{
  "id": "BRD-227",
  "slug": "brd-227",
  "title": "The emailed verification link expires after a week",
  "statement": "The Authentication+ verification link and PIN expire after seven days and must be re-requested.",
  "rationale": "Two different clocks run on the same vet: thirty days for the vet, seven for the mail inside it — so the link dies three weeks before the vet does, and a contact who returns from leave to find the message finds a link that no longer works. Requesting a fresh one is simple and nothing tells you that it is what you need.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "the Authentication+ email link",
  "severity": "HIGH",
  "detectability": [
    "UNDETECTABLE_PRE_SUBMISSION"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "AWS",
    "Vonage",
    "Telnyx",
    "Aegis"
  ],
  "applicability": {
    "entityTypes": [
      "PUBLIC_PROFIT"
    ]
  },
  "applicabilityText": "Applies when the brand is a public company.",
  "universal": false,
  "remediation": "Re-request the verification mail rather than waiting on the old one, and have the contact complete it the same day it arrives. Done when the PIN is accepted and the brand reports Authentication+ active.",
  "notes": "The seven-day figure comes from the CPaaS documentation and is marked UNVERIFIED against a secondary source in the research; the thirty-day vet window (BRD-226) is TCR's own and is firm. What the user has to do is treat the link as short-lived whichever number is right: request it when the contact is available, not before.",
  "catalogIds": [
    "OPS-307"
  ],
  "phase": "approval",
  "automated": false,
  "attestation": {
    "question": "Will the contact be available to complete the PIN the same day the mail arrives?",
    "howToCheck": [
      "Request the verification mail when the contact is at their desk — the link is short-lived, roughly seven days inside a thirty-day vet window.",
      "If they return from leave to a dead link, re-request a fresh mail rather than waiting on the old one. Nothing tells you that is what you need."
    ],
    "failureLooksLike": "The link dies three weeks before the vet does. The contact finds the message, clicks it, and gets an error that suggests the whole vet has failed."
  },
  "url": "https://ekas.io/rules/10dlc/brand/brd-227/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-227.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
