{
  "id": "BRD-166",
  "slug": "brd-166",
  "title": "The sender must be identified and authenticated before any message goes out",
  "statement": "Sufficient identifying information must be obtained to verify and authenticate the sender's identity before that sender sends any message.",
  "rationale": "This is the know-your-customer duty the whole registration framework implements, and it sits on the aggregator rather than on the brand: nobody may send until somebody has established who they are. It is worth stating explicitly because it explains why so many of the other brand rules are unyielding about evidence — they are how this obligation is actually discharged.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "the brand identity bundle",
  "severity": "BLOCKING",
  "detectability": [
    "EXTERNAL_DATA"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Complete brand registration and identity verification before enabling any traffic, and keep the identity evidence on file for as long as the sender is active. Done when no number can send under this brand before its identity status is verified.",
  "notes": "CTIA Messaging Principles §3.2.4 places this duty on the CPaaS or aggregator, not on the brand, so it is not something a registration can satisfy by itself. What the user has to confirm is that their provider actually enforces it — a provider that lets traffic flow before verification is a risk to its customers rather than a convenience, because the enforcement lands later and harder.",
  "phase": "approval",
  "automated": false,
  "attestation": {
    "question": "Does your provider actually block traffic under this brand until its identity status is verified?",
    "howToCheck": [
      "Ask the provider directly, or test it: attempt a send under an unverified brand and see whether it is refused.",
      "Keep the identity evidence on file for as long as the sender is active — this duty sits on the aggregator, and the evidence is how it is discharged."
    ],
    "failureLooksLike": "A provider that lets traffic flow before verification looks like a convenience and is a liability: the enforcement lands later, on a live programme, and harder."
  },
  "url": "https://ekas.io/rules/10dlc/brand/brd-166/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-166.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
