Your Customer.io SMS Isn't Being Filtered, It's Being Blocked: The A2P 10DLC Registration You Can't Skip

By·Published·Updated
Your Customer.io SMS Isn't Being Filtered, It's Being Blocked: The A2P 10DLC Registration You Can't Skip

By the middle of the 1920s, American radio had become unlistenable in places. Stations crowded onto the same frequencies and broadcast straight over one another, and in the worst spots the signal dissolved into interference. Too many transmitters, and no real gatekeeper deciding who got which slice of the air.

Congress fixed it with the Radio Act of 1927, signed on 23 February that year. The act created the Federal Radio Commission and gave it one job above the rest: decide who gets a licence, and on what frequency. An earlier law, the Radio Act of 1912, had required operators to hold a licence, but it hadn't kept the air clear. The 1927 act changed that: the new commission could assign frequencies and refuse or revoke a licence. From then on, if you didn't hold one, you had no lawful place on the dial. Not a worse slot. No slot.

US business texting is having its Radio Act moment, and most teams switching on SMS haven't noticed.

If you're adding SMS to your Customer.io setup for a US audience, one step sits before your first send and quietly decides whether any message arrives: A2P 10DLC registration. SMS is one of the highest-intent channels in any omnichannel messaging mix, but in the US it has an on-switch, and the switch is registration. Skip it and you don't get worse delivery—you get none. This post covers what A2P 10DLC actually is and the fork in Customer.io setup that decides whether you register through Customer.io or your own Twilio account. It also covers what to prepare before you start, and why the clock runs one to two weeks.

Filtered is survivable. Blocked is not.

The shift that matters is simple: US carriers used to filter suspicious business texts, and now they reject them. Filtering is survivable. A filtered message might reach fewer phones, arrive late, or get throttled, but some of it lands, and you can work on improving it. Blocking is a different thing. The message never leaves the carrier's network. Nothing arrives, and there's no spam folder for the recipient to rescue it from.

Application-to-person (A2P) traffic on ordinary 10-digit numbers is now the blocked kind. Infobip's 2026 compliance guide puts it plainly: without registration, messages 'will be blocked, delayed, or sent at lower throughput', and unregistered traffic 'is not allowed'. Telnyx is blunter still: carriers 'will block all unregistered long-code traffic, making it impossible to send business SMS messages from unregistered numbers'. Unregistered messages end up 'either silently dropped or returned with an error code'. AT&T moved first and enforces hardest; the other major carriers followed, and by early 2025 the block was effectively across the board.

The unkind part is how it looks from your side. Your Customer.io send can report success while the carrier bins the message. You see sent. Your customer sees nothing. That's why an unregistered number doesn't underperform—it delivers nothing, and it does so invisibly, which is worse, because you can spend weeks tuning copy on a channel that was never going out.

What A2P 10DLC actually is

A2P 10DLC is the standard US carriers use to vet business texting, and in practice it comes down to two registrations. First, a little decoding. A2P stands for application-to-person: any message sent by software rather than typed by one human to another. Carriers treat everything from a texting platform as A2P, so your Customer.io sends count. 10DLC stands for 10-digit long code, an ordinary local number, as opposed to a short code or a toll-free number. Put together, A2P 10DLC is business texting from a normal 10-digit number, and it's the traffic carriers now insist on vetting.

The vetting has two parts. Twilio's documentation describes them as the two main components of registration: you create a brand, and you create a campaign. The brand says who is sending: your legal business name, address and tax ID, so carriers know there's a real, accountable company behind the messages. The campaign says what you'll send and how people consent: your use case (marketing, order updates, reminders), sample messages, and how recipients opt in, opt out, and ask for help.

Both go to The Campaign Registry, the central registry the major carriers appointed to hold this data. Telnyx describes carriers then using that registration data to decide throughput, deliverability and filtering. You rarely touch The Campaign Registry yourself. Your messaging provider, Customer.io or Twilio underneath it, submits on your behalf. But the information it needs is yours to supply, and that's where most of the delay comes from.

The Customer.io fork: native SMS or your own Twilio

Customer.io gives you two ways to set up SMS, and which one you're on depends on where you're based and who you're texting. Get this fork right early, because it decides who you register with.

The native route lets you handle numbers and billing inside Customer.io, with no separate Twilio account. Customer.io's SMS setup guide limits it to senders who meet three conditions: your business is based in the US or Canada, and you only send to people there. The third: you don't need advanced Twilio analytics like revenue attribution or sending queues. Miss any one of those and the native route isn't for you. It's also still rolling out. Customer.io calls it available to 'select users right now', so eligibility is confirmed by signing up, not assumed. Don't build a launch plan around native SMS until Customer.io has told you you're in.

Everyone else runs their own Twilio account and connects it to Customer.io. That's most teams with any audience outside the US or Canada, plus anyone who wants those revenue-attribution and queue features. Setup is short: create the Twilio account, buy a sender number there, then paste your Twilio Account SID and Auth Token into Customer.io under Workspace Settings > SMS. After that you send through Customer.io as normal, with Twilio sitting underneath.

One quiet detail is worth knowing. Customer.io routes SMS through Twilio's US region regardless of where your recipients are. If you have strict data-residency rules, EU processing for GDPR, say, that's a constraint to check before you commit. And if your audience sits mostly outside the US, SMS may not even be the right first channel. In many markets your audience is easier to reach on native WhatsApp and LINE, which Customer.io now supports.

What to prepare before you start

Most of the one-to-two-week wait is spent on things only you can supply, so prepare them before you contact anyone. Customer.io's checklist for getting a phone number names four, and each one is a common reason registrations bounce back.

A privacy policy that mentions SMS. It needs to say you collect phone numbers, what you use them for, and that you won't sell or share them for anyone else's marketing. A generic policy with no mention of text messaging gets flagged.

Terms and conditions covering your messaging. Message frequency, that message and data rates may apply, and how to stop. Carriers read these.

An opt-in and opt-out flow. This is the part carriers scrutinise hardest. You need real, provable consent before the first message: a checkbox that isn't pre-ticked, a keyword sign-up, a form. And you need to handle STOP and HELP replies. In Customer.io, that consent maps onto per-channel subscription preferences, so an SMS opt-out never costs you the email subscriber, and onto your suppression and frequency rules so a STOP is honoured everywhere.

Sample messages that match what you'll actually send. Written the way the real ones will read, for each use case you'll register. Registrations get rejected when the samples describe marketing but the campaign is registered as transactional, or the other way round. Match them.

Have those four ready and the registration is mostly filling in boxes. Turn up without them and you'll spend the fortnight writing them under time pressure while the clock runs.

The one-to-two-week clock

Approval runs one to two weeks, and it's out of your hands once you submit. Customer.io is candid about it: you need sign-off from both Twilio and the cellular carriers, and it 'can take longer if Twilio and carriers request changes to your privacy policy and terms and conditions'. Two reviewers, each able to send you back a step.

What drags it past two weeks is almost always a second round: a rejection, a fix, a resubmission, another wait. The privacy policy that didn't mention SMS. Sample messages that don't match the registered use case. A consent flow the reviewer can't verify. Each one restarts the clock. The way to avoid a second round is to make the first submission clean, which is the whole point of the preparation above.

So start the registration the day you decide to add SMS, not the week you want to launch. The work you can do in parallel, building flows and importing numbers into the phone attribute, won't send a thing until the registration clears. The registration is the critical path. Treat it that way.

Toll-free is a different track

If someone suggests dodging all this with a toll-free number, they're half right, and it matters which half. Toll-free numbers can send business texts to the US, but they are not part of A2P 10DLC. Twilio states it directly: 'Toll-Free numbers and short code numbers aren't part of the A2P 10DLC system'.

They have their own gate instead. Toll-free numbers go through toll-free verification, a separate submission with its own review, run through Twilio's toll-free onboarding rather than the 10DLC brand-and-campaign flow. Short codes, those five-to-six-digit numbers, are a third track again, and more expensive to run. None of them is a shortcut around registration; they're different registrations. Pick the number type on its merits, toll-free can be reasonable for lower-volume, nationwide sending that doesn't need a local look, but don't pick it thinking it skips the paperwork. It just changes which form you fill in.

Once you're through, SMS earns its place

Once the registration clears, SMS stops being a liability and becomes the fastest channel you own. It earns its place in the flows where timing decides the outcome: a dunning sequence that escalates from email to a text when a payment fails, a shipping alert, a same-day reminder. All of it sits behind the one step you can't send a single message without.

If a fortnight of privacy-policy edits and campaign forms isn't how you want to spend the run-up to launch, that's the kind of setup we do for Customer.io teams. Tell us where you're sending and who to, and we'll get the registration clean the first time. Start a conversation here.

Frequently asked questions

Q: Why did my Customer.io SMS send successfully but never arrive?

The most likely cause is that your number isn't registered for A2P 10DLC. US carriers block unregistered business texts at the network, so Customer.io can report a message as sent while the carrier drops it before it reaches the phone. Telnyx notes unregistered messages are 'either silently dropped or returned with an error code'. Check your registration status first: a clean 'sent' with zero deliveries is the classic signature of an unregistered 10-digit number.

Q: Do I need A2P 10DLC if I only send a handful of texts?

Yes. Twilio's rule is that anyone sending SMS from a 10-digit number to the US must register, and that explicitly includes 'individuals and hobbyists'. There's no low-volume exemption; low senders just register as a Sole Proprietor brand, a lighter tier, rather than skipping registration. The one narrow exception is pure one-time-passcode traffic, which can use Twilio Verify instead. Ordinary marketing or lifecycle texts don't qualify for that carve-out.

Q: Does Customer.io register me, or do I set up Twilio myself?

It depends on the fork. If your business is in the US or Canada, you only text people there, and you don't need advanced Twilio analytics, you may qualify for Customer.io's native SMS. On that route, Customer.io helps you register and manages your numbers and billing. Everyone else sets up their own Twilio account, connects it to Customer.io, and registers through Twilio. Either way, registration isn't fully automated: you supply the brand and campaign details, and Twilio and the carriers still approve.

Q: How long does SMS registration take in Customer.io?

Roughly one to two weeks. Customer.io says you need approval from both Twilio and the carriers, and it 'can take longer if Twilio and carriers request changes to your privacy policy and terms and conditions'. The biggest single cause of delay is a rejected first submission, so prepare your privacy policy, terms, consent flow and sample messages before you start.

Q: What happens to messages sent from an unregistered number?

They're blocked, not delivered. Infobip states unregistered traffic 'is not allowed' and will be 'blocked, delayed, or sent at lower throughput'; Telnyx says carriers block all unregistered long-code traffic outright. You can still be charged for them, too: Twilio notes unregistered senders 'receive additional carrier fees'. The worst case isn't slow delivery, it's paying to send messages nobody receives.

Q: Do toll-free numbers need A2P 10DLC?

No, toll-free is a separate track. Twilio confirms that 'Toll-Free numbers and short code numbers aren't part of the A2P 10DLC system'. Toll-free numbers still need their own toll-free verification before they'll send reliably, so it isn't a way to skip registration, just a different registration with a different form.

Q: What do I need to prepare before I register?

Four things, per Customer.io's checklist: a privacy policy that mentions SMS, terms and conditions covering your messaging, and an opt-in and opt-out flow with provable consent and STOP and HELP handling. The fourth is sample messages that match your real use case. Having these ready before you contact Customer.io is the difference between a clean approval and a fortnight of back-and-forth.

Q: Does any of this apply if I send outside the US?

A2P 10DLC is a US carrier framework, so it governs US-bound texts specifically. But sending outside the US or Canada pushes you onto your own Twilio account rather than Customer.io's native SMS, and other countries have their own SMS rules to meet. For a mostly non-US audience, SMS may not be the best first channel anyway; WhatsApp and LINE often reach further in those markets.

Q: What's the difference between a brand and a campaign in A2P 10DLC?

The brand is who's sending; the campaign is what you're sending. Twilio describes registration as two components: a brand (your legal business identity, including name, address and tax ID) and a campaign (your use case, sample messages, and opt-in, opt-out and help handling). One brand can run several campaigns for different message types, such as one for marketing and one for order notifications.

Q: Can I use my own existing phone number to send SMS through Customer.io?

No. On the Twilio route, Customer.io's docs are explicit: 'You can't use your own phone number to send SMS; you need to purchase a number from Twilio'. Your sender can be a standard 10-digit number, a short code, or an alphanumeric ID, but it has to come from the provider. Store your recipients' numbers in the phone attribute in E.164 format (the international +country-code form, like +14155550123) so they send correctly.

Q: Does A2P 10DLC apply to transactional texts, or only marketing?

Both. Registration is about the number and the sender, not whether the content is promotional. Appointment reminders, order updates and one-off notifications all count as A2P traffic from a 10-digit number and need a registered campaign. You declare the use case (transactional, marketing, and so on) as part of the campaign, but no content type is exempt from registration itself. The only carve-out is pure verification codes sent through Twilio Verify.

Q: Should I start registration before building my SMS flows?

Yes, start it first. You can build campaigns and import phone numbers in parallel, but nothing sends until the registration clears, so it's the critical path. Kick it off the day you decide to add SMS, not the week you want to go live.

Sources

Want this working in your Customer.io workspace?

It's what we do all day for SMBs—strategy, automations, deliverability and hands-on execution.

See how we work as a Customer.io agency →
David Crowther
Book a free consultation →

On our call, you'll be speaking with David Crowther, founder of NerveCentral.

Our initial consultation is not a sales call—you'll talk, I'll listen and ask questions—then I'll come back to you within 48 hours with our best ideas on how to grow your business.