the details and submit for approval, and it typically takes anywhere from a few days to a couple of weeks to get fully approved.
What happens without registration - it's not "maybe," it's blocked
This isn't a theoretical risk. Twilio, which powers GoHighLevel's SMS layer, has fully blocked messages sent from unregistered 10DLC numbers since September 1, 2023, returning error code 30034. In practice, that means an appointment reminder, a post-meeting follow-up, or a review request sent from an unregistered number simply disappears. There's no error the customer sees, no prominent warning in the interface - the message fails silently, and most businesses only discover it when a customer complains they never got anything.
TCPA - the law that decides whether you're allowed to send at all
A2P 10DLC registration solves a technical problem - whether the message goes through. It doesn't answer the legal question - whether you're allowed to send it in the first place. That's governed by the TCPA (Telephone Consumer Protection Act), a U.S. federal law that requires explicit consent from every recipient before sending an automated or marketing SMS. The law lets any recipient who received a message without consent sue for statutory damages of $500 per message, and up to $1,500 if the violation is shown to be willful - with no aggregate cap, meaning a campaign that accidentally goes out to 1,000 recipients without proper opt-in carries a theoretical exposure of up to $1.5 million.
This isn't a marginal risk. Between January and April 2025 alone, 880 TCPA lawsuits were filed in the U.S. - a 44% increase over the same period in 2024 (source: compliancepoint.com). Most of these are filed as class actions, which multiplies the financial exposure for a business running automation without documented consent.
What's safe to automate
- Operational messages to an existing customer who already provided contact details as part of an active transaction (booking confirmation, reminder for an appointment already scheduled) - relatively lower risk, but documented consent on the intake form is still recommended.
- An automated review request after a job is completed - only if the customer opted in to receiving SMS specifically, not just handed over a phone number.
- Any marketing or promotional message - requires prior express written consent, not implied consent.
The practical rule: any form that collects a phone number for automation purposes needs a clear consent line ("I agree to receive SMS messages from...") that the business keeps a record of - not just an empty phone field.
Running GHL automation and not sure it's compliant?
We set up and maintain GoHighLevel systems for businesses - including A2P 10DLC registration and proper consent workflows, not just the automation itself.
Get started