Skip to content

A2P 10DLC Campaign Rejected? The Problem Is Almost Never Your Form

Your A2P 10DLC campaign was not rejected because you filled the form in wrong. It was rejected because a stranger opened your website looking for the opt-in you described, and could not find it.

An A2P 10DLC campaign gets rejected when the consent you claimed in the registration cannot be verified in public. The three most common causes are an SMS opt-in checkbox that is missing or already ticked, a privacy policy that never says mobile numbers are not shared with third parties, and a website that does not name the business or mention its messaging program at all. Fix those on the site first, then resubmit by editing the rejected campaign rather than creating a new one, because the vetting fee is charged once per campaign.

We have delivered 500+ projects across 30 countries, and every one of them that sends a text message passes through this same gate. Registration is not paperwork. It is a claim about something that has to exist and be publicly visible, and somebody goes and checks.

The mistake: fixing the one code you were given

The loop is always the same. Campaign rejected. You read the code, change that one thing, resubmit. Rejected again, different code. Change that, resubmit. Rejected again, and by now you are explaining to a client why their texts still will not send.

That is not bad luck, and HighLevel says so in its own support documentation. A campaign can carry more than one rejection reason, all of them should be corrected before you resubmit, and addressing only some of them will likely result in another rejection. Its FAQ adds the part that stings: carriers may surface additional issues on subsequent reviews.

The rejection code tells you what a reviewer noticed first. It does not tell you what is wrong.

Every lap has a price, and Twilio publishes the sentence that makes it expensive. A vetting fee is assessed only once per campaign, so resubmitting the same campaign avoids a new fee. Turn that around and you have the trap. Delete the rejected campaign, create a fresh one, and you have bought a second vetting fee for the privilege of repeating the mistake in a new record. Edit the campaign you already have.

How most people resubmit

"Read the code, change that one thing, submit again."

Four laps, three weeks, and a fresh vetting fee every time somebody deletes the campaign and starts over.

How it clears

"Audit the whole submission and the whole website, fix all of it, submit once."

One review cycle, one fee, and you find the other three problems before a carrier does.

What the reviewer actually does

Twilio publishes the test, which is more than most people selling you registration help will do. Reviewers at The Campaign Registry verify four things before approving a campaign. The collection mechanism, meaning your message flow describes every way end users give consent, whether that is a web form, an SMS keyword, a paper form or a QR code. The required disclosures. Public verifiability, meaning they can reach and confirm the opt-in experience themselves. And all paths listed, meaning if you use more than one opt-in method, every method appears in the same field.

Read that as a job description rather than a checklist. Somebody is going to your website. They are looking for the thing you said exists. Public verifiability is the whole game, and it is why so many rejections are really website problems wearing a compliance costume.

4
disclosures that must sit next to the opt-in box
2,049
character ceiling on the message flow field, so there is room to prove it
5
standard brands per tax ID before campaigns start failing vetting

The website codes say it plainly. There is one for a site that lacks business information or any mention of the messaging program. One for a site that is only a lead capture form with no business context. One for a site behind a login that reviewers cannot access. One for a site under construction or on a non standard URL. None of those are form errors, and none of them get fixed inside the registration.

If your codes look unfamiliar, that is because the system changed. Since March 23, 2026 the broad catch-all codes have been replaced by granular ones, so instead of a general content or high risk code you now get one that names the specific problem. That is a real improvement. It also means a lot of the A2P advice sitting on the internet is describing a system that no longer exists.

The four lines that fail most opt-in forms

Almost every rejection I see clusters in one place: the box on the form.

The checkbox is missing, or it is ticked for you. There is a code for exactly this. What clears it is an unchecked by default checkbox specifically for SMS consent, not the general one you inherited from the newsletter signup.

Consent is bundled into something the customer has to accept anyway. If agreeing to messaging is buried inside mandatory terms, or one button grants every permission at once, it is not consent. A consumer has to be able to decline messaging and still use your service.

The four disclosures are not next to the box. Message type, message frequency, message and data rates may apply, and how to stop. All four, beside the checkbox, not on a legal page three clicks away.

Marketing and transactional consent are collected as one thing. Promotional consent has to be collected separately. If you only ever send transactional messages, say that explicitly in the campaign description instead of leaving a reviewer to guess.

Then one line in your privacy policy, which is the cheapest fix on this entire page. It has to state that mobile information will not be shared with third parties for marketing purposes, and it has to be reachable from the opt-in flow. One sentence. It carries its own rejection code, twice over, once for the policy that shares data and once for the policy a reviewer cannot find, and writing it takes about ninety seconds.

Four moves before you resubmit

Brand approved
Campaign submitted
Reviewer checks your site
Campaign approved
01
Fix the website before you touch the form
A public page with no login, your company name, what the business does, contact details, a privacy policy, and one plain line describing your SMS program and who it is for. Four separate rejection codes cover websites alone: no business information or messaging disclosure, a bare lead capture form with no business context, a site behind a login, and a site that is under construction or on a non standard URL. A landing page with a form on it and nothing else fails.
02
Rebuild the opt-in box
Unchecked by default. Separate and optional, so a customer can decline messaging and still use your service. Marketing consent collected apart from transactional consent. And the four disclosures sitting right next to the box: what messages you send, how often, that message and data rates may apply, and how to stop. A single button that grants every permission at once is its own rejection.
03
Write the message flow as evidence, not a summary
Twilio publishes a failing example in full: End users opt in on our website. The passing version names the URL, describes the exact action the user takes, discloses frequency and rates, and links both the terms page and the privacy policy. If consent also arrives by paper form, QR code or keyword, describe every path in the same field, and host a screenshot at a public URL for anything a reviewer cannot reach.
04
Fix everything, then edit the campaign you already have
Do not delete and recreate. Read every rejection reason on the record rather than the first one, correct all of them, and resubmit the same campaign. That single habit is the difference between one vetting fee and four.

That is roughly a day of work, most of it on your website rather than in a console, and it is the difference between approved on the next review and approved in October. If you would rather not spend that day learning a carrier rulebook, this is exactly the kind of thing a dedicated GoHighLevel developer should be doing for you rather than handing you a rejection code and a shrug.

The bottom line

A2P 10DLC is not a tax on texting. It is carriers asking you to prove, in public, that the people you are about to message asked to be messaged. Every rule above is downstream of that one idea, which is why the fixes are so unglamorous: a checkbox, a sentence in a privacy policy, a paragraph on a page that says what your business does.

We register brands and campaigns as part of every build, so this is the loop I spend my weeks inside. It is the foundation under our TCPA-compliant AI calling setup and under the messaging side of our GoHighLevel work, and it is the same layer any AI voice agent needs before it texts a lead after the call. Book a 30-minute call at cal.com/zeeshanwaheed/30min, or email [email protected], and bring the rejection codes with you.

Frequently Asked Questions

Being legitimate is not what is being tested. Campaign reviewers at The Campaign Registry check whether the consent you described can be verified by somebody with no access to your systems. Twilio publishes the four things they look at: the collection mechanism, the required disclosures, public verifiability, and whether every opt-in path is listed in the same message flow field. A real business selling a real product still gets rejected if its opt-in sits behind a login, its website is a bare lead form, or its privacy policy does not state that mobile numbers are not shared with third parties.
It depends on what you click. Twilio states plainly that a vetting fee is assessed only once per campaign, and that editing and resubmitting the rejected campaign avoids a new fee. Deleting the campaign and creating a fresh one is a new campaign, so edit rather than recreate. HighLevel notes that fee handling can vary by rejection type and by current carrier requirements, so confirm what your own provider charges before you start a second lap.
No, and it is the most expensive mistake agencies make. The brand is meant to be the business whose name appears in the messages. Twilio documents that each tax ID may register up to five standard or low volume standard brands, and that beyond this limit the extra brands still register but their campaigns may be rejected at manual vetting unless there is a clear and valid business reason. There is a dedicated rejection code for the same EIN appearing across multiple brands, and another for opt-in evidence that shows a different company than the one registered. Register each client under their own EIN.
Volume and identity. Twilio's own brand chart states that standard and low volume standard brands require a tax ID, which the sole proprietor path does not. A sole proprietor brand carries one campaign and is capped at 1,000 SMS segments and MMS per day to T-Mobile, roughly 3,000 a day across US carriers. A standard brand may carry up to five campaigns, and starts at 2,000 segments a day to T-Mobile and rises from there depending on your trust score. If you registered as a sole proprietor but your website, sample messages or campaign copy carry an LLC or Inc name, that mismatch is its own rejection code, and the fix is to re-register as a standard brand using your EIN.

Stuck in the rejection loop?

Send me the rejection codes and your opt-in page before you resubmit again. I will tell you on the call what a reviewer is going to fail you on next, and what it takes to clear it in one cycle.

Book a 30-Minute Call