Technical10 min read

A2P 10DLC, Demystified: A Step-by-Step Guide

Everything agencies need to register messaging the right way and avoid deliverability headaches.

Farhad, founder of GHL Spark
Farhad · Founder, GHL Spark
Cover illustration for the A2P 10DLC guide — a teal grid motif on a dark green background, marked GHL Spark, Technical

In short

A2P 10DLC is two separate registrations, not one: a Brand, which proves who your business legally is, and a Campaign, which declares what you intend to send. Each fails for different reasons. Brand rejections are almost always an EIN or legal-name mismatch against IRS records, because the registry does an exact string comparison. Campaign rejections are almost always a website problem — no visible opt-in checkbox, or a privacy policy that does not state SMS consent is never shared with third parties. Your Trust Score, derived from verifiable business identity data, then sets your daily message ceiling and your throughput.

Key takeaways

  • A2P 10DLC is two separate registrations, not one — a Brand (who you legally are) and a Campaign (what you will send), and each fails for different reasons.
  • Brand rejections are almost always an EIN or legal-name mismatch against IRS records. The registry does an exact string comparison, so LLC, Inc and DBA names all matter.
  • Campaign rejections are almost always a website problem — no visible opt-in checkbox, no privacy policy, or a privacy policy that does not state SMS consent is never shared with third parties.
  • Your Trust Score sets your daily message ceiling with T-Mobile and your per-minute throughput with AT&T. It is derived from verifiable business identity data, not from how well you behave.
  • Carriers bill and throttle by segment, not by message. A single emoji or curly apostrophe silently switches encoding and can turn one 160-character segment into three.

Nothing generates more support tickets in a GoHighLevel agency than A2P 10DLC. Not workflows, not funnels, not DNS. A2P — because it is the one part of the platform where the failure is opaque, the feedback is a single unhelpful line of rejection text, and the consequence is that your client's messages simply do not arrive.

The good news is that A2P rejections are boringly repetitive. Once you understand what the carriers are actually checking, the failure modes collapse into about six causes, and every one is fixable in an afternoon.

What is A2P 10DLC, and why did the carriers introduce it?

A2P means Application-to-Person — a message sent by software rather than typed by a human. 10DLC means 10-Digit Long Code, which is the technical term for an ordinary local phone number.

Local numbers were never designed for bulk messaging. They existed for person-to-person texting, and for years businesses quietly used them for automated sending because they were cheap and looked friendly. Carriers tolerated it, then throttled it, then — as spam volumes grew — started filtering it invisibly. You would send 500 messages, see 500 "delivered" receipts from your provider, and none of them would land.

A2P 10DLC is the fix. Rather than guessing which local numbers are legitimate businesses, US carriers now require every business sending automated traffic to register itself and its intent in a central registry — The Campaign Registry, which administers 10DLC registration on behalf of the US carriers. In return, registered traffic gets a sanctioned, throttle-managed delivery path.

The rules governing what you may send, and on what consent, are set out in the CTIA's Messaging Principles and Best Practices — the industry document carriers enforce against. It is not law, but it is the standard your registration is judged by, and it is worth skimming before you register anything.

The mental shift: registration is not paperwork you file to be allowed to send. It is the thing that makes your messages deliverable at all. An unregistered local number sending A2P traffic in the US is not slow. It is blocked.

What is the difference between a Brand and a Campaign?

This is the single most common conceptual confusion, and almost every rejection makes more sense once you have it straight.

A Brand answers "who are you?" It is a legal-identity record — legal business name, EIN or tax ID, entity type, registered address, website, industry vertical, and a contact human. The registry attempts to verify you exist as a real company by matching that submission against authoritative business records, most importantly IRS records for the name/EIN pair.

A Campaign answers "what will you send?" It is a use-case record attached to the Brand. Declared use case (customer care, marketing, mixed, 2FA), a description of what the messages do, several sample messages, and a description of how people opt in and opt out.

They are vetted by different systems for different things. Brand checks are largely automated identity matching. Campaign checks are content and consent checks, often with a human reviewer opening your website to look for a consent checkbox.

Which is why the fix depends entirely on which one failed. A Brand rejection is a records problem. A Campaign rejection is almost always a website problem.

What is a Trust Score, and what actually moves it?

When your Brand is registered, the registry assigns it a Trust Score — a numeric rating, scored 0–100, reflecting how confidently it could verify your business identity (Twilio: Message throughput and Trust Scores for A2P 10DLC). It is not a reputation score. It has nothing to do with how politely you send or how few complaints you generate. It measures how legible your business is to the verification systems, and it sets your volume ceiling:

Brand tierWhat it usually meansPractical daily volume with T-MobilePractical AT&T throughput
Sole proprietorNo EIN, verified by phone OTPLowest tier, typically capped around a thousand messages a day and one numberMinimal — not viable for marketing
Low scoreEIN verified, but thin or inconsistent public dataLow thousands per dayConstrained per-minute rate
Medium scoreClean EIN match, consistent public footprintTens of thousands per dayStandard per-minute rate
High scoreEstablished entity, strong verifiable data, or externally vettedSix figures per dayHighest standard rate

The exact numbers shift as carriers revise their policies, so treat the ladder as the durable part and confirm current figures in your Trust Center before promising a client anything. What does not shift is the mechanism. Three things move the score:

  • Register as a real legal entity, not a sole proprietor. The sole-proprietor path exists for genuinely tiny senders and it is severely capped. If your client has an EIN, use it.
  • Be consistent everywhere. Legal name, EIN, address, website. The verification is a string match, not a judgement call. "Acme Marketing, LLC" and "Acme Marketing LLC" can be the difference between a clean match and a failure.
  • Pay for external vetting if you land low. Legitimate young companies with a thin public footprint often score badly. You can request third-party vetting, where a specialist provider re-examines the Brand and issues a new score. It costs a modest one-time fee and is usually the fastest path out of a bad tier. There is also an appeal window after scoring — check the current appeal and re-vetting fees with your provider before paying, since they change.

How do you register A2P 10DLC inside GoHighLevel?

The flow lives in the sub-account, under Settings, in the Phone Numbers area — look for the Trust Center or A2P tab. HighLevel documents the screen-by-screen flow in A2P Standard Brand Registration for 10DLC; the order below is what stops you failing it. Do it in this order.

  1. Gather the client's real documents first. You need the exact legal business name as filed with the IRS, the EIN, the registered address, the website, and an authorised contact. Do not take the name off their letterhead. Ask for the EIN confirmation letter (Form CP-575) and copy it character for character.
  2. Fix the website before you submit anything. This step is out of order in most people's heads, and it is why most people get rejected. A reviewer will open the site. It needs a live privacy policy and visible consent language wherever a phone number is collected.
  3. Submit the Business Profile — this creates the Brand. Legal name, EIN, entity type, address, vertical, website. This is the step where a single wrong character costs you a week.
  4. Wait for Brand verification. Largely automated, usually quick. If it fails, the culprit is almost always the name/EIN pair.
  5. Check the Trust Score before you build the Campaign. If it came back low, decide now whether to pursue external vetting. Finding out after you have promised a client 50,000 sends a day is a bad afternoon.
  6. Create the Campaign and declare the use case honestly. Most agency sub-accounts are genuinely "mixed" — appointment reminders plus some promotional content. Declaring "customer care" because it sounds safer, then submitting promotional samples, is a guaranteed rejection.
  7. Write sample messages that are literally what you will send. Include the business name in every sample and opt-out language in at least one. If your workflows send links, include a link. Sanitised copy that bears no resemblance to your automation gets caught.
  8. Describe opt-in in concrete terms. Not "customers consent." Say where and how — "end users opt in by submitting the contact form at example.com/contact, which contains an unchecked consent checkbox with full disclosure language." If opt-in happens on paper or in person, say so and be ready to provide an image.
  9. Link your numbers to the approved Campaign. Numbers not attached to an approved Campaign do not benefit from the registration.
  10. Test on a real handset across each major carrier before turning on volume. Provider-side "delivered" is not the same as arrived.

Why do A2P registrations actually get rejected?

Here is the whole list, in roughly the order you will encounter it.

Rejection causeWhat is actually happeningThe fix
EIN / legal-name mismatchThe name/EIN pair does not match IRS records exactlyCopy the name verbatim from the CP-575 letter. Include or omit commas, LLC, Inc. exactly as filed. Never submit a DBA as the legal name
No visible opt-in languageThe reviewer opened your site and could not find consent language at the point of phone-number collectionAdd an unchecked consent checkbox to every form collecting a phone number, with disclosure text naming the business, message frequency, that message and data rates may apply, and how to opt out
No privacy policyThe site has no policy, or it is behind a login, or the link is brokenPublish a real, publicly reachable privacy policy and link it in the footer
Privacy policy does not address SMSThe policy exists but says nothing about text messagingAdd an explicit statement that mobile opt-in data and SMS consent are never shared with or sold to third parties for marketing. Carriers now check for this specifically, and its absence alone will fail you
Sample messages do not match the use caseYou declared customer care and submitted promotional samples, or declared marketing with only remindersDeclare the use case that matches reality — usually mixed — and make the samples reflect actual production messages
Missing opt-out languageNo sample message contains STOP instructionsInclude Reply STOP to unsubscribe (or equivalent) in at least one sample, and make sure your live workflows include it too
Inconsistent business addressThe address in the registration, on the website, and in public records disagreePick the registered address and make all three match. A virtual mailbox is acceptable if it is consistently the address of record
Website is not live, or is a placeholderUnder-construction pages and link-in-bio pages failShip a real site with a home page, contact page, privacy policy and terms before you register

The pattern under all of these is the same. The carriers are not evaluating whether your messages are good. They are evaluating whether a stranger, given only your submission and your website, could confirm that a real business obtained real permission from a real person. Every rejection is that check failing somewhere.

What do throughput and segment limits mean day to day?

Two things constrain you, and they are different.

Throughput is rate. AT&T meters your Campaign in messages per minute; T-Mobile enforces a daily message cap per Brand. Both are tied to your Trust Score. The practical consequence is that a blast to 20,000 contacts does not go out in one burst — it queues and drains at your permitted rate. With a low-tier Brand and a big list, a "send now" campaign can take hours, or hit the daily ceiling and stall until tomorrow.

Segments are how the carriers count. A plain-text SMS holds 160 characters in the standard GSM-7 encoding. Go over that and the message is split, with each part carrying overhead, so a concatenated message gets roughly 153 characters per segment (Twilio: what is the SMS character limit?).

The trap is encoding. Insert a single emoji, a curly apostrophe pasted from Word, or an em dash, and the message silently switches to Unicode — which holds only 70 characters per segment, or about 67 when concatenated. A message you thought was one segment quietly becomes three. You are billed for three, and all three count against your throughput. This is the most common reason an agency's SMS bill is triple what the character count suggested. Strip smart quotes from your templates, and budget for emoji deliberately.

How long does each stage really take?

Be honest with clients here, because the temptation to say "a couple of days" is strong and usually wrong.

  • Brand registration — minutes to a few hours, automated.
  • Trust Score assignment — immediate on Brand approval.
  • External vetting, if needed — typically a few business days.
  • Campaign vetting — usually a few business days for a standard use case. Special use cases such as charity, political and franchise take materially longer and often require extra evidence.
  • Carrier-side approval after registry approval — varies by carrier, can add days.
  • Any rejection-and-resubmit cycle — resets the clock on the failed stage.

End to end, for an agency doing this properly and getting it right on the first or second attempt, one to two weeks is the realistic planning number. Anyone quoting 48 hours is describing the best case and hoping.

What should you check before you submit?

The highest-return habit in the whole process is a pre-flight check. Before any submission, confirm all four:

  1. The legal name and EIN are copied verbatim from the client's IRS documentation.
  2. The website is live, has a footer-linked privacy policy, and that policy explicitly states SMS consent is not shared with third parties.
  3. Every form collecting a phone number has an unchecked consent checkbox with full disclosure language.
  4. The declared use case, the sample messages, and what your workflows actually send are the same thing.

Four checks, twenty minutes. They eliminate the overwhelming majority of rejections — a considerably better trade than losing a fortnight and a client's launch date to a missing comma in a company name.

Sources and further reading

Carrier and registry policies change. Before you promise a client a volume or a timeline, confirm the current figures against the primary sources:

Frequently asked questions

What is A2P 10DLC in plain English?
A2P stands for Application-to-Person and 10DLC stands for 10-Digit Long Code — an ordinary local phone number. A2P 10DLC is the system US carriers use to register any business that sends automated text messages from a normal local number. You tell the carriers who you are and what you intend to send, and in exchange they deliver your messages instead of silently filtering them. It is mandatory. Unregistered A2P traffic on a US local number is blocked, not merely deprioritised.
Why does my A2P registration keep getting rejected?
In practice there are six culprits. Your legal business name or EIN does not match IRS records exactly. Your website has no visible opt-in language or consent checkbox. You have no privacy policy, or the privacy policy does not explicitly state that SMS consent is not shared or sold to third parties. Your sample messages do not match the use case you declared. Your samples are missing opt-out language such as Reply STOP to unsubscribe. Or your business address is inconsistent between your registration, your website and your public records.
How long does A2P 10DLC approval take in GoHighLevel?
Brand registration is largely automated and usually returns a verdict within minutes to a few hours. Campaign vetting is the slow part — a standard use case commonly clears in a few business days, but carrier-side review can extend that, and special use cases such as charity, political or franchise take longer. If you get rejected and resubmit, expect the whole cycle to run one to two weeks. Start the process before you need it, not the week your client launches.
What is a Trust Score and how do I improve mine?
A Trust Score is a numeric rating assigned to your Brand by The Campaign Registry based on how confidently it can verify your business identity against authoritative data sources. It sets your throughput ceiling. You improve it by registering as a proper legal entity with an EIN rather than as a sole proprietor, by making sure your legal name, EIN, address and website are consistent everywhere, and — if you still land low — by paying for third-party external vetting, which re-scores the Brand using a specialist vetting provider.
Do I need a separate A2P registration for every sub-account?
Yes, if each client is a distinct legal business sending under its own name. The Brand must be the entity whose identity the recipient would recognise, which means each client registers their own Brand and their own Campaign against their own EIN, opt-in flow and privacy policy. You cannot legitimately register one agency Brand and route every client's marketing through it — that is exactly the pattern the carriers built 10DLC to stop, and it puts your whole messaging footprint at risk.

About the author

Farhad, founder of GHL Spark

Farhad

Founder, GHL Spark

Farhad is the founder of GHL Spark, where he builds and white-labels GoHighLevel SaaS platforms for agencies and SaaS operators. He writes about the parts of GoHighLevel that actually break in production — A2P registration, onboarding, support load and automation.

Want this handled for you?

We set up, configure and white-label your GoHighLevel SaaS — so you can sell it instead of building it.

Fixed quote · No lock-in · Launch-ready in ~7 days