Policy change

Toll-free verification and A2P 10DLC merge on 15 September 2026

What is changing

Twilio is bringing toll-free verification and A2P 10DLC under a single content policy with effect from 15 September 2026. Until now the two have been reviewed against overlapping but separately worded rules, which is why a business could pass one and fail the other on what looked like the same question. After that date they are judged against one policy.

The change introduces a new block of rejection codes numbered 30532 to 30567, thirty six of them. Every code in that block is eligible for resubmission. None of them is terminal, so none behaves like the content codes in the 30940 to 30964 range where the only remedy is a new brand and a new campaign.

One existing code is affected rather than replaced. 30530 is refined by the new policy, not superseded by it, so it keeps its own page and its own code number.

Where this comes from, and what is not confirmed yet

The change is described in Twilio help article 9321443984155, captured from a browser session on 10 August 2026. That article is the source for the effective date, the code range, and the resubmission status of the new block.

Two things are worth stating plainly, because they affect how much weight to put on any per-code advice you find elsewhere before that date.

  • As of 10 August 2026 there are no per-code documentation pages for 30532 to 30567. Requests to the usual documentation URL for codes in that range return a 404.
  • None of the thirty six codes appears in Twilio's machine-readable error export, which is the file that feeds the public error dictionary.

Both were checked directly rather than assumed. So the codes are announced but not yet documented per code. The pages here are built from the help article text captured on 10 August 2026, and each one says so in place of a per-code documentation link, because no such link exists yet.

The thirty six new codes

Grouped by the category Twilio assigns to each. Every one of them is eligible for resubmission, so none behaves like the content codes in the 30940 to 30964 range where the only remedy is a new brand and a new campaign.

Business Information (4)

  • 30532: Personal use cases are not supported
  • 30533: Person-to-person (P2P) use cases are not supported
  • 30534: Testing use case is missing business or program details
  • 30535: Viral messaging is missing required compliance disclosures

Business Website (1)

  • 30536: Privacy policy URL is missing or inaccessible

Message Program Details (6)

  • 30537: Business model does not match the messaging use case
  • 30538: A message sample is missing for a selected use case
  • 30539: Opt-out instructions or keywords are missing or noncompliant
  • 30540: Double opt-in confirmation message is required
  • 30541: Political campaign is missing an FEC or state committee ID
  • 30542: Political messaging must use the Political use case category

Opt-In and Consent (14)

  • 30543: Live opt-in link not provided
  • 30544: Call-to-Action does not state the message purpose
  • 30545: Call-to-Action does not state message frequency
  • 30546: Opt-in agreement expired without the required changes
  • 30547: Call-to-Action is missing opt-out instructions
  • 30548: Charitable program does not separate consent for donation requests
  • 30549: No Terms of Service link found in the opt-in flow
  • 30550: No Privacy Policy link found in the opt-in flow
  • 30551: Consent does not specify SMS or text messaging
  • 30552: Opt-in is not customer-facing
  • 30553: SMS is forced for two-factor authentication
  • 30554: Charitable donations collected insecurely over SMS
  • 30555: First message sent without documented prior consent
  • 30556: SMS consent is bundled with other communication channels

Privacy Policy and Terms of Service (8)

  • 30557: Terms of Service missing business or program name
  • 30558: Terms of Service missing message frequency disclosure
  • 30559: Terms of Service missing product description
  • 30560: Terms of Service missing customer support information
  • 30561: Terms of Service missing opt-out information
  • 30562: Terms of Service missing message and data rates disclosure
  • 30563: Terms of Service missing carrier liability disclosure
  • 30564: Terms of Service and Privacy Policy links not near opt-in

High Risk (1)

  • 30565: Prescription Drugs and GLP-1s: Informational Use Only

Disallowed Content (2)

  • 30566: Academic Fraud and Cheating Services Are Prohibited
  • 30567: Phishing and Simulated Phishing Messages Are Prohibited

What to do before 15 September 2026

Nothing about the existing codes stops working on that date. A rejection you received before the change still means what the page for that code says it means, and the fix is still the fix.

The practical risk is narrower than it sounds. If you have a rejection open across the changeover, the reason it was rejected does not change, but the code you are quoted afterwards may. Keep the original rejection response, including every code in it, rather than only the code you were told about. That record is what lets you show the same problem was already being worked before the policy moved.

Two ways forward

Have it handled for you

A2P registration is handled for you on Growth at $597/mo and on Scale at $1,197/mo. Registration, resubmissions, and the compliance work behind them are included.

See Growth and Scale

Fix it yourself

Send your email and we will send the fix playbook for registration rejections.

Verified against Twilio documentation on 2026-08-10. Policy change captured from Twilio help article 9321443984155 on 2026-08-10.