# BRD-119 — Confirm the mailbox accepts outside mail before triggering 2FA

> The brand contact mailbox must be able to receive external mail before Authentication+ 2FA is triggered.

- **Rule ID:** BRD-119
- **Layer:** Brand (`BRAND`)
- **Checks:** `brand.business_contact_email deliverability`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** Not knowable before submission — reported with its deadline
- **Fix type:** Wait on an external system or a required interval
- **Required by:** Twilio
- **Applies:** Applies when the brand is a public company.
- **Canonical URL:** https://ekas.io/rules/10dlc/brand/brd-119/

## Why this rule exists

Corporate mail filters reject or quarantine unfamiliar senders, and a verification mail that is silently dropped looks identical to one that was never sent — the brand waits in an authentication-required state and nobody knows why. Larger companies, which are exactly the ones registering as public, have the strictest filters.

## How to fix it

Send a test message from an outside domain to this mailbox and confirm it lands in the inbox rather than in quarantine. Where IT filters unknown senders, have the provider's sending domain allow-listed before the vet is ordered.

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio | `21738` | yes |

## Check this yourself

**Has a test message from an outside domain reached this mailbox's inbox, rather than its quarantine?**

1. Send the test from a personal account and have the contact confirm it landed in the inbox — not in a junk folder or a quarantine digest.
2. In a filtered corporate environment, get the provider's sending domain allow-listed by IT before the vet is ordered.
3. The 30-day vet window runs whether or not the mail arrived, so do this first.

*What wrong looks like:* A silently quarantined verification mail is indistinguishable from one that was never sent. The brand waits in an authentication-required state and nobody knows why.

## Notes

Deliverability is only observable after the mail is sent. What the user has to do is test it first — one message from a personal account — and, in a filtered environment, get the verification sender allow-listed before ordering the vet, because the 30-day window (BRD-226) runs whether or not the mail arrived.
