Most outbound teams treat "DNC compliance" as a single checkbox: scrub against the federal registry, done. But there are three separate lists in play, they carry different levels of liability, and the one that generates the most winnable lawsuits isn't the federal registry at all. It's the list you built yourself — the people who already told you to stop.

Full disclosure: I work for Ready, an SMS platform, and we sell a scrubbing add-on I'll reference below. I'm going to try to be honest about what scrubbing does and doesn't buy you, because "we screened your list" is not the same as "you're safe."

Three lists, three very different risks

When someone says "check the DNC," they could mean any of these:

ListWhat it isWho maintains itLiability if you ignore it
Federal DNC (National Registry)Consumers who registered to stop telemarketing broadlyFTCReal, but you can often argue prior business relationship or consent
Internal / company-specific DNCPeople who told your company to stopYouHighest — it's your own record proving you knew
Litigator / DNC-complainer listsNumbers belonging to serial TCPA plaintiffs and habitual complainersThird-party data vendorsCatastrophic per-contact — these people sue for a living

Each one requires a different action, and skipping any of them is a different kind of expensive.

Why your internal list is the one that sinks you

Here's the uncomfortable part. If you text a number on the federal registry, a defense attorney has room to work — maybe you had an established business relationship, maybe you captured consent, maybe the registration was stale.

If you text someone who replied STOP to you last month, there is no argument. You have a timestamped record, in your own system, of that person revoking consent. The plaintiff's attorney doesn't have to prove anything about intent. Your own database is the evidence.

Under the TCPA, each of those texts is exposed to $500 to $1,500 in statutory damages. That's per message, not per person. A workflow that fires four texts to someone who opted out is four violations from one revoked contact. If a batch of 60 opted-out numbers slips back into a blast, you're staring at 60 × 4 × up to $1,500 on the high end — and unlike a federal-registry dispute, there's nothing to argue.

Regulators and plaintiff's attorneys know this, which is why the internal suppression list is the first thing they ask for in discovery. It's the cheapest violation to prove.

How opt-outs leak back in

The internal list breaks in predictable ways:

  • A CSV re-import. Someone exports a lead list, cleans it in a spreadsheet, and re-uploads. The suppression flags don't ride along on a raw CSV, so a person who opted out three months ago is now a "fresh" row again.
  • Opt-out that doesn't cross campaigns. Someone replies STOP to your promo campaign but stays active in your appointment-reminder campaign because the two live in different silos.
  • Opt-out that doesn't cross channels. They text STOP, and your dialer keeps calling them because voice and SMS suppression aren't wired together. We wrote a whole piece on that failure — why opt-out rarely crosses channels and the fix.
  • Manual list management. Any process where a human is supposed to remember to remove someone is a process that will eventually fail on a busy day.

Every one of these puts a known-revoked number back in the send queue.

What automatic STOP handling actually fixes

The first line of defense is making opt-out impossible to miss. In Ready, inbound STOP / UNSUBSCRIBE is honored automatically, and — this is the part that matters — the opt-out propagates across campaigns so that contact can't be messaged again from another campaign in your account. That closes the "opted out of promos, still in reminders" gap by default rather than relying on someone to sync it.

That's the internal list, maintained by the system, updated in real time as replies come in. It's not optional configuration you can forget to turn on.

But automatic STOP handling only captures opt-outs that happened inside the platform. It doesn't know about:

  • Numbers you suppressed in your old tool before you migrated
  • Complaints that came in by phone, email, or a rep noting "please stop"
  • People who never contacted you but are on external litigator lists

For those, you need a scrub.

Where litigator scrubbing fits — and where it doesn't

Ready's standalone TCPA & DNC Litigator Scrub is $0.005 per contact. One scrub checks each number against known TCPA-litigator lists and DNC-complainer lists and auto-suppresses the matches before send. You pay only for what you scrub.

Run the math on a 10,000-contact list before a campaign:

  • 10,000 × $0.005 = $50 to screen the whole list.

Compare that to a single successful claim from one flagged litigator: $500 to $1,500 for one text, and these plaintiffs rarely stop at one. Fifty dollars to keep a known serial filer out of a 10,000-contact blast is not a hard decision.

But be clear on what this buys and what it doesn't:

  • Litigator scrubbing catches known plaintiffs and complainers. It does not catch someone who opted out of your list but isn't on any national list — that's your internal suppression's job.
  • Scrubbing is a risk reducer, not immunity. You can scrub a clean list and still get sued if your consent record is weak. Compliance is ultimately the sender's responsibility.
  • Timing matters. Scrubbing after you've already imported and started sending is too late — the violation is the text that already went out. We covered exactly this in why scrubbing litigators after import is too late. Scrub before the send, every send, not once at onboarding.

The three-layer setup that actually holds

Put together, a defensible outbound process runs all three lists, in this order, before every campaign:

  1. Internal suppression (automatic). Every STOP reply is honored and propagated across campaigns automatically. Never re-import a raw CSV over the top of a list with existing opt-outs — import into the same system so suppression flags stay attached.
  2. Litigator + DNC-complainer scrub ($0.005/contact). Run it against the list you're about to send, not once at setup. Fifty dollars per 10,000 contacts.
  3. Federal DNC + supporting hygiene. Honor the national registry, and pair it with quiet-hours enforcement (Ready holds sends outside the recipient's permitted local hours) and consent attestation captured on bulk and API sends so you have an audit trail when someone asks how a number got on your list.

None of these three replaces the others. The federal registry doesn't know your opt-outs. Your internal list doesn't know who the litigators are. The litigator scrub doesn't know who told you personally to stop. You need all three running, and you need them running before the send fires — not as a cleanup after.

The practical takeaway

If you only fix one thing this week, fix the internal list. It's the cheapest violation to prove because you built the evidence yourself, and it's the one that leaks back in every time someone re-imports a spreadsheet. Automatic, cross-campaign STOP handling closes most of that gap without anyone remembering to do it.

Then layer the litigator scrub on top at $0.005 a contact before each send, and keep honoring the federal registry with quiet hours and consent records behind it. That's not lawsuit-proof — nothing is — but it's the difference between a plaintiff having a case handed to them from your own database and having to actually build one.

If you want to see how the automatic STOP handling and the scrub add-on fit together, they're both part of Ready's SMS platform, and you can start with 2,500 free credits to test the flow on a small list before you trust it with a big one.