{
  "id": "BRD-112",
  "slug": "brd-112",
  "title": "Brand contact email must not be a role or distribution address",
  "statement": "The brand business-contact email must be an individual mailbox, not a role or group address such as info@ or sales@.",
  "rationale": "The contact address receives the Authentication+ verification PIN, and a shared inbox either loses it or is not monitored inside the short expiry window. Several providers reject role addresses outright for that reason, which surprises brands who deliberately used a \"professional\" address.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "brand.email",
  "severity": "HIGH",
  "detectability": [
    "DETERMINISTIC"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "AWS",
    "Twilio"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Use a named individual mailbox on the business domain that someone actually monitors — the verification PIN expires quickly and cannot be resent indefinitely.",
  "example": "jane.doe@acmecoffee.com rather than info@acmecoffee.com",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/brand/brd-112/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-112.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
