All 915 10DLC rules

A2P 10DLC rule registry

10DLC brand rules

Vetting compares the strings you submit against IRS and business records mechanically, so differences a person would read straight past are the entire failure mode. These rules cover the legal name, EIN, address, contact, entity classification, vetting, appeals and every lifecycle operation performed on a brand after it exists.

196 rules· 121 blocking · 47 high · 24 medium · 4 low

BRD-001A legal company name is required for every entity but a sole proprietorbrand.company_nameBlockingBLOCKING

The legal company name field must be populated for every entity type except sole proprietor, where TCR wants it omitted and the person's name used instead.

BRD-002Legal name must match the IRS record for the EINbrand.company_name + brand.einBlockingBLOCKING

The registered legal company name must match the IRS CP-575 / 147C record for the submitted EIN, character for character.

BRD-003Legal name must carry its exact entity suffix as filedbrand.company_nameBlockingBLOCKING

The registered legal name must include the entity suffix exactly as filed — no abbreviation, expansion, or omission.

BRD-008Legal name must not carry an appended personal name or rolebrand.company_nameBlockingBLOCKING

The legal name field must contain only the entity name — not a contact person or role suffix appended to it.

BRD-009The legal name field takes the legal name, not the trading namebrand.company_name vs brand.dbaBlockingBLOCKING

A DBA, trade name, subsidiary name, or product name must not be submitted in the legal company name field.

BRD-011A legal business name may back only one brand across the whole registrybrand.company_nameBlockingBLOCKING

A legal business name already registered as a brand at TCR cannot be registered again, by anyone.

BRD-012Name fields must read as natural business textbrand.display_name + brand.company_name + brand.first_name + brand.last_nameBlockingBLOCKING

The display name, company name, and any first and last name fields must contain real, natural text — not obfuscated, garbled, or placeholder strings.

BRD-013A brand must be a business, not a personbrand.company_name + brand.entity_typeBlockingBLOCKING

Outside the sole-proprietor tier, the registered brand must be a business entity rather than an individual's personal identity.

BRD-015A brand covers exactly one senderthe brand recordBlockingBLOCKING

Each brand must be scoped to a single message sender — one brand per company, client, franchise or subsidiary, and no number shared between brands.

BRD-017A tax ID is required for every entity but a sole proprietorbrand.einBlockingBLOCKING

A tax ID or business registration number must be supplied for every entity type except sole proprietor.

BRD-019EIN must be nine digitsbrand.einBlockingBLOCKING

The EIN must be exactly nine digits (formatting characters aside).

BRD-020Submit the US EIN hyphenatedbrand.einBlockingBLOCKING

A US EIN must be submitted in the hyphenated XX-XXXXXXX form.

BRD-021An SSN is not a business registration numberbrand.einBlockingBLOCKING

A Social Security Number must not be submitted in the business registration number field.

BRD-022A DUNS number is not a US business registration numberbrand.einBlockingBLOCKING

A DUNS number must not be submitted as the US business registration number.

BRD-023The identifier type must be one of the supported valuesbrand.business_registration_identifierBlockingBLOCKING

Where a business-registration identifier type is declared, it must be one of EIN, DUNS, CBN, CN, ACN, CIN, VAT, VATRN, RN or Other.

BRD-024The identifier value must match the type declared for itbrand.business_registration_identifier + brand.einBlockingBLOCKING

The business-registration identifier value must be in the form its declared type requires.

BRD-025The issuing country must be declared, and must match the country of registrationbrand.ein_issuing_country + brand.countryBlockingBLOCKING

einIssuingCountry must be a valid ISO-3166 alpha-2 code and must equal the country the business is registered in.

BRD-028A business absent from the verification databases must upload its registration documentregistration document attachmentBlockingBLOCKING

Where the entity does not appear in third-party verification databases, an official registration or IRS document must be uploaded with the brand.

BRD-032Submit the identifier in the form the issuing country requiresbrand.einBlockingBLOCKING

For a country on TCR's VAT-optimised list, submit only the numeric portion of the VAT ID; elsewhere submit the corporation registration number or national tax ID.

BRD-035The country of registration must be on the permitted listbrand.country + brand.ein_issuing_countryBlockingBLOCKING

A brand registered in a country outside TCR's permitted-country list cannot be registered at all.

BRD-038Some providers require an external vet for every non-US brandbrand.country + external vet recordBlockingBLOCKING

At least one provider requires external vetting on every non-US customer before the brand can be used.

BRD-039The sending-volume tier decides whether the sole-proprietor path is availablebrand.entity_type + requested volume tierBlockingBLOCKING

A registration that requests a volume tier requiring a tax ID cannot be filed on the sole-proprietor path.

BRD-040Entity type must be one of the five supported valuesbrand.entity_typeBlockingBLOCKING

entityType must be exactly one of PRIVATE_PROFIT, PUBLIC_PROFIT, NON_PROFIT, GOVERNMENT or SOLE_PROPRIETOR.

BRD-041The entity type must match the classification on the tax recordbrand.entity_type vs the tax recordBlockingBLOCKING

The selected entity type must match how the business is classified on its tax record, with documentation where the classification is not machine-verifiable.

BRD-042A non-US organisation registers as private for profitbrand.entity_type + brand.countryBlockingBLOCKING

A brand whose country of registration is not the US must be PRIVATE_PROFIT — GOVERNMENT and NON_PROFIT are US-only classifications.

BRD-043The business-type field takes its own enum, not the entity typebrand.business_typeBlockingBLOCKING

Where a business_type is declared, it must be one of Co-operative, Corporation, Limited Liability Corporation, Non-profit Corporation or Partnership.

BRD-045PUBLIC_PROFIT means the shares actually tradebrand.entity_typeBlockingBLOCKING

The PUBLIC_PROFIT classification is available only to a company whose shares are genuinely publicly traded.

BRD-047Public companies must supply stock symbol and exchangebrand.stock_symbol + brand.stock_exchangeBlockingBLOCKING

A PUBLIC_PROFIT brand must declare both its ticker symbol and the exchange it trades on.

BRD-048The stock exchange must be a recognised enum valuebrand.stock_exchangeBlockingBLOCKING

A public company's stock exchange must be one of the supported registry values.

BRD-050A stock symbol may back only one brandbrand.stock_symbolBlockingBLOCKING

A stock symbol already registered against another brand cannot be used again.

BRD-057A charity brand needs an arm's-length accreditationaccreditation listing URLBlockingBLOCKING

A brand running the charity use case must be accredited by at least one independent non-profit accreditation body.

BRD-058Keep the charity evidence bundle togethercharity evidence bundleBlockingBLOCKING

A charity brand must retain its organisation name, EIN, charity website and accreditation listing URL as proof of 501(c)(3) standing.

BRD-060A 501(c)(3) may not run certain use casesbrand.tax_exempt_status + campaign.use_caseBlockingBLOCKING

A brand holding 501(c)(3) status must not register the Agents & Franchises, Carrier Exempt, Proxy, Social or Sweepstake use cases.

BRD-062GOVERNMENT is for US government bodies onlybrand.entity_typeBlockingBLOCKING

The GOVERNMENT entity type is reserved for US federal, state or local government bodies.

BRD-065Sole proprietor must have no EINbrand.einBlockingBLOCKING

The SOLE_PROPRIETOR tier is for a US individual without an EIN. Supplying an EIN disqualifies the registration.

BRD-068Sole proprietor brand name must be a person, not a companybrand.company_nameBlockingBLOCKING

The sole proprietor brand name must be the individual’s first and last name — never an LLC, Inc, Corp or other registered entity name.

BRD-070The verification number must be a real US or Canadian mobilebrand.mobile_phoneBlockingBLOCKING

The sole-proprietor mobile number must be an active US or Canadian wireless number in E.164 that can receive SMS.

BRD-072Sole proprietor mobile number has a reuse limitbrand.phoneBlockingBLOCKING

A mobile number used for sole proprietor OTP verification may back at most three brand registrations, and must not be a CPaaS-issued number.

BRD-075The verification text must be answered within 24 hourssole-proprietor OTP stateBlockingBLOCKING

The sole-proprietor OTP must be answered YES within 24 hours, or the verification must be re-triggered.

BRD-076Changing the mobile number re-runs the verificationbrand.mobile_phoneBlockingBLOCKING

Any change to the sole-proprietor mobile number reverts the brand to UNVERIFIED and requires the OTP to be run again.

BRD-081A sole-proprietor brand cannot buy its way to more throughputexternal vet orderBlockingBLOCKING

External vetting, and the throughput increases vetting buys, are not available on a sole-proprietor brand.

BRD-082RCS brand assets are not available on the sole-proprietor tierbrand.assetsBlockingBLOCKING

Logo and banner assets for RCS cannot be uploaded to a sole-proprietor brand.

BRD-084Sole proprietor is not supported by every providerbrand.entity_typeBlockingBLOCKING

Some providers refuse sole proprietor registrations outright, and one also refuses sole proprietor appeals.

BRD-091A complete physical business address is requiredbrand.street + city + state + postal_code + countryBlockingBLOCKING

Street, city, state or region, postal code and a two-letter country must all be populated.

BRD-092US and Canadian addresses use the two-letter state codebrand.stateBlockingBLOCKING

For a US or Canadian address, the state or province must be the two-letter abbreviation.

BRD-093The address must match the registration record component by componentbrand.street … brand.postal_codeBlockingBLOCKING

The registered address must match the address on the IRS or national registration record exactly, including abbreviation style.

BRD-095The address must validate as deliverablebrand.street … brand.postal_codeBlockingBLOCKING

House number, street, locality and postal code must all resolve to a deliverable address at the postal authority.

BRD-096Brand address must be a physical address, not a PO boxbrand.streetBlockingBLOCKING

The registered business address must be a street address; PO boxes are rejected.

BRD-099The address is checked against spam and scam complaint databrand.streetBlockingBLOCKING

The registration address must not appear in known spam or scam complaint data.

BRD-103The support phone must be in E.164brand.phoneBlockingBLOCKING

The brand support phone must be submitted in E.164: a leading plus, the country code, and digits with no separators.

BRD-107The representative's phone number may back only one brandbrand.authorized_rep.phoneBlockingBLOCKING

An authorised representative's phone number already used on another brand cannot be used again.

BRD-108The brand support email must be well formedbrand.emailBlockingBLOCKING

The brand support email must be a syntactically valid address.

BRD-109Brand contact email must not use a free consumer domainbrand.emailBlockingBLOCKING

The brand support/business contact email must be on a domain the business controls, not a free consumer mail provider.

BRD-111The contact email domain must be provably the brand'sbrand.business_contact_email domainBlockingBLOCKING

The brand contact email must be on a domain the business demonstrably owns — shown on its website, matching WHOIS, or verified by DNS.

BRD-114Disposable mailboxes are refused outrightbrand.emailBlockingBLOCKING

The brand contact email must not be on a disposable or temporary mail domain.

BRD-115The email domain must resolvebrand.email domainBlockingBLOCKING

The brand contact email domain must resolve with an MX or A record.

BRD-117A public company must supply a business contact emailbrand.business_contact_emailBlockingBLOCKING

A PUBLIC_PROFIT brand must carry a business contact email — it is mandatory and it triggers the Authentication+ 2FA.

BRD-120Changing a public brand's contact email resets its identitybrand.business_contact_emailBlockingBLOCKING

Any change to a PUBLIC_PROFIT brand's business contact email resets identity verification and requires the 2FA to be completed again.

BRD-122A well-known brand name on a consumer mail domain reads as impersonationbrand.company_name + brand.emailBlockingBLOCKING

A widely recognised company name paired with a free or non-corporate email domain must be treated as probable impersonation.

BRD-125The website URL must carry an explicit schemebrand.websiteBlockingBLOCKING

The brand website must be submitted with an explicit http:// or https:// scheme.

BRD-135A website may back only one brandbrand.websiteBlockingBLOCKING

A website URL already registered against another brand cannot be registered again.

BRD-143A brand with no website must attach its policy documentpolicy attachmentBlockingBLOCKING

Where the brand registers no website, a compliant policy document must be attached to the registration or hosted at a public URL.

BRD-145A display name is required, and so is the DBA fieldbrand.display_name + brand.dbaBlockingBLOCKING

The display name must be populated within its length bound, and the DBA field must be populated even when it is identical to the legal name.

BRD-147A DBA used publicly must be registered on the brandbrand.dba vs website and message contentBlockingBLOCKING

Any trading name the business uses publicly — on its site or in its messages — must be declared in the DBA field rather than substituted silently.

BRD-150The vertical must be one of the 23 registry valuesbrand.verticalBlockingBLOCKING

The industry vertical must be one of the 23 TCR values, and is required for every entity type except sole proprietor.

BRD-153brandRelationship must be one of the five account tiersbrand.brand_relationshipBlockingBLOCKING

Outside the sole-proprietor tier, brandRelationship must be one of BASIC_ACCOUNT, SMALL_ACCOUNT, MEDIUM_ACCOUNT, LARGE_ACCOUNT or KEY_ACCOUNT.

BRD-160Register the message sender, not the agency or platformbrand.company_nameBlockingBLOCKING

The brand must be the legal entity whose messages are sent — never the agency, ISV, reseller, or software platform acting on its behalf.

BRD-165A toll-free contact needs a full first and last nametfv.contact_first_name + .contact_last_nameBlockingBLOCKING

The toll-free registration contact must be an authorised representative's full first and last name.

BRD-166The sender must be identified and authenticated before any message goes outthe brand identity bundleBlockingBLOCKING

Sufficient identifying information must be obtained to verify and authenticate the sender's identity before that sender sends any message.

BRD-173One brand per tax IDbrand.ein across the registryBlockingBLOCKING

At most one brand may be registered against a given tax ID.

BRD-177A duplicate on any identity field blocks the submissionthe seven-field duplicate keyBlockingBLOCKING

A brand submission is blocked where it matches an existing brand on legal name, registration number, mobile number, representative phone, email, website or stock symbol.

BRD-189A failed brand can be updated by API and not in the consolethe remediation pathBlockingBLOCKING

Remediating a failed brand differs by interface: the API permits an update in place, while the console requires delete and recreate.

BRD-191The two bundle identifiers must not be transposedthe bundle identifiersBlockingBLOCKING

The customer-profile and A2P bundle identifiers must be distinct, belong to the same account, and not be swapped.

BRD-195Deactivate every campaign before deleting a brandthe campaign states under the brandBlockingBLOCKING

All campaigns on a brand must be deactivated before the brand can be deleted.

BRD-197Brand deletion cannot be undonethe delete requestBlockingBLOCKING

A deleted brand cannot be reactivated; the deletion is final.

BRD-199Do not move suspended traffic onto a new brandthe brand or campaign migrationBlockingBLOCKING

Traffic under suspension or carrier review must not be migrated to a new brand or campaign.

BRD-200A suspension follows the tax ID to the next brandbrand.ein after a suspensionBlockingBLOCKING

After a suspension, new brands created on the same tax ID should be expected to be restricted.

BRD-203The starter brand class is deprecatedthe brand classBlockingBLOCKING

A deprecated starter-class brand must not be created or updated.

BRD-207Campaigns cannot be submitted while vetting is in reviewthe vet stateBlockingBLOCKING

A campaign must not be submitted while the brand's vetting is still in review.

BRD-215The vetting provider must support this entity type and countryvet provider vs brand.entity_type / brand.countryBlockingBLOCKING

The chosen vetting provider must support the brand's entity type and country of registration.

BRD-216An imported vet must match the brand exactly, and carry its tokenthe vet import payloadBlockingBLOCKING

On a vet import, the legal name and entity type must match the vetting report exactly, and the vetting token must be supplied.

BRD-217Some vet classes cannot be imported at allthe vet import classBlockingBLOCKING

An Authentication+ class vet must not be submitted for import — the class does not support it.

BRD-223Website and contact email must be in place before an identity-plus vetbrand.website + brand.business_contact_emailBlockingBLOCKING

The brand website and business contact email must be populated before an Authentication+ or RBM vet is ordered.

BRD-224Public companies must clear Authentication+ before campaignsbrand.identity_statusBlockingBLOCKING

A PUBLIC_PROFIT brand must reach identity VERIFIED with Authentication+ ACTIVE before any campaign can be registered.

BRD-225Authentication+ must now be ordered explicitlythe Authentication+ vet orderBlockingBLOCKING

Under Authentication+ 2.0 the vet must be ordered explicitly after the identity check; it no longer runs automatically.

BRD-226The 2FA PIN must be completed inside the vet's windowthe Authentication+ 2FA stateBlockingBLOCKING

The business contact must complete the Authentication+ 2FA PIN within 30 days of the vet being submitted, or the vet must be re-submitted.

BRD-230Identity-plus vetting is for public companies onlythe vet order + brand.entity_typeBlockingBLOCKING

An Authentication+ vet must not be ordered for a brand that is not PUBLIC_PROFIT.

BRD-231Identity information is frozen once Authentication+ completesthe identity fields after Authentication+BlockingBLOCKING

After Authentication+ verification completes, brand identity information cannot be changed; a new brand must be created instead.

BRD-233Some providers require vetting for every use case above the lowest tierthe vet record + campaign.use_caseBlockingBLOCKING

At least one provider requires standard or enhanced brand vetting for any use case beyond the lowest-volume mixed tier.

BRD-237Short-code assignment needs a successful vetting statusthe vetting statusBlockingBLOCKING

A successful vetting status on the brand and the content provider is required to be assigned a short code or to extend a lease.

BRD-241Political vetting is satisfied by exactly one recognised artefactthe political vetting artefactBlockingBLOCKING

A political brand must hold exactly one of: a Campaign Verify token, an Aegis political vet, or verified 501(c)(3/4/5/6) status.

BRD-242A tax-exempt organisation must not order a political vetbrand.tax_exempt_status + the political vet orderBlockingBLOCKING

A political vet must not be requested or imported for a brand that already holds 501(c)(3), (4), (5) or (6) status.

BRD-243A 527 organisation needs a token and its filing reference on recordthe Campaign Verify token + the filing referenceBlockingBLOCKING

A 527 political organisation must hold a Campaign Verify token, and must record the FEC ID or state filing URL used to obtain it.

BRD-244A political token imports only onto an eligible, campaign-free brandthe Campaign Verify import targetBlockingBLOCKING

A Campaign Verify token may be imported only onto a US-based non-profit brand without 501(c) status, and only while the brand has no active campaigns.

BRD-246A political token is used once and once onlythe Campaign Verify tokenBlockingBLOCKING

Each Campaign Verify token is single-use and unique to one brand and CSP; a second use requires a reissue or a fresh political vet.

BRD-247Check the token has not expired before importing itthe token expiryBlockingBLOCKING

A Campaign Verify token must be checked for expiry before it is imported.

BRD-248One political import at a timethe Campaign Verify import queueBlockingBLOCKING

A second Campaign Verify import must not be submitted while one is in progress.

BRD-249The political filing email must match the registrationthe political filing emailBlockingBLOCKING

For an Aegis political vet, the filing email must exactly match the email on the political registration, and must not be a consumer domain.

BRD-250The political vetting contact must be named in the registrationthe political vetting contact nameBlockingBLOCKING

The contact name on an Aegis political vet must match an authorised name in the political registration — not the CSP's or the aggregator's.

BRD-251A federal donation programme needs a current FEC registrationthe FEC registrationBlockingBLOCKING

A federal candidate, committee or party running a donation programme must be currently registered with the FEC.

BRD-254Appeal only a vet that has finishedthe vet stateBlockingBLOCKING

An appeal may be filed only against a vet in a final state — never against one still pending.

BRD-255Choose an appeal category valid for this entity typeappeal.appeal_categoriesBlockingBLOCKING

At least one appeal category must be selected, and it must be one that is valid for the brand's entity type.

BRD-256The low-score category does not apply to an identity appealappeal.appeal_categoriesBlockingBLOCKING

The LOW_SCORE appeal category is valid only for an external vetting appeal, never for an identity-status appeal.

BRD-263Appeal a missing status attribute even on a verified brandthe optional attributes + the appealBlockingBLOCKING

A VERIFIED non-profit or government brand must still appeal where its tax-exempt or government attribute is missing.

BRD-267Every brand field must be within its maximum lengthall brand text fieldsBlockingBLOCKING

Each brand text field must be within the strictest cap its downstream targets enforce.

BRD-268Brand contact fields must contain no spacesbrand.email + brand.phoneBlockingBLOCKING

The brand contact email and phone fields must contain no whitespace.

BRD-269No emoji in any brand fieldall brand text fieldsBlockingBLOCKING

No brand field may contain an emoji or pictograph.

BRD-270Placeholder values are not answersbrand contact and address fieldsBlockingBLOCKING

Required brand contact and address fields must not hold placeholder values such as N/A, TBD or none.

BRD-274RCS brand assets have exact dimension, size and format constraintsbrand.assetsBlockingBLOCKING

An RCS logo must be 224×224 pixels and at most 50 KB, a banner 1440×448 and at most 200 KB, both JPEG or PNG, with at most 50 of each per brand.

BRD-275Brands that buy, sell or share consumer data are not carriedbrand.vertical + brand fields + website contentBlockingBLOCKING

A brand whose business is buying, selling or sharing consumer information with third parties must not be registered for A2P messaging.

BRD-276Gambling, betting and lottery brands are not carriedbrand.vertical + brand fields + website contentBlockingBLOCKING

A brand whose business is gambling, betting, casino, lottery or raffle must not be registered for A2P messaging.

BRD-277High-risk financial services brands are not carriedbrand.vertical + brand fields + website contentBlockingBLOCKING

A brand whose business is high-risk financial services — payday and short-term lending, indirect loan marketing, stock alerts or crypto must not be registered for A2P messaging.

BRD-278Cannabis, CBD and related brands are not carried, whatever the trafficbrand.vertical + brand fields + website contentBlockingBLOCKING

A brand whose business is cannabis, CBD, hemp derivatives, kratom or drug paraphernalia must not be registered for A2P messaging.

BRD-279Third-party job boards are not carriedbrand.vertical + brand fields + website contentBlockingBLOCKING

A brand whose business is a third-party job board or staffing aggregator must not be registered for A2P messaging.

BRD-281Sweepstakes brands are not carriedbrand.vertical + brand fields + website contentBlockingBLOCKING

A brand whose business is sweepstakes must not be registered for A2P messaging.

BRD-282Debt collection, debt relief and credit repair brands are not carriedbrand.vertical + brand fields + website contentBlockingBLOCKING

A brand whose business is third-party debt collection, debt consolidation or relief, or credit repair must not be registered for A2P messaging.

BRD-283Get-rich-quick, work-from-home and MLM brands are not carriedbrand.vertical + brand fields + website contentBlockingBLOCKING

A brand whose business is get-rich-quick, work-from-home, multi-level marketing, mystery shopping or risky investment schemes must not be registered for A2P messaging.

BRD-284Controlled substance, prescription drug and pyrotechnics brands are not carriedbrand.vertical + brand fields + website contentBlockingBLOCKING

A brand whose business is controlled substances, prescription drugs, or fireworks and pyrotechnics must not be registered for A2P messaging.

BRD-286Fabricated business details are a permanent disqualificationthe whole brand recordBlockingBLOCKING

The brand record must describe a real business; fabricated details or a known scam pattern must never be submitted.

BRD-006Submit every name line above the address on a multi-line IRS recordbrand.company_nameHighHIGH

Where the IRS CP-575 or 147C prints the entity name across more than one line, every line above the address line belongs in the legal name, and nothing below it.

BRD-007TCR takes only the first line of the IRS-registered namebrand.company_nameHighHIGH

On a submission that goes to TCR directly, the company name is the first line of the IRS-registered name and nothing after it.

BRD-010Take the legal name from the CP-575 or 147C, never a W-2 or W-9brand.company_nameHighHIGH

The legal name must come from the IRS CP-575 confirmation letter or a 147C letter — the name on a W-2 or W-9 is not authoritative for this purpose.

BRD-014An acquired business registers the details it filed taxes underbrand.company_name + brand.einHighHIGH

Where the business has been acquired, the brand must carry the company information used for tax reporting at the time — not the acquirer's.

BRD-027EIN must be old enough to have propagated to IRS recordsbrand.einHighHIGH

A newly issued EIN is not yet present in the records vetting providers query; registration fails until it propagates.

BRD-034Validate a non-US identifier against its home register before submittingbrand.einHighHIGH

A non-US registration identifier should be confirmed against the issuing country's official register before it is submitted.

BRD-036A non-US brand should expect automated identity verification to failbrand.countryHighHIGH

A brand registered outside the US will usually fail the initial automated identity check and must budget for an appeal or an external vet.

BRD-044Changing an identity field re-runs verification, and costs the fee againbrand.entity_type + brand.ein + brand.ein_issuing_country + brand.company_nameHighHIGH

Any change to entity type, EIN, EIN issuing country or legal name re-runs brand verification and resets the identity status.

BRD-049Stock fields must be empty for non-public entitiesbrand.stock_symbol + brand.stock_exchangeHighHIGH

stockSymbol and stockExchange must be omitted entirely when the entity type is not PUBLIC_PROFIT.

BRD-053Tax-exempt status must be verified against the IRS registersbrand.einHighHIGH

A NON_PROFIT registration must be backed by an EIN that appears in the IRS Tax-Exempt Organization Search.

BRD-055Non-profit classification must be consistent across every fieldbrand.entity_type + brand.verticalHighHIGH

A non-profit brand must be marked as non-profit consistently across entity type, vertical, and any company-type field.

BRD-064A government brand must carry the government attribute to get its classbrand.optional_attributes.government_entityHighHIGH

A GOVERNMENT brand must have the governmentEntity attribute set before the top carrier class can be assumed.

BRD-067A business trading under a DBA belongs on the standard tierbrand.dba + brand.entity_typeHighHIGH

A sole-proprietor registration that declares a DBA must be re-filed as a standard brand.

BRD-086Sole-proprietor throughput is capped, and the CSP enforces itsole-proprietor send rateHighHIGH

Sole-proprietor traffic is capped at roughly 1,000 messages a day and 15 a minute, enforced at the CSP rather than by the carrier.

BRD-087Monthly sole-proprietor traffic reports are due by the 7thsole-proprietor traffic reportHighHIGH

Where a CSP is enabled for sole-proprietor brands, monthly traffic reports must reach TCR by the 7th of the following month.

BRD-097Include the suite or unit number the registry holdsbrand.street (secondary line)HighHIGH

Where the registration record carries a suite, unit or apartment number, the brand address must carry it too.

BRD-098Register the company address, not the branch you work frombrand.streetHighHIGH

A branch or local-office address must not be submitted where the official registered company address differs.

BRD-101Express PIN delivery needs a real street addressbrand.streetHighHIGH

A PO box, mailbox service or general-delivery address cannot be used when express PIN delivery is requested for political vetting.

BRD-104The support phone must reach the businessbrand.phoneHighHIGH

The brand support number must route to the business and be answerable during business hours.

BRD-112Brand contact email must not be a role or distribution addressbrand.emailHighHIGH

The brand business-contact email must be an individual mailbox, not a role or group address such as info@ or sales@.

BRD-119Confirm the mailbox accepts outside mail before triggering 2FAbrand.business_contact_email deliverabilityHighHIGH

The brand contact mailbox must be able to receive external mail before Authentication+ 2FA is triggered.

BRD-121The support contact must be the end customer's, not the agency'sbrand.email vs the registering tenantHighHIGH

The brand contact email must reach the business being registered, not the ISV, agency or reseller that filed the registration.

BRD-132The website domain must relate recognisably to the brand namebrand.website vs brand.company_name / brand.dbaHighHIGH

The registered website's domain must bear a recognisable relationship to the legal name or the DBA.

BRD-144The registered vertical must match the business on the websitebrand.vertical vs website contentHighHIGH

The declared industry vertical must match the business the registered website actually describes.

BRD-146The DBA must be consistent with the legal name and every other fieldbrand.dba vs brand.company_nameHighHIGH

The DBA must be recognisably the same business as the legal name, the website, and the campaign — not an unrelated third name.

BRD-149The opt-in evidence must be on the brand's own domainevidence domain vs brand.websiteHighHIGH

The website domain shown in the opt-in evidence must match the brand's registered domain.

BRD-164The named contact must be authorised to act for the businessbrand.authorized_repHighHIGH

The brand contact must be an authorised representative of the business, not a generic, third-party or aggregator name.

BRD-168Consent must name the seller whose messages are deliveredthe consent text vs the sending entityHighHIGH

Where a reseller or agency sends, the consent must authorise messages delivered, or caused to be delivered, by the named seller.

BRD-172Document every Texas exemption you rely onTexas exemption evidenceHighHIGH

Where a Texas exemption is relied upon, the basis for it must be documented and retained.

BRD-174Per-EIN brand counts are capped even where several are allowedbrand.ein across the registryHighHIGH

Where a provider permits more than one brand per tax ID, the number is still capped and each additional brand needs a documented business reason.

BRD-178Brand contact details must be unique across brandsbrand.email + brand.phone + brand.streetHighHIGH

Each brand must have its own contact address, email and phone; reusing them across brands is a policy violation.

BRD-194Subscribe to brand status events instead of pollingthe webhook configurationHighHIGH

Brand status changes should be received as events on a webhook rather than discovered by polling.

BRD-208A score below the threshold means fixing the data, not re-vettingbrand.vetting_scoreHighHIGH

Where the vetting score is below the carrier or use-case threshold, the underlying brand data must be corrected before a re-vet.

BRD-209The score maps to specific throughput termsbrand.vetting_scoreHighHIGH

The vetting score determines the carrier class and daily throughput the brand receives, and 75 or above is the target.

BRD-210A low trust score blocks or narrows campaign registrationbrand.trust_scoreHighHIGH

A provider trust score at or below the gate blocks campaign registration entirely, and one just above it restricts which use cases are available.

BRD-218Import the same token into every instance of the same brandthe vet token across brand instancesHighHIGH

Where the same brand is registered by more than one CSP, the same vetting token must be imported into each instance.

BRD-222Editing the brand expires a completed vetthe brand diff vs the vet stateHighHIGH

A completed vet expires when the brand information behind it changes.

BRD-227The emailed verification link expires after a weekthe Authentication+ email linkHighHIGH

The Authentication+ verification link and PIN expire after seven days and must be re-requested.

BRD-232Only three registration shapes may skip the automatic vetbrand.skip_automatic_sec_vetHighHIGH

The skip-automatic-vetting flag may be set only for Low-Volume Standard registrations, 527 political organisations, and Campaign-Verify-registered brands.

BRD-234Vet before the campaign, not after the volume disappointsthe vet recordHighHIGH

External vetting should be ordered before registering a campaign that needs material volume.

BRD-235The daily carrier cap is an EIN-level allowance, pooled across CSPsdaily volume against brand.einHighHIGH

The T-Mobile daily brand cap is an allowance against the tax ID, pooled across every campaign and every CSP that registered it, resetting at midnight Pacific.

BRD-238Re-vet annuallythe vet ageHighHIGH

Brand vetting must be renewed each year, with the 2FA verification completed again to the brand email on file.

BRD-260Attach every page of a multi-page documentthe appeal attachmentsHighHIGH

Where a supporting document runs to several pages, all of them must be attached — partial submissions are rejected.

BRD-261Only federal tax documentation counts in an appealthe appeal attachmentsHighHIGH

Appeals must rely on federal-level tax documentation; state-level documents are not accepted.

BRD-271Brand content must be submitted in Englishall brand text fieldsHighHIGH

Every brand text field must be submitted in English; non-English submissions are rejected as untranslatable.

BRD-272The end-business block must be complete, not partly filledthe end-business blockHighHIGH

On a toll-free verification, every end-business detail must be populated rather than a subset of them.

BRD-273Contact, email, address and URL must each stand up on their ownbrand.authorized_rep + brand.email + address + brand.websiteHighHIGH

The representative, the email, the address and the website must each independently resolve or validate.

BRD-037Low-Volume Standard is not available to a non-US brand that needs vettingbrand.country + brand classMediumMEDIUM

A non-US brand cannot stay on the Low-Volume Standard class once additional vetting is required of it.

BRD-051Russell 3000 membership sets the starting carrier classbrand.company_name + the Russell 3000 listMediumMEDIUM

A verified public brand on the Russell 3000 starts at the top carrier classes; one that is not starts at the bottom until it is vetted.

BRD-059A unified fundraising short code needs five years of operating historycharity operating historyMediumMEDIUM

A charity seeking a single unified short code for fundraising must demonstrate at least five years of operation.

BRD-090A sole-proprietor brand cannot move between providersbrand migration requestMediumMEDIUM

Sole-proprietor brands cannot be migrated from one CSP to another.

BRD-106The business phone should be findable in a web searchbrand.phoneMediumMEDIUM

The registered business phone number should be discoverable through a public web search for the business.

BRD-126The brand website is the root domain, not a page inside itbrand.websiteMediumMEDIUM

The brand website must be submitted as the root domain rather than a deep link or sub-path.

BRD-151Vertical must come from the correct provider-specific listbrand.verticalMediumMEDIUM

The industry vertical must be chosen from the list the target platform uses, which is not always the TCR vertical list.

BRD-154The account tier cannot be changed more than once a quarterbrand.brand_relationshipMediumMEDIUM

brandRelationship must not be changed more than once in any three-month period.

BRD-155Regions of operation come from a five-value enumbrand.business_regions_of_operationMediumMEDIUM

business_regions_of_operation must be drawn from AFRICA, ASIA, EUROPE, LATIN_AMERICA and USA_AND_CANADA.

BRD-156The representative needs an enum job position and their real titlebrand.authorized_rep.job_position + .titleMediumMEDIUM

job_position must come from Director, GM, VP, CEO, CFO, General Counsel or Other, and the representative's exact business title must be supplied alongside it.

BRD-157Say whether you are the business or a reseller registering for itbrand.business_identity + brand.is_resellerMediumMEDIUM

The business-identity and reseller flags must say correctly whether the registering party is the brand itself or an ISV, reseller or partner.

BRD-163Name the ISV on a toll-free verification filed for someone elsetfv.isv_nameMediumMEDIUM

Where a toll-free verification is submitted on behalf of an end business, the ISV or reseller name must be disclosed.

BRD-169Decide whether this brand is the seller or the telemarketerthe brand's role classificationMediumMEDIUM

The brand's role — seller or telemarketer — must be established, because the obligations and the liability differ.

BRD-170An agency arrangement does not shield either party in Virginiathe brand's role classificationMediumMEDIUM

Virginia holds the telephone solicitor and the seller jointly liable, and an agency arrangement does not shield either from the other's failure.

BRD-181A CSP has a default cap on how many brands it may registerthe CSP brand countMediumMEDIUM

A CSP must not exceed the default cap of 1,000 registered brands without requesting an increase.

BRD-182A brand has a default cap on how many campaigns it may carrythe campaign count under the brandMediumMEDIUM

A brand must not exceed the default cap of 50 campaigns without requesting an increase.

BRD-186Some providers lock a verified brand entirelythe brand record after verificationMediumMEDIUM

On at least one provider, a brand's details become uneditable once it is verified.

BRD-212Vetting is not a remedy for a rejectionthe reason a vet is being orderedMediumMEDIUM

External vetting exists to raise throughput, not to reverse a rejection, and it is not guaranteed to raise anything.

BRD-214An enhanced vet buys nothing on top of a top standard scorebrand.vetting_score + vet classMediumMEDIUM

An enhanced vet must not be ordered where the standard vet has already returned a score at the top band.

BRD-221Respect the cooldown before re-ordering a vetthe re-vet request + the brand diffMediumMEDIUM

A vet must not be re-ordered against unchanged brand information, nor more than once in three months after the first post-registration re-vet.

BRD-229An unanswered 2FA is not an appealable failurethe Authentication+ failure reasonMediumMEDIUM

An Authentication+ failure caused by an unanswered 2FA email must be resolved with a new vet rather than an appeal.

BRD-257Keep the appeal explanation inside its limitappeal.explanationMediumMEDIUM

The appeal explanation must be no longer than 1,024 characters.

BRD-258Respect the appeal attachment limitsthe appeal attachmentsMediumMEDIUM

An appeal may carry at most ten attachments, each no larger than 10 MB, and no more than 30 MB in total.

BRD-026An alternate identifier needs its type alongside itbrand.alt_business_id + brand.alt_business_id_typeLowLOW

Where altBusinessId is supplied, altBusinessIdType must be one of DUNS, GIIN, LEI or NONE.

BRD-158Social profiles corroborate a brand that is otherwise thinbrand.social_profilesLowLOW

Social-media profile URLs should be supplied to strengthen brand verification.

BRD-204Test against mock brands, not real onesbrand.mockLowLOW

Non-production submissions should use mock brands so fees are not charged and duplicate detection is not polluted.

BRD-211Some score inputs cannot be fixed by editing the formthe firmographic profileLowLOW

Company size, years in operation and domain age drive the trust score and cannot be improved by data entry.

The other 7 layers

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.