# BRD-227 — The emailed verification link expires after a week

> The Authentication+ verification link and PIN expire after seven days and must be re-requested.

- **Rule ID:** BRD-227
- **Layer:** Brand (`BRAND`)
- **Checks:** `the Authentication+ email link`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** Not knowable before submission — reported with its deadline
- **Fix type:** Wait on an external system or a required interval
- **Required by:** AWS, Vonage, Telnyx, Aegis
- **Applies:** Applies when the brand is a public company.
- **Canonical URL:** https://ekas.io/rules/10dlc/brand/brd-227/

## Why this rule exists

Two different clocks run on the same vet: thirty days for the vet, seven for the mail inside it — so the link dies three weeks before the vet does, and a contact who returns from leave to find the message finds a link that no longer works. Requesting a fresh one is simple and nothing tells you that it is what you need.

## How to fix it

Re-request the verification mail rather than waiting on the old one, and have the contact complete it the same day it arrives. Done when the PIN is accepted and the brand reports Authentication+ active.

## Check this yourself

**Will the contact be available to complete the PIN the same day the mail arrives?**

1. Request the verification mail when the contact is at their desk — the link is short-lived, roughly seven days inside a thirty-day vet window.
2. If they return from leave to a dead link, re-request a fresh mail rather than waiting on the old one. Nothing tells you that is what you need.

*What wrong looks like:* The link dies three weeks before the vet does. The contact finds the message, clicks it, and gets an error that suggests the whole vet has failed.

## Notes

The seven-day figure comes from the CPaaS documentation and is marked UNVERIFIED against a secondary source in the research; the thirty-day vet window (BRD-226) is TCR's own and is firm. What the user has to do is treat the link as short-lived whichever number is right: request it when the contact is available, not before.
