Back to insights
Checking Compliance Practices

How to remove DNC?

Learn how to remove DNC contacts correctly under the new 10-business-day rule. Avoid $53,088 fines with contact-level suppression, logging, and opt-out ...

How to remove DNC?

How to remove DNC?

Key Facts

The New 10-Day Clock and What It Means for Your Team

Until early 2025, your team had a full month to stop calling someone who opted out. That grace period is gone — and the penalty for missing the new deadline is steeper than most teams realize.

Effective April 11, 2025, callers must honor opt-out and revocation requests within 10 business days, down from the prior 30-day window, according to compliance guidance for outbound sales teams and TCPA penalty analysis. Three weeks of slack just became two — and best practice is to treat ten days as the legal ceiling, not the target. Suppression should happen the moment the request lands.

The financial stakes are significant. The FTC's civil penalty for Telemarketing Sales Rule violations now reaches up to $53,088 per violation — and since each unwanted call can count as its own violation, a single unprocessed opt-out can multiply fast. Add TCPA private damages of $500 per violation, trebled to $1,500 for willful violations with no damages cap, and a slow opt-out process becomes a serious liability.

The change that catches the most teams off guard, though, is this: entity-specific requests override every exemption. Per the FTC's own guidance, if a consumer asks your company specifically not to call, you may not call — even with an established business relationship, even within the 18-month purchase window, even with prior written consent that has since been revoked. "They're a current customer" is not a defense.

That means your removal process must handle requests arriving through every channel, because under the FCC's revocation rules, any reasonable method counts. Your team needs a workflow that covers:

  • STOP-family keyword replies ("stop," "unsubscribe," "quit," "cancel," "end," "opt out")
  • Verbal requests made mid-call — the most failure-prone channel, since they only enter your system if a rep logs them
  • IVR opt-outs and any designated website or phone number
  • Voicemail and email requests, which are treated as reasonable unless rebutted

Two operational rules make the 10-day clock workable. First, suppress at the contact level, not the number level — as Aloware puts it, an opt-out belongs to the person, not the handset, so every number attached to that contact goes dark. Second, timestamp and log everything, and make sure opt-out records survive contact deletion and CRM re-imports. A re-imported "clean" record still counts as a violation because intent is not an element of the offense.

There's one wrinkle worth watching: the cross-program "revoke-all" provision — where one opt-out applies to all future calls and texts — is delayed until January 31, 2027. But plaintiffs' firms already argue for it, so building account-wide suppression now is the safer play.

This is exactly the kind of question to raise when vetting any growth partner. At Worqd, fast follow-up only works because it's permission-aware — every inquiry we handle comes with explicit consent, and opt-outs are honored across the whole lead-handling path, not just one list. Ask any provider how they propagate revocations downstream; if they can't show you timestamped logs, keep looking.

Contact-Level Suppression: Why Number-Only Blocking Fails

Here's a scenario that catches a lot of teams off guard: a contact texts "STOP," you suppress that number, and your team later calls them on their second line. That's still a violation. Under the rules that took effect April 11, 2025, an opt-out belongs to the person, not the handset — and regulators treat intent as irrelevant.

The architectural rule is simple to state and easy to get wrong. As compliance guidance for outbound teams puts it: "Wrong: suppress the number. Right: suppress the contact, then every number attached to it." That means one removal request should flip the entire contact record — mobile, work line, and any other number attached — into a do-not-call state.

The stakes are real. The FTC's civil penalty now runs up to $53,088 per violation, and TCPA private damages add $500 per call — trebled to $1,500 if the violation is found willful. Per the FTC, an entity-specific request to stop calling overrides everything, including an established business relationship.

Durability is the second half of the rule, and it's where most systems quietly fail. An opt-out record has to survive contact deletion, CRM re-imports, and syncs. If a contact gets deleted and re-imported with a "clean" record, that's still a violation — because intent is not an element of the offense. When we build follow-up systems at Worqd, suppression is treated as a permanent flag on the person, not a field on a record that a sync can wipe.

A practical suppression setup should do four things:

  • Suppress the full contact record and every attached number, not just the one that opted out.
  • Timestamp every opt-out automatically, with a documented record you can produce later.
  • Block re-imported or synced contacts whose suppression flag exists anywhere in your system.
  • Capture verbal opt-outs from reps in one keystroke — "I'll pass it along" is not compliance.

That last point matters more than most teams expect. Verbal requests mid-call are the most failure-prone channel because they only enter the system if a rep logs them. And if you cannot produce the artifact, an investigator will treat the control as absent.

There's also a supply-chain version of this problem. Industry analysis calls it the "orphaned opt-out" — a valid revocation received by one party that never travels to a downstream caller who keeps dialing, leaving the caller placing the call to inherit the liability. If you work with lead-gen partners or outreach vendors, ask exactly how they propagate and log revocations.

The clock is tight — 10 business days to honor a request — and the number of TCPA class actions is climbing. Build suppression around the person, and make it impossible to undo by accident.

Capturing Every Valid Revocation Channel Without Gaps

A consumer who says "stop calling me" mid-call has just handed you a legal obligation — and if your rep doesn't log it, your company inherits the liability anyway. Under FCC consent-revocation rules effective April 11, 2025, any reasonable method counts as a valid revocation, which means your opt-out capture has to cover far more than STOP replies.

The channels you must capture include:

  • STOP-family keywords — "stop," "unsubscribe," "quit," "cancel," "end," or "opt out"
  • Verbal requests during a live call, such as "stop calling me"
  • IVR opt-outs and any designated website or phone number
  • Email and voicemail opt-outs, which are treated as reasonable unless rebutted

According to compliance guidance for outbound teams, all of these channels must feed a single suppression system that timestamps and logs every request automatically. The stakes are real: the FTC's civil penalty runs up to $53,088 per violation, and an entity-specific do-not-call request overrides even an established business relationship.

Verbal opt-outs are the highest-risk failure point. A texted "STOP" triggers an automated response; a spoken "take me off your list" only enters your system if a human logs it. As Aloware puts it, every rep needs one keystroke that suppresses the contact — because "I'll pass it along" is not compliance. If the request dies in a rep's memory, the 10-business-day clock is already running, and you cannot prove it ever started.

The logging gap compounds downstream. Plura AI calls this the "orphaned opt-out": a valid revocation received by one party that never travels to the downstream caller who keeps dialing. The caller placing the call inherits the liability — a particular concern in lead-gen supply chains where leads pass through multiple hands before anyone picks up the phone.

When you evaluate a growth partner — Worqd included — ask exactly how revocations propagate. Do verbal requests captured by an AI SDR or a live rep suppress the entire contact in one action, with a timestamp that survives CRM re-imports and syncs? A re-imported "clean" record still constitutes a violation, because intent is not an element of the offense. And with the cross-program revoke-all provision expected to take effect January 31, 2027, account-wide suppression is the safe default now, since plaintiffs' firms already argue for it.

Automated Timestamping and Cross-System Propagation

An opt-out that exists only in a sales rep's memory is an opt-out that doesn't exist. When regulators or plaintiffs' attorneys come asking, the only thing that protects you is a documented, timestamped trail — and a suppression that reaches every system and partner dialing on your behalf.

The core rule is simple: revocation handling must be automated and logged, with a documented timestamp for every opt-out received. This isn't bureaucratic box-checking. Continued calling after an opt-out supports a willfulness finding, which can treble TCPA damages from $500 to $1,500 per violation — and the absence of DNC scrub logs in discovery is itself treated as evidence of willfulness.

The inverse is also true. Courts have declined to treble awards where a company ran a genuine compliance program and made a good-faith mistake. Your logs are the difference between an expensive error and a catastrophic one. As one compliance analysis puts it: if you cannot produce the artifact, an investigator will treat the control as absent.

In a lead-generation supply chain, the deadliest failure mode is what Plura AI calls the orphaned opt-out: a valid revocation received by one party that never travels to the downstream caller who keeps dialing. The caller placing the call inherits the liability — even though they never heard the request.

That means your suppression process has to flow outward, not just inward:

  • Suppress at the contact level, not the number level — the opt-out belongs to the person, so every number attached to that contact goes dark.
  • Push every suppression to downstream partners, affiliates, and any third party dialing from your lists.
  • Make opt-out records survive contact deletion, CRM re-imports, and syncs — a re-imported "clean" record is still a violation, because intent is not an element of the offense.
  • Capture revocations from any reasonable method: STOP-family keywords, verbal mid-call requests, IVR opt-outs, email, voicemail, or designated web channels.

This is exactly what to probe when vetting a growth or outreach partner. At Worqd, permission-aware outreach and explicit consent capture are built into how leads are handled from the first touch — because a suppression that lives in one system while another keeps dialing is a liability, not a process.

One more deadline belongs on your compliance calendar. The FCC's cross-program "revoke-all" provision — where a single opt-out applies to all future calls and texts from your organization, including unrelated subjects — is currently waived until January 31, 2027, per Aloware's regulatory tracking and Plura AI's analysis.

Don't wait for the deadline. Plaintiffs' firms already argue for account-wide revocation in litigation today, so building account-wide suppression now is the prudent move. Pair it with the surrounding discipline: scrub against the National DNC Registry every 31 days with dated download receipts, and retain consent and opt-out records for at least five years to clear the TCPA's four-year statute of limitations.

With 258+ million numbers on the Registry and FTC penalties reaching $53,088 per violation, the businesses that treat timestamping and propagation as core infrastructure — not afterthoughts — are the ones that stay out of the enforcement headlines.

Compliance Artifacts That Hold Up in Discovery

When a DNC lawsuit hits discovery, the question is never "did you mean well" — it's "where are your records." Courts have declined to treble damages when a company ran a genuine compliance program and made a good-faith mistake, but the absence of scrub logs is itself treated as evidence of willfulness, pushing TCPA damages from $500 per violation to $1,500, according to TCPA penalty analysis.

Three artifacts matter most. First, dated DNC Registry scrub receipts: you must scrub your calling lists against the National Registry at minimum every 31 days, and each scrub needs a timestamped download record. As compliance guidance for outbound teams puts it bluntly: "A scrub you cannot date is a scrub you cannot defend." Second, consent and opt-out records retained for at least 5 years — long enough to clear TCPA's 4-year statute of limitations. Third, a documented suppression process that survives CRM re-imports and syncs, because a re-imported "clean" contact is still a violation when intent is not an element of the offense.

Your discovery-ready paper trail should include:

  • Dated download receipts for every 31-day National Registry scrub
  • Timestamped opt-out logs, with the request method captured (STOP reply, verbal, IVR, email)
  • Contact-level suppression records showing every attached number was suppressed, not just one
  • Consent records held 5+ years, covering every lead source and downstream partner

The stakes are real. The FTC has filed 173 lawsuits against 570 companies and 449 individuals since 2003, collecting nearly $400 million, and TCPA class actions rose 23% year-over-year through April 2026. The FTC's own guidance is equally unforgiving on entity-specific requests: once a consumer asks your company directly to stop calling, even an established business relationship won't save you, with civil penalties reaching $53,088 per violation.

This is why, when you evaluate any growth partner running outreach on your behalf, you should ask to see their revocation logging — not hear about it. At Worqd, our outreach work is built on permission-aware practices, and we'd expect any provider you consider to demonstrate the same: automated, timestamped opt-out capture that propagates to every suppression list, including downstream callers. If a partner can't produce the artifact, treat the control as absent — because sooner or later, an investigator will.

Frequently Asked Questions

How long do we have to remove someone from our calling list after they opt out?
Effective April 11, 2025, you must honor opt-out and revocation requests within 10 business days, down from the prior 30-day window, per compliance guidance for outbound sales teams. Best practice is to treat ten days as the legal ceiling, not the target — suppression should happen the moment the request lands.
If a customer opts out, can we still call them because we have an existing business relationship?
No. Per the FTC's own guidance, an entity-specific do-not-call request overrides every exemption — including an established business relationship, the 18-month purchase window, and even prior written consent that has since been revoked. "They're a current customer" is not a defense.
Is blocking the phone number enough, or do we need to do more when someone opts out?
Number-level blocking is not enough — an opt-out belongs to the person, not the handset. As Aloware puts it, you suppress the contact, then every number attached to it, so their mobile, work line, and any other number all go dark. The record must also survive contact deletion and CRM re-imports, since a re-imported "clean" record is still a violation.
What counts as a valid opt-out — does it have to be a STOP text?
No — under FCC revocation rules, any reasonable method counts. That includes STOP-family keywords ("stop," "unsubscribe," "quit," "cancel," "end," "opt out"), verbal requests mid-call, IVR opt-outs, designated websites or phone numbers, and even email or voicemail, per TCPA penalty analysis. Verbal requests are the most failure-prone channel because they only enter your system if a rep logs them.
What are the actual penalties if we keep calling someone after they opted out?
The FTC's civil penalty for Telemarketing Sales Rule violations reaches up to $53,088 per violation, and each unwanted call can count separately. On top of that, TCPA private damages run $500 per violation, trebled to $1,500 for willful violations with no cap — and the absence of DNC scrub logs in discovery is itself treated as evidence of willfulness, per TCPA penalty analysis.
What should we ask a lead-gen or outreach partner about their opt-out handling?
Ask exactly how they propagate revocations downstream and whether they can show timestamped logs — a valid opt-out received by one party that never reaches the downstream caller is an "orphaned opt-out," and the caller placing the call inherits the liability, per industry analysis. At Worqd, every inquiry comes with explicit consent and opt-outs are honored across the whole lead-handling path, not just one list — if a provider can't produce the artifact, treat the control as absent.

Make Every Opt-Out Count — and Provable

Removing a DNC request the right way comes down to a few non-negotiables: honor opt-outs within 10 business days, suppress the whole contact rather than a single number, capture revocations from every reasonable channel (especially verbal ones), and keep timestamped records that survive CRM re-imports and syncs. With FTC penalties reaching up to $53,088 per violation and TCPA class actions climbing, the businesses that stay out of trouble are the ones that treat suppression as infrastructure, not an afterthought. Your next step is an honest audit: can you produce dated scrub receipts, timestamped opt-out logs, and evidence that revocations propagate to every system and partner that dials on your behalf? If any link in that chain is missing, close the gap before a plaintiff's attorney finds it for you. And when you evaluate a growth partner like Worqd, ask to see their revocation logging — not hear about it. If you want follow-up that's fast and permission-aware from first click to booked call, book a growth call and see how the whole path can work without the compliance risk.

Want help putting this into action?

Book a Growth Call
Topicshow to remove DNCDNC compliance rules 2025do not call list removalTCPA opt-out requirementscontact-level suppressionDNC registry scrubbingrevocation of consent rules

Stay in the Loop