Bulk SMS, OTP and DLT Compliance Checklist for India
A practical pre-launch checklist for entity registration, headers, templates, consent, telemarketer mapping, URLs, records and campaign controls.
The short answer.
Before sending commercial SMS or OTP traffic in India, a business should identify the correct principal entity, register through the applicable DLT ecosystem, use approved headers and content templates, complete required telemarketer and delivery-chain mappings, preserve consent and preference controls, match message content to the approved template and test variables, URLs and reporting before scale.

Four points to carry into the next decision.
Start with the TCCCPR framework and current directions
TRAI’s Telecom Commercial Communications Customer Preference Regulations, 2018 created the framework for commercial communication according to recipient preferences. TRAI continues to issue amendments, directions and sender guidance, so an old onboarding checklist should not be treated as permanently current.
The business sending the communication remains responsible for its use case, data and customer journey. A technology provider can coordinate registration and delivery, but it cannot convert an unlawful or misleading campaign into a compliant one. Review current operator and TRAI requirements before each materially different use case.
Verify principal-entity and header ownership
Confirm the legal entity that customers recognise and the authorised administrator controlling its DLT account. Business documents, authorised signatory information and contact details should be accurate. Avoid operating long-term campaigns through another party’s principal-entity identity when the brand should own the communication.
TRAI describes a header as the registered identity assigned to a sender for commercial communication and states that commercial communication must use registered headers. Select a header that fits the approved category and brand identity, and keep an inventory of active, inactive and partner-used headers.
Register and test the exact content-template logic
The approved template and the submitted message should match according to applicable DLT and provider rules. Review fixed text, variable locations, brand identification, contact information, URLs and opt-out language. Broad variables that can replace most of the message create operational and misuse risk.
Maintain a template register with use case, category, header, approval reference, owner and sample output. Test realistic variable lengths and characters. A template that passes registration can still fail in production when the actual message structure, header or chain mapping does not match.
- Approved fixed text and variable positions
- Correct header and content category
- Brand identity visible to the recipient
- Verified URL domains and call-to-action details
- Sample messages tested through the production route
Align consent, preference and purpose
Marketing communication requires a defensible basis and customer-preference treatment. Store consent source, wording, timestamp, purpose and withdrawal status where applicable. Do not reuse service or transaction data for unrelated promotion merely because the phone number exists in a database.
Provide a workable opt-out or preference path and ensure suppression applies across campaign tools and vendors. Segment service, transactional, OTP and promotional journeys according to the real purpose, not the label that offers the easiest route.
Confirm telemarketer and delivery-chain mapping
Document the registered telemarketer, technology provider and delivery relationship used for the campaign. Complete the mappings required by the relevant DLT ecosystem and verify that the production account uses the same approved entity, header and template combination.
Restrict user access, protect credentials and review who can upload data, create templates and schedule campaigns. Header or template misuse can create complaints and enforcement exposure. TRAI’s directions specifically address misuse controls, so governance must continue after onboarding.
Run a controlled preflight before bulk volume
Send a small internal and controlled sample across representative networks and devices. Check sender display, final content, variables, URLs, landing-page disclosures, delivery reporting, OTP expiry, duplicate suppression and customer-support readiness.
Record rejection codes and investigate them instead of repeatedly resubmitting traffic. Keep campaign approvals, list source, consent evidence, template IDs, logs and escalation contacts together. Compliance interpretation and operator rules can change; obtain appropriate specialist advice for high-risk campaigns.
This checklist is operational guidance, not legal advice. The principal entity should verify current TRAI, access-provider and DLT requirements for its exact communication.
Check the current source before implementation.
Platform, carrier and regulatory requirements can change. These links were reviewed when this guide was published.
Continue from insight to execution.
Sachin Kumar Mittal
Founder & CEO of EASY SERVE Communication, working across CPaaS, RCS, WhatsApp Business, Voice AI, IVR, SMS, CRM integration and business communication since 2015.
View founder profile →Guidance, not a guaranteed outcome.
This article provides practical business information. Platform approvals, delivery, pricing, compliance interpretation, rankings and campaign outcomes remain subject to the applicable provider, operator, regulator, customer data and implementation conditions.
Related knowledge guides.
DLT Registration, Headers and SMS Templates: An India Guide
A business-friendly overview of entity registration, headers, content templates, consent requirements, telemarketer relationships and pre-launch checks.
Read next →CPaaS Architecture for Indian Enterprises: Design Guide
Design a secure, measurable and resilient communication layer across RCS, WhatsApp, SMS, voice, email, CRM, consent and analytics.
Read next →Apply this framework to your business.
Share your use case, audience, expected volume, systems and required outcome.