← Back to list

Two Verification Texts Sparked a TCPA Case. Here’s What Businesses Should Learn

Two plain verification code texts just became the center of a TCPA ruling that outbound teams should know about.

Noah Wieder | US Data API Blogs · 2026-05-27 21:43 · 0 claps · 5.8 min read
#tcpa #tcpa-compliance #verification #sms #marketing-campaign
Open on Medium ↗
Wiki topics: ECO · Economy · General MKT · Marketing · General

Two Verification Texts Sparked a TCPA Case. Here’s What Businesses Should Learn

Two Verification Texts Sparked a TCPA Case

Two Verification Texts Sparked a TCPA Case

Two plain verification code texts just became the center of a TCPA ruling that outbound teams should know about.

No long marketing campaign. No sales pitch. No coupon code. Just two SMS verification codes sent by Wonder Group.

That is what makes the ruling worth paying attention to.

Companies send SMS codes, login alerts, account messages, password reset notices, and customer verification texts every day. When those messages go to mobile numbers, the wording can matter more than many teams realize.

The case was *Zelma v. Wonder Group Inc.*, decided by the U.S. District Court for the District of New Jersey on May 20, 2026.

The case involved Wonder Group and a plaintiff named Richard Zelma. TCPAWorld covered the ruling, noting that the court dismissed the Do-Not-Call and opt-out claims with prejudice because the texts had no promotional language, no links, no product mentions, and nothing that looked like marketing.

The ruling gives businesses a useful example of how courts may review the actual wording of a text message before deciding whether it counts as advertising.

For outbound teams, lead buyers, app companies, and support teams, the case is worth understanding. Message content matters. So do consent records, phone data quality, and the way a company separates transactional texts from promotional outreach.

What Happened in the Wonder Group TCPA Case

Zelma received two texts from Wonder Group on November 13, 2024. Both were verification codes:

  • “Your Wonder verification code is 041797”
  • “Your Wonder verification code is 475599”

They arrived about one minute apart.

Zelma said his number had been listed on federal and state Do-Not-Call lists since 2003. He also said he had no relationship with Wonder and had never asked to receive messages from the company.

He filed TCPA claims, including claims tied to DNC rules and opt-out notice requirements.

The case came down to one basic question: what did the texts actually say?

The court looked at the messages and found no advertising language. The texts did not promote anything. They did not encourage a purchase. They did not include a link. They did not point Zelma to Wonder’s website, products, or services.

They were just codes.

Why the Court Dismissed the TCPA Claims

The TCPA treats promotional messages differently from transactional or informational messages.

For a DNC or opt-out claim to move forward, the message generally needs to qualify as a “telephone solicitation” or an “unsolicited advertisement.”

The court found these texts did not meet that standard.

Zelma argued that the messages were a “trojan horse.” His theory was that the unclear verification codes were designed to make him look up Wonder and engage with the company.

The court rejected that argument.

It pointed to Third Circuit guidance from Mauthe v. National Imaging Associates, which warned against treating any message from a company as an ad just because the sender sells something.

That point matters for businesses. A company can sell products or services and still send a non-advertising message. The court focused on what the texts actually said, not what the plaintiff believed they were trying to do.

The Court’s Issue With the Amended Complaint

This was not Zelma’s first try.

The court had already given him a chance to amend his complaint. It also told him what he needed to add: facts showing the verification texts were advertisements under the TCPA.

His amended complaint added claims that the texts encouraged him to engage with Wonder’s website and services.

The court was not persuaded.

The texts did not include a link. They did not mention products. They did not say anything about buying, ordering, subscribing, visiting a website, or using a service.

The court found the new allegations lacked factual support.

That led to a stronger ruling. The claims were dismissed with prejudice, which means Zelma cannot keep amending those claims in that case.

The Sanctions Situation

Wonder Group asked for Rule 11 sanctions.

Rule 11 sanctions can apply when a filing is legally or factually unsupported. The court seemed to agree that Zelma’s amended filing had serious problems. Wonder’s sanctions request had a procedural issue.

Rule 11 requires specific steps:

  1. File the sanctions motion separately.
  2. Serve it on the other party first.
  3. Give the other party 21 days to withdraw or fix the filing.
  4. File it with the court only after that safe-harbor period.

Wonder did not follow those steps, so the court denied the sanctions motion on procedural grounds.

The story did not end there. The court used its own authority to order Zelma to show cause why sanctions should not be imposed anyway. That means the court still viewed the conduct seriously, even though Wonder’s Rule 11 request was procedurally flawed.

Why This Matters for Verification Texts

This ruling helps companies that send short authentication messages.

Many businesses send texts for:

  • Login codes
  • Two-factor authentication
  • Password resets
  • Account verification
  • Delivery updates
  • Security alerts
  • Appointment confirmations

Those messages can raise TCPA questions when they are sent to mobile numbers.

This case shows that a plain verification code is not the same as a marketing text. Businesses should not treat the ruling as permission to get careless.

A verification text should stay clear and direct. Adding marketing language changes the risk.

This is safer:

“Your verification code is 123456.”

This creates more risk:

“Your verification code is 123456. Order today and get 20% off.”

The second version mixes authentication with promotion. That moves the message closer to an advertising claim.

This ruling does not mean every verification text is automatically safe. It means courts may look closely at whether the message actually promotes something.

What to Check Before Sending SMS Campaigns

Before sending any text campaign, teams should separate transactional messages from promotional ones in both policy and system settings.

Here are a few questions to review:

  • Are verification texts limited to account or security purposes?
  • Do they include unnecessary links?
  • Do they mention products, discounts, services, or offers?
  • Are marketing texts clearly separated from transactional ones?
  • Are opt-out rules handled properly for promotional campaigns?
  • Are DNC checks used before sales or lead-generation outreach?
  • Are consent records stored in a way your team can review later?

This case clarifies one narrow point: two bare verification codes were not advertisements.

Businesses still need strong consent records, suppression lists, and clear internal rules.

What Plaintiffs Should Learn

The ruling also has a warning for TCPA plaintiffs.

Courts need facts. Not guesses. Not broad claims. Not theories that ignore what the message actually says.

If a text does not include promotional language, proving it was an advertisement gets harder.

The amended complaint issues matter too. When a court explains what is missing, the next filing needs to fix that gap with real facts. Repeating the same theory with stronger wording can create more problems.

Key Point for Defendants

For TCPA defendants, this case supports a practical defense.

What the message says matters.

If the message only provides a verification code and does not promote anything, DNC and opt-out notice claims may be weaker.

Businesses should keep organized records. Courts look at details, and a good compliance file should show:

  • What message was sent
  • When the message was sent
  • Why the message was sent
  • Whether the message was transactional or promotional
  • What system triggered it
  • Whether consent or account activity supported it

Those records can help show that a message was not part of a sales campaign.

How Searchbug Helps Teams Review Phone Data Before Outreach

Verification texts are not the same as marketing texts, and businesses still need accurate phone data before sending outreach campaigns.

Searchbug helps teams review phone records before calls or texts go out. The Phone Validator API checks phone status, line type, carrier details, and timezone information.

For outreach campaigns, DNC Check screens numbers against federal and state Do-Not-Call lists, known DNC complainers, and TCPA litigators.

For companies working with older lead lists or customer records, the Reassigned Number Database API helps identify numbers that may have changed ownership. That matters because consent belongs to the person, not the phone number.

TL;DR

The safest verification text is boring.

Keep it short. Keep it functional. Avoid sales language. Do not add promotional links. Do not turn a login code into a marketing opportunity.

For companies in food delivery, fintech, healthcare, insurance, retail, apps, lead generation, real estate, and customer support, this ruling is a useful reminder.

Transactional messages and marketing messages should not be blended.

Clear message content and well-kept phone records can make a real difference when a TCPA claim shows up.

Searchbug helps outbound teams verify phone data and support documented compliance. API users can add checks into existing workflows and start with a FREE API Test Account with $10 in credits. Non-API users can use Bulk Processing to clean larger lists before outreach.


메타데이터
post_id
00dceb18f66c
slug
two-verification-texts-sparked-a-tcpa-case-business-lessons-00dceb18f66c
url
https://medium.com/@searchbug/two-verification-texts-sparked-a-tcpa-case-business-lessons-00dceb18f66c
canonical_url
https://medium.com/@searchbug/two-verification-texts-sparked-a-tcpa-case-business-lessons-00dceb18f66c
author_url
https://medium.com/@searchbug
status
ok
fetched_at
2026-06-09 15:37:30