New WhatsApp API Number Restricted? Check the Chain First

New WhatsApp API Number Restricted? Check the Chain First

A brand-new WhatsApp API number can be restricted before it sends a single blast. Meta can judge the whole business behind it. Here is how to find the layer.

Siti NabilahSiti NabilahGeneral
2 Oct 26
14m
Part of the series:WhatsApp Automation for Malaysian Businesses: The Complete 2026 Guide

A brand-new WhatsApp number can be restricted right after official WhatsApp API onboarding because Meta does not judge the number on its own. It can look at the whole chain behind it: your Meta Business Portfolio, your WhatsApp Business Account (WABA), your business details, your display name, your templates, how you message, and how customers react. The number is new. The business environment it plugs into usually is not.

So the first job after a restriction is not buying another SIM. It is finding which layer was actually restricted, and fixing that layer.

Key Takeaway

Meta can restrict a freshly connected WhatsApp number because it evaluates the business environment around it, not the SIM card. A restriction can sit at the Business Portfolio, the WABA, the phone number, a template or the messaging behaviour, and swapping the number only helps when the number itself was the problem. Official API access gives you a legitimate channel with rules; it does not make any number, on any provider, ban-proof.

Why would Meta restrict a WhatsApp number that has never sent anything?

Because from Meta's side, a number is only the last link in a longer chain. When you onboard to the WhatsApp Business Platform, you are not just registering a phone number. You are connecting a business identity, a WABA, a phone number and a messaging operation to Meta's ecosystem, and any of those can carry history or raise questions.

Most owners use "WhatsApp API", "WhatsApp Business Account", "Business Manager" and "my WhatsApp number" as if they were the same thing. They are not. The useful model is three nested boxes:

How the WhatsApp Business Platform chain is structured

Meta Business Portfolio. The business environment that holds your Facebook Page, Instagram account, ad accounts, apps, users and permissions.
WhatsApp Business Account (WABA). The WhatsApp account inside that portfolio. It holds your phone numbers, display names, message templates, messaging limits and quality signals.
Phone number. The number your customers see, connected to the WABA and shown under your display name.
Your WhatsApp software or provider. The platform that connects to the WhatsApp Business Platform on your behalf.
Your CRM, inbox and automation. Where your team actually reads and sends messages.

Take a clinic, ABC Dental Sdn Bhd in Petaling Jaya. Its portfolio might already hold a Facebook Page, an Instagram account and an ad account that has been running for three years. It then creates a WABA and connects a SIM bought last week. The number has no history. The portfolio has plenty. When something goes wrong, the number is the easiest thing to blame and often the least likely cause.

Which layer can a restriction actually sit on?

A restriction can sit on any of these layers, and each one has a different fix:

LayerWhat can cause troubleWhere to look first
Business PortfolioAnother restricted asset, such as an ad account or Page, or unresolved policy issuesBusiness Support Home
Business verificationLegal name, address, website or documents that do not match each otherBusiness Support Home
Business categoryGoods or services that fall under WhatsApp's prohibited or restricted policiesWhatsApp Business Messaging Policy
WABAAccount status, limits or quality at the account levelWhatsApp Manager
Phone numberRegistration incomplete, verification code failing, number tied to another setup, display name under reviewWhatsApp Manager
TemplatesA template rejected or paused for its contentWhatsApp Manager
Messaging and feedbackCustomers blocking, reporting or ignoring messages they did not wantWhatsApp Manager quality view

Notice that only one row is about the number. Documentation from providers such as Respond.io and WATI describes cases where restrictions on existing business assets, or on the Business Manager itself, affected WhatsApp onboarding or new WABAs. If your ad account was restricted last year, a fresh SIM does not give you a fresh business.

Why a new number is not the fix most people think it is

The instinct after a restriction is to start clean: new number, sometimes a new WABA, sometimes a whole new portfolio. That instinct usually makes things worse.

Here is what we have seen across the MSME sending accounts we work with. The moves that show up right before trouble are a new template, a sudden jump in volume, or switching to a new number. And the account that gets hit usually already had reports or problems building against it. So the new number is not an escape hatch. On an account that already has issues, it can be one of the triggers.

It also wrecks troubleshooting. Once you have spun up a second portfolio, a second WABA and a third number, nobody can tell which asset carried the original problem, and any appeal has to explain a pile of accounts instead of one clear business.

Swap the number only when the number is the problem

Replacing the number makes sense when the restriction is clearly on the number itself: it is still registered to another WhatsApp setup, it cannot receive its verification code, or it is not eligible. If the restriction sits on the portfolio or the WABA, the new number joins the same problem.

We have also seen numbers restricted no matter how carefully they sent, because the business category itself sits outside WhatsApp's commerce policy. That is not something a new number or a better template can fix. If you are unsure whether your category is sensitive, ask us before you build around it.

Does your business identity look the same everywhere?

Meta's view of your business is built from what you tell it, so the details should match. Inconsistency does not automatically trigger a restriction, but it can complicate verification and eligibility.

A clean setup reads the same at every stop: legal name ABC Dental Sdn Bhd, website abcdental.com.my, portfolio named ABC Dental Sdn Bhd, WhatsApp display name ABC Dental. A messy one looks like this: legal name ABC Dental Sdn Bhd, website on an unrelated domain, portfolio named "John's Personal Business", display name "ABC Deals". Each piece is explainable on its own. Together they look like four different businesses.

Your website matters here. It should say plainly who you are, what you sell, and how to contact you. That matters more in sensitive categories. A clinic should present itself as a healthcare provider; a financial services firm should say what services it offers.

Category also matters. The WhatsApp Business Messaging Policy lists prohibited goods and services, including alcohol, tobacco, drugs, gambling, adult products and multi-level marketing, and notes that these prohibitions apply regardless of any licences your business holds. Healthcare, financial services, insurance and supplements are not automatically prohibited, but they carry extra policy considerations. The exact message matters: "Your appointment is confirmed for 3:00 PM on Tuesday" is a very different thing from "Buy this medical product now at 50% off". Read the current policy yourself before you onboard; it changes.

What does official API access actually protect you from?

Official API access protects you from running on an unofficial, unsupported channel. It does not protect you from Meta's rules. That is true whether you connect through a large global provider, a local platform, Raion, or directly through Meta's Cloud API. Meta controls eligibility, policies, templates, limits and enforcement. Providers build tools to help you comply. None of them can override enforcement, and none can honestly promise you will never be restricted.

Three rules do most of the work once you are connected.

Consent. The policy says you may only contact people on WhatsApp if they gave you their number and you have received opt-in permission from them. A number sitting in your CRM is not WhatsApp marketing consent. If you have 20,000 numbers collected over five years, "send them all a promotion" is the single riskiest thing you can do in week one. Record consent separately: opt-in yes or no, where it came from (website form, walk-in, ad), and the date.

The customer service window. Meta's Cloud API documentation says that when a customer messages you, a 24-hour customer service window opens, and while it is open you can reply with normal service messages. When the window closes, you can only send pre-approved template messages. Your team needs to know the difference between replying to someone and starting a new conversation with them.

Templates. A template is a structured message with variables, such as Hi {{1}}, your appointment at {{2}} is confirmed for {{3}}. Templates suit reminders, confirmations, order updates and payment notices, and marketing where it is permitted. Approval is not a loophole. An approved template sent to people who never wanted it still collects blocks and reports.

How do blocks and reports lead to a restriction?

Customers can block you, report you, ignore you or opt out. When unwanted messages keep producing those reactions, your quality signals fall, and sustained poor quality can lead to limits and restrictions. We cover the mechanics in why WhatsApp quality ratings actually drop.

The better question is not "did Meta approve my number?" but "are the people receiving this glad they got it?" Giving people an easy way out helps. A recipient who can reply STOP has less reason to tap Report spam, which is why an opt-out line can grow your reach instead of shrinking it.

Before any message goes out, four questions settle most of it. Who is receiving it? Did they agree to WhatsApp messages from you? Why are you sending it: support, an appointment, a transaction, a follow-up or marketing? Is the content appropriate under Meta's policy, the law, their consent and your own standards?

Frequently Asked Questions

Yes, it can. Meta may evaluate the Business Portfolio, the WhatsApp Business Account, business verification details and category, not only the phone number. A new number connected to a portfolio with an existing restricted asset or policy issue can still be affected.
Not straight away. First find out which layer was restricted: the portfolio, the WABA, the number, a template or your messaging activity. A new number only helps when the number itself is the problem. If the issue is at business level, the new number inherits it, and switching numbers can itself be one of the moves that precedes trouble.
No. The official API is the legitimate channel, but Meta still controls eligibility, policies, templates, limits and enforcement. No provider, including Raion, can guarantee a number will never be restricted.
Start with the exact error or notice, then check Business Support Home for restrictions on your portfolio and other Meta assets, and WhatsApp Manager for the status of your WABA, phone number, templates, quality and limits.
Only people who gave you their number and opted in to WhatsApp messages from you. The WhatsApp Business Messaging Policy requires opt-in permission. Having someone's number in your records is not the same as WhatsApp marketing consent.

What to do if Meta restricts your WhatsApp account

Do not panic, and do not replace the number yet. Work down the chain in order:

How to troubleshoot a WhatsApp Business Platform restriction

Read the exact error. Note the reason, the status, any error code, which asset is affected, and whether a review or appeal option is shown.
Check Business Support Home. Look for restrictions on your portfolio and on other Meta assets such as Pages or ad accounts.
Check WhatsApp Manager. Review WABA status, phone number status, quality, messaging limits and template status.
Review your business details. Confirm your business information, website and category are accurate, and look for other restricted assets.
Request a review if one is offered. Give factual information: what your business does, your website, what you sell, how you use WhatsApp, how contacts were collected, how opt-in works and how you message.
Do not resubmit the same appeal. Repeated requests with no new information do not help. Fix something, then explain what you fixed.

For the review request itself, on both the Business app and the API, see what to do when your WhatsApp Business number gets banned. And if your replies simply stopped arriving this week, rule out the billing change first: WhatsApp replies not sending since 1 October is a payment-method problem, not a restriction.

What is the right onboarding order for the WhatsApp API?

The wrong order is the one we see most: connect the number, import the whole database, blast everyone. The right order builds each layer before the next one depends on it.

Get your business information right and choose an accurate category. Check the portfolio you are using and look for existing restrictions before you connect anything. Verify your business details. Then connect the WABA, register the number and confirm the display name. Test an inbound message and an outbound reply. Only after that should you set up templates, put your opt-in process in place, switch on automation, and start watching quality.

Automation deserves its own caution. Follow-ups should stop when the customer replies or opts out, and an AI assistant should never invent guarantees, medical claims, financial promises or discounts that do not exist. Automation handles the typing. The business is still responsible for what gets sent.

This is the part a CRM should make easier. In Raion HUB, opt-in status and opt-in source can live as fields on each customer record next to the full conversation, follow-up sequences pause when the customer replies, and broadcasts go to segments you choose by tag, so contacts who opted out can be left out. It is a set of tools and controls designed to support compliant messaging. It does not stop Meta from restricting anyone, and we will not pretend it does. For the wider setup, our WhatsApp automation guide for Malaysian businesses walks through the rest.

Pre-onboarding checklist for the WhatsApp Business Platform

Run this before you connect a number, and again before your first broadcast:

You are using the correct Meta Business Portfolio, with accurate business information
No unresolved restrictions or disabled assets in the portfolio, including ad accounts and Pages
Legal business name, website, portfolio name and display name all describe the same business
Your business category is accurate and you have read the current WhatsApp Business Messaging Policy
The WABA is the correct one, active, and owned or controlled by your business
The phone number is controlled by your business, can receive its verification code, and is not registered to another WhatsApp setup
You have an opt-in process and can tell marketing contacts apart from everyone else
Templates are approved and every marketing message has a clear way to opt out
Your team understands the 24-hour customer service window
Follow-ups stop when a customer replies or opts out
After activation you test inbound and outbound, then watch delivery, blocks, reports, failed messages, template status and quality

The bottom line

Key Takeaway

A restriction on a new WhatsApp API number is a question about your whole business setup, not a verdict on the SIM card. Identify the restricted layer first, whether portfolio, WABA, number, template or messaging, and fix that layer instead of reaching for another number. The businesses that stay out of trouble are the ones whose identity is consistent, whose contacts agreed to hear from them, and who watch quality before Meta has to.

Ready to grow with Raion

Know who agreed to hear from you before you hit send

Raion HUB keeps opt-in status, source and every reply on the customer record, so your team can see who should get a message and who should be left alone.