A sales manager checking an internal do not call list on a laptop in an office

The national registry is a file you download. An internal do not call list is built out of sentences people say to you on the phone. One of those is easy to automate and the other one is where teams get caught, because a request only reaches the list if somebody, or something, was listening when it was made.

What is an internal do not call list?

It is your own record of the people who have told you directly to stop calling. Under the FCC's telemarketing rules, anyone placing sales calls to a residential subscriber has to have procedures for keeping that list, and the entry has to carry the person's name if they gave one plus the phone number. The rule text sits at 47 CFR 64.1200(d), read on 1 September 2026.

No two companies have the same one. Your internal do not call list holds the people who asked you, and it will contain numbers that appear on no public registry anywhere.

How is it different from the national registry?

The national registry is run by the FTC and a consumer signs up once, for everyone. You are expected to scrub against a copy obtained no more than 31 days before the call goes out, and to keep records showing you did.

The internal list works the other way around. It is small, it is yours, and it beats your exemptions. Someone who gave you written consent last month, or who bought from you last year and gave you an established business relationship, is still off limits the moment they ask you to stop. Plenty of teams treat a signed consent record as the end of the argument. It is not. A direct request outranks it.

How fast do you have to honor a request?

Three numbers do most of the work here.

One line in the same paragraph gets overlooked and matters a lot for anyone using an outside call center: if a third party records or holds the requests, the company on whose behalf the calls were made is liable for any failure to honor them. Outsourcing the dialing does not outsource that.

Where do opt-outs actually go missing?

A person can revoke consent through any reasonable means. In practice that means the request shows up through whichever door happens to be open:

Each of those is a separate pipe, and your internal do not call list is only as good as the leakiest one. Three checks are worth running this week.

Check your call dispositions

The live call is the most common intake point and the easiest one to lose. If your disposition list has no option that writes straight to suppression, the request ends up as free text in a note that no query will ever read. That is a call disposition design problem before it is a compliance problem.

Check your inbound texts

For SMS the FCC named a set of words that count as a request on their face when sent as a reply: stop, quit, end, revoke, opt out, cancel, and unsubscribe. Keyword matching handles those. It does not handle "lose my number" or "take me off your list", which is how people actually write. Read the replies your keyword filter skipped, or have something read them for you. The same discipline applies to the sender reputation work behind 10DLC registration.

Click your own unsubscribe link

Actually click it, in a real send, on a real device. The most common broken opt-out we come across is a template variable that was never wired up, so the link renders as a placeholder and quietly does nothing. Every recipient who tried to opt out that month was ignored, and nothing in your reporting will say so.

What is in force right now, and what is not

The FCC's 2024 opt-out order also said that a revocation sent in response to one kind of message has to stop all of that caller's robocalls and robotexts, including unrelated ones from a different part of the business. That single piece has been waived twice. The Bureau's Second Extension Order of 6 January 2026 pushed it out to 31 January 2027.

Everything else in the opt-out order applies today, and the waiver changes nothing about your duty to honor a reasonable opt-out request. A delay is not a repeal. The cheapest moment to build one shared suppression table across voice, SMS and email is well before the date you are required to have one.

Why deleting the contact is the wrong reflex

Someone says take me off your list, and the instinct is to delete the record. It feels like honoring the request. It does the opposite.

Delete the contact and two things happen. The number comes back on your next list import, because nothing in your system remembers that it was ever suppressed. And you have destroyed your own evidence. Your proof that you did not call somebody is not an empty call log, since an empty log is also what a lost request looks like. The proof is a dated request, a suppression flag on a record you still hold, and an audit trail behind both.

Suppress and keep. Never delete, and never rely on a rep remembering to skip the row. Numbers that fail your phone number validation pass get quietly dropped by the carrier the same way, which is another reason to trust a suppression flag over the absence of a call.

What about affiliates and downline offices?

The rule is narrower than most people assume. Absent a specific request otherwise, a do-not-call request applies to the entity that made the call or had it made, and does not automatically extend to affiliated entities unless the consumer reasonably would expect it, given how the caller identified itself and what was being sold.

Read that "reasonably would expect" test against how an agency actually looks from the outside. If six offices all introduce themselves with the same brand name and sell the same product, a consumer has every reason to think one request covered all six. The safe build is a single shared suppression list across the whole group, with per-office lists as an extra layer rather than the only layer.

The flip side is also in the rule: passing a person's request to anyone who is not the seller or an affiliate needs that person's prior express permission first.

The two requirements that are not data at all

Software will not cover these two, and they are the ones an audit reaches for early.

A written policy, available on demand. You need a document describing how you maintain your internal do not call list, and you have to hand it over to anyone who asks for it. One page is enough. Zero pages is a problem.

Trained people. Anyone involved in any part of your telemarketing has to be informed and trained in the existence and use of the list. That is a slide in onboarding and a note in the rep handbook, and it is worth dating the record of who was trained and when.

What good looks like

Pull these together and the working version is simple to describe:

  1. One suppression list per company, shared across voice, SMS and email.
  2. Every channel writes into it, including a disposition on the live call.
  3. Requests are recorded the day they arrive and suppressed inside ten business days.
  4. Records are kept for at least five years, and contacts are suppressed rather than deleted.
  5. A written policy exists, and the people dialing have read it.

None of that is exotic. It gets skipped because it lives in five different tools, and a request that arrives in the SMS inbox has no route into the dialer's suppression table. That gap is the whole reason we built SellifyGPT as one dialer, CRM and messaging platform rather than a stack of connected ones. You can start a 14-day free trial and cancel before it ends if it turns out you were fine already.

Worth saying plainly: this is a plain-English read of published rules for sales teams, not legal advice. Your own counsel should sign off on the process, and state rules can be stricter than the federal ones. If you record your calls as well, the consent rules there are separate again and covered in our piece on sales call recording laws.

See it on your own calls.

SellifyGPT puts the dialer, CRM, and an AI coach in one place. 14-day free trial, cancel before it ends.

Start free