# BRD-111 — The contact email domain must be provably the brand's

> The brand contact email must be on a domain the business demonstrably owns — shown on its website, matching WHOIS, or verified by DNS.

- **Rule ID:** BRD-111
- **Layer:** Brand (`BRAND`)
- **Checks:** `brand.business_contact_email domain`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page; External record we cannot query — reported as a warning to verify
- **Fix type:** Fix the field — a better value in the form clears it
- **Required by:** Twilio, TCR
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/brand/brd-111/

## Why this rule exists

Authentication+ sends a PIN to this mailbox and treats whoever answers it as the business, so domain ownership is the thing being verified rather than a formality about tidy addresses. A domain that appears nowhere on the brand's own site cannot be tied back to it, and the verification is refused rather than delayed.

## How to fix it

Use a mailbox on the same domain as the registered website, and make sure that domain appears as a contact address somewhere on the site. Where the business uses a different mail domain, publish it on the site's contact page before submitting. Done when the domain in the email can be found on the brand's own website.

## Example of a compliant value

```text
business_contact_email: jane.doe@acmecoffee.com · website: https://acmecoffee.com
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio | `21736` | yes |

## Check this yourself

**Can the email domain on this brand be found on the brand's own website?**

1. Open the registered website and look for an address on this domain — the contact page is where a reviewer looks.
2. Where the business uses a different mail domain from its website, publish it on the contact page before submitting. That is the cheapest way to establish ownership.
3. Authentication+ sends a PIN to this mailbox and treats whoever answers it as the business, so the domain is the thing being verified.

*What wrong looks like:* A mail domain that appears nowhere on the site cannot be tied back to the business, and the verification is refused rather than delayed.

## Notes

Absorbs BRD-118, which is the same ownership requirement stated for the Auth+ flow. Recommended universally and mandatory for public companies. The crawl can tell us whether the domain appears on the site; WHOIS and DNS TXT verification are external, so where the site does not show the address the user has to establish ownership another way — usually by publishing it on the contact page, which is also the cheapest fix.
