Guides

Do Not Call registry compliance for outbound calling campaigns

The FTC's 31-day National Do Not Call Registry scrub, the safe-harbor conditions, penalties, and what a carrier or spam-reputation check can and can't do before you dial. Not legal advice.

By Published 6 min read

On this page

Under the FTC's Telemarketing Sales Rule, a telemarketer's safe harbor for the National Do Not Call Registry requires scrubbing calling lists against a registry version obtained no more than 31 days before any call (16 CFR 310.4(b)(3)(iv)), on top of written procedures, staff training, an internal do-not-call list and ongoing monitoring. A phone number check is not a substitute for any of that: it tells you whether a number is even reachable and whether it's already flagged as a nuisance source, not whether it's legally callable. This guide separates the two, and shows where each fits in a call center's pre-dial pipeline.

This is not legal advice. It summarizes federal rules as published by the FTC and Cornell Law School's Legal Information Institute, current as of this writing. State telemarketing and calling laws add further requirements in many states. Consult your own counsel before relying on it, and see our TCPA checklist for SMS for the parallel FCC rules that apply to texts and to some of the same calls.

Who does the Telemarketing Sales Rule cover?

The TSR is an FTC rule, separate from the FCC's TCPA rules covered in our SMS checklist, though the two overlap for live and prerecorded calls. It reaches "a plan, program, or campaign" to sell goods or services through interstate phone calls. Two carve-outs matter most for outbound programs:

  • Business-to-business calls are mostly exempt. The FTC's own guidance states plainly that "most phone calls between a telemarketer and a business are exempt from the TSR," with a narrow exception for calls selling nondurable office or cleaning supplies (FTC, Complying with the TSR). Outbound B2B lead-gen calling still has to respect other rules, but the federal registry check isn't one of them for most B2B campaigns.
  • Charities calling for themselves are outside the TSR, but a for-profit telefunder calling on a charity's behalf is covered (FTC, same source). If you run outbound calls for a nonprofit client, check which side of that line your program sits on.

Everything below assumes a covered program: consumer-facing calls selling something, run by or for a business that isn't exempt.

A calendar ringed at day 31 beside a dial list with one row rejected for a registry match, feeding a safe-harbor shield, a five-item procedure checklist and a per-violation penalty tag.A calendar ringed at day 31 beside a dial list with one row rejected for a registry match, feeding a safe-harbor shield, a five-item procedure checklist and a per-violation penalty tag.
A 31-day registry scrub and a documented safe-harbor process, not a number check, keep a call list compliant.

What does the 31-day safe harbor actually require?

The rule doesn't ban every call to a registered number outright; it defines a safe harbor that protects a seller who made a good-faith mistake. To claim it, 16 CFR 310.4(b)(3) requires the seller or telemarketer to show it has:

  1. Written procedures to comply with the registry and internal do-not-call requirements.
  2. Trained personnel, and anyone assisting with compliance, in those procedures.
  3. Maintained and recorded its own do-not-call list — the numbers people have told you, specifically, not to call.
  4. Used a current registry, "obtained from the Commission no more than thirty-one (31) days prior to the date any call is made" (16 CFR 310.4(b)(3)(iv)).
  5. Monitored and enforced compliance with all of the above.

Meet all five and a call made to a registered number by mistake isn't a violation; miss any one and you lose that defense. The safe harbor is earned with documented process, not something you get by accident. A 31-day-old scrub with no written procedure behind it doesn't qualify.

When can you call a registered number anyway?

Two narrow exceptions in 310.4(b)(1)(iii)(B), and both depend on records you keep, not on anything a number-intelligence API can tell you:

  • Signed written agreement. The person gave you express written agreement, naming the specific number, to be called — the agreement itself, not a database lookup, is your proof.
  • Established business relationship. You have an existing relationship with that person. The rule doesn't fix a universal duration in this section; treat it as something your own transaction and consent records need to demonstrate, and confirm current limits with counsel for your situation.

A carrier lookup or spam-reputation check has no visibility into either exception. Don't treat "the number looks fine" as license to call it — that's a separate question from "are we allowed to call this person."

What can a phone check actually do here?

It removes numbers that are wrong to dial for reasons that have nothing to do with consent, before your dialer ever gets to them:

SignalWhat it catchesService
Invalid or impossible numberTypos, malformed entries from a form or a purchased listFormat validation (every lookup)
Line typePremium-rate, shared-cost or other special-rate ranges you shouldn't be autodialing intoCarrier lookup
Disconnected numbersNumbers that are no longer in serviceLive network status (HLR)
Reassigned numbersNumbers that changed hands since your list was built (use the FCC's Reassigned Numbers Database — see our guide)Not offered by MobileValidate
Spam and nuisance-call historyNumbers already flagged in regulator, government or community reports — a leading indicator of future complaints regardless of registry statusSpam reputation (limited access)

None of these check the registry, your consent records, or your own suppression list. That work stays entirely on your side, ideally as the very first filter your list passes through — checking a number's line type before you've even confirmed you're allowed to call it wastes the check.

What does a pre-dial pipeline look like?

Order matters: free and mandatory filters first, paid checks last, so you never pay to check a number you weren't going to call anyway.

StepWhat happensWhose responsibility
1. Normalize and dedupeE.164 format, one row per numberYours
2. SuppressRemove registry matches (31-day scrub), your internal do-not-call list, and opt-outsYours
3. Confirm a lawful basisSigned agreement, established relationship, or a B2B/nonprofit exemption appliesYours
4. Line-type and reputation checkDrop premium-rate/special ranges; review numbers already flagged as nuisance sourcesMobileValidate
5. Dial with monitoringLog outcomes; feed complaints back into your suppression listYours

Step 4, as a real test-mode request against the carrier check:

Shell
curl https://api.mobilevalidate.com/v1/lookup \
  -H "Authorization: Bearer $MOBILEVALIDATE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"numbers": ["+447700900001"], "checks": ["carrier"], "wait": 5}'
JSON
{"e164": "+447700900001", "country": "GB", "number_status": "valid",
 "checks": {"network.carrier": {"status": "completed", "registered": true,
   "attributes": {"line_type": "mobile", "carrier": "Test Carrier", "country": "GB"},
   "billed": false, "reason": null}}}

And a simple gate that only decides "is this number dialable at all," never "are we allowed to call it":

JavaScript
const REFUSE = new Set(["premium_rate", "shared_cost", "uan"]);

function preDialGate(r) {
  if (r.number_status !== "valid") return "remove_from_list";
  const line = r.checks?.["network.carrier"]?.attributes?.line_type; // undefined when unknown
  if (REFUSE.has(line)) return "remove_from_list";
  return "eligible_for_step_5"; // still needs steps 1-3 to have already passed
}

Spam reputation is limited access — approved customers only, and priced separately from the carrier check — because it aggregates community and regulator reports rather than answering a live network query. If you're approved, run it after step 3 as well, and treat a risk_level of high as a reason to review the number manually rather than an automatic removal, since regulator and community reports can be wrong or outdated.

What should you keep for the "monitoring" requirement?

The safe harbor's fifth condition — monitoring and enforcing your own procedures — is easiest to satisfy if your records already show the filters ran. Keep, per campaign:

  • The date you pulled the registry version you scrubbed against, and who ran the scrub.
  • Your internal do-not-call list and how requests reach it (support calls, opt-outs, complaints).
  • The line-type and reputation results for the list you actually dialed, timestamped.
  • A record of complaints received against that campaign, fed back into suppression before the next one.

That combination — a documented registry scrub plus a documented number-quality pass — is a stronger position than either alone, and it's the same discipline the rule expects you to prove if a call is ever questioned.

What are the key takeaways?

  • The TSR's safe harbor needs a registry version no more than 31 days old, written procedures, trained staff, your own do-not-call list and ongoing monitoring — not just "we checked the registry once."
  • Most B2B calls and a charity's own calls are exempt from the TSR; a for-profit telefunder calling for a charity is not.
  • Signed written agreement and established business relationships can let you call a registered number, but neither is provable by a phone check — that's your consent and CRM data.
  • Violations can carry a civil penalty in the tens of thousands of dollars per call under current FTC guidance; confirm the current figure before relying on it.
  • A carrier or spam-reputation check removes dead, wrong-type and already-flagged numbers before you dial. It never checks the registry, and it should run after your own suppression step, not instead of it.

Sources

  1. 16 CFR 310.4 — Abusive telemarketing acts or practices — Legal Information Institute, Cornell Law School, 2026
  2. Complying with the Telemarketing Sales Rule — Federal Trade Commission, Business Guidance, 2026
  3. National Do Not Call Registry FAQs for businesses — Federal Trade Commission, Business Guidance, 2026

Frequently asked questions

How often must we refresh our Do Not Call Registry data?

The Telemarketing Sales Rule's safe harbor requires using a version of the registry obtained no more than 31 days before any call is made (16 CFR 310.4(b)(3)(iv)). Refreshing monthly is the minimum, not a target; refresh more often if your campaign runs long or your list grows between pulls.

Does the TSR apply to business-to-business calls?

Mostly no. The FTC's own guidance says most calls between a telemarketer and a business are exempt from the TSR, with a narrow exception for selling nondurable office or cleaning supplies. B2B lead-gen calling still has to follow other rules, including any state law and carrier requirements, but the federal Do Not Call Registry check is not one of them for most B2B calls.

Can we call a number on the registry if we have a relationship with that person?

The rule allows calls to numbers you have signed, written agreement to call, naming that number, and separately allows calls within an established business relationship. Neither exception is proven by a phone or carrier check; you need your own consent and relationship records to rely on either one.

What's the penalty for calling a registered number?

The FTC can seek civil penalties in the tens of thousands of dollars per violation. The amount is adjusted for inflation every year, so check the current figure on ftc.gov before relying on it, and remember that each call can be a separate violation.

Does a MobileValidate check tell us whether a number is on the Do Not Call Registry?

No. We don't offer Do Not Call Registry lookups. Our carrier and spam-reputation checks tell you the line type and whether a number shows up in spam or nuisance-call reports, which helps you avoid dialing dead, wrong-type or already-flagged numbers. They say nothing about registry status or consent, which you must track yourself.

All articles

Know before you send.

Tell us about your use case. We review every request and set you up with test and live keys.