Marketing, utility or authentication: picking a category
What each WhatsApp template category is for, how Meta enforces the choice against your actual content, and why a mismatch stalls or breaks a campaign.
· 5 min read
The category is a declaration, and it is checked
When a template is submitted, the business declares a category for it. That declaration is not a filing convenience or an internal label. It determines the consent the business needs before sending, the rate the message is billed at, and the restrictions the content must satisfy. Meta then checks the declaration against what the template actually says.
There are three categories a template can be submitted under: marketing, utility and authentication. Service messages are often mentioned alongside them and are a different thing entirely — free-form replies sent inside an open customer service window, which are not templates and are not submitted for approval. Keeping service separate in your head avoids a lot of confusion, because it is the one case where no template and no category is involved.
The reason the check exists is that the categories carry different obligations. If a business could route a promotional message through the transactional category, the consent requirement attached to marketing would be trivially avoidable. So categorisation is enforced against content, both at review and afterwards through ongoing monitoring.
Utility: tied to something the customer already did
A utility template relates to an existing transaction or an arrangement the customer has already entered into. Order confirmations, dispatch and delivery updates, appointment reminders, payment receipts and account notices are the archetypes. The defining test is not tone or format but whether the message follows from something the customer already did, and whether they would recognise it as a consequence of that action rather than as an approach from a business.
Utility messages are the workhorse of most small-business WhatsApp usage, and for good reason. They are genuinely wanted, so they attract few complaints. They correspond to moments the customer cares about. And because they follow from a transaction, the consent position is far simpler than it is for marketing.
The most common way a utility template goes wrong is accretion. A confirmation gets a discount code added, or a delivery update gains a line about a sale. Each addition seems small and each pushes the message toward marketing. The message that results is a promotional send carrying a transactional label, which is the exact pattern the categorisation check is built to catch. Splitting it — a confirmation that only confirms, and a separate marketing template for the offer — keeps both messages honest and both categories clean.
Marketing: anything intended to sell, and the consent it needs
Marketing covers anything promotional: a sale, a new arrival, a restock alert, a re-engagement nudge, a cart reminder, an invitation to buy again. If the purpose of the message is commercial rather than informational, it is marketing, regardless of how conversational the wording is.
Two consequences follow. Marketing requires opt-in from the recipient for marketing specifically, and consent given for one category does not transfer to another. Someone who agreed to receive delivery updates has not agreed to receive promotions, and treating a transactional consent record as blanket permission is a policy violation even though the number was collected legitimately. Marketing also sits at the higher end of the rate structure, so the same recipient list costs more to reach with a promotion than with a confirmation.
Marketing is also where account risk concentrates. Promotional messages to people with a weak or absent relationship to the business are what produce blocks and reports, and those feed the quality signals that decide how many people the business is allowed to message at all. This is the practical argument for restraint that has nothing to do with policy compliance: the cost of an unwanted marketing send is not only the message fee but a share of future reach.
Authentication: codes, and deliberately nothing else
Authentication templates deliver one-time passcodes and verification codes. The category is narrow on purpose and carries the strictest content rules of the three: no URLs, no media attachments, no emojis, and a tight character limit on any parameter.
These restrictions routinely surprise businesses that are trying to be helpful. A verification message that includes a link back to the app, or a reassuring line about what to do if the code did not arrive, will be rejected on format grounds rather than assessed on intent. The restriction is enforced automatically, so there is no version of the argument that the extra content improves the experience.
The reasoning is defensive. Passcode messages are among the most heavily abused message types anywhere, because a convincing verification message is the core of most account-takeover attempts. A category that structurally cannot contain a link is far harder to weaponise. A business that finds the constraints frustrating is running into a rule that exists to protect its customers from people impersonating it, which is a rule worth having.
How a mismatch actually surfaces
A miscategorised template fails in one of two ways, and the second is worse. The visible failure is rejection at review, recorded as a categorisation mismatch. That costs a review cycle and is annoying, but it is a contained problem discovered before anything was sent.
The expensive failure is a template that gets through review and is caught later. Meta monitors categorisation on an ongoing basis, and a business that repeatedly routes promotional content through the utility category risks escalating restrictions on its ability to send utility messages at all. That is a serious operational problem, because utility messages are usually the ones the business cannot do without — the confirmations and reminders customers actively rely on. Trading a small saving on marketing rates for the possibility of losing transactional messaging is a bad exchange even on purely commercial terms.
Meta may also recategorise a template rather than reject it, which changes the consent required and the rate charged. A business that assumed a message was utility can find it billed and governed as marketing, so the category a template is operating under is worth checking rather than assumed from what was submitted.
A test that settles most category questions
When a category is genuinely unclear, one question resolves most cases: would this message still need to be sent if the business had nothing to sell right now? A delivery update would. A restock announcement would not. The first is utility, the second is marketing, and the test works because it isolates whether the message serves an obligation to the customer or an objective of the business.
A second, blunter check helps with the accretion problem: read the template and ask what would be lost by deleting the last sentence. If the answer is "the offer", the message is doing two jobs and should be two templates. If deleting it removes information the customer needs, it belongs where it is.
When the answer is still ambiguous, declaring the stricter category is the safer error. Submitting as marketing something that might have qualified as utility costs slightly more per message and requires marketing consent. Submitting as utility something that was really marketing risks the categorisation-enforcement problem that can affect transactional sending. The asymmetry is not close, and it points in one direction.
Common questions
How do I decide between utility and marketing when a message does both?
Treat that as a sign it should be two templates. Ask whether the message would still need sending if you had nothing to sell right now: if yes, the informational part is utility; the part that fails that test is marketing. Splitting them keeps the confirmation deliverable to everyone who transacted, and sends the offer only to people who opted in to marketing.
Can I send a marketing template to someone who gave me their number at checkout?
Not on that basis alone. Consent is category-specific. A number provided to complete a purchase supports transactional messages about that purchase; it is not marketing opt-in. You need consent for marketing specifically, captured in a way you can evidence, along with a record of when it was given and what it covered.
Why can't my one-time passcode template include a link?
Authentication templates prohibit URLs, media and emojis, and the rule is applied automatically rather than judged case by case. The category is deliberately narrow because verification messages are a favoured tool for impersonation, and a message type that structurally cannot carry a link is much harder to abuse against your own customers.
What happens if Meta disagrees with the category I chose?
Either the template is rejected with a categorisation mismatch, or it is recategorised, which changes the consent you need and the rate you pay. Repeated miscategorisation can escalate to restrictions on your utility sending. Because that affects the confirmations and reminders customers depend on, the safer error when a category is ambiguous is to declare the stricter one.