I Got My Twilio Number Blocked in My First Week. The A2P Mistake Everyone Makes
My texts just stopped showing up. Not all of them — enough that I noticed, with no error message telling me why. It took longer than I'd like to admit to find the real cause: I'd never registered my number the way US carriers require.
The part nobody tells you upfront
Here's the plain version, no acronyms first: before a business can text customers reliably in the US, carriers want proof you're a real business, not a spam operation hiding behind a phone number. Tell them who you are and what you're texting people about, and your messages move through the network with trust behind them. Skip it, and carriers quietly start filtering you — no warning, no error, just messages that never arrive.
The industry calls this A2P 10DLC registration — a Brand (your business identity) and a Campaign (what you're texting people about). It's not a Twilio fee or a Twilio invention. Every provider on the US phone network passes this along, because every carrier is asking the same question: how do you tell a real business from a spam bot?
Why it's actually a good thing
My first reaction was annoyance — one more form standing between me and just sending a text.
But once I understood why it exists, it stopped feeling like a hoop and started feeling like the reason the system works at all. Verified businesses get to text their customers reliably, at scale, without competing against actual spam for the same bandwidth. That's a trade worth making.
What I'd tell anyone starting today
Handle this before you need the number, not after your texts start disappearing. Registration happens directly with your carrier — Twilio or Telnyx — before you ever connect that number to anything else, and there's no shortcut around it. It's the carrier verifying who you are; no dashboard can do that step for you.
Once it's done, though, it's genuinely done. Register once, and every tool you plug that number into afterward — TelBuddy included — just works.
Frequently asked questions
Does A2P 10DLC registration cost money? Yes — a one-time brand fee and a small ongoing campaign fee, on top of your regular number and usage costs. A modest price for texts that actually arrive.
How long does approval take? Not instant — plan ahead, and register before you're depending on the number for real conversations with real customers.
Does this affect calls too, or just texting? Just SMS and MMS. Voice has its own separate trust system — a different story for a different day.
Is there a way to skip figuring this out myself? Not the registration itself — that happens directly with your carrier and requires your real business information, so it's not something any third-party dashboard can complete for you. See our full A2P 10DLC registration guide for the plain-English walkthrough of exactly what to submit and where.
The second thing that got me blocked: my own website
Once I finally sat down to register, I assumed the hard part would be the form. It wasn't. The form took twenty minutes. What bounced my submission was two pages on my own site that I hadn't thought about in years — my Terms of Service and my Privacy Policy.
Here's the part I didn't understand: a human being reads those pages. You hand over two URLs during registration, and somebody opens them and checks whether what you claim your texting program does matches what your published policies say it does. Mine said nothing about texting at all. Rejected.
The second attempt got approved, and the only thing that changed was the wording on those two pages. So here's exactly what had to be in them.
What the reviewer is actually checking
They're not grading your prose. They're looking for a specific set of statements, and they're checking that three things agree with each other:
- The place people opt in — the form, checkbox, or process where someone hands you their number.
- Your campaign description — what you typed into the registration form.
- Your published policy pages — what a stranger can read on your website right now.
If those three tell the same story, you pass. If your campaign says "appointment reminders" and your Privacy Policy is silent on SMS, the story doesn't hold together, and that's a rejection — not because you're doing anything wrong, but because there's no published evidence that you're doing it right.
The eight things your policy pages need to say
1. Give it its own heading
Put a section in each document with a heading that says what it is — something like Text Communications or Call & Text Communications. Don't bury messaging language inside a general "Communications" or "Miscellaneous" clause. The reviewer is skimming for it. Make it findable in three seconds.
2. Name the exact place consent happens
This is the one most people get wrong. Vague language like "by using our services, you agree to receive communications from us" does not work, because it doesn't point at a moment where a person knowingly gave you their number.
Name the mechanism:
By submitting your mobile phone number through our website contact form, you consent to receive transactional SMS messages related to your reservation.
Now the reviewer can go to your website, find that form, and confirm it exists. Swap in whatever is true for you — a booking form, a quote request, a checkout field, a signed intake sheet.
3. Say what kind of program it is — in the same words you used on the form
If you registered a transactional or customer-care campaign, your policy should describe transactional messages. If you registered marketing, it should describe marketing. A mismatch between the campaign type and the policy language is a rejection, even when both are individually fine.
4. List the actual messages you send
Be concrete:
These messages may include booking confirmations, check-in instructions, appointment reminders, logistical updates, and customer support responses.
This does double duty. It shows the reviewer your use case is real and narrow, and it stops your own campaign description from looking like a guess.
5. Include the two boilerplate lines, word for word
Message frequency varies. Message and data rates may apply.
Both sentences. Every time. They're short, they're expected, and leaving them out is a needless flag.
6. Spell out STOP and HELP
Not just STOP — reviewers look for both keywords by name:
You may opt out at any time by replying STOP to any message. For assistance, reply HELP or contact us directly.
7. The sentence that got me approved
If there's one line to take away from this entire post, it's this one, and it belongs in your Privacy Policy:
We do not sell or share your mobile number with third parties.
Carriers care enormously about this. The entire point of the registration system is stopping numbers collected in one place from being resold and blasted somewhere else. A policy that never rules that out reads, to a reviewer, like a policy that permits it. State it plainly.
If you genuinely don't send promotions, say that too — it narrows your program and makes it easier to approve:
We do not send marketing or promotional SMS messages.
8. The carve-out that keeps #7 honest
Here's the trap. You do hand the customer's number to somebody else — your messaging provider. That's how the text gets sent. So a blanket "we never share your information with anyone" is not true, and it can be picked apart.
The fix is one sentence that draws the line in the right place:
We disclose information only to service providers acting on our behalf — for example, payment processors and messaging providers — under confidentiality agreements.
That's what lets "we do not sell or share your mobile number" stand up. You're not sharing it with third parties for their own use; you're using a vendor to deliver your own message. Say both, and the pair is accurate and complete.
Put it in both documents
The Terms of Service and the Privacy Policy both need a messaging section. They serve different jobs — the Terms establish what you'll send and how to stop it, the Privacy Policy establishes what happens to the number itself — and the reviewer opens both URLs. Covering it in one and not the other is a common near-miss.
Make sure the pages are actually reachable
Sounds obvious, but this catches people. The two URLs you submit have to load for someone who isn't you:
- No login, no paywall, no cookie wall covering the text
- Not rendered only after a script runs
- Not a PDF download
- Linked from your site, ideally in the footer
- Live before you submit, not published the same afternoon
Open both in a private browsing window before you hit send. If you can read the messaging section there, so can the reviewer.
One honest warning
All of this only works if it's true. These aren't magic words to paste in — they're a description of a real program, and carriers do audit. If your policy describes transactional booking confirmations and you start sending weekly promotions, the campaign can be revoked, and that's a worse position than never registering.
Write the pages to match what you actually do. If what you actually do is hard to describe in these terms, that's usually a sign the program needs adjusting, not the wording.
And the obvious footnote: I'm describing what worked, not giving legal advice. If your business is in a regulated space, have someone qualified read it.
Frequently asked questions
Do my Terms and Privacy Policy both need an SMS section for A2P 10DLC?
Yes. Reviewers open both URLs. The Terms should cover what you send and how to opt out; the Privacy Policy should cover what happens to the number — specifically that you do not sell or share it with third parties.
What is the most common reason an A2P 10DLC campaign gets rejected?
Policy pages that say nothing about text messaging, or consent language too vague to point at a real opt-in. "By using our services you agree to receive communications" is not enough — name the form or checkbox where the number is collected.
If I say I never share mobile numbers, does using a messaging provider contradict that?
Only if you word it as a blanket promise. Pair the no-selling statement with a service-provider carve-out — that you disclose information to vendors acting on your behalf, such as payment processors and messaging providers, under confidentiality agreements. Both statements together are accurate.
Skip the Twilio Console entirely
TelBuddy turns everything in this guide into point-and-click settings: IVR menus, forwarding, voicemail, webhooks, and A2P sync, on top of your own Twilio account.