You bought a list of leads, maybe from a mortgage aggregator, a real estate lead platform, a solar co-op, or a Facebook campaign routed through a landing-page vendor. The vendor swears every name on it opted in. You start texting. Then one of them tells a lawyer they never filled out any form in their life.
Is the vendor's word enough to survive that? A federal court in Michigan just answered the question, and the answer should worry anyone whose entire consent record for a purchased lead lives in someone else's database, not their own.
What Happened in Dobronski v. Rocket Mortgage
Mark Dobronski says he got roughly twenty single-ring, dropped calls from Rocket Mortgage in August 2025. When he called the number back, an agent told him Rocket had been trying to reach him about refinancing. He told them his number was on the Do Not Call registry and to stop. He says a call and a text came anyway the following month, and he sued.
Rocket moved to compel arbitration, pointing to a clause buried in the terms of an online mortgage-inquiry form. Its business records showed a form submitted under the name "Testq Testing," using Dobronski's phone number, from an IP address the company's records tied to a residence in Ann Arbor. Dobronski filed a sworn declaration denying all of it: he never submitted the form, never authorized anyone to submit it on his behalf, never used that IP address, and had no connection to the Ann Arbor address it traced to, which turned out to be a Humane Society, not a house.
In Dobronski v. Rocket Mortgage, LLC, No. 25-12798, 2026 WL 2296669 (E.D. Mich. Aug. 10, 2026), the court sided with Dobronski on this narrow point: a company's clean-looking business records aren't self-proving. A consumer's sworn denial is evidence too, and here it was enough to create a genuine factual dispute over whether Dobronski himself ever agreed to anything. The court froze the rest of the case and limited discovery to one question: did Dobronski, or someone authorized to act for him, actually submit that form.
Why This Isn't Just an Arbitration Problem
The ruling turned on whether an arbitration agreement was ever formed, not on the underlying calls and text. But the evidentiary gap is identical either way. Prior express consent is an affirmative defense. The sender has to prove the consumer agreed, not the other way around. If a company can't establish that the person on the other end of the line actually submitted the form that supposedly generated consent, an IP address and a name typed into a web form don't close that gap. Neither does a vendor's contractual promise that the lead was "TCPA compliant," because that promise isn't evidence of what the actual consumer did.
This exposure isn't limited to purchased mortgage leads. Real estate brokerages are seeing the same pattern from the calling side: in Cribier v. Compass, Inc., 2026 WL 2280654 (S.D. Cal. Aug. 7, 2026), a federal court let a plaintiff amend an existing Do Not Call class action to add a second theory over prerecorded calls, a category of violation that isn't subject to the bona fide error defense and carries the same statutory exposure as any other TCPA claim. Courts are letting these cases widen, not narrowing them.
The One-to-One Consent Rule Is Dead. "Provable" Isn't.
Some of the confusion here traces back to a rule that no longer exists. In December 2023 the FCC adopted a "one-to-one consent" requirement that would have limited a single lead-form consent to the one specific company named on that form, killing the practice of one lead generating outreach from a dozen buyers off a single checkbox. The rule never took effect. The Eleventh Circuit vacated it on January 24, 2025, three days before it was due to take effect, holding the FCC had exceeded its authority under the TCPA's actual text. The FCC formally conformed its rules to that decision in an order released July 14, 2025 and published in the Federal Register that August, reinstating the prior, broader consent standard.
Practically: a shared lead, meaning one consumer's consent supporting outreach from several sellers off the same form, is legal again in 2026, the same way it was before 2023. That part of the lead-buying model survived. What Dobronski shows is that the fight has moved one step earlier. It's no longer just about whether one consent record can cover multiple sellers. It's about whether you can prove there was ever a real consent record at all, tied to a real person, at a specific place and time. A rule vacated in Atlanta doesn't help you in Michigan if you can't put a name to an IP address.
What Actually Counts as Proof
A timestamp, a name field, and an IP address are the minimum a lead vendor hands over, and per Dobronski, the minimum is not enough once a consumer swears under oath they didn't do it. What tends to hold up better:
- A retained, replayable record of the actual submission. Not just a database entry claiming one happened, but something that captures the session itself (screen activity, form field entries, timestamp) so it can be reproduced later. Third-party certification services like TrustedForm exist specifically to create this kind of independent record at the moment of capture; if your lead vendor can't produce one, ask why.
- Device and session data beyond IP address alone. The court in Dobronski noted the IP geolocation Rocket relied on didn't even point to a plausible address for the consumer. It pointed to an animal shelter. IP address by itself proves a request came from somewhere on that network, not that a specific person typed it.
- A documented chain from the original consumer action to your specific outreach, especially if you didn't collect the lead yourself. If you bought the list, you inherited the consent problem along with the phone numbers. Get the vendor's underlying proof, not just their assurance.
- Immediate honoring of any stop, revoke, or dispute. None of the above matters much if you keep texting someone who's already told you to stop. 47 U.S.C. § 227 sets statutory damages at $500 per violation, $1,500 if the violation is found willful, and courts generally count every individual text or call as a separate violation, not every phone number or campaign.
None of this is legal advice, and nothing here substitutes for your own counsel reviewing your specific lead sources. It's a description of what one court, on one record, found insufficient, and a reasonable floor to build above.
Where Android Texter Fits, and Where It Doesn't
Android Texter routes messages through a user-owned Android phone as person-to-person SMS, not through the A2P 10DLC carrier pipeline that Twilio and similar aggregators use. That matters for lead-gen operators specifically because A2P 10DLC campaign vetting routinely blocks or throttles lead-generation and real-estate-adjacent traffic regardless of whether the underlying consent is solid. The carrier gate doesn't know or care about your TrustedForm certificate. P2P routing through a real handset doesn't add that second layer of approval on top of the TCPA.
What it doesn't do is verify your leads for you. Android Texter has no visibility into where a phone number came from or whether the person on the other end ever filled out a form, and it doesn't claim otherwise. The channel being open doesn't change who has to prove consent if a recipient disputes it. That responsibility sits with the operator, the same as it would with any provider. If you can't currently produce a record like the ones described above for a given list, that's worth fixing before the first message goes out, not after a demand letter arrives.
Frequently Asked Questions
Does a lead vendor's "TCPA compliant" guarantee protect me if I get sued?
No. A contractual promise from a vendor might give you grounds to seek indemnification from them later, but it isn't evidence of consent in your own defense. Courts look at what the actual consumer did, not what your vendor's terms of service claim happened. Get the underlying proof, not just the assurance.
Is the one-to-one consent rule still in effect in 2026?
No. The Eleventh Circuit vacated it in January 2025 before it ever took effect, and the FCC formally removed it from its rules in mid-2025. A single consumer consent can again support outreach from multiple sellers, provided the underlying consent itself is real and documented.
What is TrustedForm, and do I need it?
TrustedForm is a third-party service that creates an independent, timestamped, replayable record of a lead form submission at the moment it happens. It isn't the only option, but if your current lead source can't produce something comparable when asked, that's a gap worth closing before you rely on that list for outbound texting.
Does using Android Texter reduce my TCPA exposure?
No, and we don't claim it does. Android Texter changes which carrier-level gate your messages pass through (P2P instead of A2P 10DLC), not what the TCPA requires. Consent, documentation, and honoring opt-outs are the operator's responsibility regardless of which channel sends the message.
What should I do if a lead I texted claims they never opted in?
Stop texting that number immediately and pull whatever consent record you have for it. If the record doesn't hold up to the standard a court applied in Dobronski (a real, attributable, timestamped submission rather than just a database row), treat it as a live legal exposure and talk to counsel before any further contact with that number.
Bottom Line
A purchased lead list is only as good as the weakest link in its consent chain, and as of this ruling, courts are willing to let consumers challenge that chain directly under oath. If you're buying leads to text through Android Texter or any other channel, the open carrier gate isn't the part that needs shoring up. The paper trail behind the leads is.
