{
  "id": "BRD-111",
  "slug": "brd-111",
  "title": "The contact email domain must be provably the brand's",
  "statement": "The brand contact email must be on a domain the business demonstrably owns — shown on its website, matching WHOIS, or verified by DNS.",
  "rationale": "Authentication+ sends a PIN to this mailbox and treats whoever answers it as the business, so domain ownership is the thing being verified rather than a formality about tidy addresses. A domain that appears nowhere on the brand's own site cannot be tied back to it, and the verification is refused rather than delayed.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "brand.business_contact_email domain",
  "severity": "BLOCKING",
  "detectability": [
    "CRAWL",
    "EXTERNAL_DATA"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "Twilio",
    "TCR"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "21736",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Use a mailbox on the same domain as the registered website, and make sure that domain appears as a contact address somewhere on the site. Where the business uses a different mail domain, publish it on the site's contact page before submitting. Done when the domain in the email can be found on the brand's own website.",
  "example": "business_contact_email: jane.doe@acmecoffee.com · website: https://acmecoffee.com",
  "notes": "Absorbs BRD-118, which is the same ownership requirement stated for the Auth+ flow. Recommended universally and mandatory for public companies. The crawl can tell us whether the domain appears on the site; WHOIS and DNS TXT verification are external, so where the site does not show the address the user has to establish ownership another way — usually by publishing it on the contact page, which is also the cheapest fix.",
  "catalogIds": [
    "BRD-118"
  ],
  "phase": "approval",
  "automated": true,
  "attestation": {
    "question": "Can the email domain on this brand be found on the brand's own website?",
    "howToCheck": [
      "Open the registered website and look for an address on this domain — the contact page is where a reviewer looks.",
      "Where the business uses a different mail domain from its website, publish it on the contact page before submitting. That is the cheapest way to establish ownership.",
      "Authentication+ sends a PIN to this mailbox and treats whoever answers it as the business, so the domain is the thing being verified."
    ],
    "failureLooksLike": "A mail domain that appears nowhere on the site cannot be tied back to the business, and the verification is refused rather than delayed."
  },
  "url": "https://ekas.io/rules/10dlc/brand/brd-111/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-111.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
