Your A2P 10DLC campaign was not rejected because you filled the form in wrong. It was rejected because a stranger opened your website looking for the opt-in you described, and could not find it.
An A2P 10DLC campaign gets rejected when the consent you claimed in the registration cannot be verified in public. The three most common causes are an SMS opt-in checkbox that is missing or already ticked, a privacy policy that never says mobile numbers are not shared with third parties, and a website that does not name the business or mention its messaging program at all. Fix those on the site first, then resubmit by editing the rejected campaign rather than creating a new one, because the vetting fee is charged once per campaign.
We have delivered 500+ projects across 30 countries, and every one of them that sends a text message passes through this same gate. Registration is not paperwork. It is a claim about something that has to exist and be publicly visible, and somebody goes and checks.
The mistake: fixing the one code you were given
The loop is always the same. Campaign rejected. You read the code, change that one thing, resubmit. Rejected again, different code. Change that, resubmit. Rejected again, and by now you are explaining to a client why their texts still will not send.
That is not bad luck, and HighLevel says so in its own support documentation. A campaign can carry more than one rejection reason, all of them should be corrected before you resubmit, and addressing only some of them will likely result in another rejection. Its FAQ adds the part that stings: carriers may surface additional issues on subsequent reviews.
The rejection code tells you what a reviewer noticed first. It does not tell you what is wrong.
Every lap has a price, and Twilio publishes the sentence that makes it expensive. A vetting fee is assessed only once per campaign, so resubmitting the same campaign avoids a new fee. Turn that around and you have the trap. Delete the rejected campaign, create a fresh one, and you have bought a second vetting fee for the privilege of repeating the mistake in a new record. Edit the campaign you already have.
"Read the code, change that one thing, submit again."
Four laps, three weeks, and a fresh vetting fee every time somebody deletes the campaign and starts over.
"Audit the whole submission and the whole website, fix all of it, submit once."
One review cycle, one fee, and you find the other three problems before a carrier does.
What the reviewer actually does
Twilio publishes the test, which is more than most people selling you registration help will do. Reviewers at The Campaign Registry verify four things before approving a campaign. The collection mechanism, meaning your message flow describes every way end users give consent, whether that is a web form, an SMS keyword, a paper form or a QR code. The required disclosures. Public verifiability, meaning they can reach and confirm the opt-in experience themselves. And all paths listed, meaning if you use more than one opt-in method, every method appears in the same field.
Read that as a job description rather than a checklist. Somebody is going to your website. They are looking for the thing you said exists. Public verifiability is the whole game, and it is why so many rejections are really website problems wearing a compliance costume.
The website codes say it plainly. There is one for a site that lacks business information or any mention of the messaging program. One for a site that is only a lead capture form with no business context. One for a site behind a login that reviewers cannot access. One for a site under construction or on a non standard URL. None of those are form errors, and none of them get fixed inside the registration.
If your codes look unfamiliar, that is because the system changed. Since March 23, 2026 the broad catch-all codes have been replaced by granular ones, so instead of a general content or high risk code you now get one that names the specific problem. That is a real improvement. It also means a lot of the A2P advice sitting on the internet is describing a system that no longer exists.
The four lines that fail most opt-in forms
Almost every rejection I see clusters in one place: the box on the form.
The checkbox is missing, or it is ticked for you. There is a code for exactly this. What clears it is an unchecked by default checkbox specifically for SMS consent, not the general one you inherited from the newsletter signup.
Consent is bundled into something the customer has to accept anyway. If agreeing to messaging is buried inside mandatory terms, or one button grants every permission at once, it is not consent. A consumer has to be able to decline messaging and still use your service.
The four disclosures are not next to the box. Message type, message frequency, message and data rates may apply, and how to stop. All four, beside the checkbox, not on a legal page three clicks away.
Marketing and transactional consent are collected as one thing. Promotional consent has to be collected separately. If you only ever send transactional messages, say that explicitly in the campaign description instead of leaving a reviewer to guess.
Then one line in your privacy policy, which is the cheapest fix on this entire page. It has to state that mobile information will not be shared with third parties for marketing purposes, and it has to be reachable from the opt-in flow. One sentence. It carries its own rejection code, twice over, once for the policy that shares data and once for the policy a reviewer cannot find, and writing it takes about ninety seconds.
Four moves before you resubmit
That is roughly a day of work, most of it on your website rather than in a console, and it is the difference between approved on the next review and approved in October. If you would rather not spend that day learning a carrier rulebook, this is exactly the kind of thing a dedicated GoHighLevel developer should be doing for you rather than handing you a rejection code and a shrug.
The bottom line
A2P 10DLC is not a tax on texting. It is carriers asking you to prove, in public, that the people you are about to message asked to be messaged. Every rule above is downstream of that one idea, which is why the fixes are so unglamorous: a checkbox, a sentence in a privacy policy, a paragraph on a page that says what your business does.
We register brands and campaigns as part of every build, so this is the loop I spend my weeks inside. It is the foundation under our TCPA-compliant AI calling setup and under the messaging side of our GoHighLevel work, and it is the same layer any AI voice agent needs before it texts a lead after the call. Book a 30-minute call at cal.com/zeeshanwaheed/30min, or email [email protected], and bring the rejection codes with you.