IOSOR Learn
Opt-in evidence for 10DLC: what auditors need before the campaign
A compliance checklist for 10DLC campaign registration — what opt-in evidence auditors actually check, capture methods that hold up, and how to keep evidence retrievable in minutes, not archaeology.
10DLC campaign review does not trust a marketing claim of "users opted in" — it wants evidence: the exact screen, the exact language, the exact timestamp, and a chain of custody a stranger can follow six months later. Teams that treat opt-in as a checkbox on a slide deck get throttled, rejected, or suspended mid-launch. This guide is for compliance and product owners running a prepaid white-label messaging program who need campaign approval to survive a real audit, not just a first submission.
IOSOR expects opt-in evidence next to the same prepaid control plane as spend — a program is not "ready" because a form exists somewhere; it is ready because evidence retrieval takes minutes, not archaeology. At around USD 1,000+ monthly platform usage, campaign registration reviewers assume production discipline, not a screenshot found five minutes before the call.
What "evidence" actually means
| Claim | What it says | Evidence auditors want |
|---|---|---|
| "Users opted in on our site" | Trust us | Archived screenshot of the exact form and copy at capture time |
| "Consent is in our CRM" | Trust us | Timestamped record tied to the phone number and message |
| "We follow the rules" | Trust us | A written policy plus a retrievable log matching it |
What auditors check line by line
- Exact opt-in language shown to the user, not a paraphrase
- Whether the number captured matches the number actually messaged
- Capture method (web form, keyword join, verbal/paper, checkout box) documented per source
- Timestamp and method logged at the moment of consent, not reconstructed later
- Scope: transactional vs marketing consent kept distinct, never merged after the fact
Capture methods that hold up
- Web form with an unticked box and visible message frequency / HELP-STOP language
- Keyword join (text START) logged with the exact inbound and reply pair
- Verbal or paper consent scripted, stored, and retrievable within the campaign's registered use case
- Checkout opt-in shown at the point of purchase, not buried in generic terms
What to log at the moment of consent
| Field | Why it matters |
|---|---|
| Timestamp (UTC) | Proves consent predates the first message |
| Exact copy shown | Proves language matched what the campaign promised |
| Capture channel | Ties evidence to the registered use case |
| IP / device or source reference | Supports dispute resolution |
Red flags
- "We'll pull the evidence together if the campaign gets flagged"
- Screenshots with no timestamp or unclear source
- One evidence trail covering every campaign a business runs
- Consent copy in a doc but never shown in the live product
- No named owner for opt-in evidence requests
Start with IOSOR
Upload your archived opt-in screenshots and consent logs directly into the IOSOR console before submitting your 10DLC campaign for review. Configure your webhooks to pass exact UTC timestamps, IP records, and captured opt-in language with every subscriber entry. Place your messaging queue on hold until the compliance gate verifies your evidence package.
- compliance gates before A2P
- Exporting WhatsApp Opt-In Audit Logs for Template Verification
- DID volume review: rent more vs expand the same numbers
IOSOR takeaway
Passing a 10DLC opt-in audit requires verifiable, timestamped proof recorded at the exact moment a user consents, not retroactive assertions gathered after a carrier flag. Documenting exact form copy, explicit un-ticked consent boxes, and capture channels ensures your brand remains audit-ready from day one.
Do log UTC timestamps, capture sources, and full opt-in language for every phone number before dispatching your first message. Don't rely on broad privacy policies, unverified CRM records, or shared consent trails across multiple distinct campaigns.
Was this guide helpful?
Related guides
- Implementing Business KYC Gates for High-Risk International Routes
Secure cross-border traffic by setting automated KYC verification gates, holding prepaid funds, and validating destination rules before dispatch.
- Preserving Consent Evidence During Dedicated Short Code Migrations
Learn how to audit, transfer, and preserve subscriber consent evidence when migrating active messaging programs across dedicated short codes.
- Enforcing Restricted Content and Age-Gating Rules in Production
Configure automated content filtering and age-gating rules in your white-label CPaaS console to maintain carrier compliance.