All posts

The $500-Per-Text Risk Hiding in Your CRM Setup

Your CRM fires off automated follow-up texts the moment a lead fills out a form. Good. Speed-to-lead wins deals. But every one of those texts carries a statutory price tag if your consent documentation has a gap: $500 per message. Willful violations run $1,500. There is no cap on the number of messages a plaintiff can claim.

A single drip campaign sent to 200 contacts without proper prior express written consent creates $100,000 to $300,000 in potential liability. That is not a hypothetical number. TCPA class-action filings against real estate companies have grown steadily since the FCC tightened its consent rules in 2024, and plaintiff attorneys now specialize in scraping agent texting records during discovery.

Most CRMs ship with auto-text features enabled by default. Almost none of them walk you through the consent documentation you need before flipping that switch. This checklist fills that gap.

TL;DR: TCPA penalties run $500 to $1,500 per unsolicited text with no cap on message count. Your CRM's auto-follow-up creates liability every time it fires without documented consent. This 7-point checklist covers what to audit: consent records, DNC scrubbing, opt-out handling, A2P registration, and AI disclosure rules effective in 2026.

What TCPA Says About Agent Texting Right Now

The Telephone Consumer Protection Act requires prior express written consent before you send automated text messages to leads. "Automated" includes any message sent by software on a schedule or trigger, which covers every CRM drip sequence and AI follow-up workflow on the market. Penalties are $500 per unsolicited text, rising to $1,500 for willful violations. There is no per-campaign or per-plaintiff cap.

Since April 2025, the FCC has also required that you honor opt-out requests made in any reasonable form within 10 business days. That means a lead who replies "please stop texting me" or "take me off the list" has revoked consent just as effectively as someone who replies STOP. If your CRM only processes the keyword STOP and ignores plain-language requests, every subsequent message is a violation.

The one-to-one consent rule is dead. The underlying consent requirement for automated texts is not. Every CRM auto-text still needs documented prior express written consent.

One important clarification: the FCC's one-to-one consent rule, which would have required lead generators to obtain separate consent for each company that contacts a consumer, was vacated by the Eleventh Circuit Court of Appeals in January 2025. The FCC later dropped the rulemaking entirely. A single lead form can still support consent for multiple parties, as long as the disclosure identifying those parties is clear and conspicuous. But the underlying consent requirement for automated messages remains fully in force.

The 7-Point CRM Compliance Checklist

Run this audit today. Every "no" you find is cheaper to fix now than to defend later.

Work through each item against your current CRM setup. If you can't confirm a "yes" on any point, pause your automated sequences for that contact segment until you can.

1. Consent records exist for every contact in your texting list

Every phone number that receives automated texts from your CRM must have a documented consent record: who consented, when, through which form, and what the disclosure language said. If you imported a CSV of contacts from a networking event, a purchased list, or an old database backup, those contacts almost certainly lack valid consent records. Remove them from automated sequences immediately or obtain fresh consent before texting them.

2. Consent language specifically authorizes automated messages

A lead who fills out a "contact me" form has given consent to be contacted. They have not necessarily given consent to receive automated text messages. The TCPA distinguishes between these consent types. Your web forms, landing pages, and lead capture tools must include language that specifically mentions automated text messages, not just phone calls or general contact. Check the exact wording on every form that feeds into your CRM. If it says "I agree to be contacted" without mentioning automated texts, it is not sufficient.

3. DNC registry is scrubbed every 31 days

The FCC requires businesses making telemarketing calls or texts to scrub their contact lists against the National Do Not Call Registry at least every 31 days. Your CRM may or may not automate this. If it does not, you need a third-party scrubbing service and a calendar reminder. Texting a number on the DNC registry carries the same $500 to $1,500 per-message penalty as any other TCPA violation. The 31-day window means a number can appear on the registry after your last scrub and before your next one, creating a narrow but real window of liability.

4. Opt-outs are processed within 10 business days

Since the FCC's April 2025 rule change, consumers can revoke consent "in any reasonable manner." Your CRM must process opt-outs triggered by STOP, stop, Unsubscribe, "take me off the list," "don't text me," or any other plain-language refusal. If your system only watches for the STOP keyword, every message sent after a plain-language revocation is a willful violation at the $1,500 tier. Check whether your CRM parses free-text opt-out requests or only responds to exact keyword matches.

5. Business texting uses A2P 10DLC registered numbers

Application-to-person (A2P) messaging through 10-digit long codes requires registration with The Campaign Registry. This is a carrier-level requirement, not technically a TCPA rule, but unregistered numbers face message filtering and delivery failures. More importantly for compliance, A2P registration creates a documented audit trail of your texting campaigns, which is exactly what you want if you ever need to demonstrate compliance. If you are sending automated texts from a personal cell phone number, you are almost certainly not A2P registered, and your messages may not even be delivered reliably.

6. AI-generated texts disclose automation

If your CRM uses AI to generate or personalize text messages, those messages may qualify as communications sent using an "automatic telephone dialing system" (ATDS) under the TCPA. The FCC has signaled that AI-generated responses trigger the same consent requirements as any other automated message. Several states, including California and Washington, have additional disclosure requirements for AI-initiated communications. If your CRM's AI follow-up feature generates contextual replies that appear to come from a human agent, add a disclosure to the message or the initial consent language that automated and AI-generated messages may be used.

7. Imported leads have consent documentation from the original source

When you buy leads from a portal, referral network, or lead generation service, the consent the lead gave was to that service, not to you. Under the current framework (post-vacatur of the one-to-one rule), shared consent can work if the original form clearly disclosed that the lead's information would be shared with specific types of businesses. But "clearly disclosed" is doing heavy lifting in that sentence. If the lead generation company's consent language was vague, your texting those leads creates liability for you, not for the lead company. Request copies of the consent language used on the forms that generated your purchased leads. If the vendor cannot or will not provide it, do not add those contacts to automated text sequences.

Where CRM Compliance Breaks: 3 Common Failures

Most TCPA violations don't come from bad intent. They come from CRM imports, personal phones, and consent-type mismatches that nobody audited.

The bulk import problem

An agent joins a new brokerage, exports 3,000 contacts from their old CRM, and imports them into the new one. The consent records from the old system do not transfer. The new CRM has no documentation that any of those 3,000 people consented to automated texts from this new brokerage entity. But the auto-follow-up sequences fire anyway, because the CRM treats every imported contact as eligible. This is the single most common source of TCPA liability in real estate. If you recently migrated CRMs, audit your imported contacts before running any automated campaigns against them.

The personal phone problem

Some agents text leads from personal cell phones using the CRM's mobile app. This creates two issues. First, personal numbers are not A2P registered, so messages may be filtered or flagged. Second, if the agent leaves the brokerage, the consent was tied to the brokerage entity, not the agent's personal number. Continued texting from that number without re-establishing consent is a violation. Use dedicated business lines for all automated outreach. If your CRM offers a built-in dialer or texting number, use it. Your CRM comparison should include whether the platform provides compliant texting infrastructure.

The consent-type mismatch

Transactional messages (appointment confirmations, showing updates, closing timeline notifications) require a lower level of consent than promotional messages (new listing alerts, market update campaigns, re-engagement drips). Many CRMs do not distinguish between these categories. If a past client consented to transactional updates during their purchase, that consent does not cover promotional texts six months later asking them to refer friends. Segment your contact lists by consent type and restrict promotional sequences to contacts with explicit promotional consent.

The Practical Math: Why This Matters for Small Teams

A solo agent running a modest CRM setup might send 200 automated texts per week across lead follow-up, appointment reminders, and drip campaigns. That is roughly 10,400 texts per year. If even 5% of those contacts lack proper consent documentation, that is 520 potentially non-compliant messages. At $500 per message, the statutory exposure is $260,000. At the willful rate of $1,500, it reaches $780,000.

For a 5-person team sending 1,000 texts per week, the annual volume hits 52,000 messages. A 5% consent gap means $1.3 million to $3.9 million in potential liability. That's why TCPA class actions are among the most common lawsuits filed against businesses that use automated communications, and why plaintiff attorneys actively target industries with high text volumes and inconsistent compliance practices.

The fix is not to stop texting. Speed-to-lead is too important, and automated follow-up genuinely converts when done right. The fix is to audit your consent documentation, close the gaps, and make compliance part of your CRM onboarding process. It is cheaper to run this checklist once than to defend a single lawsuit.

What to Do This Week

  1. Export your CRM contact list and identify every contact that lacks a documented consent record. Move unconsented contacts out of automated sequences.
  2. Review every web form that feeds leads into your CRM. Confirm the consent language specifically mentions automated text messages.
  3. Set up DNC scrubbing on a 31-day cycle. Use your CRM's built-in feature or a third-party service like DNC.com.
  4. Test your opt-out processing. Send a test text and reply with plain language like "please stop" (not STOP). If the system doesn't catch it, talk to your CRM vendor.
  5. Register your business texting numbers for A2P 10DLC if they are not already registered.

If you're shopping for a CRM and compliance is a factor (it should be), our real estate CRM comparison covers the platforms that include built-in compliance tooling versus those that leave it to you. And if you want a platform that was built with agent workflows and compliant follow-up in mind, start your RobinFlow onboarding here.

FAQ

Do I need written consent for every single text I send to a lead?

For automated texts sent by your CRM on a schedule or trigger, yes. The TCPA requires prior express written consent for automated messages. Manual, one-to-one texts that you type and send yourself from your phone are generally covered by implied consent if the lead gave you their number. But the moment your CRM sends a message automatically, the written consent requirement applies. The safest approach is to treat every contact in an automated sequence as requiring documented prior express written consent.

What makes a TCPA violation "willful" versus standard?

The $1,500 penalty applies when a court determines the violation was knowing or intentional. Continuing to text someone after they have requested to stop is the clearest willful violation. Ignoring a plain-language opt-out because your CRM only processes the STOP keyword is another. Courts have also found willfulness when businesses failed to implement reasonable compliance procedures despite knowing the TCPA requirements. Running this audit and documenting your compliance efforts is evidence against willfulness if a claim is ever filed.

Does the FCC one-to-one consent rule still apply?

No. The FCC's December 2023 rule requiring one-to-one consent (each company that contacts a lead must have its own separate consent) was vacated by the Eleventh Circuit in January 2025. The FCC dropped the rulemaking entirely after the court ruling. The pre-existing framework applies: a single lead form can support consent for multiple parties, but the disclosure must clearly identify those parties. The underlying requirement for prior express written consent for automated messages hasn't changed.

Can my brokerage be held liable for an agent's texting violations?

Yes. Courts have held brokerages vicariously liable for agents' TCPA violations when the texting was done in the course of business. Some states have additional agency liability rules. Brokerages should establish texting policies, require agents to use compliant CRM-provided numbers rather than personal phones, and audit consent documentation regularly. The compliance exposure belongs to the entire organization, not just the individual agent who pressed send.