A client forwards you a spreadsheet. 40,000 rows. Name, email, phone, some purchase history. "We bought this from a partner in the space — same customer profile as ours. Blast them the launch offer." The math looks incredible: 40,000 contacts, one text, a 2% conversion at a $60 AOV is $48,000 in revenue for maybe $1,000 in send cost.

The problem is that spreadsheet carries something the client didn't mention: zero valid SMS consent, and a liability meter that starts ticking the second you hit send.

Full disclosure: I work for Ready, an SMS platform. We sell tools that reduce this risk — litigator scrubbing, consent capture, quiet-hours enforcement. I'm not going to pretend those make a rented list safe to text. They don't. What follows is why the list is a problem in the first place, and the only path I know of that turns those numbers into something you can legally message.

A phone number is not permission

Here's the distinction the whole thing hinges on. Under the TCPA, sending marketing SMS to a mobile number requires prior express written consent — the recipient affirmatively agreed to receive marketing texts from that specific sender, in a way that's documented.

"Having someone's number" and "having permission to text that number" are two completely different assets. A purchased list gives you the first and almost never the second.

Think about how those numbers were collected. Someone signed up for a competitor's newsletter. Someone entered a giveaway. Someone bought a candle three years ago and left a phone field. In every one of those cases — if consent was even captured — it was consent to hear from that business. Not from your client. Not from a "partner in the space." Consent doesn't ride along with the data.

Consent is not transferable — and the FCC has said so plainly

This is the part list vendors gloss over. Express written consent is tied to a specific relationship between a specific consumer and a specific sender. It cannot be sold, rented, licensed, or bundled into a data package.

The FCC closed the door on the "lead generator" workaround too. Companies used to argue that a single checkbox on one website granted consent for dozens of "marketing partners." The rules now require consent to be one-to-one — the consumer names or clearly identifies the seller they're agreeing to hear from. A blanket "I agree to receive offers from our partners" no longer covers your client, even when it existed.

So when a vendor tells you their list is "TCPA-compliant" or "opt-in verified," ask the only question that matters: opted in to receive marketing texts from whom? If the answer isn't your client's business by name, the consent doesn't exist for your purposes.

What sending to it actually costs

Let's price the downside honestly, because the upside is the only number the client is looking at.

TCPA statutory damages run $500 per text, tripled to $1,500 for willful violations — and courts have treated "you knew it was a purchased list" as willful. There's no cap. Damages are per message.

Run it against that 40,000-row list:

ScenarioContacts textedPer-message exposureTotal exposure
1% of recipients complain/sue400$500$200,000
1% complain, willful400$1,500$600,000
0.1% complain, willful40$1,500$60,000

Even the conservative bottom row — one in a thousand — wipes out the $48,000 the send was supposed to make, several times over. And that's before legal fees, before the class-action multiplier, before carriers flag your 10DLC campaign for spam complaints and quietly throttle every other client you send for.

That last part matters for agencies specifically: a bad list doesn't just burn one campaign. Elevated complaint rates degrade your sender reputation across the number, hurting deliverability for the clients who did build their lists correctly. We wrote more on where that liability lands in When Your Client's Bad List Gets Texted, Who Gets Sued?.

"But I'll scrub it first" — scrubbing helps, it doesn't rescue

I sell scrubbing, so hear me clearly: scrubbing a rented list is a good idea and it will not make the list compliant.

Ready's litigator and DNC scrub runs each number against known TCPA-litigator lists and DNC-complainer lists at $0.005 per contact, suppressing matches before send. On 40,000 contacts that's $200. It's cheap insurance and it does one specific job well: it removes the people most likely and most equipped to sue you.

What it cannot do is manufacture consent for the remaining 39,000. Scrubbing removes known bad actors from a list you still have no permission to text. The people left aren't litigators — they're just consumers who never agreed to hear from you, any one of whom can file a complaint. Scrubbing lowers the probability of the worst outcome; it doesn't change the legal status of the send.

Worth knowing too: a bought list needs scrubbing far more often than one you grew, because you have no idea when those numbers last changed hands or landed on a DNC list — more on that in the source-based scrub schedule.

The one compliant path: re-permission

You can turn a rented list into a mailable list. It just requires the recipients to opt in themselves, and it means accepting that most of them won't.

The move is to reach those contacts through a channel where you do have permission — usually email, if the list came with opted-in emails and your client can lawfully use them — and invite them to opt into SMS. Something like:

We'd love to text you early-access drops and 20% welcome codes. Reply with your number or tap here to opt in — msg & data rates apply, reply STOP to cancel anytime.

The contact who taps that link and confirms is now yours, legitimately, with a documented consent record. Ready captures that opt-in attestation as an audit trail, so if anyone ever asks who agreed and when, you have the answer.

Be ready for the conversion reality. Re-permission opt-in on a cold, rented list is often low — think low single-digit percentages, framed loosely. Out of 40,000, you might net a few hundred to a couple thousand real subscribers. That feels like a brutal haircut against the 40,000 the client paid for.

It isn't. Those few hundred are the only people on that list you could ever safely text — and they're worth vastly more per contact than the untargeted mass. The nonprofit world sees the same pattern: a checkout opt-in is worth about 4x a rented-list contact because consent source predicts downstream value.

The re-permission checklist

  • Confirm the email consent is real and usable before you send anything — a bought email list has its own CAN-SPAM constraints.
  • Make the ask explicit: marketing texts, from your client's named brand, with rates disclosure and STOP language.
  • Capture and store the opt-in — timestamp, source, the exact language they agreed to. Ready records this automatically for bulk and API sends.
  • Only import confirmed opt-ins into your SMS list. Delete the rest, or leave them in email-only.
  • Scrub the confirmed opt-ins too against DNC and litigator lists before the first send — belt and suspenders.

Where the honest advice lands

If your client already grew a real opt-in list at checkout or via a popup, you've got a clean asset and none of this applies — go read about popup vs. checkout opt-in value and build from there.

But a rented or purchased list is not a shortcut. It's a spreadsheet of numbers you have no right to text, sold with a compliance story that doesn't survive a single specific question. The choices are: don't text it, or re-permission it and text only the fraction who say yes. There's no third option that's both cheap and legal.

Compliance is ultimately the sender's responsibility — no platform, ours included, makes an unlawful send lawful. What a platform can do is capture consent properly the first time, scrub what needs scrubbing, hold sends outside quiet hours, and honor every STOP automatically so a mistake doesn't compound.

If you want to see how the consent capture and scrubbing pieces fit together — and start with 2,500 free credits, no card required — take a look at Ready or sign up here. Bring the list you grew, not the one you bought.