SMS Compliance · Knowledge Hub

Bulk SMS, OTP and DLT Compliance Checklist for India

A practical pre-launch checklist for entity registration, headers, templates, consent, telemarketer mapping, URLs, records and campaign controls.

← All insights
Direct answer

The short answer.

Before sending commercial SMS or OTP traffic in India, a business should identify the correct principal entity, register through the applicable DLT ecosystem, use approved headers and content templates, complete required telemarketer and delivery-chain mappings, preserve consent and preference controls, match message content to the approved template and test variables, URLs and reporting before scale.

Bulk SMS OTP and DLT compliance checklist for Indian businesses
Bulk SMS OTP and DLT compliance checklist for Indian businesses · EASY SERVE Communication knowledge guide
Key takeaways

Four points to carry into the next decision.

01Treat the principal entity, header, template and telemarketer chain as connected records.
02Classify service, transactional, promotional and OTP communication correctly for the actual use.
03Keep variables, URLs, contact details and consent evidence consistent with the approved journey.
04Monitor rejections, complaints and misuse signals instead of treating approval as permanent immunity.

Start with the TCCCPR framework and current directions

TRAI’s Telecom Commercial Communications Customer Preference Regulations, 2018 created the framework for commercial communication according to recipient preferences. TRAI continues to issue amendments, directions and sender guidance, so an old onboarding checklist should not be treated as permanently current.

The business sending the communication remains responsible for its use case, data and customer journey. A technology provider can coordinate registration and delivery, but it cannot convert an unlawful or misleading campaign into a compliant one. Review current operator and TRAI requirements before each materially different use case.

Verify principal-entity and header ownership

Confirm the legal entity that customers recognise and the authorised administrator controlling its DLT account. Business documents, authorised signatory information and contact details should be accurate. Avoid operating long-term campaigns through another party’s principal-entity identity when the brand should own the communication.

TRAI describes a header as the registered identity assigned to a sender for commercial communication and states that commercial communication must use registered headers. Select a header that fits the approved category and brand identity, and keep an inventory of active, inactive and partner-used headers.

Register and test the exact content-template logic

The approved template and the submitted message should match according to applicable DLT and provider rules. Review fixed text, variable locations, brand identification, contact information, URLs and opt-out language. Broad variables that can replace most of the message create operational and misuse risk.

Maintain a template register with use case, category, header, approval reference, owner and sample output. Test realistic variable lengths and characters. A template that passes registration can still fail in production when the actual message structure, header or chain mapping does not match.

  • Approved fixed text and variable positions
  • Correct header and content category
  • Brand identity visible to the recipient
  • Verified URL domains and call-to-action details
  • Sample messages tested through the production route

Confirm telemarketer and delivery-chain mapping

Document the registered telemarketer, technology provider and delivery relationship used for the campaign. Complete the mappings required by the relevant DLT ecosystem and verify that the production account uses the same approved entity, header and template combination.

Restrict user access, protect credentials and review who can upload data, create templates and schedule campaigns. Header or template misuse can create complaints and enforcement exposure. TRAI’s directions specifically address misuse controls, so governance must continue after onboarding.

Run a controlled preflight before bulk volume

Send a small internal and controlled sample across representative networks and devices. Check sender display, final content, variables, URLs, landing-page disclosures, delivery reporting, OTP expiry, duplicate suppression and customer-support readiness.

Record rejection codes and investigate them instead of repeatedly resubmitting traffic. Keep campaign approvals, list source, consent evidence, template IDs, logs and escalation contacts together. Compliance interpretation and operator rules can change; obtain appropriate specialist advice for high-risk campaigns.

This checklist is operational guidance, not legal advice. The principal entity should verify current TRAI, access-provider and DLT requirements for its exact communication.
Primary references

Check the current source before implementation.

Platform, carrier and regulatory requirements can change. These links were reviewed when this guide was published.

About the author

Sachin Kumar Mittal

Founder & CEO of EASY SERVE Communication, working across CPaaS, RCS, WhatsApp Business, Voice AI, IVR, SMS, CRM integration and business communication since 2015.

View founder profile →
Editorial note

Guidance, not a guaranteed outcome.

This article provides practical business information. Platform approvals, delivery, pricing, compliance interpretation, rankings and campaign outcomes remain subject to the applicable provider, operator, regulator, customer data and implementation conditions.

Reviewed Sep 2026IndiaEASY SERVE

Apply this framework to your business.

Share your use case, audience, expected volume, systems and required outcome.

Discuss the requirement
Frequently asked questions

Practical answers before you begin.

Is DLT registration required for commercial SMS in India?

The applicable TCCCPR and DLT framework requires commercial communication to use registered identities such as the principal entity, header and content template, subject to the current rules and use case.

Can an approved SMS template be changed during sending?

Actual content should follow the approved template and permitted variables. Material changes may require a new or updated template and can otherwise cause rejection or compliance risk.

Is OTP messaging exempt from all DLT requirements?

No blanket assumption should be made. The entity must classify the use correctly and follow the current registration, header, template and delivery requirements applicable to that traffic.

Who is responsible for SMS compliance?

The principal entity remains responsible for its purpose, data and communication, while telemarketers, providers and access providers have their own obligations in the delivery chain.