Text messaging is the highest-performing channel a loan officer has — and the one most likely to get you sued. In 2026, a single text sent without the right consent, or at the wrong time of day, or after someone typed “STOP,” is a standalone violation of the Telephone Consumer Protection Act worth $500 to $1,500 in statutory damages. Send 5,000 of them in a campaign and you’re staring at a number that ends careers, not quarters.
The rules moved in 2025 and 2026 — some in your favor, some against — and most originators are still texting on the assumptions they had two years ago. This is the plain-English breakdown for mortgage brokers and loan officers: what a compliant text actually requires now, which 2025 regulatory changes matter for your database outreach, why A2P 10DLC registration is no longer optional, and how to wire the guardrails into GoHighLevel so the system enforces them instead of relying on you to remember.
What actually changed for mortgage texting in 2025–2026
The short version: consent got a little easier to obtain, opt-outs got much harder to ignore, and you now legally cannot send business texts through the carriers without registering first. Here’s the timeline every loan officer should have on the wall.
- •Feb 2025
Carriers block unregistered A2P texts
Every major U.S. carrier now blocks business texting traffic that isn't registered through A2P 10DLC. No registration, no delivery.
- •Jan 24, 2025
One-to-one consent rule vacated
The Eleventh Circuit struck down the FCC's one-to-one consent rule; the FCC declined to appeal in April 2025. Shared-consent lead gen survives — for now.
- •Apr 11, 2025
New opt-out rule takes effect
Consumers can revoke consent 'in any reasonable manner.' You must honor it within 10 business days, across all channels.
- •2025
TCPA litigation surges ~60%
About 2,628 TCPA suits filed, with plaintiff firms pivoting to text-timing and opt-out-failure theories.
- •Jan 2026
Carrier surcharges rise again
T-Mobile and others raised A2P pass-through fees, making unregistered or sloppy campaigns even costlier to run.
None of these are lender-specific — the TCPA governs anyone sending marketing calls or texts — but mortgage is squarely in the crosshairs because originators text a lot, text about money, and text past clients whose consent may be years old. Let’s take the pieces one at a time, starting with why any of this is worth your attention.
What one non-compliant text really costs
The TCPA is a private right of action with statutory damages of $500 per violation, trebled to $1,500 for willful or knowing violations — and critically, the plaintiff doesn’t have to prove they suffered any actual harm (The Farber Law Firm, 2025). Each text is a separate violation. That’s the mechanic that turns a routine blast into an existential threat: damages scale linearly with your send volume, and a single class action covering 10,000 recipients can expose a business to $5 million or more (ActiveProspect, 2025).
This isn’t theoretical anymore. TCPA filings climbed roughly 60% in 2025 to about 2,628 cases, and class actions specifically exploded — one analysis counted a 112% year-over-year jump in TCPA class actions filed in the first quarter of 2025 (ActiveProspect, 2025). The plaintiff bar is organized, well-funded, and actively hunting for the exact mistakes loan officers make: texting numbers without documented consent, texting after an opt-out, and texting outside permitted hours.
The point of that chart isn’t to scare you off texting — SMS is still the best channel you have, and we’ve written about why SMS is the right channel for time-sensitive rate-drop alerts. The point is that the downside is asymmetric. A well-run text program is one of the highest-ROI things a loan officer can do. A sloppy one is a lawsuit generator. The entire game is building the guardrails once so every message that goes out is already clean.
Consent: what “prior express written consent” means now
To send a marketing text to a mobile number using an automated system, the TCPA requires prior express written consent — a clear, conspicuous agreement, signed (an online checkbox counts), that authorizes marketing messages to that specific number and isn’t a condition of buying anything. That baseline hasn’t changed. What changed is the scope of a single consent.
In 2023 the FCC adopted a “one-to-one” consent rule that would have required a consumer to consent to each seller individually, and only for communications “logically and topically” related to the interaction that produced the consent. That rule was aimed squarely at lead generators who collect one consent and sell it to dozens of buyers. But on January 24, 2025, the Eleventh Circuit vacated it, holding that it conflicted with the ordinary meaning of “prior express consent” in the statute — and in April 2025 the FCC confirmed it would not challenge the decision (Day Pitney, 2025).
For a mortgage originator, the practical implications are simple:
- Your intake forms are your consent record. Every calculator, rate-quote form, and landing page that captures a phone number should carry clear TCPA consent language above the submit button, and you should store the timestamp, IP, the exact language shown, and the URL. If you ever have to defend a text, that record is the whole defense.
- Old consent decays. A borrower who opted in three years ago for a purchase loan is a gray area for a cash-out refi blast today. Best practice — and a requirement in some states — is periodic re-consent. Our TCPA-compliant mortgage marketing guide walks through an annual re-consent flow.
- Purchased leads inherit their consent quality. If you buy leads, the consent language and the seller’s documentation are now your liability. Get copies of the consent record, not just the phone number.
This is exactly where the pre-qualification follow-up playbook and compliant capture meet: the fastest follow-up in the world is worthless if the underlying consent won’t survive a deposition.
The 2025 opt-out rule: 10 business days, any reasonable means
This is the change that trips up the most loan officers, because it flips a convenient assumption. Under the FCC’s opt-out rule that took effect April 11, 2025, a consumer may revoke consent “in any reasonable manner” — and you can no longer dictate the one magic word they have to use (BCLP, 2025).
Three specifics matter for your workflows:
- “Any reasonable means” is broad. Replying STOP, QUIT, END, REVOKE, OPT-OUT, CANCEL, or UNSUBSCRIBE to a text all count as valid revocation — and so can a reply in plain English like “please stop texting me” (TermsFeed, 2025). Your system can’t only listen for the literal word “STOP.”
- You have 10 business days to honor it. Revocation must be processed “as soon as practicable,” and no later than 10 business days after receipt (BCLP, 2025). In practice you should suppress instantly; ten days is the outer legal limit, not a target.
- Opt-out crosses channels. If a borrower texts “STOP,” that revocation extends to robocalls and robotexts regardless of how it was sent — you can’t keep auto-dialing someone who opted out of texts (BCLP, 2025).
Quiet hours and the new time-of-day lawsuits
Here’s the violation that’s quietly generating the most new suits. The TCPA restricts telemarketing calls and texts to between 8:00 a.m. and 9:00 p.m. in the recipient’s local time zone (ActiveProspect, 2026). The trap is that this is the recipient’s time zone, not yours. A loan officer in California scheduling a “morning” blast for 8:15 a.m. Pacific is texting 11:15 a.m. on the East Coast — fine — but an East Coast LO firing an 8:30 p.m. Eastern nurture text is hitting Pacific-time borrowers at 5:30 p.m. their time (fine) while a 9:15 p.m. Eastern send hits Central-time contacts at 8:15 p.m. (fine) and Mountain contacts at 7:15 p.m. — but the same 9:15 p.m. Eastern send is already past 9:00 p.m. for every borrower in the Eastern zone.
If that sentence was annoying to parse, that’s the point: humans get time-zone math wrong, and plaintiff firms know it. In March 2025, a single South Florida law firm filed more than 100 TCPA lawsuits in one month, all alleging time-of-day violations from texts sent outside permitted hours (CompliancePoint, 2025). Time-of-day is now one of the most actively litigated theories in the statute.
The fix is not discipline — it’s automation. Every outbound text should be gated by the recipient’s time zone so a message queued at 10 p.m. simply doesn’t send until 8 a.m. their local morning. This is trivial for software and nearly impossible for a human running a database of borrowers across four time zones.
A2P 10DLC: the registration you can’t skip
Even a perfectly consented, perfectly timed text won’t reach anyone if you haven’t registered. Since February 2025, every major U.S. carrier blocks unregistered application-to-person (A2P) business texting traffic entirely (GoHighLevel Support, 2026). A2P 10DLC is the system carriers use to vet and approve business texting on standard 10-digit numbers, and it’s now the price of admission.
Registration has two layers and modest, mostly one-time costs:
- Brand registration — you register your business identity. Roughly $4 for a sole proprietor or about $48+ for a standard brand (which includes secondary vetting) (Signal House, 2026).
- Campaign registration — you register the type of messages you’ll send (e.g., “customer care” or “marketing”), at about $15 per campaign plus a small monthly fee, on top of per-message carrier surcharges of roughly $0.003–$0.005 (Signal House, 2026).
The whole process typically takes one to four weeks, and lending is a category that can draw extra scrutiny during vetting — so accurate, honest campaign descriptions matter. Carriers raised A2P pass-through fees again in January 2026, so the cost of registered texting ticked up, but it remains a rounding error against a single recovered loan.
The compliant mortgage text: a field checklist
Put it all together and a defensible outbound marketing text to a mortgage lead clears every one of these before it sends:
| Requirement | What it means in practice |
|---|---|
| Prior express written consent | A stored, timestamped opt-in for this number, with the exact consent language and source URL on record. |
| A2P 10DLC registered | Brand + campaign approved; the message type matches the registered campaign. |
| Sender identification | The business identifies itself clearly in the message (“This is [Name] at [Company]…”). |
| Opt-out instructions | A visible way to stop (e.g., “Reply STOP to opt out”) — even though any reasonable revocation now counts. |
| Quiet-hours safe | Sent between 8am–9pm in the recipient’s time zone, honoring any stricter state window. |
| No false or misleading claims | No guaranteed rates, no “you’re approved,” no implying you’re the lender if you’re a broker. Estimates are estimates. |
| Suppression checked | The contact is not on the Do-Not-Contact / prior opt-out list before the message queues. |
| Logged | The send, the consent, and any opt-out are written to an audit-ready record. |
That’s eight checks on every single message. No human runs a growing database and gets all eight right every time under pressure — which is the entire argument for letting software enforce them.
How to make GHL enforce compliance for you
The recurring theme should be obvious by now: compliance fails at the human layer and succeeds at the systems layer. Every rule above is something a busy loan officer will eventually get wrong by hand, and something GoHighLevel can get right automatically every time. Here’s what “built-in” looks like in practice, and how the Mortgage Snapshot ships it:
- Consent capture on every form. The calculators and landing pages carry TCPA consent language above the submit button and write the timestamp, IP, and language to the contact record — so your consent proof is created automatically at the moment of opt-in. This is the same capture layer behind putting mortgage calculators on your site.
- Instant, cross-channel opt-out suppression. Any recognized opt-out language — not just the literal “STOP” — flags the contact as Do-Not-Contact and halts every SMS, voice, and marketing-email workflow at once, well inside the 10-business-day limit.
- Time-zone-aware sending. Outbound texts respect the recipient’s local 8am–9pm window automatically, so a queued 10 p.m. message waits until morning instead of becoming a lawsuit.
- A2P 10DLC guidance at onboarding. Registration is handled as part of setup, with campaign descriptions written to match what the account actually sends.
- Audit-ready logs. Who consented, when, to what, and every opt-out — exportable for a compliance review or, if it ever comes to it, a defense.
This is the difference between hoping your team texts carefully and knowing the system won’t let a non-compliant message leave the building. For the full rule-by-rule breakdown — including disclosures, re-consent cadence, and the “don’t make false promises” line brokers cross most often — pair this article with our TCPA-compliant mortgage marketing guide, and see how it fits the broader AI and automation stack for loan officers.
Frequently asked questions
Mortgage text-message compliance — quick answers
How much can one non-compliant text cost under the TCPA?
$500 in statutory damages for a negligent violation, trebled to $1,500 if the violation is willful or knowing — per text, with no cap, and the plaintiff doesn't have to prove any actual harm (The Farber Law Firm, 2025). Because every message is its own violation, a 10,000-recipient campaign can expose a business to $5 million or more.
Did the one-to-one consent rule make texting illegal?
No — the opposite. The FCC's one-to-one consent rule was vacated by the Eleventh Circuit on January 24, 2025, and the FCC declined to appeal (Day Pitney, 2025). Shared-consent lead generation remains legally viable. But you still need genuine prior express written consent to send marketing texts — 'looser' is not 'gone.'
What is the new TCPA opt-out rule, and when did it start?
Effective April 11, 2025, consumers can revoke consent 'in any reasonable manner' — STOP, QUIT, CANCEL, UNSUBSCRIBE, or even plain-English requests all count — and you must honor it within 10 business days, across every channel (BCLP, 2025). Best practice is to suppress instantly, not to use the full ten days.
What are TCPA quiet hours for text messages?
Telemarketing texts are restricted to 8:00 a.m. to 9:00 p.m. in the recipient's local time zone (ActiveProspect, 2026). Time-of-day violations are a fast-growing lawsuit theory — one Florida firm filed 100+ such suits in a single month in 2025. Some states impose narrower windows, so gate sends by each contact's location, not a national clock.
Do loan officers really have to register for A2P 10DLC?
Yes. Since February 2025 every major U.S. carrier blocks unregistered business texting, so without A2P 10DLC brand and campaign registration your texts simply won't be delivered (GoHighLevel Support, 2026). Costs are modest — roughly $4–$48 for brand vetting and about $15 per campaign — but registration is separate from TCPA consent; you need both.
Can the Mortgage Snapshot handle TCPA compliance automatically?
It builds the guardrails in: TCPA consent language and timestamped capture on every form, instant cross-channel opt-out suppression for any recognized revocation, quiet-hours-aware sending in the recipient's time zone, A2P 10DLC guidance at onboarding, and audit-ready logs. It's not legal advice — always confirm your practices with qualified counsel — but it removes the manual steps where compliance usually breaks. You can book a demo or get the Snapshot.
About the author
Derek Osei is a Compliance & Operations Advisor for the mortgage niche based in Columbus, OH. He writes about TCPA consent, opt-out handling, 10DLC registration, audit trails, and the operational guardrails that keep AI messaging and SMS outreach on the right side of the rules. His goal is simple: help originators move fast without skipping the steps that matter. Derek is a fictional editorial persona for Mortgage Snapshot. This article is general information, not legal advice — consult qualified counsel about your specific TCPA and state-law obligations.
Related reading
- The TCPA-compliant mortgage marketing playbook — the full rule-by-rule guide this article builds on: consent, disclosures, re-consent, and audit logs.
- Rate-drop refi alerts: winning back past borrowers — the highest-ROI text automation, and why consent and opt-out handling have to run inside it.
- The pre-qualification follow-up playbook — the follow-up cadence that only works when the underlying consent will survive scrutiny.
- AI for Mortgage Loan Officers: the 2026 guide — where SMS, AI messaging, and compliance guardrails meet.
- Why every mortgage broker needs FHA, VA, USDA, and refi calculators — the consented capture layer that feeds every compliant text.
