Carriers reject toll-free verification requests over non-compliant websites, missing legal pages, or unclear opt-in flows — regardless of how clean the rest of the submission is. Meet the website, opt-in, and consent requirements below before you submit through the Plivo console.
Who this applies to
Any business submitting a toll-free number for SMS verification in the US or Canada through the Plivo console.Key terms
- KYC (Know Your Customer) — carrier-mandated verification of the business behind a number before it can send SMS, aimed at increasing consumer trust and reducing spam.
- Opt-in — explicit consent from a recipient to receive SMS, captured via web form, paper form, verbal script, or a combination (mixed).
- Double opt-in — a two-step consent flow: an initial opt-in (verbal, paper, or web) followed by a confirmation SMS asking the recipient to reply YES.
- DBA (Doing Business As) — a registered trade name a business operates under, distinct from its legal entity name.
- CP 575 / W-9 — US government-issued documents confirming a business’s legal name and EIN, used to check submission accuracy.
Website & digital presence requirements
The customer’s website is the first thing carriers check during review. A submission with an underdeveloped or non-compliant website is rejected regardless of how clean the rest of the submission is.Website existence & accessibility
- The website is not a “coming soon” or placeholder page.
- The website URL uses the business’s own domain — not a third-party platform (e.g.
sale-fish.com,oneinc.com). - The website loads without errors and renders properly on desktop and mobile.
- The domain matches the business name on the submission, or the DBA relationship is clearly established.
- The website is publicly accessible without requiring login or account creation.
- All navigation and internal links are functional — no broken links or 404 errors.
Business information on the website
- Business name displayed clearly on the homepage and consistently across all pages.
- Physical business address listed on the website matches the address provided during submission.
- Contact information (phone number, email).
- A substantive description of the products or services offered.
- Business hours, if applicable.
- Footer contains links to Privacy Policy, Terms & Conditions, and Contact Us.
Required legal pages
- A Terms of Service / Terms and Conditions page at a publicly accessible URL.
- A Privacy Policy page at a publicly accessible URL.
- Both URLs must load without authentication.
- Both pages must be linked from the homepage footer or navigation.
- Both links must also be present and clickable at the exact point of SMS opt-in.
Privacy Policy requirements (critical)
The Privacy Policy must contain explicit no-sharing language for SMS opt-in data. Include this language, or equivalent:“No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.”
Terms & Conditions requirements (critical)
The Terms & Conditions page must include:- Program or brand name.
- Program description — what types of messages will be sent.
- How customers can opt in to receive messages.
- STOP opt-out instructions.
- HELP instructions.
- Message frequency disclosure (e.g. “Message frequency may vary” or “Approx. X msgs/month”).
- A “Message and data rates may apply” statement.
- Customer care contact — both an email address and a phone number.
- A clickable link to the Privacy Policy.
- The carrier liability disclaimer: “Carriers are not liable for any delayed or undelivered messages.”
If your website is minimal
A dedicated business website is the most compliant and recommended option. As an alternative digital footprint, carriers may accept:- An active and verified Google Business Profile with customer reviews, or
- An active Facebook/Instagram Business Page with recent posts, contact info, and customer interactions, or
- Listings on Yelp, Better Business Bureau, or industry directories.
Opt-in & consent requirements
Web form opt-in
- The phone number field is explicitly labeled and disclosed as being for SMS use.
- An SMS consent checkbox is present, separate from any general Terms of Service checkbox.
- The checkbox is unchecked by default — pre-checked boxes trigger denials.
- The checkbox label discloses: the business name (matching the registered legal or DBA name), the specific message types the user will receive (must match the registered use case, e.g. “appointment reminders, account notifications, promotional offers”), the message frequency (e.g. “approximately 2 messages per month”), the “Msg & data rates may apply” language, and “Reply STOP to opt out, HELP for help.”
- Privacy Policy and Terms & Conditions links are visible and clickable near the SMS consent checkbox or in the opt-in language.
- For mixed use cases (transactional + marketing), the form has two separate checkboxes — one per use-case category.
- The form does not require SMS consent to submit — consent must be genuinely optional.
- The call-to-action button (e.g. “Submit”, “Sign Up”) does not itself imply SMS consent; consent is captured via the checkbox only.
Paper opt-in
- The paper form has a dedicated SMS consent section, not a generic intake form.
- An unchecked checkbox, or a dedicated SMS consent signature line.
- The business name printed on the form matches the legal entity name exactly as it appears on government-issued documents such as the CP 575 or W-9.
- The DBA name, if applicable, with the relationship to the legal name explicitly stated.
- Full disclosure printed on the form: message types, message frequency, “Message & data rates may apply” statement, and STOP & HELP instructions.
- A dedicated consent section for each use case, if more than one.
- A customer signature line.
- Signed forms are scanned and retained in business records.
- A direct Privacy Policy URL printed on the form (e.g. “View our Privacy Policy at [URL]”).
- Consent is logged in a CRM or system with a timestamp, customer name, phone number, and a reference to the signed form.
Verbal opt-in
- A written script is available for staff/agents to read verbatim, including: business name, specific message type/purpose, message frequency, “Message & data rates may apply” statement, STOP & HELP instructions, a statement that SMS consent is optional and won’t affect service, and a phone number confirmation question.
- The caller must affirmatively say “Yes” — silence or continuation is not consent.
- Consent is captured in a CRM/system with a timestamp, agent name, and customer phone number.
Verbal opt-in is used only for transactional use cases. Marketing messages require a separate, written consent capture mechanism.
Double opt-in (verbal/paper/web + SMS confirmation)
- The first opt-in (verbal, paper, or web) is documented per the requirements above.
- A secondary SMS confirmation is sent: “Reply YES to confirm subscription.”
- The recipient must reply YES to be enrolled.
- If there’s no response within 24 hours, the opt-in expires automatically.
How to submit a toll-free verification request
Toll-free verification requests are submitted directly through the Plivo console under Compliance > Toll-Free Verification. The submission has four steps — Business Information, Authorised Representative, Business Address, and Toll-Free Verification — and each must be completed accurately before proceeding.Step 1: Business information
- Brand Name — the name your business operates under (DBA if applicable).
- Website URL — your business’s primary website URL (e.g.
https://www.businessname.com), not a sub-page or Privacy Policy page. Ensure the URL doesn’t return any errors when accessed. - Business Entity Type — select the entity type that matches your business registration (see table below).
- Industry — select the industry that best describes your business.
- Registered Business Name — the exact legal name as filed with the IRS or state corporate registry, including punctuation, capitalization, and suffix (e.g. “Inc.”, “LLC”, “Corporation”). Must match government-issued documents such as the CP 575 or W-9 exactly.
- EIN — your business registration number, exactly as it appears on official government-issued documents, with no extra spaces or formatting errors.
- EIN Issuing Country — the country where your business is registered.
Step 2: Authorised representative
The authorised representative is the individual permitted to register this submission on behalf of the business. Plivo or carrier partners may contact them if clarification is needed.- First Name and Last Name of the business representative.
- Email — an official business-domain email address (e.g.
name@businessname.com). Avoid personal email addresses from free providers such as Gmail or Yahoo. - Phone Number — a valid, reachable phone number for the representative.
- Position — the representative’s role within the business (e.g. Manager, Owner, Director).
Step 3: Business address
Provide the official registered business address. For multi-property submissions, each toll-free number must reflect the unique address of the property it serves — no two submissions can share the same address.- Business Name — legal business name as registered.
- Street Address, City, State, Country, Postal Code.
Step 4: Toll-free verification
- Toll-Free Number — select the toll-free number being verified from your account.
- Use Cases — select only the use cases that accurately reflect the messages being sent. Do not select unrelated use cases to broaden your submission.
- Use Case Summary — a detailed description of who sends the messages, who receives them, what types of messages are sent, and how recipients opted in. Must not be vague or generic, and must not just repeat the Use Case field.
- Message Sample — at least one sample message per registered use case. Each sample must begin with the brand name and include “Reply STOP to opt out”, “Reply HELP for help”, and “Message and data rates may apply”.
- Opt-in Image URL — a publicly accessible URL of the opt-in form or proof of consent. Do not use Google Drive links, since carriers often can’t access them; alternatively, upload the opt-in proof directly via the file-upload option.
- Consent Method — the method that accurately reflects how your users provide consent:
- Monthly Message Volume — a realistic estimate of the number of messages you expect to send per month.
Passing Plivo’s review does not guarantee carrier approval. The carrier independently reviews all submissions and reserves the right to approve or deny any submission at its sole discretion, even when all guidelines have been followed.
Upcoming console fields
These fields aren’t yet available in the console submission flow but are planned for an upcoming update.
- Additional Information — business overview (industry, what the business does), customer base/audience, opt-in process explanation, and a clear justification for the use case of the number. Do not include internal notes. A justification is required when a single entity has more than 5 toll-free numbers.
- Upload Files — for uploading additional files related to the brand or the request.
- OptIn Confirmation Response — the automated message sent to a user immediately after they opt in. Must include the brand name, confirmation of what they signed up for, message frequency, “Message and data rates may apply”, and STOP and HELP instructions. Example: “[Business Name]: You’re now signed up to receive [message type]. Message frequency may vary. Message and data rates may apply. Reply STOP to opt out, HELP for help.”
- Help Message Response — the message sent when a user texts HELP. Must include the brand name, a support contact, and the STOP instruction. Example: “[Business Name]: For assistance contact us at [email] or call [phone number]. Message and data rates may apply. Reply STOP to unsubscribe.”
- Terms & Conditions URL — a publicly accessible link to your Terms & Conditions page, including all required SMS disclosures listed above.
- Privacy Policy URL — a publicly accessible link to your Privacy Policy page, including the SMS no-sharing clause and all required data-handling disclosures listed above.
FAQ
Does passing Plivo’s review guarantee carrier approval?
No. The carrier independently reviews all submissions and can approve or deny any submission at its sole discretion, even when all guidelines have been followed.Can I use a Google Drive link for my opt-in proof?
No. Carriers often can’t access Google Drive links. Provide a publicly accessible URL instead, or upload the opt-in proof directly using the file-upload option.Can verbal opt-in be used for marketing messages?
No. Verbal opt-in is only for transactional use cases. Marketing messages require a separate, written consent capture mechanism.What happens if a recipient doesn’t reply YES to a double opt-in confirmation?
The opt-in expires automatically if there’s no response within 24 hours, and the recipient is not enrolled.Can two toll-free number submissions share the same business address?
No. For multi-property submissions, each toll-free number must reflect the unique address of the property it serves — no two submissions can share the same address.Related resources
- US and Canada Messaging — where toll-free numbers fit among US/Canada source number types.
- Toll-free Verification API — create and manage verification requests programmatically.
- Toll-free Verification quickstart — SDK code samples for submitting a verification request.
- 10DLC Registration Guidelines — the equivalent guidelines for 10-digit long code brand and campaign registration.