Is iMessage Marketing Legal? What the Rules Actually Say
TL;DR
Yes, iMessage marketing is legal in the United States when you have documented consent and honor opt-outs quickly. The TCPA governs marketing texts based on what you send and who you send it to. Bubble color is irrelevant to the statute. Untargeted blasting to scraped lists is where real legal risk lives. General information, not legal advice.
On this page
- 01The short answer: legal with consent, risky without
- 02Which laws apply to a blue-bubble text?
- 03Prior express consent vs written consent
- 04What changed April 11, 2025
- 05Is B2B outreach exempt from TCPA?
- 06State mini-TCPA laws are stricter
- 07The July 2026 ruling (ignore it)
- 08Apple's terms vs legal compliance
- 09The compliance checklist
- 10A decision rule and the arithmetic behind it
- 11Frequently asked questions
The short answer: legal with consent, risky without
Legal when done with consent and honored opt-outs. Risky when done as untargeted blasting. Everything below is the detail.
Texting people who agreed to hear from you is legal outreach in the United States. The TCPA and FCC rules regulate the message and the consent, not the protocol.
Blasting 50,000 scraped numbers is where the real legal risk lives. This is general information from operators, not legal advice: have a lawyer review your consent language, data sources and opt-out handling.
- The statute: TCPA, 47 U.S.C. § 227, enacted 1991 and amended since
- The FCC rules: 47 C.F.R. § 64.1200
- Private right of action: $500 per violation under § 227(b)(3), which a court may increase up to three times for willful or knowing violations
- No carve-out anywhere in the statute or the rules for iMessage, RCS, SMS, or any other messaging protocol
- That review costs a few thousand dollars. A class action costs far more
Which laws apply to a blue-bubble text?
The federal TCPA and the FCC's implementing rules apply, plus whichever state telemarketing statute covers the recipient. There is no iMessage-specific law.
Courts treat a marketing text as a marketing text, governed by consent, opt-out handling and how it was sent. Section 227(b)(1)(A)(iii) restricts texts to cellular numbers sent with an automatic telephone dialing system.
Facebook v. Duguid (2021) narrowed that to equipment generating numbers randomly or sequentially, so sending to a known CRM list generally sits outside it. It is also the most misread case in outbound sales.
- A2P 10DLC is a carrier registration program, not a law. Blue Reacher requires no A2P registration, and that changes nothing about your TCPA obligations, which attach to you as the sender on every channel.
Prior express consent vs written consent
Two different standards, and mixing them up is the most common B2B compliance failure. Prior express consent covers transactional messages: appointment reminders, delivery updates, account notices.
Prior express written consent is what marketing requires: a written agreement with the person's signature, authorizing marketing and specifying the number.
Rule 64.1200(f)(9) defines it as clear authorization with conspicuous disclosure of what they are signing up for and a statement that consent is not a condition of purchase. Electronic signatures count under E-SIGN.
- In January 2025 the Eleventh Circuit vacated the FCC's stricter one-to-one consent rule, so consent can validly cover more than one seller.
- Treat that as a floor, not a strategy. Consent through a lead form listing 200 partner brands is technically defensible and practically indefensible.
What changed April 11, 2025
The FCC's revocation rules took effect on April 11, 2025. Recipients can revoke by any reasonable means, and the rule creates a rebuttable presumption in their favor.
Stop, quit, end, revoke, opt out, cancel and unsubscribe are examples rather than an exhaustive list. Reject an opt-out method and you have to show it was unreasonable.
Revocation must be honored within a reasonable time, no later than ten business days from receipt. You may send exactly one confirmation message, with no marketing content in it.
- The confirmation message is presumed valid if it is sent within five minutes.
- Rule 64.1200(a)(10), which makes one revocation cut off all future calls and texts on unrelated topics, was delayed to April 11, 2026 and then extended to January 31, 2027. Build for the revoke-all standard now; it is easier than retrofitting.
Is B2B outreach exempt from TCPA?
No. There is no business-to-business exemption in the TCPA. The FTC's Telemarketing Sales Rule exempts most B2B calls and the Do Not Call registry covers residential subscribers, but neither is a TCPA carve-out.
In B2B the number is almost always a personal cell used for work, and the FCC has presumed since 2003 that a wireless number on the Do Not Call list is residential.
In Chennette v. Porch.com (9th Cir. 2022) contractors' mixed-use cell numbers were presumptively residential, with the burden of proving otherwise on the caller in discovery.
- The genuine grey areas: whether a given mixed-use number is residential or business, whether your sending method counts as automated under state law, and whether an established business relationship covers the specific message.
- Reasonable lawyers disagree on all three. Have one review your specific program.
State mini-TCPA laws are stricter
More than a dozen states have passed their own telemarketing statutes since 2021, several stricter than federal rules. They matter more than the TCPA for most outbound teams.
State definitions of an automated system do not track Facebook v. Duguid, and several carry statutory damages with a private right of action.
Status below is verified against the statutes and named analyses. State telemarketing law moves fast. Re-check before you launch, and have counsel confirm coverage for the states you actually sell into.
| State | Law | Core requirement | Damages | Watch-out |
|---|---|---|---|---|
| Florida | Florida Telephone Solicitation Act, Fla. Stat. § 501.059, narrowed by HB 761 signed May 25, 2023 | Prior express written consent for texts sent by an automated system for the selection and dialing of numbers; 8am to 8pm local; max 3 commercial texts on one subject per 24 hours | $500 per violation, trebled for willful | Recipient must reply STOP and give you 15 days to cure before suing; statute targets consumer goods and services |
| Oklahoma | Oklahoma Telephone Solicitation Act of 2022, effective November 1, 2022 | Prior express written consent for automated-system sales calls and texts; 3 calls per 24 hours on the same subject to people physically present in Oklahoma | $500 per violation, trebled for willful or knowing | Uses selection or dialing, which is broader than Florida's post-2023 and |
| Washington | Commercial Electronic Mail Act, RCW 19.190 | Clear affirmative consent in advance before commercial text messages to Washington numbers | $500 per message or actual damages, whichever is greater; also a per se Consumer Protection Act violation | Aaland v. CRST Home Solutions, 575 P.3d 1279 (Wash. Ct. App. 2025) extended coverage to recruiting texts |
| Maryland | Stop the Spam Calls Act of 2023, effective January 1, 2024 | Prior express written consent, signed, specifying the number, with clear and conspicuous disclosure | Civil penalties up to $10,000 per violation and $25,000 for repeat violations, plus private claims | Explicitly exempts business-to-business sales, the friendliest of the four for B2B |
The July 2026 ruling (ignore it)
Steidinger v. Blackstone Medical Services (7th Cir., July 14, 2026) held that a text is not a telephone call under § 227(c)(5). Private Do Not Call claims over marketing texts are gone in Illinois, Indiana and Wisconsin.
Change nothing because of it. Section 227(b) liability for texts is untouched, it binds three states out of fifty, and every state mini-TCPA claim survives completely.
States are where B2B texting exposure has been concentrating for three years, and Supreme Court review is plausible. Consent capture is a database column; opt-out automation is a setting.
Apple's terms vs legal compliance
Apple's iCloud Terms and Conditions prohibit sending "unsolicited or unauthorized" advertising, promotional material, junk mail, or spam. That is a contract between Apple and its users, distinct from TCPA compliance.
Breaking platform terms is not a TCPA violation and creates no private right of action for recipients. It is service risk, owned by a different party. Both matter; they are not the same conversation.
Ask any vendor who bears the risk if a sending identity gets disrupted, what the remediation timeline is, and whether that answer appears in the contract. Compliance obligations still sit with you as the sender.
The compliance checklist
Run this before your first send and re-run it quarterly. It is not a substitute for counsel reviewing your specific program, and we will keep saying that.
- Capture prior express written consent for every marketing contact: signature or electronic equivalent, the specific number, clear disclosure of what they are agreeing to, and a statement that consent is not required to buy
- Log consent provenance per contact: source, exact language shown, timestamp, IP or channel. If you cannot produce it on demand, you do not have it
- Identify yourself in the first message. Business name, and a reason the person is hearing from you
- Include opt-out instructions on marketing messages and honor any reasonable revocation, not only the word STOP
- Automate opt-out processing so it fires in minutes without a human in the loop, and confirm the automation actually works by testing it monthly
- Maintain an internal do-not-call list per 47 C.F.R. § 64.1200(d) and retain records for five years
- Suppress across every channel and every campaign, not just the one that got the STOP, because the revoke-all rule lands January 31, 2027
- Scrub against the national Do Not Call registry, and treat mixed-use cell numbers as presumptively residential per Chennette
- Respect state calling windows and frequency caps, including Florida's 8am to 8pm local and 3-per-24-hours cap
- Never text a purchased or scraped list. Chennette started with numbers scraped from Yelp and YellowPages
- Keep one written compliance owner on the team, with the vendor contract, consent language, and suppression logs in one place
- Have TCPA counsel review the whole thing before launch and after any material change to your consent flow
A decision rule and the arithmetic behind it
Test any list before sending. Can you produce where the number came from, what they agreed to, and when? If someone replies no, does your system stop within an hour with no human involved?
Statutory damages start at $500 a message. Send to 5,000 contacts at four messages each, and a 1% claim rate is $100,000 of exposure before willfulness or defense counsel.
TCPA filings hit 507 in Q1 2025, up 112% on Q1 2024. A clean list of 5,000 beats a dirty list of 50,000, and converts better, because people who agreed actually reply.
- Would you show the list's provenance to a judge? Any hesitation means the list is not ready.
- Getting consent right costs a checkbox, a column and an afternoon.
- This is general information, not legal advice. Your industry, states, data sources and consent flow change the analysis. Get a lawyer who does this work to review your program before you send.
Frequently asked questions
Is iMessage marketing legal in the United States?
Yes, with documented consent and honored opt-outs. The TCPA (47 U.S.C. § 227) and FCC rules (47 C.F.R. § 64.1200) apply to marketing texts regardless of protocol. There is no iMessage-specific exemption. The risk sits in untargeted blasting to lists you cannot document.
Does the TCPA apply to B2B text messages?
Yes. There is no B2B exemption in the TCPA. The FTC's Telemarketing Sales Rule exempts most business-to-business calls at 16 C.F.R. § 310.6(b)(7) and the national Do Not Call registry covers residential subscribers, but neither is a TCPA carve-out. In B2B the number is usually a personal cell used for work.
How fast do I have to honor an opt-out?
The FCC rules effective April 11, 2025 require you to honor a revocation within a reasonable time, no later than ten business days. Treat that as a legal ceiling rather than a target, and automate suppression to fire within minutes. State laws are tighter, or offer no cure period at all.
What counts as a valid opt-out?
Any reasonable method that clearly expresses the desire to stop. The FCC named stop, quit, end, revoke, opt out, cancel and unsubscribe as examples and said the list is not exhaustive. Reject an opt-out method and the burden falls on you to show it was unreasonable.
Does "no A2P registration required" mean fewer compliance obligations?
No. A2P 10DLC is a carrier registration program governing how messages are delivered over carrier networks, and it is separate from the law. Blue Reacher requires no A2P registration, and that changes nothing about your TCPA duties, your state law duties, or your consent and opt-out obligations.
Is iMessage marketing against Apple's terms?
Apple's iCloud terms prohibit sending "unsolicited or unauthorized" advertising, promotional material, junk mail, or spam. That is a contract question between Apple and its users, distinct from the legal question of TCPA compliance. Breaking platform terms creates no private right of action for recipients.
Did the July 2026 Seventh Circuit ruling make texting safer?
Only marginally, and only in three states. Steidinger v. Blackstone Medical Services (7th Cir., July 14, 2026) held texts are not calls under § 227(c)(5), removing private Do Not Call claims for texts in Illinois, Indiana and Wisconsin. Section 227(b) liability is untouched, and every state mini-TCPA claim survives.
Keep reading
More on compliance
HIPAA and iMessage: What to Know Before You Text Patients
A plain-language walk through HIPAA for teams that want to text: who the law covers, what counts as PHI, what a business associate agreement is, which messages are safe because they carry no health information at all, and where the do-not-guess line sits.
TCPA Compliance for Text Outreach: The 2026 Operator Guide
What a B2B texting program actually has to build to stay inside the TCPA in 2026, from consent capture through the 10-business-day revocation clock, logging, and per-message damages exposure.
Put this on your pipeline
Blue Reacher runs outbound iMessage for B2B sales teams, from your CRM, with setup handled for you.
Book a demo