
New WhatsApp API Number Restricted? Check the Chain First
A brand-new WhatsApp API number can be restricted before it sends a single blast. Meta can judge the whole business behind it. Here is how to find the layer.
A brand-new WhatsApp number can be restricted right after official WhatsApp API onboarding because Meta does not judge the number on its own. It can look at the whole chain behind it: your Meta Business Portfolio, your WhatsApp Business Account (WABA), your business details, your display name, your templates, how you message, and how customers react. The number is new. The business environment it plugs into usually is not.
So the first job after a restriction is not buying another SIM. It is finding which layer was actually restricted, and fixing that layer.
Meta can restrict a freshly connected WhatsApp number because it evaluates the business environment around it, not the SIM card. A restriction can sit at the Business Portfolio, the WABA, the phone number, a template or the messaging behaviour, and swapping the number only helps when the number itself was the problem. Official API access gives you a legitimate channel with rules; it does not make any number, on any provider, ban-proof.
Why would Meta restrict a WhatsApp number that has never sent anything?
Because from Meta's side, a number is only the last link in a longer chain. When you onboard to the WhatsApp Business Platform, you are not just registering a phone number. You are connecting a business identity, a WABA, a phone number and a messaging operation to Meta's ecosystem, and any of those can carry history or raise questions.
Most owners use "WhatsApp API", "WhatsApp Business Account", "Business Manager" and "my WhatsApp number" as if they were the same thing. They are not. The useful model is three nested boxes:
How the WhatsApp Business Platform chain is structured
Take a clinic, ABC Dental Sdn Bhd in Petaling Jaya. Its portfolio might already hold a Facebook Page, an Instagram account and an ad account that has been running for three years. It then creates a WABA and connects a SIM bought last week. The number has no history. The portfolio has plenty. When something goes wrong, the number is the easiest thing to blame and often the least likely cause.
Which layer can a restriction actually sit on?
A restriction can sit on any of these layers, and each one has a different fix:
| Layer | What can cause trouble | Where to look first |
|---|---|---|
| Business Portfolio | Another restricted asset, such as an ad account or Page, or unresolved policy issues | Business Support Home |
| Business verification | Legal name, address, website or documents that do not match each other | Business Support Home |
| Business category | Goods or services that fall under WhatsApp's prohibited or restricted policies | WhatsApp Business Messaging Policy |
| WABA | Account status, limits or quality at the account level | WhatsApp Manager |
| Phone number | Registration incomplete, verification code failing, number tied to another setup, display name under review | WhatsApp Manager |
| Templates | A template rejected or paused for its content | WhatsApp Manager |
| Messaging and feedback | Customers blocking, reporting or ignoring messages they did not want | WhatsApp Manager quality view |
Notice that only one row is about the number. Documentation from providers such as Respond.io and WATI describes cases where restrictions on existing business assets, or on the Business Manager itself, affected WhatsApp onboarding or new WABAs. If your ad account was restricted last year, a fresh SIM does not give you a fresh business.
Why a new number is not the fix most people think it is
The instinct after a restriction is to start clean: new number, sometimes a new WABA, sometimes a whole new portfolio. That instinct usually makes things worse.
Here is what we have seen across the MSME sending accounts we work with. The moves that show up right before trouble are a new template, a sudden jump in volume, or switching to a new number. And the account that gets hit usually already had reports or problems building against it. So the new number is not an escape hatch. On an account that already has issues, it can be one of the triggers.
It also wrecks troubleshooting. Once you have spun up a second portfolio, a second WABA and a third number, nobody can tell which asset carried the original problem, and any appeal has to explain a pile of accounts instead of one clear business.
Replacing the number makes sense when the restriction is clearly on the number itself: it is still registered to another WhatsApp setup, it cannot receive its verification code, or it is not eligible. If the restriction sits on the portfolio or the WABA, the new number joins the same problem.
We have also seen numbers restricted no matter how carefully they sent, because the business category itself sits outside WhatsApp's commerce policy. That is not something a new number or a better template can fix. If you are unsure whether your category is sensitive, ask us before you build around it.
Does your business identity look the same everywhere?
Meta's view of your business is built from what you tell it, so the details should match. Inconsistency does not automatically trigger a restriction, but it can complicate verification and eligibility.
A clean setup reads the same at every stop: legal name ABC Dental Sdn Bhd, website abcdental.com.my, portfolio named ABC Dental Sdn Bhd, WhatsApp display name ABC Dental. A messy one looks like this: legal name ABC Dental Sdn Bhd, website on an unrelated domain, portfolio named "John's Personal Business", display name "ABC Deals". Each piece is explainable on its own. Together they look like four different businesses.
Your website matters here. It should say plainly who you are, what you sell, and how to contact you. That matters more in sensitive categories. A clinic should present itself as a healthcare provider; a financial services firm should say what services it offers.
Category also matters. The WhatsApp Business Messaging Policy lists prohibited goods and services, including alcohol, tobacco, drugs, gambling, adult products and multi-level marketing, and notes that these prohibitions apply regardless of any licences your business holds. Healthcare, financial services, insurance and supplements are not automatically prohibited, but they carry extra policy considerations. The exact message matters: "Your appointment is confirmed for 3:00 PM on Tuesday" is a very different thing from "Buy this medical product now at 50% off". Read the current policy yourself before you onboard; it changes.
What does official API access actually protect you from?
Official API access protects you from running on an unofficial, unsupported channel. It does not protect you from Meta's rules. That is true whether you connect through a large global provider, a local platform, Raion, or directly through Meta's Cloud API. Meta controls eligibility, policies, templates, limits and enforcement. Providers build tools to help you comply. None of them can override enforcement, and none can honestly promise you will never be restricted.
Three rules do most of the work once you are connected.
Consent. The policy says you may only contact people on WhatsApp if they gave you their number and you have received opt-in permission from them. A number sitting in your CRM is not WhatsApp marketing consent. If you have 20,000 numbers collected over five years, "send them all a promotion" is the single riskiest thing you can do in week one. Record consent separately: opt-in yes or no, where it came from (website form, walk-in, ad), and the date.
The customer service window. Meta's Cloud API documentation says that when a customer messages you, a 24-hour customer service window opens, and while it is open you can reply with normal service messages. When the window closes, you can only send pre-approved template messages. Your team needs to know the difference between replying to someone and starting a new conversation with them.
Templates. A template is a structured message with variables, such as Hi {{1}}, your appointment at {{2}} is confirmed for {{3}}. Templates suit reminders, confirmations, order updates and payment notices, and marketing where it is permitted. Approval is not a loophole. An approved template sent to people who never wanted it still collects blocks and reports.
How do blocks and reports lead to a restriction?
Customers can block you, report you, ignore you or opt out. When unwanted messages keep producing those reactions, your quality signals fall, and sustained poor quality can lead to limits and restrictions. We cover the mechanics in why WhatsApp quality ratings actually drop.
The better question is not "did Meta approve my number?" but "are the people receiving this glad they got it?" Giving people an easy way out helps. A recipient who can reply STOP has less reason to tap Report spam, which is why an opt-out line can grow your reach instead of shrinking it.
Before any message goes out, four questions settle most of it. Who is receiving it? Did they agree to WhatsApp messages from you? Why are you sending it: support, an appointment, a transaction, a follow-up or marketing? Is the content appropriate under Meta's policy, the law, their consent and your own standards?
Frequently Asked Questions
What to do if Meta restricts your WhatsApp account
Do not panic, and do not replace the number yet. Work down the chain in order:
How to troubleshoot a WhatsApp Business Platform restriction
For the review request itself, on both the Business app and the API, see what to do when your WhatsApp Business number gets banned. And if your replies simply stopped arriving this week, rule out the billing change first: WhatsApp replies not sending since 1 October is a payment-method problem, not a restriction.
What is the right onboarding order for the WhatsApp API?
The wrong order is the one we see most: connect the number, import the whole database, blast everyone. The right order builds each layer before the next one depends on it.
Get your business information right and choose an accurate category. Check the portfolio you are using and look for existing restrictions before you connect anything. Verify your business details. Then connect the WABA, register the number and confirm the display name. Test an inbound message and an outbound reply. Only after that should you set up templates, put your opt-in process in place, switch on automation, and start watching quality.
Automation deserves its own caution. Follow-ups should stop when the customer replies or opts out, and an AI assistant should never invent guarantees, medical claims, financial promises or discounts that do not exist. Automation handles the typing. The business is still responsible for what gets sent.
This is the part a CRM should make easier. In Raion HUB, opt-in status and opt-in source can live as fields on each customer record next to the full conversation, follow-up sequences pause when the customer replies, and broadcasts go to segments you choose by tag, so contacts who opted out can be left out. It is a set of tools and controls designed to support compliant messaging. It does not stop Meta from restricting anyone, and we will not pretend it does. For the wider setup, our WhatsApp automation guide for Malaysian businesses walks through the rest.
Pre-onboarding checklist for the WhatsApp Business Platform
Run this before you connect a number, and again before your first broadcast:
The bottom line
A restriction on a new WhatsApp API number is a question about your whole business setup, not a verdict on the SIM card. Identify the restricted layer first, whether portfolio, WABA, number, template or messaging, and fix that layer instead of reaching for another number. The businesses that stay out of trouble are the ones whose identity is consistent, whose contacts agreed to hear from them, and who watch quality before Meta has to.


