# The Do-Not-Contact Sync: One Suppression List Across Every Tool

*You will run a single suppression list that captures every opt-out the same day, propagates it to every sending and sourcing tool, and blocks re-import so an opted-out person is never contacted again.*

- Canonical URL: https://www.refolk.ai/guides/do-not-contact-sync-suppression-list
- Pillar: Process, data, and compliance
- Format: Playbook
- Published: 2026-09-26
- Last reviewed: 2026-09-26
- Reading time: 16 min
- Keywords: how to sync opt-outs across tools, single suppression list recruiting, do not contact list across CRM and sequencer, prevent re-importing opted-out contacts, honor opt-out email SMS phone, suppression list before enrichment export

## Key takeaways

- The FCC deliberately aligned TCPA revocation with CAN-SPAM, so one honor-within-10-business-days SLA can now govern email, SMS, and calls across your entire stack.
- Deletion is the most common silent breach: the next CRM import, ecommerce sync, migration, or CSV upload puts the same address back, and old unsubscribes return months later.
- A single un-suppressed record in a blast multiplies linearly; one documented case counted 14 texts sent after an emailed opt-out as 14 separate TCPA violations.
- Latency, not coverage, is where mature stacks fail; a nightly or weekly sync leaves a window where campaigns keep firing against records that should already be blocked.
- Since April 11, 2025, honoring only STOP keyword replies is no longer legally sufficient; the FCC requires honoring revocation through any reasonable method.
- Sephora paid a $1.2 million CCPA settlement, the first-ever, for failing to honor global opt-outs including the Global Privacy Control.

Keeping one opt-out honored across a single send is easy. Keeping every opt-out honored forever, across a sequencer, a CRM, an ATS, a dialer, an SMS platform, and an enrichment pipeline that all touch the same person, is where suppression quietly breaks. This guide is the operating procedure for recruiting operations, revenue operations, and anyone answerable for how contact data was gathered: it delivers a single authoritative do-not-contact list that captures every opt-out the same day, propagates it to every tool, kills active sequences, and blocks re-import.

I will be plain about one limit up front. Refolk's index returned repeated credit errors during research for this guide, so the exclusive aggregate figures I would normally build the spine from are not available. Everything below is sourced from primary public material, and the tables are safe to cite as-is. Where a headline number would have come from the index, I say so rather than invent one.

## Why one suppression list, not one per tool

A suppression list is a persistent record of every person who must not be contacted, held as the single source of truth that every sending and sourcing tool obeys before it acts. The reason it must be one list, not one per tool, is that opt-outs leak the instant a system holds a private copy. The core operational risk is re-introduction: a person who opted out returning to an addressable audience through a new import, a purchased database, a CRM synchronization, a sales tool, an enrichment process, or another email platform.

The failure is almost never malice. It is a teammate running a fresh import, a nightly sync overwriting a flag, or an enrichment job re-hydrating a record that was cleaned last quarter. The next import, sync, migration, or CSV upload puts the same address back, and old unsubscribes return months later. Persistence of the record, not its removal, is what enforces the opt-out.

> An opt-out that lives in only one tool is not honored. It is waiting to be overwritten by the next sync.

The mature pattern is a central suppression layer connected to the CRM, enrichment pipelines, dialers, and email platforms. The system checks every outbound event against current suppression rules before a message, call, or audience sync goes out. A suppression record is useful only when every sending system obeys it, which means the record has to be the authority and every tool has to be a subscriber.

> **Rule:** One record, every tool reads it
>
> Suppression must be authoritative and centralized. No sending or sourcing tool may hold a private opt-out state that another sync can overwrite. Every send, call, and audience build reads the same source before it fires.

## What the law requires you to honor, and how fast

Three regimes govern this work in the United States, and the good news is that their timelines now converge. CAN-SPAM governs email, the FCC's TCPA rules govern calls and texts, and state privacy laws govern opt-out preference signals like the Global Privacy Control. The FCC deliberately aligned TCPA revocation with CAN-SPAM, so a single honor-within-10-business-days rule can now cover the whole stack.

That alignment matters operationally: if one channel is slower to process an opt-out than the others, that channel becomes your audit weak point. The table below is the deadline reference to keep next to the intake queue.

| Regime | Channel | Deadline to honor | Scope |
|---|---|---|---|
| CAN-SPAM | Email | 10 business days | Sender + vendors |
| FCC TCPA revocation | Calls/texts | 10 business days | All robocalls/robotexts from that company |
| FCC "revoke-all" (pending) | Calls/texts | Effective Jan 31, 2027 | One STOP = all message types |

Two details on that table change how you build intake. First, CAN-SPAM applies to every follow-up in a sequence, not just the first email. If your first email includes an unsubscribe link but a later one does not, you violate the law, and an opt-out captured after email one must remove the person from every remaining step. Second, since April 11, 2025, the FCC requires honoring revocation through any reasonable method, including keywords like "stop" and "revoke" but not limited to them. Honoring only STOP keyword replies is no longer legally sufficient.

Liability reaches your vendors, too. If you hire an agency, CRM, or affiliate to send on your behalf, you remain legally responsible, must set clear rules for third-party providers, and must monitor them. Both your company and the provider can be held liable. That is why the suppression list has to govern outsourced sending, not just your own seats.

### Quiet hours and the strictest-window rule

Text messages have a second constraint layered on opt-outs: quiet hours. The TCPA prohibits sending marketing texts before 8am and after 9pm in the recipient's time zone, and several states tighten the window further.

| Jurisdiction | Window | Delta vs federal |
|---|---|---|
| Federal TCPA | 8am-9pm | baseline |
| Florida | 8am-8pm | 1 hr tighter (derived) |
| Oklahoma | 8am-8pm | 1 hr tighter (derived) |
| Washington | 8am-8pm | 1 hr tighter (derived) |
| Texas (Sun) | noon-9pm | 4 hrs tighter, Sunday (derived) |

You can either segment by state and apply each window, or adopt the single strictest window across the whole program. Most teams choose the second because it is simpler to operate and easier to audit. Adopting the tightest window everywhere removes an entire class of routing errors, and it means your suppression and scheduling logic stays legible when a regulator asks how you enforce it.

## What a suppression record must carry

An exam-ready suppression record carries enough that the team can prove opt-out, bounce, complaint, and resubscribe history without a human present to explain it. Practitioner guidance splits the needed controls into three groups: compliance controls, deliverability controls, and operational controls. Miss one group and the record looks complete while failing under scrutiny.

- **Compliance controls:** opt-outs, deletion restrictions, jurisdiction-specific contact limits, and documented reason codes.
- **Deliverability controls:** hard bounces and spam complaints, which also belong on the suppression list.
- **Operational controls:** one shared source of truth across tools, with timestamps, audit logs, and clear rule ownership.

At the field level, a consent record typically carries consent status, the reason, who requested the change, and the timestamp. Build every suppression entry to that shape. The test is simple: could you hand the record to an auditor and have it prove, on its own, that this person opted out, when, through what channel, and where the opt-out was applied.

**$53,088 - Maximum CAN-SPAM civil penalty cited per email**

A single un-suppressed record in a large blast multiplies this figure linearly, because each message can be counted separately.

#### The suppression record, outermost to innermost

1. **Compliance** - opt-out status, reason code, deletion restriction, jurisdiction limits
2. **Deliverability** - hard bounces and spam complaints suppressed alongside opt-outs
3. **Operational** - timestamp, source channel, rule owner, audit log
4. **Identity** - normalized email, E.164 phone, social handle, external ID

*Each layer proves something an auditor asks about; drop a layer and the record fails under scrutiny.*

## The end-to-end procedure

The procedure below runs from capturing an opt-out to retaining proof of it. It is written so a person new to the stack can execute it start to finish. The one ordering question the sources disagree on is whether to sync suppression back to the warehouse first and then out to tools, or push a central layer directly to tools; either works as long as every sender reads the same source before it sends.

#### Stand up and run the do-not-contact sync

1. **Capture every opt-out same-day, any channel** - Route STOP replies, unsubscribe clicks, email replies, voicemails, and web-form requests into one intake queue. The FCC requires honoring any reasonable method, not just the STOP keyword, so non-SMS channels must feed the same queue.
2. **Normalize identifiers** - Standardize email, phone in E.164 format, and social handles so one person resolves to one record. Done when dedupe matches across systems on email, phone, or external ID.
3. **Write the authoritative suppression record** - Capture timestamp, channel, source, scope, reason code, and where the suppression was applied. Done when the record can prove opt-out history with no human to explain it.
4. **Propagate to every sender and sourcer before any send** - Push the suppression state to the sequencer, CRM or ATS, dialer or SMS platform, and ad and social suppression audiences. Done when every system reads the same source of truth.
5. **Kill active sequences** - Immediately remove the person from all live cadences. CAN-SPAM allows up to 10 business days, but best practice is immediate removal so no follow-up fires.
6. **Block re-import and enrichment refresh** - Screen every upload against the suppression list and exclude suppressed records from enrichment jobs. Done when suppressed contacts cannot re-enter through import or a data refresh.
7. **Screen every new audience pre-send and pre-upload** - Check each campaign audience and each import against the current suppression list before it ships. Done when no audience or upload leaves without a check.
8. **Audit and retain evidence** - Sample campaign audiences before send and reconcile opt-out records monthly or quarterly. Done when you can produce timestamped proof of opt-out for any contact on demand.

#### How one opt-out travels

1. **Intake** - STOP, unsubscribe, reply, voicemail, or form lands in one queue
2. **Normalize** - identifiers resolved to a single person record
3. **Record** - authoritative suppression entry written with full metadata
4. **Propagate** - pushed to sequencer, CRM/ATS, dialer, SMS, and ad audiences
5. **Enforce** - every send and upload screened against the record before it fires

*Every opt-out follows the same path from any channel to a persistent record every tool obeys.*

The step most teams underinvest in is enrichment. Contacts who have opted out or requested deletion must be excluded from enrichment refreshes automatically. If a suppressed record can be re-hydrated by a scheduled data refresh, the opt-out is defeated silently. Run the suppression screen before any enrichment export, not after.

This is also where a plain-English sourcing layer earns its place. When you need to find the operators who own this machinery, describe them and get them back, rather than reverse-engineering a boolean string. [Refolk](/) resolves a role, stack, and jurisdiction into named people you can screen against your suppression list before a single message goes out.

Ask me this: `Deliverability or email compliance managers who have worked with HubSpot and Salesforce Marketing Cloud` - [run the search](https://www.refolk.ai/start?q=Deliverability%20or%20email%20compliance%20managers%20who%20have%20worked%20with%20HubSpot%20and%20Salesforce%20Marketing%20Cloud).

*Returns named practitioners who have built cross-tool suppression and unsubscribe sync between a CRM and a marketing platform, with the profiles to verify it.*

## Where suppression silently breaks

Suppression rarely fails loudly. It fails when a dashboard says "0 pending" while a general inbox holds an ignored opt-out, or when a "cleaner" database has quietly erased the memory of who opted out. Below are the documented failure modes, what each looks like when it lies, and the check that catches it.

| Failure mode | What it looks like when it lies | Check that catches it |
|---|---|---|
| STOP-only intake | Dashboard shows "0 pending" while emailed and voicemail opt-outs sit unlogged | Audit non-SMS channels against the suppression queue |
| Delete instead of suppress | Smaller, "cleaner" database that looks healthier | Confirm a persistent record survives deletion |
| Per-recruiter scope | Opt-out honored in one cadence but not the account | Query suppression at the person level across all sequences |
| Nightly-sync latency | Every tool "connected" yet sends keep firing | Confirm real-time or pre-send lookup, not batch |
| Enrichment re-hydration | Suppressed contact reappears after a refresh | Verify suppressed IDs are excluded from enrichment jobs |
| Reassigned numbers | A now-valid number gets contacted again | Query the FCC Reassigned Numbers Database before dialing |

Two of these deserve extra weight because they are the ones that break at scale.

**Deletion instead of suppression** is the most common silent breach, and it is usually done to save money, not to cut a corner. In one widely used CRM, opting out an existing contact still counts as a billable contact unless you delete and re-import them. That cost pressure pushes teams toward the exact deletion that destroys the audit trail. Resist it. Keep the person, mark them opted out, and reconcile the opt-out property against your deletion logs so nobody quietly trades compliance for a lower bill.

**Latency, not coverage,** is where mature stacks fail. Even with every tool connected, waiting for a nightly sync or a weekly import creates a window where campaigns keep firing against records that should already be blocked. The fix is a pre-send lookup: the audience is checked against the live suppression list at send time, not against a snapshot from last night.

> **Watch out:** One late message is priced as many violations
>
> Plaintiffs argue each off-hours or post-opt-out message is a separate violation. In one documented case, 14 texts sent after an emailed opt-out counted as 14 separate TCPA violations, at $500 to $1,500 each. A single un-suppressed record in a blast multiplies linearly.

The intake gap deserves a named example too, because it is easy to build without noticing. In one documented incident, an SMS platform processed only STOP keyword replies; a person's opt-out email went to a general inbox and was never processed. The platform's dashboard was clean. The opt-out was not honored. Route every reasonable channel into the same queue, or you will ship a system that reports success while failing the law.

## Enforcement is not theoretical

Regulators have already priced opt-out failures, and the numbers are large enough to justify the whole build. The first-ever CCPA enforcement action was a $1.2 million settlement with Sephora over failing to honor global opt-outs, including the Global Privacy Control. It was not a fringe case; it set the template.

| Action | Year | Penalty | Trigger |
|---|---|---|---|
| Sephora | 2022 | $1,200,000 | GPC not honored |
| American Honda | 2025 | $632,500 | opt-out process defects |
| Todd Snyder | 2025 | $345,178 | opt-out process defects |

The 2025 sweep matters because it was joint across California, Colorado, and Connecticut, and it targeted opt-out process defects rather than a single missing link. As of January 1, 2026, twelve states require recognition of universal opt-out mechanisms: California, Colorado, Connecticut, Montana, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Delaware, Oregon, and Texas. Among them, California, Colorado, and Connecticut have confirmed that the Global Privacy Control qualifies. Colorado was first to make GPC recognition mandatory, effective July 1, 2024.

There is one more requirement people forget: your internal company do-not-call list is required separately under 47 CFR 64.1200(d), and auditors check it first. It is not covered by a general suppression flag unless you deliberately map it. And the FCC's Reassigned Numbers Database, live since November 2021, gives you a safe-harbor defense if you query it before dialing a number that may have changed hands.

> **Note:** The "revoke-all" rule is coming
>
> The FCC's provision that one STOP kills all message types from a company is delayed to January 31, 2027. Build for it now: treat a revocation on any channel as evidence to review that person's status across every channel, rather than scoping it narrowly.

## A copy-paste record and a pre-launch checklist

Below is the field skeleton I use for a suppression entry. Adopt the field names to your stack, but keep every field: each one answers a question a regulator or a teammate will ask.

**Suppression record skeleton**

```
person_id:            <normalized internal ID>
email:                <lowercased>
phone_e164:           <+countrycode...>
social_handles:       <comma-separated>
suppress_scope:       all | email | sms | voice | ads
consent_status:       opted_out | bounced | complained | resubscribed
reason_code:          unsubscribe | stop | reply | voicemail | webform | complaint | bounce
requested_by:         <recipient | agent | system>
source_channel:       email | sms | voice | web | crm | vendor
timestamp_utc:        <ISO 8601>
applied_to:           sequencer, crm/ats, dialer, sms, ad_audiences
jurisdiction_note:    <e.g. GPC signal / state UOOM, if applicable>
notes:                <free text, e.g. "STOP via email to shared inbox">
```

*One row per person. Keep every field; drop one and the record cannot prove itself.*

Before you call the sync live, run this checklist. It is the difference between a system that reports success and one that delivers it.

#### Before you call the do-not-contact sync live

- [ ] Every opt-out channel - STOP, unsubscribe click, reply, voicemail, web form - writes to one intake queue.
- [ ] Non-SMS opt-outs are processed, not just the STOP keyword.
- [ ] Identifiers are normalized so one person is one record across email, phone, and social.
- [ ] The suppression record carries timestamp, channel, source, scope, reason code, and where applied.
- [ ] Suppression state is pushed to the sequencer, CRM/ATS, dialer, SMS platform, and ad audiences.
- [ ] Sends and audience builds use a pre-send lookup, not a nightly or weekly batch.
- [ ] Opted-out contacts are suppressed, never deleted, so the record survives future imports.
- [ ] Suppressed IDs are excluded from every enrichment refresh automatically.
- [ ] Every new import and audience is screened against the current suppression list before it ships.
- [ ] The internal DNC list is mapped separately, and numbers are checked against the Reassigned Numbers Database before dialing.
- [ ] You can produce timestamped proof of opt-out for any contact on demand.

## Keeping the sync honest over time

A suppression sync is not a project you finish; it is a control you maintain, because new tools, new teammates, and new imports keep testing it. The single highest-value maintenance habit is sampling campaign audiences before send and reconciling opt-out records against deletion logs on a monthly or quarterly cadence. That is how you catch the billable-count workaround, the enrichment re-hydration, and the well-meaning colleague's fresh CSV before any of them sends a message.

Re-check the legal windows on a schedule rather than assuming they hold. The state UOOM count moves, quiet-hour windows tighten, and the FCC's revoke-all provision lands on January 31, 2027. Watch the mechanism, not a snapshot: subscribe to your privacy counsel's updates and re-confirm the strictest window your program operates under each quarter.

Finally, treat every new tool as a subscriber to the list, never as a new owner of opt-out state. When you add a dialer, an ad platform, or a sourcing tool, wire it to read the authoritative record before it can send or build an audience. The whole point of one suppression list is that it survives the next tool, the next hire, and the next import. Build it so that an opted-out person is never contacted again, no matter who tries.

## Frequently asked questions

### How do I sync opt-outs across tools when they live in the sequencer but the CRM keeps re-adding people?

Make the suppression list the source of truth, not the sequencer. Capture every opt-out into one intake, write a persistent suppression record, then push that state back to the CRM, ATS, dialer, and ad audiences so no tool holds a private copy. The most common break is a per-tool opt-out that other systems overwrite on the next sync, so the record must persist and every sender must read it before sending.

### How fast do I legally have to honor an opt-out across email, SMS, and phone?

CAN-SPAM requires honoring email opt-outs within 10 business days, and the FCC's TCPA revocation rule requires the same 10-business-day window for calls and texts. Because the two now align, one honor-within-10-business-days SLA can govern the whole stack. Best practice is immediate suppression rather than waiting the full window, since any message that fires in between can be a separate violation.

### Is deleting an opted-out contact the same as suppressing them?

No, and treating them as the same is the most common silent breach. Deletion removes the record's memory, so the next import, sync, migration, or CSV upload puts the same address back and the old unsubscribe returns months later. Keep a persistent suppression record that survives deletion so every future upload can be screened against it.

### Do I need to honor an opt-out sent by email if it came through my SMS program?

Yes. Since April 11, 2025, the FCC requires honoring revocation through any reasonable method, so an emailed or spoken opt-out for an SMS program must be processed. In one documented case, 14 texts sent after an emailed opt-out counted as 14 separate TCPA violations. Route non-keyword channels into the same intake queue as STOP replies.

### Should I build per-state quiet-hour logic or use one window?

Most practitioners adopt the single strictest window across the whole program rather than segmenting by state, because it is simpler to operate and easier to audit. Federal TCPA sets 8am to 9pm local time; Florida, Oklahoma, and Washington require 8am to 8pm, and Texas restricts Sunday marketing texts to noon to 9pm. Applying the tightest window everywhere removes an entire class of routing errors.

### Why do opted-out contacts keep coming back after enrichment?

Enrichment refreshes re-hydrate records from external sources, and if suppressed IDs are not excluded from those jobs, the contact re-enters your addressable set. Contacts who have opted out or requested deletion must be excluded from enrichment refreshes automatically. Run the suppression screen before any enrichment export, and verify suppressed IDs are on the exclusion list for every scheduled refresh.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/guides/do-not-contact-sync-suppression-list*
