HVSMS

Compliance

Prohibited SMS Content: Understanding SHAFT and Carrier Restrictions

SHAFT is only the start. Learn where law, carrier enforcement, and messaging-platform policy diverge—and how to keep questionable SMS campaigns out of production.

What counts as prohibited SMS content?

Prohibited SMS content is not one universal list. In US business texting, a message can be unacceptable because it is illegal, because a wireless carrier or messaging provider will not carry it, or because the program lacks the consent and disclosures required for that use. SHAFT—sex, hate, alcohol, firearms, and tobacco—is the most familiar shorthand, but it does not answer every approval question. Cannabis, gambling, deceptive financial offers, phishing, and certain high-risk business models can be blocked even though they are outside the acronym. [2] [6]

The commercial answer is simple: assess the product, the actual copy, the linked destination, the audience, the opt-in, and the sending pattern together. A legally sellable product is not automatically text-message eligible. Conversely, an approved SMS program still needs lawful consent and truthful advertising. The FCC says commercial robotexts require written consent, while informational texts may rely on oral consent; it also says consumers may revoke consent at any time in any reasonable manner. [3] This article is operational guidance, not legal advice. Have counsel assess laws that apply to your company, offer, recipients, and states.

SHAFT SMS compliance: categories have different outcomes

CTIA defines SHAFT as content related to sex, hate, alcohol, firearms, or tobacco. Its messaging security guidance identifies SHAFT content as evidence that may be relevant to an unwanted-message investigation. [2] In practice, the five letters should trigger different review paths—not a single yes-or-no conclusion.

CategoryTypical carrier or platform posturePractical business decision
SexAdult content, services, and sexually explicit promotion are commonly prohibited on standard business messaging routes.Do not try to soften wording or move explicit material behind a link. Use another channel only after legal and platform review.
HateHate speech, discriminatory content, threats, and material that incites violence are unacceptable and may be treated as abusive traffic.Block at both copy and landing-page review. Escalate any edge case involving protected groups, violence, or harassment.
AlcoholSome US provider policies may allow alcohol traffic with age verification and other controls; the policy outcome can vary by provider and route.Treat as conditional, not pre-approved. Obtain written provider confirmation for the intended program before building it.
FirearmsStandard business SMS channels commonly prohibit firearms and related product promotion.Do not rely on age gating, licensing, or a lawful retail operation to make a campaign routable.
TobaccoTobacco, vape, e-cigarette, and related promotions are commonly prohibited on standard messaging channels.Exclude from SMS marketing plans and review affiliates, promotions, and linked catalog pages for indirect promotion.

This is policy posture, not a complete statement of law. Telnyx, for example, says standard channels do not permit firearms, tobacco, or vaping, while alcohol may be allowed in some US cases with age verification and other controls. [6] Your provider, number type, carrier route, and registration may be narrower.

Carrier restrictions and platform policies can be stricter than the law

Carriers and communications platforms manage network abuse and consumer trust, so they evaluate more than whether a product is legal in a particular state. CTIA’s principles call for affirmative steps against unlawful, harmful, misleading, harassing, excessively violent, obscene, fraudulent, privacy-invasive, or threatening content. [1] Providers can vet campaigns, audit traffic, filter messages, or suspend capability under their own terms.

  • Cannabis, CBD, hemp-derived products, and related accessories may be prohibited by the route even in states where a product is lawful. Telnyx states that state legalization does not override its carrier messaging policies. [6]
  • Gambling, betting, investment tips, cryptocurrency schemes, payday lending, debt collection, and lead generation can face heightened restrictions or provider bans. Do not treat a registered business category as automatic SMS approval. [6]
  • The destination matters. A harmless teaser that links to an adult, cannabis, deceptive, or inaccessible landing page can fail the same review as the message itself.
  • Traffic behavior matters. Repetitive messages from many numbers, misleading sender identity, unsolicited bulk traffic, or attempts to evade filters can independently trigger enforcement. Twilio expressly prohibits snowshoeing and intentional evasion of detection mechanisms. [7]
  • Carrier and platform policy changes. Make the current written policy for your provider and route part of every restricted-category launch file.

This is why A2P 10DLC registration guidance is necessary but insufficient. Registration describes who is sending and what the campaign is for; it does not override content bans, consent problems, or a destination that contradicts the registered use case. Build a campaign description that matches the message, product, opt-in language, and live web experience.

Regulated content needs a separate decision path

Do not use SHAFT as a substitute for a regulated-content inventory. A program may be restricted by its product, claims, recipient age or location, or provider conditions. Start with a product-and-jurisdiction assessment led by the business owner and counsel, then obtain written route feasibility confirmation.

Use casePrimary risk to checkOperational default
AlcoholApplicable law, recipient age, geography, provider policy, and how age eligibility is verified.Hold until the provider confirms the route and controls in writing.
Cannabis or CBDFederal and state law, plus route-level policy that may prohibit the category regardless of state legalization.Assume standard SMS is unavailable unless your selected provider explicitly approves the exact program.
Financial, health, or wellness offersTruthfulness, substantiation, privacy, sector rules, and heightened filtering of high-risk claims.Require claim substantiation and legal review before copy approval.
Gambling or bettingJurisdiction, recipient eligibility, licensing, and provider limitations or required prior approval.Do not send until the route, program type, and audience controls are documented.
Pharmacy or controlled productsProduct legality, authorization, claims, privacy, and provider prohibitions.Treat direct promotion as restricted and obtain specialist legal and provider review.

The Federal Trade Commission’s baseline is broadly relevant: advertising claims must be truthful, not deceptive or unfair, and evidence-based. It specifically notes the need for solid proof for health-related claims. [5] In an SMS program, that standard reaches the short message, the offer terms, and the landing page. A short character count is not a reason to make an unqualified claim or hide a material limitation.

Age gating is a control, not a universal permission slip

Age-gated SMS marketing requires more than a checkbox somewhere on a website. Where a provider conditionally permits a category such as alcohol, its policy may require an appropriate age-verification control, and law may impose further conditions based on the product and jurisdiction. [6] An age gate cannot turn a prohibited firearms, tobacco, adult, cannabis, or other barred use case into an approved one.

  1. Confirm whether the exact category is allowed by your messaging provider, number type, and target carrier route before collecting SMS opt-ins.
  2. Define the legal age and any state or local eligibility limits with counsel; do not use a generic age threshold by habit.
  3. Verify eligibility before enrollment, store the verification event and outcome, and suppress a person who cannot be verified or is ineligible.
  4. Keep the text, linked page, offer terms, and data practices consistent with the approved audience. Avoid sending a neutral SMS that resolves to restricted content without the required gate.
  5. Recheck approval when adding a new product, state, affiliate, promotion, or provider. A prior approval is not a blanket authorization.

Separate age eligibility from marketing consent. A verified adult has not necessarily agreed to promotional texts. Build the consent flow to satisfy the applicable legal standard and the provider’s policy, then preserve the consent evidence. See HVSMS’s practical guide to SMS opt-in requirements and the framework for a defensible consent records audit trail.

Deceptive content can be blocked even when the product is permitted

A campaign need not mention SHAFT to create a prohibited-content problem. CTIA identifies deceptive, phishing, privacy-invasive, threatening, and misleading content as traffic senders should prevent. [1] Telnyx also identifies phishing, impersonation, misleading financial offers, guaranteed returns, obscured lead-generation intent, and manipulative traffic as high-risk prohibited content. [6]

  • Do not impersonate a bank, government agency, delivery company, marketplace, or another brand. Sender identity and the real business relationship should be obvious.
  • Do not use false urgency, fabricated account problems, bait-and-switch offers, hidden recurring charges, or “guaranteed” outcomes you cannot substantiate.
  • Do not collect passwords, account credentials, Social Security numbers, or payment data through a text journey that looks like a scam or sends users to an untrusted destination.
  • Do not bury opt-in scope, material offer terms, or opt-out instructions. CTIA says calls to action should be clear and conspicuous and not use deceptive language or obscure opt-in details in terms and conditions. [2]

A branded domain, recognizable sender, honest offer, and clear destination reduce ambiguity but do not cure a misleading claim. For a broader operating baseline, review the SMS marketing compliance guide before a campaign reaches copy review.

Use a pre-send review workflow that catches the whole campaign

Make review short enough to run before every launch and rigorous enough to stop risky campaigns before they reach a carrier. Assign one marketing or lifecycle owner with defined escalation to legal, compliance, and the messaging provider. Review the live experience, not just copy.

  1. Classify the program: transactional, informational, promotional, conversational, or mixed. If a purportedly informational text includes a coupon or purchase prompt, treat it as promotional for review purposes.
  2. Screen the product and business model against SHAFT, cannabis, gambling, financial, health, controlled-product, and other provider-restricted categories.
  3. Map recipients: consent source, message purpose, age or geographic eligibility, last opt-in event, and suppression status. The FCC states that commercial robotexts require written consent. [3]
  4. Inspect every message variant, dynamic field, media asset, short link, redirect, landing page, checkout, and terms page for prohibited content or deceptive claims.
  5. Confirm operational fit: brand identification, registered campaign use case, approved number type, provider documentation, message frequency, and opt-out handling.
  6. Record the approval packet: reviewer, date, final copy, URLs, screenshots, policy decision, consent logic, and any provider exception or approval.
  7. Monitor after launch for filtering, delivery errors, complaints, opt-outs, changed destinations, and unapproved copy changes. Pause first when a material issue appears; investigate before resuming.

Review the message and destination together

Weak reviewWhy it failsStronger review
“Flash sale: Tap here.”The text alone hides whether the link leads to a restricted product, misleading terms, or an age gate that does not work.Open the final mobile landing page, test redirects, check offer disclosures, and capture the approval evidence.
“Your account is locked. Verify now.”Even for a legitimate brand, unexplained urgency and an unfamiliar link can resemble phishing.Identify the brand, explain the transaction, use a recognizable domain, and send only to customers expecting the account message.
“Save 20% today.”A discount may convert an informational order alert into promotional content and can exceed the recipient’s consent scope.Keep transaction notices genuinely transactional, or send the promotion only to the documented promotional-consent segment.

This discipline also improves deliverability. CTIA says providers may add protections such as pre-approval, vetting, in-market audits, and filtering. [1] Learn the warning signs in HVSMS’s guide to why carriers filter text messages, then make copy, destination, and audience changes through the same approval workflow.

Build the controls into your CRM, not a one-time checklist

A content policy fails if the CRM can send restricted or opted-out contacts into a campaign. Put consent type, source, timestamp, category approval, relevant age-verification status, permitted geography, provider approval, and global opt-out in the data model. Route records with missing or contradictory fields to non-send.

Create a version-controlled content library with approved claims, prohibited terms, restricted-category flags, current domains, and required disclosures. Require a new review when creative is materially changed, a destination is swapped, an offer expands to another state, or an automation adds promotional language. Explicitly test STOP and related revocation handling. The FCC says consumers can opt out of robotexts at any time and in any reasonable manner; CTIA expects senders to retain opt-in and opt-out records. [1] [3] Use HVSMS’s SMS opt-out requirements guide to turn that expectation into a tested suppression flow.

For established programs, review policy quarterly and after provider notices, complaint spikes, or blocked campaigns. HVSMS can map strategy, audience architecture, registration inputs, and implementation controls. We do not replace counsel or promise carrier acceptance.

Frequently asked questions

Questions about prohibited SMS content

Is SHAFT content illegal to send by SMS?

Not necessarily. SHAFT is an industry shorthand for sex, hate, alcohol, firearms, and tobacco, not a single statute. Whether a message is lawful depends on the facts and applicable laws. Separately, carriers and messaging platforms may prohibit or condition the category even when the underlying product is legal. Treat every SHAFT-related program as a legal and route-policy review, not as an automatic approval or rejection. [2] [6]

Can an alcohol brand use SMS marketing if it has age gating?

Possibly, but only if the applicable law, audience eligibility, and the specific provider and carrier route allow the program. Provider policies can vary; Telnyx, for example, describes alcohol as conditionally restricted and potentially permitted in certain US cases with age verification and compliance controls. Age gating does not itself establish legal compliance or carrier approval. Obtain written provider confirmation for the exact use case before launch. [6]

Are cannabis or CBD promotions allowed by SMS in states where they are legal?

State legality does not guarantee SMS eligibility. Major messaging providers may prohibit cannabis, CBD, hemp-derived products, and related traffic across their US and Canada channels. Telnyx expressly states that state-level legalization does not override carrier messaging policies. Check the live policy for your provider and route, and do not collect opt-ins for a program until feasibility is confirmed. [6]

What should be included in an SMS content approval record?

Keep the final message variants, media, live URLs and screenshots, business and product classification, target segment, consent basis, age or geography controls where relevant, registered use case, provider decision, reviewer, and approval date. Preserve the original opt-in and later opt-out events as well. These records make provider inquiries, internal audits, and campaign changes far easier to investigate. [1] [7]

Free strategy teardown

Make your SMS program easier to approve and harder to block

Book a free SMS strategy teardown. HVSMS will identify content, consent, routing, and workflow gaps that could slow a launch or damage deliverability—then show you the practical implementation path.Get Your Free SMS Strategy Teardown →

References

[1]CTIA Messaging Principles and Best Practices (May 2023)

[2]CTIA Messaging Security Best Practices (October 2025)

[3]FCC: Stop Unwanted Robocalls and Texts

[4]FCC: One-to-One Consent Rule for TCPA Prior Express Written Consent FAQ

[5]FTC: Advertising and Marketing

[6]Telnyx: Forbidden Messaging Use Cases in the US and Canada

[7]Twilio Messaging Policy