Skip to content
Start free trialFree trial

Deliverability and consent6 min read

WhatsApp opt-in, and how not to get blocked

Meta requires opt-in before you message someone on WhatsApp. What counts, what the record should hold, and which behavior gets numbers restricted.

A checked permission card clipped to a green message form.A checked permission card clipped to a green message form.

Meta requires businesses to obtain opt-in before messaging someone on WhatsApp. Its current opt-in guide sets the policy minimum, while the Business Messaging Policy explains opt-outs, quality, and enforcement. The two practical questions are what a defensible opt-in looks like and what happens when a business ignores it.

Recipient feedback is central to enforcement. People who did not expect your message can block or report the business, those signals feed its quality rating, and sustained poor quality can restrict sending. WhatsApp may also evaluate opt-in flows and policy violations directly. The practical lesson is the same: a permission record that only exists in a spreadsheet will not rescue an unexpected message.

What counts as an opt-in

At Meta's policy minimum, an opt-in means the person gave the business their mobile number and agreed to receive subsequent messages or calls from that named business. Since the November 2024 policy update, the permission may be general rather than WhatsApp-specific if it still complies with applicable law. A channel-specific, purpose-specific record remains clearer for the customer and easier for the business to defend.

Three properties make the permission useful.

The person has to know it is you. Your business name, as they would recognize it, at the point of agreement. Consent given to a brand they have never heard of is consent to nothing.

Make the channel explicit when the flow allows it. Meta's minimum can accept a general permission, but "we will message you on WhatsApp" avoids surprise and may be required by local law. A person who agreed only to email did not agree to WhatsApp.

They have to know roughly what they are agreeing to receive. Order updates and weekly promotions are different products. Which brings us to the part most lists get wrong.

Someone who messaged you asking where their order is has opened a service conversation. That does not, by itself, establish a standing permission for future promotions. Someone who selected delivery notifications should not be treated as having requested a Black Friday campaign.

Meta recommends either explaining the categories covered by an opt-in or collecting separate permission by category. Treating every permission as identical is easy when a system stores consent as one flag on a contact record. If your platform can only answer "is this person opted in", it cannot answer the useful question, which is "what did they agree to receive".

Record the scope of the permission, not just a single yes/no flag. This helps distinguish a requested appointment update from a later promotion.

What a usable record contains

The following is an operational recordkeeping checklist, not a statement of the legal retention period that applies to your business. It should let your team explain why a particular message was permitted.

  • The exact wording shown to the person
  • Where it was collected: which page, which form, which point in a flow
  • When it was collected, with a consistent timestamp and time zone
  • The purpose it covers
  • The channel it covers
  • What changed it since, including opt-outs, and when

That last line is the one usually missing. Consent is a history rather than a state. A contact who opted in, opted out, and opted back in is different from one who never opted out, and the two look identical if you only store the current value. Recording each change in an activity history makes that sequence visible.

Ways businesses actually collect it

These can all support a compliant opt-in when the wording clearly states the business and the communication the person is agreeing to receive.

  • A clearly labelled, unticked checkbox at checkout or on a form, naming your business and WhatsApp
  • A "message us on WhatsApp" entry point that starts a service conversation, followed by a clear permission request before future marketing. You can create the entry point with the free WhatsApp link and QR generator; the resulting chat does not grant marketing permission.
  • A click-to-WhatsApp ad whose wording and first interaction make the future communication clear
  • An in-store or on-call agreement, recorded at the time with the wording used
  • Double opt-in: the person confirms once more inside WhatsApp before any marketing goes out

Double opt-in can help confirm that the intended person wants the messages. It adds a step and does not guarantee engagement, lower complaints, or a particular quality rating. Choose the flow based on the permission you need and the risk of mistaken sign-ups.

What is not an opt-in

  • A purchased or rented list, in any form, with any assurance attached
  • Numbers collected for delivery, verification, or account recovery, then reused for marketing
  • A conversation the person started two years ago about something unrelated
  • Numbers scraped from a marketplace, a directory, or a group chat
  • An opt-in given to a different brand you also own, unless that was stated at the time
  • Permission limited to email or another purpose, reused for WhatsApp without checking whether the agreed scope covers it

If a list arrived without a story about how each number agreed, there is no opt-in, and sending to it is the fastest way to damage a number.

Opt-out has to be immediate and global

An opt-out is an instruction, not feedback. Three requirements make it real.

Immediate. Effective before the next send instead of the next list rebuild. A suppression list checked at send time is the mechanism, because someone can opt out after the audience was assembled.

Match the scope of the request. A marketing opt-out should apply across that business’s marketing campaigns. A broader request to stop all contact must not be reduced to a marketing-only preference. Record what the person asked for and enforce it before the next send.

Recognize natural requests as well as keywords. Handle known stop words consistently, including supported languages. Also route requests such as "please do not contact me again" for suppression or review; a customer should not need to guess the exact keyword.

Meta also signals marketing preferences through send failures. Error 131050 means the recipient stopped receiving marketing messages from that business. That failure should suppress future marketing automatically. Software that files it in a report and moves on is quietly re-sending to someone who already said no.

One code is different and it is worth separating: error 131049 is a per-user marketing limit. It does not mean the recipient opted out. Meta recommends waiting at least 24 hours before reconsidering the send and warns that the limit may last longer. Meta's error reference keeps these meanings current.

The behavior that actually gets numbers restricted

Beyond consent, the pattern behind most flagged numbers is the same shape.

  • Frequency. More than people expected. There is no universal right number, but the honest test is whether you would be comfortable telling them the frequency at opt-in.
  • Relevance. The same message to the whole list, including the people it does not apply to. Every irrelevant send is a small invitation to block.
  • Timing. Marketing at an unexpected local time creates avoidable surprise. Quiet hours are cheap to implement and expensive to skip.
  • Language. Messaging someone in a language they did not use with you reads as automated outreach, because it usually is.
  • No visible way out. A marketing message that does not make opting out obvious converts an annoyed person into a reporting one.

Meta's rules are the floor, not the ceiling

Everything above is about staying inside Meta's requirements and keeping a number healthy. Local law sits on top of it and is stricter in many markets, with its own rules about consent, record keeping, timing, and the right to be forgotten. Which rules apply to you depends on where your customers are, and that is a question for someone qualified to answer it rather than for a vendor's blog.

What a platform can reasonably be expected to give you is the machinery: consent recorded per purpose and per channel, suppression enforced at send time, opt-outs honoured across campaigns, and a record you can produce when someone asks.

The short version

Collect permission that names the business and states what the person is agreeing to receive. Make WhatsApp explicit when the flow and applicable law call for it. Store every grant and withdrawal, check suppression at send time, honour every stop instruction, and treat Meta's failure codes as instructions.

Permission is one part of eligibility. Keep checking template status, account restrictions, recipient preferences, and the current messaging limit before a campaign.

Published by Otobiz on . Last updated .

Ready to put this to work?

Start with one customer journey and build from there.

7-day free trial. Nothing is charged when you start. Cancel before it ends and pay nothing.