Blog / A2P 10DLC

Why A2P 10DLC Campaigns Get Rejected (And How to Fix Each One)

Saad Khan11 min readA2P 10DLC

TL;DR

Most A2P 10DLC rejections trace to five things: unverifiable consent, a website reviewers can't read, identity that doesn't match your EIN, a use case that contradicts your sample messages, or content carriers permanently ban. Read your error code's number band before the explanation. Codes 30940 through 30964 can't be fixed by editing.

Time to first messageAn A2P 10DLC launch runs brand vetting, then campaign review, then carrier approval, and lands in the three to six week range. An iMessage line needs no registration, and most teams send inside a week.A2P 10DLCBrand vettingCampaign reviewCarrier approval3 to 6 weeks, longer on a rejectionBlue ReacherSetupMost teams send inside a week
An A2P 10DLC launch runs brand vetting, then campaign review, then carrier approval, and lands in the three to six week range. An iMessage line needs no registration, and most teams send inside a week.
On this page
  1. 01Read the code number before you read the rejection text
  2. 02What changed in 2026
  3. 03Consent and opt-in rejections
  4. 04Website rejections
  5. 05Identity mismatch rejections
  6. 06Use case and sample message rejections
  7. 07The categories you can't register at all
  8. 08Why does my campaign keep getting rejected for a new reason each time?
  9. 09The pre-flight audit that replaces three review cycles
  10. 10When the paperwork isn't the problem, the channel is
  11. 11Frequently asked questions

Read the code number before you read the rejection text

Find the five-digit code and check which band it falls in. That tells you whether you have a paperwork problem or a business-model problem.

Twilio's documentation splits rejections into two types, and only the first can be fixed by correcting your submission. Content violations, high-risk flags and fraud concerns sit in the second.

The March 2026 code expansion made this band-reading trick possible. Before it, a single code like 30883 covered everything from a stray alcohol mention to a firearms retailer. Now the number carries the verdict.

  • This one check saves weeks. Operators spend three review cycles rewriting sample messages in response to a 30947 crypto rejection, which is a judgment about what they sell, not how they wrote it.
Code rangeWhat it coversFixable by editing?
30881 to 30933Registration quality: consent, website, business identity, use case, missing required fieldsYes. Correct the submission and resubmit.
30940 to 30952Disallowed content: cannabis, prescription drugs, loans, debt collection, gambling, crypto, credit repair, MLMNo. Classified as ineligible for resubmission.
30953 to 30958SHAFT: sex, hate, alcohol, alcohol without an age gate, firearms, tobacco and vapeNo. Classified as ineligible for resubmission.
30959 to 30964High risk: fraud, phishing, deceptive marketing, poor domain reputation, link shorteners, HTTP URLsNo, including 30963 and 30964, which look like quick edits but aren't filed that way.

What changed in 2026

Twilio's March 6, 2026 changelog announced more specific error codes, rolling out March 23. Granular codes replaced four catch-alls: 30883 content violations, 30884 spam, 30885 high risk, 30897 disallowed content.

Twilio's April 6, 2026 changelog set the second change. From June 30, 2026, PrivacyPolicyUrl and TermsAndConditionsUrl became required fields on new campaign registrations via the Messaging REST API.

Both must be valid, publicly accessible URLs. Miss the field entirely and you get 30933; supply one that fails compliance and you get 30908, a different fix.

  • One SHAFT code became six; one disallowed-content code became thirteen.
  • HighLevel removed its $15 A2P resubmission fee effective February 1, 2026. Twilio has no resubmission limit and charges vetting once per campaign. Calendar time is the whole cost now.

Website rejections

Reviewers open your URL in a normal browser with no account. Whatever they see is your entire case, and no campaign description repairs it.

A site that requires a login, sits behind a coming-soon page, or is just a lead form with no company context gets rejected outright.

No website or online presence means no approval. For B2B sellers with a thin site and a heavy CRM, this is the most common blind spot, because the actual business happens where reviewers cannot see it.

  • 30919: site lacks business information or any mention of an SMS program. Add company name, service description, contact details, privacy policy and a description of the messaging program.
  • 30920: the page is just a form with no business context. Wrap the form in real company information.
  • 30921: the site requires a login. Publish a public page describing the business and the messaging program.
  • 30922: site under construction or on a non-standard URL. Provide a working standard URL, and if you're pre-launch, say so in the description and attach screenshots.
  • 30891: the URL doesn't resolve or doesn't function. Test it in a private window before you submit.
  • 30907: the website doesn't line up with the registered brand or campaign. Make the site, brand record and campaign tell one story.
  • 30908: no compliant privacy policy found in the message flow or on the site. Publish one and link it directly in the message flow field.
  • 30888: no age gate where the content requires one. Add a strict age verification step.

Identity mismatch rejections

TCR checks your legal name, address and tax ID against IRS records. An incorrect legal company name, plain typos, and an address that does not match IRS records are top brand rejection causes.

Register as a sole proprietor while using an LLC or Inc name and you get 30915, which requires re-registering as a standard brand using your EIN. Register without meeting the criteria and you get 30903.

Codes 30971 and 30972 catch B2B founders: the contact email must be your business domain, not Gmail, and the named contact must be an authorized business representative.

  • 30914: campaign content doesn't match the registered sole proprietor name.
  • 30918: the DBA name doesn't match the legal name on file. Update the brand registration to include the DBA.
  • 30926: the campaign references multiple companies or brands. Register one campaign per brand.
  • 30927: opt-in evidence shows a different company than the one registered.
  • 30894: the campaign isn't associated with the correct brand.
  • 30898: the same EIN is behind too many brand registrations. Register only the brands you need.
  • A misplaced comma in a street address is enough to fail the IRS match, and neither 30915 nor 30903 is fixable by editing.

Use case and sample message rejections

Does the use case you picked match the messages you would actually send? Code 30893 fires when samples are missing, unclear or inconsistent with the use case.

Code 30886 fires when the description doesn't explain the campaign or doesn't match the selected use case. These two account for a huge share of first-attempt rejections.

Give at least two distinct samples with your brand name in every one. Include opt-out language. Use square brackets for merge fields. Never use a shortener; never use plain HTTP.

  • 30889: you selected embedded phone number but no sample message contains one.
  • 30910: registration fields contain non-English text. Submit in English with translations alongside.
  • 30911: identical copy pasted across fields or samples. Write each one separately.
  • 30928: influencer or public figure communications, which isn't a valid use case.
  • 30929: emergency alert notifications, which aren't permitted on A2P 10DLC.
  • 30930: the brand hit the 100-campaign limit. Deregister unused campaigns.
  • 30895: a lending campaign without the direct lending attribute selected.
  • 30916 fires when you confuse lead generation (acquiring new leads) with lead nurture (engaging existing customers). 30912 fires when your description reads like person-to-person texting rather than an application sending on a business's behalf.

The categories you can't register at all

Twenty-five codes describe businesses carriers won't carry on 10DLC regardless of paperwork. If your rejection lands here, editing is wasted effort. Change the offer, entity or channel instead.

SHAFT covers six codes: 30953 sex and adult content, 30954 hate speech and violent content, 30955 alcohol, 30956 alcohol without a strict 21+ age gate, 30957 firearms and explosives, 30958 tobacco and vape.

The disallowed list (30940-30952) covers cannabis, prescription drugs, payday and title loans, debt collection, gambling, sweepstakes, cryptocurrency, credit repair, lead generation and MLM.

  • Codes 30955 and 30956 are separate outcomes: one says no, the other says not like this.
  • Code 30951 catches more legitimate B2B companies than any other, because plenty of agencies resell leads.

Why does my campaign keep getting rejected for a new reason each time?

You're fixing the code you were handed instead of auditing all five categories at once. A single submission can carry more than one rejection reason, but manual review often stops at the first blocking problem.

Clear that one and the next latent defect surfaces next cycle. Fix in dependency order instead: identity, website, consent, use case and samples, then content.

Identity comes first because everything else checks against your brand record. Website is second because it is the evidence for consent claims. Content is last because it is a permanent filter, not a fix.

  • Resubmissions are free as of February 1, 2026, and Twilio charges vetting once per campaign. The calendar is doing the billing.
  • One trap: HighLevel doesn't let you edit the campaign use case or opt-in message during resubmission. If your rejection touches either field, you need a new campaign instead.

The pre-flight audit that replaces three review cycles

Run all five checks before you resubmit, every time, no matter how narrow the rejection looks. It costs an hour against review cycles measured in weeks.

HighLevel runs automated pre-submission validation across the opt-in form, privacy policy and terms of service, flagging missing disclosures before you submit.

Passing that does not guarantee carrier approval. Use it as a floor, not a ceiling.

  • Identity: legal name, address and EIN match IRS records exactly. Contact email on your business domain. Contact person authorized to represent the company.
  • Website: loads in a private browsing window with no login. Names the company, describes the service, lists contact details, links a privacy policy and terms page over HTTPS, and mentions the SMS program.
  • Consent: unchecked-by-default checkbox, marketing consent separate from transactional, all four disclosures present (message type, frequency, rates, STOP), declining costs the user nothing, privacy policy explicitly says mobile numbers aren't shared with third parties for marketing.
  • Use case: description matches the selected use case, lead generation and lead nurture used correctly, at least two distinct sample messages with brand name, opt-out language, bracketed merge fields, full HTTPS links and zero shorteners.
  • Content: nothing in the campaign, samples, website or any linked page touches SHAFT, cannabis, lending, debt, gambling, crypto, credit repair or MLM.

When the paperwork isn't the problem, the channel is

Some B2B teams realize they will never clear it cleanly. Cold outbound to purchased or sourced contacts sits awkwardly against a review process built to verify each recipient clicked a checkbox on your site.

Codes like 30909, 30896 and 30951 are where that tension shows up as a rejection. You can spend a quarter iterating, or look at what you are actually optimizing for.

Blue Reacher sends iMessage from your CRM with no A2P registration required, which takes the entire rejection code table off your critical path.

  • $249 per line per month or $1,949 a year, unlimited iMessages paced at 50 opted-in / 30 cold new contacts a day, RCS then SMS fallback, six native CRM integrations, plus Zapier, Make, n8n, API and webhooks.
  • Teams see 2-3x more booked appointments, because a channel that is live is worth more than a channel in review.
  • If your business is in a disallowed category (codes 30940-30964), that is the deciding factor. If you are a standard B2B seller with a clean site and a real opt-in flow, register properly and use the audit above.

Frequently asked questions

How long does A2P 10DLC campaign review take in 2026?

Sole proprietor campaigns tend to be approved or rejected quickly. Standard campaigns pass through several layers and can take several weeks. Plan for weeks per cycle, not days. Treat every avoidable rejection as multiple weeks of lost channel time.

Can I fix a SHAFT or disallowed content rejection by rewording my campaign?

No. Codes 30940-30964 are classified as ineligible for resubmission. Twilio separates remediable errors from content violations and high-risk flags. Only the first type can be fixed by correcting your submission. Change the offer, entity, or channel instead.

Does resubmitting a rejected A2P campaign cost money?

Not at HighLevel, which removed its $15 resubmission fee effective February 1, 2026. Twilio charges vetting once per campaign with no resubmission limit. Disallowed-content rejections may still carry charges. The real cost is the multi-week review cycle you repeat.

What's the difference between error 30933 and 30908?

Code 30933 means the PrivacyPolicyUrl field was missing or null in your API request (hard requirement since June 30, 2026). Code 30908 means you supplied a policy URL but reviewers couldn't find a compliant one on your site or in the message flow. One is an integration fix; the other is a legal copy fix.

Do the June 30, 2026 privacy policy and terms URL requirements affect campaigns I already registered?

No. The change applies only to new submissions made after June 30, 2026. Existing registered campaigns aren't affected. Both URLs must be valid and publicly accessible when you register something new or touch an existing campaign.

Why do my sample messages keep getting rejected when they look fine?

Code 30893 fires when samples are unclear or don't match the use case; 30892 fires on shorteners or non-secured links. Common misses: no brand name, no opt-out language, merge fields without square brackets, and near-identical rather than distinct samples.

Keep reading

More on a2p 10dlc

5 min read

Your A2P 10DLC Campaign Can Be Suspended After It Is Approved

Most 10DLC guides stop at the approval email. Carriers and their vetting partners do not. A registered campaign can be pulled back into review at random, suspended over a flagged link or a complaint spike, or frozen because someone edited it, and while it is down you cannot send, cannot move your numbers, and keep paying the monthly registration fee. Here is what actually triggers a post-approval suspension and how to see one coming.

4 min read

RCS Business Messaging in 2026: The Registration Nobody Mentions

RCS on iPhone made "just switch to RCS" sound like the free upgrade to green-bubble outreach. Then you read the onboarding. Business RCS needs a verified sender approved by Google and the carriers, a review measured in weeks, and an SMS fallback that still runs on your A2P 10DLC registration. Here is the part the channel's marketing leaves out.

4 min read

How to Text Leads Without A2P 10DLC Registration

A2P 10DLC registration governs one thing: sending on US SMS carrier rails. Channels that do not ride those rails require no registration, and iMessage is the one built for conversations. What registration actually demands, the path that requires none, and the compliance that applies either way.

Put this on your pipeline

Blue Reacher runs outbound iMessage for B2B sales teams, from your CRM, with setup handled for you.

Book a demo