Blue Bubble Lies
Gray-market tools route marketing texts through iMessage so they land as blue bubbles. Here is what that costs you under the FTC Act and the TCPA.
Short answer
Tools that send marketing texts through iMessage so they arrive as blue bubbles sometimes skip A2P 10DLC registration and carrier opt-out handling. Disguising a commercial message as a personal one is deceptive under Section 5 of the FTC Act, and texting without prior express written consent carries $500 to $1,500 per message under the TCPA on the first message.
Key takeaways
- —Blue-bubble tools work by skipping the A2P 10DLC pipeline, which is the same system that enforces consent and opt-outs.
- —Disguising a commercial message as a personal one is a Section 5 deception problem on its own, separate from the TCPA.
- —One unconsented automated text to a cell phone creates liability. Damages are $500 per message, or $1,500 if willful.
- —iMessage delivery and read receipts hand a plaintiff's attorney timestamped proof of every send.
- —The 2 compliant routes are 10DLC registration through The Campaign Registry and Apple Messages for Business.
This is not legal or professional advice. I am not a lawyer. The sources I cite may be incomplete, my interpretation of them may be wrong, and the law changes. Do your own research and hire a qualified attorney before you act on any of this.
Many gray-market tools can route your marketing texts through iMessage's servers instead of the carrier network, so they land on your customer's phone as a blue bubble instead of a green one. Recipients open it because it looks like a text from a friend, not a business. That's the entire product. It's also the entire problem, twice over: what it does to the person reading it, and what it exposes you to under federal law.
How it actually works
Regular business texting runs through a platform, and in the US, those platforms are subject to A2P 10DLC (application-to-person, 10-digit long code) rules. The platform registers your business and its specific use case with a body called The Campaign Registry, carriers assign a trust score, and your messages move through a pipeline built for consent tracking, opt-out handling, and spam filtering. As of February 2025, unregistered traffic on that pipeline doesn't get filtered anymore. It gets blocked outright, no exceptions.
Blue-bubble tools exist specifically to skip that pipeline. They send through iMessage's data channel instead of the carrier SMS network, so there's no 10DLC registration, no campaign approval, and no carrier in the loop to block anything. That's the pitch: higher open rates, no gatekeeper.
It's also the problem. The gatekeeper you're skipping is the same infrastructure that would have made you prove consent before you sent anything.
What blue actually promises
A blue bubble carries meaning before the message does. It tells the recipient this is someone in their contacts, replying inside a private thread, not a company running a campaign. People read that signal instantly and without thinking about it, the same way a call from a saved contact reads differently than one from an unknown number.
A tool that fakes that signal spends trust it never earned and never disclosed. The recipient can't apply the skepticism they'd bring to an obvious ad, because the message is built specifically to tell them they don't need to.
That problem doesn't go away in a hypothetical world where every message was fully TCPA-compliant. Ordinary marketing operates in the open: the recipient knows they're being pitched and judges the pitch on that basis. This tool removes that judgment before the recipient reads a word, by disguising what the message is. The deception isn't a side effect of the high open rate. It is the open rate.
It also costs more than any single campaign. A recipient who gets burned by one spoofed blue bubble doesn't just distrust that business. They start reading the color itself differently, which degrades the signal for every real personal message that follows it and every other business using the channel honestly. The tool isn't just borrowing trust from one recipient. It's spending down a shared signal everyone else is still relying on.
What the deception costs, separate from TCPA
That problem is independently illegal, not just ethically loaded. Section 5 of the FTC Act bans "unfair or deceptive acts or practices," and the Commission has spent decades applying it to exactly this pattern: a commercial message dressed up as something it isn't. The FTC's own enforcement policy statement on deceptively formatted advertisements lists advertorials formatted as news stories, direct-mail ads disguised as book reviews, and infomercials presented as regular programming as textbook violations. A sales text formatted to read as a message from a friend is the same violation in a different wrapper, and the FTC has a separate, real enforcement record against deceptive text campaigns specifically, including a $10 million judgment against a spam-text and robocalling operation in 2014.
One limit worth knowing: since a 2021 Supreme Court ruling, AMG Capital Management v. FTC, the agency can no longer go straight to federal court and win money back for a first-time Section 5 violation. It can still get an injunction, and it can still get civil penalties for violating an existing order or a formally issued rule. That's part of why TCPA remains the sharper financial threat covered below: it comes with built-in statutory damages and a private right of action that Section 5 currently doesn't. But most states run their own version of Section 5 with real teeth, and many include a private right of action the federal law currently lacks, so "the FTC probably won't come after me directly" is a narrower shield than it sounds.
Then there's the cost no statute measures. A tool built on fooling the recipient has a shrinking shelf life by design. It works exactly once per person, and it works less broadly every time someone posts a screenshot of what tricked them. The tactic doesn't scale the way ordinary marketing scales. It depletes.
The lie in the terms of service
The platforms selling these tools protect themselves in their own terms of service, usually by classifying the software as a "neutral utility" or restricting it to "non-commercial use." Neither label changes what happens when a recipient complains. The platform can point to its terms and cut your access. Your business is the one that sent the message, and your business is the one named in the complaint.
Assuming a tool is compliant because a company sells it is the wrong test. The right test is who's named as the defendant when it goes wrong. It's not the software vendor.
The law you're routing around
The Telephone Consumer Protection Act (TCPA) makes it illegal to send an automated, unsolicited commercial text to a cell phone without the recipient's prior express written consent. This is a federal statute, not a platform policy, and it doesn't care which bubble color your message shows up in.
A few specifics that matter more than people assume:
- One message is enough. Unlike a Do Not Call Registry claim, which needs a pattern of calls, an unwanted automated text to a cell phone creates liability on the first message. The recipient doesn't need to be registered anywhere.
- Damages are $500 per message, automatically. No proof of financial harm required.
- A court can raise that to $1,500 per message if it finds the violation was willful or knowing, which is a live possibility any time a business keeps texting after being told to stop.
- It's a private right of action. Any individual recipient can sue, and TCPA plaintiff's attorneys work on contingency, which is why filings are common and settlements happen fast.
Run the math on your own list. A blast to 1,000 numbers sits between $500,000 and $1,500,000 in statutory exposure, before a single dollar of attorney's fees.
What this has already cost other companies
These aren't hypothetical numbers, though the legal theory behind them isn't uniform. In the past two years:
Cash App's parent company, Block, agreed to pay $12.5 million over "Invite Friends" referral texts sent without clear consent. That one ran under Washington state consumer protection law rather than the federal TCPA, which is its own point: state statutes can create exposure even where a federal claim is arguable.
Clover Network agreed to pay up to $15 million in Bobo v. Clover Network, LLC, and Zales Jewelers settled for $7.54 million, both over promotional texts sent to numbers on the Do Not Call Registry. Both relied on the registry-violation theory under Section 227(c), the exact theory a federal appeals court has since started narrowing (more below). Neither company settled because that theory was airtight. Litigating a class action to the merits costs more than settling does, regardless of how a court might eventually rule on it.
None of these companies were using a blue-bubble spoofing tool specifically. They were using ordinary bulk texting without solid consent records. A tool built to route around the carrier's compliance rails doesn't reduce that exposure. It removes the one system that might have stopped you before you built a list-wide violation.
The paper trail you're building against yourself
iMessage relies on delivery confirmation and read receipts. Every message you send this way generates a timestamped record showing exactly when it was delivered and when it was opened. If a plaintiff's attorney requests that data, you've already handed over proof of delivery for every message in the campaign. Regular SMS carriers don't give you this problem for free. iMessage does, by design.
The opt-out you probably can't honor
Registered 10DLC campaigns come with automated STOP handling built into the carrier pipeline. Reply "STOP" to a real A2P campaign and the carrier suppresses future sends automatically, whether or not the business's own system catches it.
Gray-market iMessage tools don't have that layer. An opt-out has to be caught and processed manually or by whatever logic the tool provides, and the FCC's current rule gives a business up to 10 business days to honor a revocation once it's clearly communicated. Any message sent after that window, to someone who already said stop, is close to the clearest fact pattern a court can call willful. That's the difference between a $500 exposure and a $1,500 one, and it's a difference these tools make more likely, not less.
The platform cuts you loose first
Apple treats spam signals seriously. When a recipient taps "Report Junk" on a message, that report feeds Apple's own abuse detection, and accounts, associated numbers, and linked devices can be flagged or blocked. This happens on Apple's timeline, not yours, and it happens before any lawsuit is filed. You can lose the channel and still face the legal exposure the channel created.
What compliant actually looks like
There's no version of consent-free bulk texting that's safe. Two real options exist if you want customers to see a business text and trust it:
Register properly through 10DLC. Brand and campaign registration through The Campaign Registry takes about a week, and it buys you carrier-backed opt-out handling, deliverability, and a documented compliance trail if you're ever challenged.
Use Apple's own sanctioned channel. Apple Messages for Business (Apple Business Chat) is a real, Apple-approved program that lets legitimate businesses message customers inside Messages with proper opt-in. It's a different product entirely from the spoofing tools this piece is about, and Apple's own channel policies prohibit unsolicited messages outright. It's the compliant way to get a business message in front of someone on an Apple device.
Both routes take longer to set up than a gray-market tool. Both routes are still standing after a complaint.
The ground is still shifting, not settling
In June 2025, the Supreme Court ruled in McLaughlin Chiropractic Associates v. McKesson Corp. that federal courts are no longer bound by the FCC's past interpretations of the TCPA. Courts can now reinterpret contested questions on their own, circuit by circuit, instead of deferring to the agency.
That ruling immediately fractured how courts treat text messages under the Do Not Call registry provision specifically. In July 2026, the 7th Circuit ruled in Steidinger v. Blackstone Medical Services that text messages aren't "telephone calls" under that provision at all, cutting off registry-based text claims in Illinois, Indiana, and Wisconsin. Courts leaning the opposite direction include the 1st, 2nd, and 11th Circuits, and the 9th Circuit reached a related but distinct holding months earlier in a different case. Legal trackers count roughly 18 federal district court opinions splitting on this exact question since McLaughlin came down, with more circuit rulings pending. Multiple firms tracking the split expect it reaches the Supreme Court eventually.
None of that touches the argument in this piece. What's being narrowed is the registry-based claim: was this number on the Do Not Call list. What's not in that fight at all is the consent-based claim: did you have permission to text this person, period. A blue-bubble spoofing tool violates the second one on the first message, registry or no registry, and that claim isn't up for reinterpretation in any circuit right now.
There's no clever routing around consent. There's only whether you got it before you hit send.
Again: this is not legal or professional advice. Sources can be incomplete and interpretations can be wrong. Verify anything here against the primary source and talk to a qualified attorney before you act on it.
Sources
- FCC, Stop Unwanted Robocalls and Texts
- McLaughlin Chiropractic Associates, Inc. v. McKesson Corp., 606 U.S. 146 (2025)
- Steidinger v. Blackstone Medical Services, No. 25-2398 (7th Cir. July 14, 2026)
- Troutman Pepper Locke, Seventh Circuit Rules Text Messages Are Not Telephone Calls Under TCPA 227(c)(5)
- FTC, Enforcement Policy Statement on Deceptively Formatted Advertisements
- FTC, Defendants in Massive Spam Text Message, Robocalling and Mobile Cramming Scheme to Pay $10 Million
- Congressional Research Service, AMG Capital Management v. FTC
- AMG Capital Management, LLC v. FTC, 593 U.S. 67 (2021)
- FTC Act Section 5, 15 U.S.C. § 45
- 47 U.S.C. § 227 (TCPA)
- FCC, Rules to Stop Robocalls and Robotexts (2024 revocation order)
- Bobo v. Clover Network, LLC settlement site
- CompliancePoint, Text Messaging Lessons from the Clover TCPA Settlement
- ClassAction.org, $7.5M+ Zales settlement over alleged spam texts
- Bottoms v. Block, Inc. settlement site (Cash App, $12.5M)
- The Campaign Registry
- Twilio, A2P 10DLC compliance overview
- Apple Messages for Business
- Apple Messages for Business policies