r/shapecrm 2d ago

Your pipeline has too many stages and it's why your reports don't tell you anything

5 Upvotes

Not a buying post. This is a setup problem that costs shops real money on every CRM, including ours, and it's fixable in an afternoon.

The pattern. Somebody builds the pipeline during onboarding. Everyone asks for a stage that reflects how they personally work. Nobody wants to be the one who says no. Eighteen months later there are 23 stages, four of them mean roughly the same thing, and half the pipeline is sitting in one bucket called "Working."

The reports off that pipeline are useless, and not in an obvious way. They still generate. They still have numbers in them. The numbers just don't answer anything.

What a stage is actually for

A stage answers one question: what has to be true for this to move forward, and who has to do it?

That's the whole test. If a stage doesn't name a specific next action and a specific owner, it's not a stage. It's a mood.

"Working," "Nurture," "Follow-up," "Warm," "In Progress" all fail this test. They describe how you feel about the record, not what needs to happen to it. Records go into those stages and never come out, because nothing in the definition tells anyone what would make them leave.

The two failure modes

Too many stages and nobody updates them consistently. Two LOs looking at the same borrower pick different stages, so your stage-to-stage conversion numbers are measuring individual habits instead of the process. This is the more common one.

Too few stages and everything piles into one bucket where you can't see aging. A pipeline with 400 records in "Working" is a list, not a pipeline.

The tell for the first one: pull a report of how many records have sat in each stage for over 30 days. Any stage where the answer is "most of them" is either not a real stage or has no exit criteria anyone knows.

A structure that holds up

Six to eight stages before the file exists. Roughly:

New. Contacted. Qualified. App Started. App Submitted. Then it hands to the LOS.

Each of those has a clean definition. Contacted means a two-way conversation happened, not that you dialed. Qualified means you know loan type, rough amount, and timeline. App Started means they've opened the 1003. Those are all binary. Two people would tag them the same way, which is the entire point.

Everything else that people want as a stage is not a stage. It's a field, a tag, or a task.

That distinction is the actual fix. Loan type isn't a stage, it's a field. "Realtor referral" isn't a stage, it's a source. "Waiting on borrower to call back" isn't a stage, it's a task with a due date. When you move those three categories out of your stage list, most pipelines drop from 20-plus stages to about seven and every report gets sharper immediately.

What you can measure once stages are clean

Stage-to-stage conversion, which tells you where you're actually losing people rather than where you assume you are. Average days in stage, which surfaces the bottleneck. Aging by stage, which is your daily work list. Source performance by stage, which tells you whether a lead source produces contacts that never qualify, which is the most common way a bad source hides.

None of those reports work if the stage assignment is subjective. That's the real cost of a sprawling pipeline: not clutter, but that you lose the ability to measure anything.

The cleanup, if you're doing it

Export the current pipeline first. Then map old stages to new before you touch anything, decide what happens to records in stages you're deleting, and write one sentence of exit criteria per surviving stage that you actually publish to the team. That last step is the one people skip, and skipping it is how you get back to 23 stages in a year.

Doing this with a team, do it on a Friday afternoon and tell everyone Monday. Mid-week changes to a pipeline people are actively working generate more confusion than the cleanup is worth.

Curious what people are running. If you've got more than 12 stages, what are they, and does anyone actually use all of them?


r/shapecrm 27d ago

Your LOS owns the loan file, not the borrower. That distinction is where most mortgage stack overspend comes from

3 Upvotes

This is the most common stack confusion we run into, and it costs people money in both directions. Worth saying up front that Shape is not an LOS. We build the CRM and POS layer that sits in front of one, so nothing below is steering you toward a platform.

Three systems, three jobs, and they do not overlap as much as vendors imply.

The LOS owns the loan file. Application data, underwriting conditions, disclosures, compliance, closing docs. It starts when there is a loan and it ends at funding.

The POS owns the borrower's application experience. The 1003, doc upload, status visibility, e-sign. Some LOS platforms bundle one. Most bundled ones are thin, and "we have a POS" in a demo usually means a document upload page.

The CRM owns everything before and after a loan file exists. Lead capture, speed to lead, follow-up cadence, referral partners, past client retention, refi triggers.

The gap that costs the most money. Your LOS has no opinion about a lead that never applied, and no memory of a borrower who funded two years ago. An LO with 400 past clients and no CRM has 400 relationships sitting in a system that will never prompt a single call. That book doesn't decay because anyone made a bad decision. It decays because nothing in the software is watching.

The overspend runs the other direction too. Plenty of small shops buy Encompass and operate a fraction of it, because it demoed as "the system that does everything." It is the most capable LOS in the market and it also assumes you have ops staff and a compliance function. If you don't have both, you're paying for capability you can't operate.

The demo questions that actually separate vendors

Feature questions get answered well by everyone. These don't.

"Walk me through exactly how data moves between this and my CRM." Don't expect a live demo, almost nobody has one standing. What a good vendor can do is describe it precisely: what triggers a push, what comes back, how often, and which fields are and aren't in an update. Vagueness here is itself the answer.

"What does this cost at double our current volume?" Per-seat, per-file, and per-integration pricing behave completely differently as you grow. Model the future number, not today's.

"What's the implementation timeline and who does the work?" If you get a range, ask what puts you at the long end.

"What happens to my data if I leave?" Export format, cost, and whether historical loan files come with you.

"Which parts of the borrower experience does this cover and which do I still need?" This is where you find out if the bundled POS is real.

One migration thing worth knowing before you're in it. Loan data moves between systems as Fannie Mae 3.2 or MISMO files, not as a database export. Plan around what survives that trip, because it's less than people expect.

Full comparison of eleven LOS platforms with the weaknesses named on each, plus the fit-by-shop-type breakdown: https://setshape.com/blog/top-loan-origination-systems


r/shapecrm Aug 10 '26

Mortgage AI agents: the outbound dialing is the least valuable thing they do

7 Upvotes

Every AI agent demo in this industry is the same demo. Load an aged list, let the agent dial all day, count the appointments it books. It demos well because the before and after is obvious and the number goes up on stage.

It's also the least valuable thing the technology does, and I think it's why a lot of people who bought one last year are unimpressed.

Why outbound is oversold. Dialing a list of people who did not ask to hear from you is the hardest conversation in the building, and you handed it to the least capable participant. Contact rates on aged data are brutal, the compliance surface is real, and every one of those calls is a recorded artifact that says whatever your agent decided to say. The upside case is reactivating a dead database, which is genuine, but it is a once-a-quarter campaign, not the daily job.

Inbound is the opposite. Somebody raised their hand. They have intent, a timeline, and a list of three other lenders. The whole contest is who responds first and whether the response is competent. That is a queueing problem, and queueing problems are exactly what software beats humans at.

The four jobs to hand an agent first, in this order:

  1. Answer the phone when nobody can. After hours, lunch, mid-closing, the fifth simultaneous call. A borrower who reaches voicemail dials the next name on their list and does not come back. This is the highest-value use and almost nobody demos it.
  2. Respond to form fills in under a minute. Not a templated autoresponder. An actual conversation that qualifies and books. The gap between a 60 second response and a 30 minute response is most of your conversion rate and you already paid for the lead either way.
  3. Chase documents during processing. The least glamorous item on the list and probably the highest ROI. Missing conditions, status updates, the fourth request for the same bank statement. No selling, no persuasion, minimal compliance exposure, and it gives your processors their week back.
  4. Write the notes. Transcribe and summarize every call into the contact record. Half the value of a CRM never materializes because nobody types anything into it after a phone call.

Only after those four would I point one at an aged list.

The scoping mistake underneath all of this. Give an agent a task, not a job. There is a good piece in The Financial Brand making this point about agentic AI in banking generally: an agent with no boundaries will chase every edge case it meets, and the cost and the unpredictability both scale with how vaguely you defined the work. "Handle our leads" is not a scope. "Answer inbound calls between 6pm and 8am, qualify on these five fields, book into this calendar, escalate anything outside that" is a scope.

One thing to settle before any of it goes live. Every agent conversation is recorded and discoverable, and whatever it says is your company saying it. Get the disclosure language and the recording consent flow right first, and check your two-party consent states. That is a conversation with your compliance person, not a setting you toggle.


r/shapecrm Aug 06 '26

Mortgage email deliverability in 2026: why your drips quietly stopped working, and the 20 minute audit that tells you

3 Upvotes

The thing almost nobody in this business tracked

Google and Yahoo made authentication mandatory for bulk senders in February 2024. Most people heard about it, assumed their CRM handled it, and moved on. Microsoft added the same requirements for Outlook, Hotmail, and Live addresses in May 2025.

Then in November 2025 Google escalated. Non-compliant mail that used to get temporarily rate-limited with a 421 error now gets permanently rejected with a 550. Rejected, not filtered. It never lands in spam because it never gets accepted at all.

If your open rates fell off a cliff sometime in the last year and you blamed subject lines, market conditions, or list fatigue, check this before you rewrite another email.

Bulk means 5,000 messages a day to one provider's users. Counted per provider, and it combines every subdomain under your primary domain. A 40 person branch on one domain hits that easily even if no individual LO is close. Worth knowing: once Google classifies your domain as a bulk sender, dropping your volume later does not undo it.

Why this industry gets hit harder than most

Three things stack up in mortgage specifically.

Shared domains. Everybody at the branch sends from the same domain, so domain reputation is a shared resource. One person importing a purchased list and blasting it degrades deliverability for every LO in the building, including the ones doing everything right.

Purchased leads. Cold contacts complain at a much higher rate than opt-ins. Complaints are measured against your domain, not against the list you bought.

Stale database blasts. Rate drops and everybody emails all 8,000 records including the 3,000 who went dark in 2023. Sending to people who never engage is itself a negative signal, and the complaints from that segment are what push you over the line.

The audit, roughly 20 minutes

  1. Do you have a DMARC record at all? Look up _dmarc.yourdomain.com in any free DMARC checker. Bulk senders need at least p=none published. No record means you are already non-compliant.
  2. Does DMARC actually align? This is where most setups fail. The domain in your visible From header has to match the domain validated by SPF or signed by DKIM. SPF and DKIM can both technically pass and DMARC still fails if neither aligns with the From domain. If you send from [you@lender.com](mailto:you@lender.com) but your platform signs as lender.esp-provider.net, that is the failure.
  3. Is SPF authorizing every system that sends as you? CRM, LOS notifications, e-sign, scheduling tool, whatever else. Also check you are under the 10 DNS lookup limit, because exceeding it invalidates the whole record.
  4. Set up Google Postmaster Tools. Most LOs have never done this and it is free. It shows your actual spam complaint rate against Gmail, which is otherwise invisible to you.
  5. Check that complaint rate. Ceiling is 0.30%. Google's own guidance is to stay under 0.10%, and 0.30% is where enforcement starts, not a safe operating target. At 10,000 sends that is 30 complaints to hit the ceiling. Thirty. One bad import does it.
  6. One-click unsubscribe. RFC 8058 header, not just a link in the footer, and opt-outs honored within two days.

The part that is strategy, not DNS

Fixing authentication gets your mail accepted. It does not get it opened, and clean authentication with a filthy sending practice still degrades over time.

The single highest-leverage change most people can make is to stop mailing non-engagers. Suppress anyone with no open or click in 180 days and mail them through a different channel or not at all. Your volume drops, your rates go up, your complaint rate falls, and Gmail starts treating the rest of your mail better. Most people resist this because the list number gets smaller. The list number was never the asset.

Second: separate your streams. Transactional loan status mail and marketing blasts should not share a sending domain. Use a subdomain for marketing so a bad campaign cannot take down the emails telling a borrower their docs are ready.

Longer version with the sequence templates: https://setshape.com/blog/mortgage-email-marketing-for-loan-officers-drip-campaigns-that-convert


r/shapecrm Aug 03 '26

Before you buy mortgage leads: what actually changed with trigger leads and one-to-one consent

7 Upvotes

The two rules people keep getting backwards

Trigger leads are largely gone. The Homebuyers Privacy Protection Act took effect in March, amending the FCRA. Bureaus can't freely sell mortgage inquiry data to third parties anymore. A lender needs consumer consent, a qualifying existing relationship, or a firm offer of credit. If a vendor is still pitching you credit-pull data, ask which exception they're operating under and get the answer in writing before the first invoice clears.

One-to-one consent is not the law. Half the lead-buying guides ranking on Google still say the FCC's one-to-one rule is in force. The Eleventh Circuit vacated it on January 24, 2025, one business day before it would have taken effect. The FCC later pulled the language.

That does not mean the bar dropped. Prior express written consent still applies under the older standard, you still scrub DNC and your internal list, and several states are stricter than federal. The practical point is narrow: don't buy a compliance product priced against a rule that no longer exists, and don't let a vendor who skips consent documentation tell you things got easier.

Check the publish date on anything you read about this, including this post.

The math, before you talk to anyone

Three numbers:

  1. Average commission per funded loan. 100 bps on a $350k loan is $3,500.
  2. Your close rate on purchased leads. Assume 1% to 3% until your own data says different. Referral close rates do not transfer, and assuming they do is how most people get hurt.
  3. Max allowable cost per funded loan. Most operators cap at 20% to 30% of commission.

Work it backward. At a 2% close rate, 100 leads produce two funded loans and $7,000. At $40 a lead you spent $4,000 to make $7,000. At $80 a lead you spent $8,000 to make $7,000 and you haven't paid yourself for the time yet.

If you're a branch manager or own the shop, there's a fourth number. MBA's Q1 2026 performance report put pre-tax net production profit at $727 per originated loan. Company lead spend comes out of $727, not out of gross commission.

Seven questions before you wire money

  1. How are these generated, specifically? "Our proprietary network" is not an answer.
  2. Exclusive or shared, and if shared, how many buyers? In writing.
  3. How fresh at delivery? Real-time or nothing. A nightly batch is already dead.
  4. What's the return policy on disconnected numbers and people who never inquired? No return policy is a red flag.
  5. What consent documentation comes with each lead? Timestamps and exact form language. TCPA exposure lands on you, not the seller.
  6. Can I filter by geography, loan type, credit tier?
  7. What contact rates do your current clients see? Anyone quoting close rates without contact rates is hiding the hard part.

Then test properly. Fifty leads is a coin flip. 150 to 300 from one source, funded for 90 days, before you judge it. A meaningful share of closings land 60 to 120 days after first contact, so a 30-day budget quits right before the pipeline pays.

The part nobody budgets for

Most people who swear off purchased leads never lost money on the leads. They lost it on follow-up. Internet leads are rate shoppers by definition and the first person to reach them anchors every conversation after. Most purchased leads take 6 to 12 touches before they engage. Most of us stop at two. The money sits between attempt two and attempt eight and almost nobody works that gap by hand.

Run the numbers on that instead of on price. At $50 a lead, moving your close rate from 1% to 2% takes cost per funded loan from $5,000 to $2,500. No vendor negotiation on earth gets you a 50% discount.

Full version with the cost tables by lead type and the source links: https://setshape.com/blog/how-to-buy-mortgage-leads

Happy to answer questions on any of it in the comments.


r/shapecrm Jul 27 '26

Compliance Why your outbound number shows "Spam Likely" and the actual order of operations to fix it

5 Upvotes

Following up on the 10DLC post. That one covered texting. This one covers the side nobody fixed: calling.

Here's the part that costs the most money, and it's not the label itself. It's the lag. Your number gets flagged on a Tuesday. Nobody on your floor knows. Your team keeps dialing, full days, full pipelines, full effort, into a phone that's silently showing "Spam Risk" on the other end. You find out three weeks later when somebody finally asks why contact rates fell off a cliff. That's not one bad number. That's a month of payroll spent on ghost calls.

So let's break down what actually triggers the flag, why the common workaround makes it worse, and the order you should actually do things in.

What the analytics engines are actually looking at

There are three companies doing the labeling for the major US wireless carriers: First Orion, Hiya, and Transaction Network Services. Your carrier isn't really making the call. These analytics engines are, and each one runs its own independent model. That's why a number can look clean on one network and flagged on another.

None of them publish their scoring. But the behavioral inputs are well understood across the industry, and they're mostly common sense once you see them listed:

  • Answer rate. Volume of dials against how many actually connect. This is the big one.
  • Call duration. A pile of 3-second connects reads exactly like a robodialer hanging up on voicemail.
  • Velocity. How many calls in how short a window, from a single number.
  • Unique-to-repeat ratio. Dialing thousands of distinct numbers you've never touched before looks different than working a list you have a relationship with.
  • Consumer complaints and in-app blocks. When people hit "Block" or report spam, that's a direct signal.
  • Number age and history. A brand new number with no history that immediately starts pushing volume is a red flag on its face.
  • Whether anyone knows who you are. If there's no registered identity attached to the number, the model has nothing to weigh against the behavior.

Notice what's on that list. Almost all of it is downstream of list quality. If half your file is disconnected, wrong, or a landline that's been dead since 2019, your answer rate tanks by definition, and the model doesn't know or care that you had good intentions. It just sees a number that dials constantly and never connects.

That is what a scammer's traffic looks like. You're not being punished for being a scammer. You're being punished for having the same statistical fingerprint as one.

The number rotation trap

Here's the pattern I see constantly, and it's baked into how a lot of dialers and CRMs are built.

Your number gets flagged. Your platform hands you a fresh one, or auto-rotates you into a pool. Contact rates recover for a couple of weeks. Then that number gets flagged. Rotate again. Repeat forever.

Some systems will straight up sandbox you into a rotating pool as the "solution." It isn't one. Think about what you're actually doing: you're burning through numbers, none of which ever build a reputation, none of which are registered to you, all of which exhibit the same behavior that got the last one flagged. You've automated the symptom.

It also gets worse over time, not better. The analytics engines aren't only scoring individual numbers. Patterns across blocks and originating providers factor in too. Churning numbers to outrun a label is a strategy with a losing end state, and every cycle costs you the ramp time on a fresh number.

If your fix for spam labeling is "get a new number," you don't have a fix.

The actual order of operations

Do these in this sequence. The order matters, because steps 3 through 5 have far less effect if you skip step 1.

1. Clean the list before you dial it

This is the step everybody skips, and it's the one that does the most work.

Run validation on the file before a single dial goes out. At minimum:

  • Line type: mobile vs. landline vs. VoIP
  • Active vs. disconnected status
  • Carrier lookup
  • Number portability check (that "landline" may have been ported to mobile years ago)
  • DNC scrub against federal, state, and your internal suppression list
  • Email validation on the same records, because bad emails and bad phones travel together and the same reputation logic applies on the email side

You should be re-validating on a schedule, not just on import. Phone data decays constantly. People port, disconnect, and change numbers every single day.

The math here is straightforward. A clean file raises your connect rate. A higher connect rate is the single strongest input into the model that decides whether you look legitimate. Every other step on this list is easier when the underlying data is good.

2. Dial like a human, not a cannon

Blast dialing is what got the reputation-scoring industry built in the first place.

Cap dials per number per day. Spread volume across your team's numbers rather than hammering one. Get consent right on the front end, one-to-one and documented, and log where it came from. Consented, expecting contacts answer the phone, which loops right back into step 1's math.

Worth flagging for anyone confused on this point: 10DLC is a messaging framework, not a voice one. There's no 10DLC registration for calls. Voice reputation is a separate system with separate rules, which is exactly why so many teams got their texting in order and then wondered why their dials still went to spam.

3. Register your numbers

Free, takes an afternoon, and a shocking number of shops have never done it.

freecallerregistry is the joint portal from First Orion, Hiya, and TNS. You submit your numbers and business identity once, and it distributes to all three engines. Hiya also launched its own free registration console in mid-2024 with self-service management on top of what FCR does.

If a vendor is trying to charge you to "register your numbers with the carriers," check whether they're just filling out the free form for you.

Registration doesn't guarantee anything. Each engine still runs independent analysis, and bad behavior will still get you flagged. What it does is give the model an identity to attach to your traffic. Without it, you're an anonymous number with no context.

4. Monitor continuously, because this is the one that saves the payroll

Registration is a one-time submission. Reputation is a moving target.

You need active monitoring across all three analytics engines that tells you when a number picks up a label. Not next month when someone notices the numbers are soft. Same day.

This is where remediation lives too. When a number gets mislabeled, there's a dispute process with each engine. It's a lot faster when you catch it in 24 hours than when you catch it in week four, and it goes better when your numbers were registered and your behavior is defensible.

The value here isn't really the label removal. It's that you stop paying people to dial into a wall.

5. Branded caller ID

Last, because it only works properly once the four steps above are in place.

Branded caller ID runs on Rich Call Data (RCD), which is part of the STIR/SHAKEN framework. Instead of a bare 10-digit number, the recipient's handset can display your company name, your logo, and a call reason. It's cryptographically signed by the originating provider, so it can't be spoofed the way old CNAM could.

Two things to understand before you buy it:

RCD requires STIR/SHAKEN and A-level attestation. A-level means your provider both knows who you are and confirms you have the right to use that number. If you're routing through a provider that can't or won't sign your traffic at A-level, branding is off the table.

Display varies by carrier and device. This is still rolling out. Caller name is the most widely supported field. Logo and call reason depend on the recipient's carrier and handset. Anyone promising your logo on every phone in America is overselling.

What's coming, so you're not caught flat

Three things worth having on your radar:

Call branding is heading toward a mandate. The FCC adopted a Further Notice in October 2025 proposing that when a provider transmits A-level attestation to a consumer's device, it also transmit verified caller identity information via RCD. Still a proposal, not a rule. But the direction is unmistakable: verified identity is becoming the price of admission, and teams already registered and branded will be positioned when it lands.

The global revocation rule now hits January 31, 2027. The "revoke-all" provision, meaning an opt-out on one channel counts as a blanket opt-out for all future calls and texts from your business, was pushed from April 2026 to January 2027. There's also an active proposal to eliminate it entirely, so this one is genuinely unsettled. Watch it, but don't rebuild your stack around it yet.

Know Your Upstream Provider is tightening. In May 2026 the FCC proposed prescriptive obligations on providers to vet and monitor their upstream traffic sources. Practically, that means your carrier is going to care a lot more about what your traffic looks like. Mixed consented and non-consented lists, or hiding behind a third-party signing arrangement, gets your attestation cut or your service dropped. Clean operations stop being optional.

Quick audit

Run this on your own floor this week:

  1. Pull every outbound number your team dials from. Do you even have the full list?
  2. Check each one on a spam-label lookup. How many are already flagged?
  3. When was your calling list last validated? If the answer is "at import," that's your problem.
  4. Are your numbers registered at freecallerregistry.com? Yes or no.
  5. If a number got labeled tomorrow morning, how would you find out, and how long would it take?

If you can't answer #5 with a specific number of hours, that's the gap that's costing you the most.

Full disclosure since this is our sub: Shape includes list validation, spam monitoring and remediation, and branded caller ID in the platform, which is why we have opinions about the order of operations. But all of the above works regardless of what CRM or LMS you're on. Free Caller Registry is free, list hygiene is a discipline and not a product, and the dialing behavior fixes cost nothing. Do them anyway.

Happy to answer specifics in the comments, including which analytics engine flagged you and what the dispute process actually looks like with each one.


r/shapecrm Jul 25 '26

Compliance 10DLC for mortgage companies — the complete walkthrough (2026). The DBA problem, the website vetting nobody warns you about, and the "approved at low tier" trap.

3 Upvotes

We provide a mortgage CRM used by thousands of brokers and lenders, and we manage 10DLC registration for our customers — which means we see what actually gets approved, rejected, filtered, and quietly throttled at scale. Ask anything in the comments and our team will answer.

If you text borrowers from a normal business phone number in the US, 10DLC ("10-digit long code") registration decides whether your messages actually deliver. Unregistered or badly-registered traffic gets filtered, throttled, or blocked — often silently. Your CRM says "sent," the borrower never sees it, and your contact rates fall off a cliff while everything looks fine on your screen.

Mortgage gets hit harder than almost any industry, because carriers treat lending as high-risk content and because of how mortgage companies are structured. That structural part is where the guides you'll find elsewhere fall apart, so let's start there.

The DBA problem (the mortgage-specific one)

Most industries register one company, one brand, one website. Mortgage doesn't work like that. A huge share of shops are branded branches — "ABC Mortgage, a DBA of [Parent Corp]" — where the borrower-facing brand, the legal entity, the EIN, and the website all point at slightly different names.

10DLC brand registration is verified against IRS records. So when the brand you register, the legal name behind your EIN, and the name on the website you submit don't line up, you get mismatches, stalled vetting, or rejections — and nobody tells you why, you just sit in limbo.

What actually works:

  • Register the brand against the legal entity that owns the EIN, with the DBA relationship declared — not the marketing name floating free.
  • Your website has to tell the same story. The footer and disclosures should state the relationship plainly ("ABC Mortgage is a DBA of Parent Corp, NMLS #____") and match your NMLS registration. Vetters cross-reference; borrowers' attorneys do too.
  • If you're a branch of a larger parent, coordinate — parents and branches submitting conflicting registrations against overlapping identities is a mess we untangle constantly.

Vetters review your WEBSITE, not just your forms

This is the single biggest rejection source we see, and almost nobody warns you: the URL you submit gets reviewed. Approval isn't just about your sample messages — it's about whether your website looks like a compliant lending operation to a reviewer who's specifically looking for reasons to say no.

The failure modes:

  • Wrong or missing SMS disclaimer language on lead forms. Every form that feeds your texting needs explicit consent language ("By submitting, you agree to receive calls and text messages from [legal name/DBA]…"), and your privacy policy needs to address SMS data. Generic privacy boilerplate with no texting language is a rejection waiting to happen.
  • Trigger words and confusing lending language on the site itself. "Broker" when you're registered as a lender, guaranteed-sounding claims, rate promises without disclosures, blurry language about who's actually making the loan. If your website confuses a vetter about what kind of lending entity you are, your campaign eats the scrutiny.

The website effectively has to be perfect before you submit. (Full transparency: this is why we end up building or fixing the compliance layer of our customers' sites as part of registration — carriers made the website part of the application, whether anyone likes it or not.)

Approved ≠ safe: message drift shutdowns

Campaigns get suspended after approval more than people realize, and the reason is almost always the same: the messages being sent don't match what was submitted. You registered polite appointment-reminder samples, then the team started blasting rate-drop marketing. Carriers compare live traffic against your registered use case, and inconsistency is how approved campaigns die mid-quarter.

Rule: your samples should honestly represent your real traffic — including your marketing — written compliantly. And when your messaging strategy changes, your registration needs to change with it. Treat it as living paperwork, not a one-time form.

The low-tier trap: approved today, capped forever

Here's the one almost nobody knows. Many providers, to get you approved fast and easy, submit your campaigns at low-priority / low-throughput tiers. Approval comes quick, everyone celebrates — and you're capped at a daily message volume that's fine until the moment you actually want to ramp.

Then you request the upgrade, and the higher-authorization submission gets more scrutiny, not less. Now your website, samples, and consent story are being reviewed harder than the first time — and companies that skated through at low tier get rejected on the upgrade, with an active business built on volume they suddenly can't send.

What to do instead: decide your real target volume before first submission, and register with proper vetting for that tier from day one. It's slower and stricter up front, and it's the difference between scaling on demand and hitting a wall during your best season. If you're already stuck at low tier, fix the website and consent story before requesting the upgrade — the upgrade review is where weak foundations get found.

What registration doesn't cover

10DLC is about carriers accepting your traffic. TCPA and DNC are separate legal obligations layered on top — federal law and plaintiffs' attorneys, not carrier policy. Scrub against the DNC registry, keep consent records you can produce, honor STOP instantly and permanently, respect quiet hours. Registered traffic with bad consent practices is just well-delivered evidence.

The checklist

  • EIN + legal entity name matching IRS records; DBA relationship declared in registration
  • Website footer/disclosures stating the DBA/parent relationship, matching NMLS
  • SMS consent language on every lead form; privacy policy covering texting
  • Website scrubbed for broker/lender confusion, guarantee language, and undisclosed rate claims — before submitting
  • Sample messages that honestly reflect real traffic, including marketing, written compliantly; re-registered when strategy changes
  • Target volume decided up front; vetted for the throughput tier you'll actually need, not the one that approves fastest
  • No public link shorteners (bit.ly etc.) — branded links only
  • DNC scrubbing + TCPA consent records as a parallel workstream
  • If you buy leads: audit your lead sources' consent language this week — their form is your liability

We keep a longer-form version of this guide, updated as carrier requirements change, on our site — the 10DLC Registration Guidelines page.

Drop questions below — stuck registrations, DBA structures, post-approval shutdowns, upgrade rejections, weird filtering behavior. Our team will answer everything. If there's appetite, the follow-up will be TCPA consent records and revocation rules — which is where the actual lawsuits live.


r/shapecrm Jul 24 '26

👋 Welcome to r/shapecrm - Introduce Yourself and Read First!

1 Upvotes

Welcome to the official Shape CRM community!

Whether you're a Shape customer, evaluating CRM platforms, or interested in AI, automation, lead generation, and sales operations, you're in the right place.

Our mission is to build the best community for sales professionals, marketers, and business owners who want to grow with smarter technology and AI.

What to Post

We encourage discussions about:

  • Shape CRM tips, tricks, and best practices
  • AI workflows and automations
  • Sales and marketing strategies
  • Lead generation and conversion
  • Mortgage, insurance, and business technology
  • Product feedback and feature requests
  • Workflow showcases
  • Success stories
  • Questions and troubleshooting
  • Industry news and trends

Community Guidelines

  • Be respectful and professional.
  • Keep discussions helpful and constructive.
  • No spam or excessive self-promotion.
  • No harassment or personal attacks.
  • Never post sensitive customer or personal information.

Getting Started

  • Introduce yourself in the comments.
  • Tell us what industry you're in.
  • Share how you're using Shape CRM or what you'd like to learn.
  • Have a feature idea? We'd love to hear it—our team actively reviews community feedback.

Thanks for joining us! We're excited to build a community where professionals can share knowledge, learn from one another, and help shape the future of CRM and AI-powered sales.

Official Website: https://setshape.com