IOSOR Learn

Opt-in evidence for 10DLC: what auditors need before the campaign

A compliance checklist for 10DLC campaign registration — what opt-in evidence auditors actually check, capture methods that hold up, and how to keep evidence retrievable in minutes, not archaeology.

10DLC campaign review does not trust a marketing claim of "users opted in" — it wants evidence: the exact screen, the exact language, the exact timestamp, and a chain of custody a stranger can follow six months later. Teams that treat opt-in as a checkbox on a slide deck get throttled, rejected, or suspended mid-launch. This guide is for compliance and product owners running a prepaid white-label messaging program who need campaign approval to survive a real audit, not just a first submission.

IOSOR expects opt-in evidence next to the same prepaid control plane as spend — a program is not "ready" because a form exists somewhere; it is ready because evidence retrieval takes minutes, not archaeology. At around USD 1,000+ monthly platform usage, campaign registration reviewers assume production discipline, not a screenshot found five minutes before the call.

What "evidence" actually means

Claim What it says Evidence auditors want
"Users opted in on our site" Trust us Archived screenshot of the exact form and copy at capture time
"Consent is in our CRM" Trust us Timestamped record tied to the phone number and message
"We follow the rules" Trust us A written policy plus a retrievable log matching it

What auditors check line by line

  1. Exact opt-in language shown to the user, not a paraphrase
  2. Whether the number captured matches the number actually messaged
  3. Capture method (web form, keyword join, verbal/paper, checkout box) documented per source
  4. Timestamp and method logged at the moment of consent, not reconstructed later
  5. Scope: transactional vs marketing consent kept distinct, never merged after the fact

Capture methods that hold up

  • Web form with an unticked box and visible message frequency / HELP-STOP language
  • Keyword join (text START) logged with the exact inbound and reply pair
  • Verbal or paper consent scripted, stored, and retrievable within the campaign's registered use case
  • Checkout opt-in shown at the point of purchase, not buried in generic terms

What to log at the moment of consent

Field Why it matters
Timestamp (UTC) Proves consent predates the first message
Exact copy shown Proves language matched what the campaign promised
Capture channel Ties evidence to the registered use case
IP / device or source reference Supports dispute resolution

Red flags

  • "We'll pull the evidence together if the campaign gets flagged"
  • Screenshots with no timestamp or unclear source
  • One evidence trail covering every campaign a business runs
  • Consent copy in a doc but never shown in the live product
  • No named owner for opt-in evidence requests

Start with IOSOR

Upload your archived opt-in screenshots and consent logs directly into the IOSOR console before submitting your 10DLC campaign for review. Configure your webhooks to pass exact UTC timestamps, IP records, and captured opt-in language with every subscriber entry. Place your messaging queue on hold until the compliance gate verifies your evidence package.

IOSOR takeaway

Passing a 10DLC opt-in audit requires verifiable, timestamped proof recorded at the exact moment a user consents, not retroactive assertions gathered after a carrier flag. Documenting exact form copy, explicit un-ticked consent boxes, and capture channels ensures your brand remains audit-ready from day one.

Do log UTC timestamps, capture sources, and full opt-in language for every phone number before dispatching your first message. Don't rely on broad privacy policies, unverified CRM records, or shared consent trails across multiple distinct campaigns.

Was this guide helpful?

Related guides