Federal rules let you dial using a version of the national Do Not Call registry obtained up to 31 days earlier. That is the outer limit, not the operating cadence. Programs that hold up under scrutiny refresh federal and state registry data on a set schedule, suppress internal opt-outs continuously, and keep records showing which version of the registry was used for which call.
In This Article
A thin scrub process surfaces in a review, not in a lawsuit. The list looks clean. The vendor invoice is current. Then someone asks which version of the registry was used for the calls placed on the 28th of last month, and there is no answer, because nobody logged it. That gap, between having scrubbed and being able to show you scrubbed, is where do-not-call exposure actually sits. This post walks the process end to end: how often to scrub, which lists to scrub against, what the safe harbor really requires, and the specific places the process breaks. If you would rather have someone walk your current setup with you, the campaign compliance audit service page sets out what a review covers, from scripts and consent collection through DNC procedures, call recording practices and agent training documentation.
How often do you need to run a DNC scrub?
A DNC scrub must use a registry version no more than 31 days old at the time of the call. That is a federal ceiling on staleness, not an operating schedule, and the registry changes every day.
Both rulebooks set the same limit: the FTC’s Telemarketing Sales Rule at 16 CFR 310.4(b)(3)(iv), which sets out the six conditions of the do-not-call safe harbor, and the FCC’s parallel standard at 47 CFR 64.1200(c)(2)(i)(D), which also carries the company-specific do-not-call procedures.
A list scrubbed on the 1st and dialed on the 30th satisfies the rule. It also means thirty days of new registrations sat in your dialer the whole time. The FTC’s Do Not Call Registry Data Book for fiscal year 2025, which reports registry volumes and complaint counts each December, puts active registrations at 258.5 million as of September 30, 2025, with more than 4.7 million numbers added across that year. That is more than 12,800 a day, and more than 390,000 inside a single 31-day window. The practical question is not whether you are inside 31 days but how much of that drift you are willing to carry into a dial session.
The cleaner way to think about cadence is to tie it to dialing rather than to the calendar. Refresh registry data on a fixed schedule, suppress against it before each list load, and check internal opt-outs at dial time rather than at load time, since an opt-out taken at 10am should not be dialed again at 4pm the same day. Once the subscription is paid, another pull costs nothing but the engineering to automate it. That economics is why a continuous campaign has no reason to sit at the 31-day ceiling. If that scheduling is the part you would rather not build in-house, the DNC scrubbing setup and management service covers federal and state list integration, internal DNC management, and scrub schedules tied to campaign launches rather than to the calendar.
Which do-not-call lists do you have to scrub against?
Scrub against four sources: the national registry, any state registry where you dial, your internal company-specific list, and the Reassigned Numbers Database. Litigator lists are a common fifth, though no rule requires them.
Treating them as one list is a structural mistake that survives inside otherwise functional processes. Each answers a different question, and each fails differently.
The national Do Not Call registry
Access is sold by area code on an annual subscription, the first five area codes are free, and qualifying exempt organizations get the full list at no charge. One detail gets missed: the FCC’s rules require that a seller purchase its own access and not participate in any arrangement to share the cost of accessing the database. A vendor cannot buy one subscription and spread it across a client roster. If your provider has never asked you for a Subscription Account Number, that is worth a conversation.
State DNC registries
State registries sit on top of the national list in a subset of states. Florida, Texas and Pennsylvania are among those running their own programs, each with its own registration, fees and exemptions. Numbers appear on state lists that never appear on the federal one, and the penalties stack. Our state-by-state mini-TCPA reference guide works through how registration, bonding, calling windows and separate DNC registries diverge across a dozen states, including the Texas registration and bonding requirement under Business and Commerce Code chapter 302.
Your internal (company-specific) DNC list
The internal list is the only one of the four you build and maintain yourself, which is why it gets the least engineering. The FCC’s company-specific procedures at 47 CFR 64.1200(d), which set out the minimum standards in full, require a written policy available on demand, personnel trained in its use, the request recorded at the time it is made, and the number honored within a reasonable time not exceeding ten business days. Records of the request are kept for five years. A do-not-call request applies to the entity that was called and does not automatically extend to affiliates, and liability stays with the seller even when a third party is the one recording the request. Suppression is only half of the record: our guide to collecting, storing and documenting prior express written consent covers the other half, including the five-year retention clock and what a rendered capture of the consent page has to show.
The Reassigned Numbers Database
The Reassigned Numbers Database answers a different question than the others. It does not tell you whether someone opted out. It tells you whether the number you hold consent for still belongs to the person who gave it. The FCC provides a safe harbor for callers who query the database, receive a “no” response, and call a number that had in fact been reassigned. Operationally it belongs in the same pre-dial step as everything else.
Litigator and serial-plaintiff lists
Litigator and serial-plaintiff lists are commercial products, not a regulatory requirement. They suppress numbers associated with people who file TCPA claims as a matter of practice. A litigator scrub does not make a non-compliant campaign compliant. What it does is keep a single process error from landing in front of someone who files for a living.
The five sources side by side, with what each one is actually for.
Case | Resolved | Enforcer or court | Conduct alleged | Amount |
|---|---|---|---|---|
Campbell v. Sirius XM Radio | Final approval July 2026; appeal filed Aug. 27, 2026 | C.D. Ill. (class action) | More than one solicitation call in 12 months to numbers on the National DNC Registry or Sirius XM’s internal DNC list, 2019–2025 | $28,000,000 plus list-scrubbing and calling-policy changes |
Fried v. Kaiser Foundation Health Plan | Final approval Jan. 2026 | State court (class action) | Text messages sent after recipients replied “stop”; TCPA and Florida Telephone Solicitation Act | $10,500,000 |
Walston v. National Retail Solutions (NRS Pay) | Preliminary approval Jan. 2026 | Ill. Cir. Ct. (class action) | Prerecorded telemarketing calls to cell phones without prior express written consent | $6,500,000 |
Ryan v. Wilshire Law Firm | Final approval June 2026 | June 2026 Fla. Cir. Ct. (class action) | Prerecorded messages to cell phones | $5,975,000 |
U.S. v. Citizens Disability and CD Media | Consent order announced Sept. 30, 2025 | FTC via DOJ, D. Mass. | 109 million+ telemarketing calls, 25.7 million of them to DNC-registered numbers; leads sourced from prize and coupon sites; misrepresenting that calls answered a consumer inquiry | $2,000,000 civil penalty, suspended to $1,000,000; ban on certain prerecorded calls; required monitoring of lead generators |
U.S. v. Day Pacer and EduTrek | Final orders Jan. 2024 | FTC, N.D. Ill. | Millions of calls to DNC-registered numbers using contact data collected from job-search websites | $28,700,000 civil penalties; permanent telemarketing ban |
How to scrub leads against DNC, end to end
A complete DNC scrub runs six steps: buy registry access, classify the list, suppress against each source separately, check internal opt-outs at dial time, log which registry version you used, and retain those logs.
Only two of those six involve the actual matching. It starts with access: a Subscription Account Number, and a decision about which area codes you are buying, which follows from where you dial rather than where you are. Our resource center has a short guide with step-by-step instructions for obtaining a SAN, downloadable as a two-page PDF. Next the list comes in and gets classified, because wireless, landline and business lines carry different obligations and a list that has not been classified cannot be suppressed correctly. Then the suppression pass itself, run against each source separately so that a hit can be attributed to the list it came from. Then a dial-time check against internal opt-outs, which is a different operation from the pre-load pass and catches the same-day requests that pre-load scrubbing structurally cannot.
The fifth step is the one that gets skipped: logging which registry version was used, on what date, against which list. A Boolean field reading “scrubbed” tells a reviewer nothing about what data supported the decision. And the sixth is retention, holding those logs alongside your written procedures and training records.
Where the tools sit matters less than people expect. Programs scrub at list load through a suppression service, enforce at the dialer, or do both. Doing both catches failures that either one alone misses. What no tool does on its own is produce the written procedures and the monitoring record, which brings us to what the safe harbor actually asks for.
What does the 31-day safe harbor actually protect you from?
The safe harbor protects you from liability for a do-not-call violation that was a genuine error, but only if five other conditions were already in place. The scrub is one of six.
The Telemarketing Sales Rule lists them in full at 16 CFR 310.4(b)(3). A seller or telemarketer avoids liability for a do-not-call violation by demonstrating that, as a matter of routine business practice, it had established and implemented written procedures, trained its personnel and anyone assisting with compliance, maintained a recorded internal do-not-call list, used a process employing a registry version obtained within 31 days and kept records documenting that process, monitored and enforced compliance with those procedures, and that the offending call was the result of error rather than a failure to capture a do-not-call request. The FCC’s parallel standards add the purchasing condition described above.
Five of those six conditions are paperwork and behavior. One is the scrub. This is why teams that scrub diligently still lose the safe harbor argument: they can produce a clean list, and they cannot produce the written procedure, the training record, the monitoring log, or the evidence that the call was an isolated error rather than the predictable output of a gap. The useful audit question is not “do we scrub?” It is “if a regulator asked for all six today, what could we hand over by end of week?”
There is a second reason that question has got sharper. In June 2025 the Supreme Court decided McLaughlin Chiropractic Associates v. McKesson, which carries the full opinion and the 6 to 3 split, holding that district courts hearing TCPA cases are not bound by the FCC’s interpretation of the statute and must determine its meaning themselves, affording appropriate respect to the agency’s view rather than deference to it. It sits alongside the broader narrowing of agency deference since 2024. None of this moves the rule text: the 31-day requirement and the six safe harbor conditions read exactly as they did. What moves is how much weight an FCC reading of that text carries in front of any particular judge. The practical consequence for an operator is narrow and worth stating plainly: records showing what you did, on what date, against which version of the data, travel better than a posture resting on a favourable interpretation.
Where DNC scrubbing goes wrong
Five failure patterns come up in a DNC scrubbing review: calendar-based cadence, assuming B2B is out of scope, campaign-scoped internal lists, treating the ten-day opt-out window as an allowance, and no provenance on the scrub.
None of them look like negligence from the inside.
Cadence tied to the calendar instead of the dial. The monthly scrub is the classic. It is defensible on paper for the first day of the month and progressively less defensible after that, and it breaks entirely when a campaign runs continuously.
Assuming a B2B program is out of scope. The TSR’s do-not-call provisions do not reach business-to-business calls, which is true and widely known. What follows from it is narrower than teams assume. The exemption is about the nature of the call, not a guarantee about the contents of your list, and B2B lists routinely contain sole proprietors, home offices and personal mobile numbers supplied as a work contact. The FCC’s do-not-call rules run to residential subscribers, and the Commission has applied them to wireless numbers. A B2B list is a claim about intent, not a verified property of every row in it. The exemption itself sits at 16 CFR 310.6(b)(7), in a short section listing every call type the rule does not reach. Our explainer on the Telemarketing Sales Rule works through what the FTC’s 2024 amendments changed about it.
An internal DNC list that lives inside a campaign. Dialer-level opt-out flags scoped to one campaign mean the same number comes back through a different list next quarter. The internal list has to be a master suppression file outside any single campaign or channel, applied to everything.
Opt-out lag treated as an allowance. Ten business days is the outer bound, not the standard. The rule requires the request be honored “within a reasonable time from the date such request is made,” and then caps that reasonable time at ten business days. Where a system can suppress in hours, what counts as reasonable is measured against what that system can do, not against the cap.
No provenance on the scrub. If you cannot name the registry version behind a given call, you do not have the record the safe harbor asks for, whatever your process actually was.
The enforcement side of this is not theoretical. The FTC’s own enforcement record for the registry, which lists every action by name, stands at 151 cases brought and 147 resolved, recovering over $178 million in civil penalties and $112 million in restitution or disgorgement. If you want to run these five against your own operation, the TCPA DNC checklist is a downloadable PDF covering the 31-day registry rule alongside the 8am to 9pm calling window and the state overlays that change it.
Not sure which of the six conditions you could evidence today?
A compliance audit walks your current setup: scripts, consent collection, DNC procedures, call recording practices and agent training documentation. You get back a list of what is in place and what is not.
What does DNC scrubbing cost to run properly?
DNC scrubbing costs $85 per area code a year for registry access, capped at $23,425 nationwide. The real cost sits everywhere else: state fees, engineering time, and the documentation the safe harbor requires.
Those are the fiscal year 2027 rates, set out in the FTC’s fee announcement for fiscal year 2027, and they take effect October 1, 2026. The first five area codes are free, and an area code added during the second half of a subscription year costs $43. The figures rose from $82, $22,626 and $41 in fiscal year 2026.
$85 per area code, capped at $23,425 for nationwide access
Those other costs are where programs are actually funded or starved: state registry fees where you dial, litigator list subscriptions if you use them, the engineering time to wire suppression into the dial path rather than bolting it on at list load, and the ongoing work of maintaining written procedures, training records and monitoring logs that a reviewer would accept.
Set that against the other side. The private right of action at 47 U.S.C. 227(b)(3), which sets the damages a private plaintiff can recover, allows $500 for each violation or actual monetary loss, whichever is greater, and lets a court treble that to $1,500 where the violation was willful or knowing. FTC civil penalties under the Telemarketing Sales Rule reach $53,088 per violation, a figure set in January 2025 and unchanged for 2026, and carried in the FTC’s own guidance on complying with the rule. Per call, across a list of any size.
The upside is worth stating as plainly as the exposure. A program with documented provenance on every scrub is one that can add states without rebuilding, hand a clean answer to a client’s procurement review, and treat a single missed number as the isolated error the safe harbor was written for. That posture is the asset. The clean list is just today’s output of it.
Frequently asked questions
How often do you have to scrub against the DNC list?
The registry version used for any given call can be no more than 31 days old, under both the FTC’s Telemarketing Sales Rule and the FCC’s rules. That is a maximum, not a recommended schedule. New numbers are added daily, so an active outbound program refreshes well inside that window and applies internal opt-outs continuously rather than on a cycle.
Which do-not-call lists do you have to scrub against besides the federal registry?
Four sources in total: the national registry, any state registry covering the states you dial into, your own internal company-specific do-not-call list, and the FCC’s Reassigned Numbers Database where you are relying on older consent. A commercial litigator suppression list is available as a fifth source, and no rule requires it.
What happens if you call a number on the DNC list?
Each call can be treated as a separate violation. Under the TCPA, statutory damages are $500 per call and up to $1,500 for willful or knowing violations. The FTC can seek civil penalties of up to $53,088 per violation under the Telemarketing Sales Rule. A safe harbor exists for calls that result from error, but it requires written procedures, training, an internal do-not-call list, a documented 31-day scrub process, and active monitoring.
What is a DNC litigator scrub?
Does DNC scrubbing apply to text messages?
Yes for the rules that govern consent and opt-out. The FCC treats text messages as calls under the TCPA, so do-not-call and revocation obligations apply to SMS outreach, and a revocation request sent by text is valid when a reasonable person would read it as one.
Put a number on your current exposure
The compliance risk calculator models your monthly call volume and non-compliance rate against the statutory maximums, and returns a figure for TCPA statutory damages and TSR civil penalties. It takes about a minute and nothing is gated.






