The sender must be identified and authenticated before any message goes out

The requirementstatement

Sufficient identifying information must be obtained to verify and authenticate the sender's identity before that sender sends any message.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
the brand identity bundle
Where it liveslayer
BrandBRAND
How Ekas settles itdetectability
External recordEXTERNAL_DATA
The fact that settles it lives in a register we cannot query, such as the IRS file, a postal database, or another provider’s tenant. Reported as a warning with the evidence to check, not as a pass.
What the fix involvesfailureClass
Wait on someone elseTERMINAL_EXTERNAL
Needs an external system or a waiting period, such as IRS propagation, a vetting result, or a carrier queue.
Who requires itauthorities
CTIA
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

This is the know-your-customer duty the whole registration framework implements, and it sits on the aggregator rather than on the brand: nobody may send until somebody has established who they are. It is worth stating explicitly because it explains why so many of the other brand rules are unyielding about evidence — they are how this obligation is actually discharged.

How to fix itremediation

Complete brand registration and identity verification before enabling any traffic, and keep the identity evidence on file for as long as the sender is active. Done when no number can send under this brand before its identity status is verified.

Check this yourselfattestation

No tool can settle this one for you. Here is the check, and what wrong looks like.

Does your provider actually block traffic under this brand until its identity status is verified?

  1. 1Ask the provider directly, or test it: attempt a send under an unverified brand and see whether it is refused.
  2. 2Keep the identity evidence on file for as long as the sender is active — this duty sits on the aggregator, and the evidence is how it is discharged.

What wrong looks like: A provider that lets traffic flow before verification looks like a convenience and is a liability: the enforcement lands later, on a live programme, and harder.

Notesnotes

CTIA Messaging Principles §3.2.4 places this duty on the CPaaS or aggregator, not on the brand, so it is not something a registration can satisfy by itself. What the user has to confirm is that their provider actually enforces it — a provider that lets traffic flow before verification is a risk to its customers rather than a convenience, because the enforcement lands later and harder.

Rules you will hit next

Other brand rules at the same severity. A registration is judged as a whole, not rule by rule.

All brand rules

BRD-166 is one of 196 brand rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.