← Back to blog

Dealerships: Stop $500–$1,500 TCPA Fines with Pre Send Marketing Checks

September 2, 2026
Dealerships: Stop $500–$1,500 TCPA Fines with Pre Send Marketing Checks

Every autodialed or prerecorded marketing call or text to a wireless number requires prior express written consent under the TCPA. There is no gray area on the core rule. Before you send anything, you need documented consent, a fast process for honoring revocation, and records that survive a subpoena. Federal quiet-hours rules and Do-Not-Call obligations apply on top of that, and statutory damages run $500 to $1,500 per message. The rest of this guide shows you how to build a system that actually holds up.


TL;DR:

  • Verifying the type of consent and matching it to the campaign is critical, especially for autodialed marketing to wireless numbers, which carries the highest risk.
  • Building detailed, timestamped, and seller-specific consent records that include form language and IP addresses ensures defenses in case of future audits or disputes.
  • Regularly scrubbing lists with the National DNC Registry, reassigned numbers database, and internal suppression lists reduces violation risks due to number reassignments or consumer requests.
  • Immediate suppression of opt-outs, strict adherence to quiet hours, and clear opt-out instructions help maintain compliance and reduce potential damages.
  • Conducting independent vendor audits and performance reviews annually uncovers consent gaps and improves overall campaign legal safety and efficiency.

Table of Contents

The TCPA Compliance Marketing Checklist Every Team Should Run

Most TCPA violations don't come from bad intent. They come from a missing step in an otherwise reasonable process. A marketing team running telephone or SMS campaigns needs a repeatable sequence that catches problems before a message goes out, not after a demand letter arrives.

Before you send anything:

  1. Confirm the consent type on file (prior express consent or prior express written consent) and pull the underlying evidence, not just a flag in the CRM.
  2. Verify the line type. Landline, mobile, and VoIP numbers carry different obligations, and autodialed marketing content to wireless numbers is the highest-risk category.
  3. Check the number against the National DNC Registry, the Reassigned Numbers Database, and your internal suppression list.
  4. Confirm 10DLC or short code registration is active for the campaign you're about to run.

When you design the message itself:

  • Identify the sender clearly in the first message of any thread.
  • Include STOP language and a message/data rate notice.
  • Make sure the content matches what the consumer actually agreed to receive. A consent captured for service alerts doesn't cover a promotional blast.

On the technical side, gate sends through time-zone-aware scheduling so nothing lands outside the 8 a.m. to 9 p.m. recipient local time window, cap throughput to avoid carrier flags, and block any number lacking a valid consent record at the platform level rather than relying on a human to catch it.

After the message goes out:

  • Suppress opt-outs immediately, not at the next batch cycle.
  • Log every revocation with a timestamp and the channel it came through.
  • Retain the consent artifact tied to that number.
  • Run a periodic audit so you can produce records fast if legal counsel or a regulator asks.

Pro Tip: Build the suppression check as a hard gate in your sending platform, not a manual QA step. Manual checks get skipped during a rush campaign, and that's exactly when a violation happens.

The Aloware 2026 compliance checklist frames this as three disciplines: prove consent before contact, stop fast on revocation, and scrub your lists on a fixed cadence. That framing holds up because it matches how enforcement actually plays out. Regulators and plaintiffs' attorneys look for the gap between what you claim and what you can produce.

The TCPA recognizes two tiers of consent, and mixing them up is one of the most common and costly mistakes marketing teams make.

Prior express consent covers informational calls and texts, things like appointment reminders or account alerts, and can sometimes be inferred from the business relationship (giving a number on a credit application, for example). Prior express written consent is a higher bar required for any autodialed or prerecorded marketing call or text to a wireless number. If the message sells something, written consent is almost always the requirement.

The FCC's rules, reinforced by the Second Report and Order, specify what a compliant written consent disclosure must include:

  • A clear statement that the consumer authorizes marketing calls or texts using an autodialer or prerecorded voice
  • The name of the specific seller authorized to contact them, not a category of "partners" or "affiliates"
  • A description of the goods or services being marketed
  • Confirmation that consent is not a condition of purchase
  • The phone number the consumer is providing consent for
  • A signature, or the electronic equivalent (a checkbox tied to a timestamped form submission)

Legal analysis from Covelaw makes a point worth internalizing: courts scrutinize consent that is vague or bundled across multiple advertisers. A single checkbox authorizing contact from an unnamed list of "marketing partners" is exactly the kind of consent that fails in litigation. The FCC's rulemaking effectively closed the door on one-to-many lead models, which is why the seller-naming requirement matters so much now.

A compliant opt-in flow names your business specifically, describes what the consumer will receive, and captures a timestamp, IP address, and a copy of the exact form language shown at the moment of consent. That bundle of evidence is what maps to a defensible litigation timeline if a dispute ever surfaces.

Consent that lives only as a checkbox in your CRM won't help you in a dispute. You need a structured record, and you need it captured the moment consent happens, not reconstructed later from memory or partial logs.

At minimum, each consent record should store: the exact form copy shown to the consumer, the program or campaign name, a timestamp, the IP address, the phone number, the seller name disclosed, and a versioned reference to the disclosure asset itself (so you can show what the page looked like on that date, not just today).

  1. Validate the number in real time at the point of opt-in. Check NANP formatting, line type, and porting status so you can show the number was a live mobile line when consent was captured.
  2. For legacy lists where consent provenance is unclear, run a bulk validation pass covering line type, deliverability, and a litigator scrub, then segment records into verified, risky, and dead buckets.
  3. Set retention policy around your applicable statute of limitations. Industry guidance generally recommends keeping consent artifacts for at least four years, aligned to typical limitations windows.
  4. Gate your sending platform so it physically cannot send to a number without a valid, current consent record attached.

Pro Tip: Run a red-team test on your own opt-in flow twice a year. Have someone outside the marketing team try to complete the form the way a careless consumer would, and see if the record it generates would actually hold up in front of a judge.

Tag-manager and server-side logging approaches, like those covered in Consent Mode v2 implementations, give engineering teams a template for capturing this kind of proof without relying on a marketer to remember to screenshot a form.

List Scrubbing and Suppression: The Three-List Rule

List hygiene is where a lot of otherwise compliant programs quietly fall apart. Numbers get reassigned, consumers file new DNC requests, and internal suppression lists drift out of sync across departments.

  • Purchase and apply the National DNC Registry on a rolling basis. Industry practice treats a scrub within 31 days of a call or text as the safe-harbor standard.
  • Check the Reassigned Numbers Database before any campaign touches a number that's been dormant for a while. A number reassigned to a new subscriber invalidates the original consent entirely.
  • Maintain a single internal suppression list that every channel checks against, not separate lists per team. A revocation captured by your call center needs to suppress SMS sends the same day.
  • Run suppression tests on large lists at a fixed cadence, ideally weekly for active campaigns, to catch drift before it becomes a pattern of violations rather than a single mistake.

Scheduling these checks on a predictable rhythm, rather than reactively, cuts down on both false negatives (numbers that should be suppressed but aren't) and false positives (valid contacts accidentally blocked). A CRM hygiene playbook built around a 90-day cycle gives most marketing teams enough frequency to stay ahead of reassignment risk without over-engineering the process.

Message Content, Opt-Out Handling, and Quiet Hours

What you put in the message and how fast you honor a "stop" request both carry legal weight, not just the consent you collected up front.

  • Identify your business by name in the message, not just a shortened URL or generic brand.
  • Include STOP instructions and a message/data rate notice in the first message of any new program.
  • State message frequency where the consent form promised it (for example, "up to 4 msgs/month").
  • Treat any reasonable revocation language, not just the word "STOP," as valid. The FCC's standard is about what a reasonable person would understand as opting out, not a rigid keyword match.

Hunton's litigation guidance recommends offering multiple, easy-to-use opt-out methods, reply, phone, and email, so a consumer isn't stuck fighting a broken keyword system. Process every opt-out request within 10 business days at the outside, but immediate suppression is the safer operational target since a delay of even a day can generate a second unwanted message and a second violation.

Quiet hours run during typical waking hours in the recipient's local time zone, not the sender's. Several states layer tighter windows or additional consent requirements on top of the federal baseline, so a national campaign needs to respect the narrowest applicable window for any given number, not just the federal default.

Carrier Rules and Technical Controls Behind TCPA Marketing Strategies

Legal compliance and carrier compliance are two different gates, and failing either one stops your campaign cold.

  • Register every SMS campaign under 10DLC with accurate metadata describing the use case, sample messages, and opt-in method. Carriers reject or throttle traffic when the registered use case doesn't match what actually gets sent.
  • Monitor complaint rate, delivery rate, and opt-out rate continuously. A spike in any of these is usually the first signal something upstream, consent quality, list hygiene, message tone, has gone wrong.
  • Build an escalation path for carrier blocking. Know who at your organization can respond within hours, not days, when a carrier flags a campaign, because extended downtime on a live promotion is costly.
  • Keep documentation ready: registration records, sample opt-in language, and consent logs. Carriers and regulators alike may ask for this during a complaint investigation.

Purchased leads are where a lot of TCPA exposure hides, because the consent problem belongs to whoever sends the message, not whoever sold the list.

  • Require raw consent artifacts from any lead vendor, not a summary claim. That means the actual form capture, a timestamp, and confirmation that the consent names your business specifically as the seller.
  • Write contract clauses requiring proof on demand, indemnification for TCPA claims, and audit access to the vendor's consent collection process.
  • Bulk-validate every purchased list before it touches a live campaign, and segment out risky records for a re-permission flow rather than assuming the vendor's word is enough.
  • Set a clear internal rule for when to drop a vendor: repeated inability to produce consent artifacts on request is a decision point, not a negotiation point.

Pro Tip: Ask a vendor to produce five random consent records from a recent list sale before you sign anything. If they can't produce a real, seller-named artifact in 48 hours, that tells you everything you need to know about the other 50,000 records.

The FCC's rulemaking effectively ended the model where one consent gets resold to multiple buyers. If your vendor's business model still runs that way, the liability lands on you the moment you send.

Penalties and What to Do When a Campaign Gets Flagged

Statutory damages run $500 per violation for a negligent TCPA breach and up to $1,500 per violation when the conduct is found willful or knowing. That per-message math is what turns a single bad list into a seven-figure exposure once a class of recipients gets certified.

Enforcement typically follows one of two patterns: a class action built around a single flawed campaign, or a mass-notice regulatory inquiry triggered by a spike in consumer complaints. Both usually trace back to the same root cause, a consent gap that nobody caught before the send.

If a campaign gets flagged, move fast:

  • Stop the send immediately across every channel it touches.
  • Suspend the vendor feed tied to the flagged list.
  • Preserve every log, don't let automated retention rules purge evidence mid-investigation.
  • Notify legal counsel before responding to any outside inquiry.

Durable consent records and a documented history of honoring opt-outs within days, not weeks, are consistently what pushes a dispute toward early dismissal rather than a costly settlement.

Why Vendor Accountability Is the Missing Piece in Most Compliance Programs

Most dealership marketing teams treat TCPA compliance as a legal checkbox handled once and forgotten. That's backwards. Consent quality degrades continuously as vendors change practices, lists age, and campaigns scale across new channels.

Independent, cross-vendor performance data tends to surface consent gaps that a single vendor's self-reported numbers never will, because no vendor is incentivized to flag its own weak consent capture. When a dealership pulls performance data across every marketing source it uses, duplicate contacts and invalid sends usually show up as inefficiency long before anyone flags them as legal risk. Cleaning that up tends to improve both compliance posture and marketing ROI at the same time, since fewer wasted, noncompliant sends means more budget going toward contacts that convert.

The practical next step for most teams is straightforward: run a consent audit across your top three lead vendors this quarter, request seller-named consent artifacts, and build number validation into your platform before your next campaign launches.

— AutoROIQ

Most dealerships find out their vendor mix has a consent problem only after a complaint or a legal demand arrives. Autoroiq is the alternative to guessing which vendor is creating your exposure. As an independent marketing intelligence firm that doesn't sell advertising or represent any vendor, Autoroiq evaluates your marketing channels and vendor performance with no incentive to protect anyone's numbers but yours.

Autoroiq

That includes consent-audit support: reviewing how your current vendors capture and document consent, flagging duplicate or high-risk contacts across your marketing mix, and giving you executive-level recommendations you can hand directly to legal counsel or your marketing team. Because Autoroiq is vendor-agnostic, the findings come without the spin a vendor might apply to its own consent practices.

If your dealership hasn't had an outside look at vendor consent quality in the past year, request a marketing intelligence review and get a clear picture of where your risk actually sits, along with what it would take to fix it.

Sources

Keep these on hand when drafting disclosure language or assembling evidence for a compliance review.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.