All 915 10DLC rules

A2P 10DLC rule registry

10DLC campaign rules

A campaign is a set of promises about what you will send, to whom, and how they asked. These rules cover use-case selection, field bounds, the attribute declarations that gate throughput, and the evidence each declaration silently commits you to producing.

94 rules· 60 blocking · 24 high · 7 medium · 3 low

CMP-003Message flow must not begin or end with whitespacecampaign.message_flowBlockingBLOCKING

The opt-in / message-flow field must carry no leading or trailing whitespace.

CMP-017Every mandatory campaign attribute must be explicitly setcampaign attributesBlockingBLOCKING

The mandatory campaign boolean attributes — embeddedLink, embeddedPhone, ageGated, directLending and numberPool — must each be explicitly true or false, never left unset.

CMP-028Opt-in evidence must be a JPG, PNG or PDF under 500 KBcampaign opt-in evidence uploadBlockingBLOCKING

Uploaded opt-in evidence must be a JPG, PNG or PDF file no larger than 500 KB.

CMP-035The description must describe this programme, not messaging in generalcampaign.descriptionBlockingBLOCKING

The campaign description must describe this specific programme rather than restating that the business sends messages.

CMP-037The description must name the business that sends the messagescampaign.descriptionBlockingBLOCKING

The campaign description must name the business whose messages these are, not the platform or agency registering on its behalf.

CMP-038Campaign fields must reference one company, not severalcampaign.description + campaign.message_flow + campaign.sample[]BlockingBLOCKING

No campaign field may reference a second company, subsidiary, franchise or client brand alongside the registered one.

CMP-040Promotional content anywhere requires MARKETING to be declaredcampaign.description + message_flow + sample[] ↔ campaign.usecaseBlockingBLOCKING

Where any campaign text describes promotional or marketing content, MARKETING must be a declared use case or sub-use case.

CMP-045The programme must be application-to-person, not personal messagingcampaign.description + campaign.message_flowBlockingBLOCKING

A campaign must describe application-to-person business messaging, not person-to-person or influencer-to-follower messaging.

CMP-056An ISV registering for a customer must supply the customer's detailscampaign fields + brand.websiteBlockingBLOCKING

Where an ISV or platform registers on behalf of a customer, the campaign must carry the customer's website and brand information, not the platform's.

CMP-059Message flow must describe the mechanism end to endcampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state the exact consent-capture mechanism end to end.

CMP-060Every opt-in method in use must be listed in the message flowcampaign.message_flowBlockingBLOCKING

All opt-in methods actually in use must be described inside the single message-flow field.

CMP-061Each declared method needs its own complete workflow paragraphcampaign.message_flowBlockingBLOCKING

Every declared opt-in method must carry its own description satisfying that method's own rule set.

CMP-064The opt-in page URL must be a deep link to the consent surfacecampaign.message_flow + websiteBlockingBLOCKING

The URL in the message flow must point at the page that carries the consent surface, verified against the crawl.

CMP-065A hosted artifact is required when the opt-in is not publicly crawlablecampaign.message_flow + consent artifactBlockingBLOCKING

Where the opt-in surface is login-gated, unpublished, on paper, verbal, or in-store, a publicly hosted screenshot URL is required in the message flow.

CMP-067The hosted evidence URL must return the artifact, not an error pagehosted evidence URLBlockingBLOCKING

A hosted evidence URL must return 200 and render the artifact rather than a 404, a timeout, a redirect or a placeholder.

CMP-072Message flow must state the message typescampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state the message types the subscriber will receive.

CMP-073Message flow must state message frequencycampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state the message frequency.

CMP-074Message flow must state that rates may applycampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state that message and data rates may apply.

CMP-075Message flow must state how to get helpcampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state how the consumer gets help.

CMP-076Message flow must state how to opt outcampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state how the consumer opts out.

CMP-077Message flow must carry the termscampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state the programme terms, either in full or as a link.

CMP-078Message flow must carry the privacy commitmentcampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state the privacy policy link, or that opt-in data will not be shared.

CMP-079Message flow must describe the consumer-facing opt-in actioncampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state how the consumer is told about the programme and what they do to join.

CMP-082Message flow must state where the opt-in occurscampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state where on the site, app, or premises the opt-in happens.

CMP-084Message flow must state who opts in and whencampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state who is opting in and at what moment.

CMP-085Message flow must state how consent is recordedcampaign.message_flowBlockingBLOCKING

The message-flow / CTA field must state how consent is recorded once given.

CMP-088The opt-in path should follow a published flow templatecampaign.message_flowBlockingBLOCKING

The described opt-in should follow one of the published message-flow templates: digital, verbal, paper, or inbound keyword.

CMP-089Some opt-in must be described somewherecampaign.description + campaign.message_flowBlockingBLOCKING

The description or the message flow must describe some form of opt-in, however briefly.

CMP-091Implied consent needs a conversation the consumer startedcampaign.usecase + campaign.message_flowBlockingBLOCKING

Implied consent is acceptable only where both the use case and the message flow are conversational, with the consumer sending first.

CMP-092Consent grade must match content gradecampaign.message_flow + campaign.usecaseBlockingBLOCKING

The consent standard evidenced must match the content grade: conversational needs implied consent, informational needs express consent, promotional needs express written consent.

CMP-095A web opt-in must supply the form itself, not just describe itcampaign.message_flow + opt-in evidenceBlockingBLOCKING

A web-form or checkout opt-in must supply the link to the opt-in page, or a screenshot of the form.

CMP-096Keyword opt-in requires both the keywords and the confirmation textcampaign.optin_keywords + campaign.optin_messageBlockingBLOCKING

A keyword-based opt-in must populate both the opt-in keywords and the opt-in confirmation message.

CMP-097A keyword opt-in must give the keyword and the number to text it tocampaign.message_flowBlockingBLOCKING

A keyword opt-in must state the exact keyword and the exact destination number in the message flow.

CMP-100The declared opt-in methods must match the flow describedcampaign.opt_in_methods[] + campaign.message_flowBlockingBLOCKING

The opt-in methods ticked on the form must be the ones the message flow describes, in both directions.

CMP-101A QR opt-in must supply the QR code image itselfopt-in evidence (OptInImageURLs)BlockingBLOCKING

A QR-code opt-in must include the QR image in the registration evidence.

CMP-103A QR flow must say where the code leadscampaign.message_flow + QR destinationBlockingBLOCKING

A QR opt-in must state whether the code opens a hosted opt-in form or a pre-filled SMS in the native messaging app.

CMP-112A promotional programme cannot rest on spoken consent alonecampaign.usecase + declared consent methodsBlockingBLOCKING

A campaign whose content requires express written consent must not declare a spoken opt-in as its only collection method.

CMP-119Consent collected on a third-party platform must still name the registered brandopt-in evidence captured on a third-party surfaceBlockingBLOCKING

Consent evidence captured on a third-party platform must show the registered brand as the party the consumer agreed to hear from.

CMP-129Evidence must come from one company, not severalopt-in evidence across the bundleBlockingBLOCKING

A campaign's opt-in evidence must all come from the registered brand, not from subsidiaries, franchises or client brands.

CMP-132Where the platform has no upload field, proof must be a URL in the flow textcampaign.message_flow + hosted evidence URLsBlockingBLOCKING

On a platform offering no evidence upload, every artifact must be reachable from a public URL written into the message-flow text.

CMP-139Each declared sub-use case needs its own sample messagecampaign.sample[] + campaign.sub_use_cases[]BlockingBLOCKING

A campaign declaring sub-use cases must carry at least one sample message for each of them.

CMP-141Sample count must meet the minimum for the declared use casecampaign.sample[] + campaign.usecaseBlockingBLOCKING

The campaign must carry at least the number of sample messages its use case requires.

CMP-142Use case must be available to the brand entity typecampaign.usecase + brand.entity_typeBlockingBLOCKING

Restricted use cases must only be selected by the entity types eligible for them.

CMP-175Subscriber attributes must be true where the API accepts nothing elsecampaign.subscriber_optin + subscriber_optout + subscriber_helpBlockingBLOCKING

On a CSP whose API accepts only true for the subscriber opt-in, opt-out and help attributes, none of the three may be submitted false.

CMP-176Declaring opt-in requires opt-in keywords where the provider pairs themcampaign.optin_keywords + campaign.subscriber_optinBlockingBLOCKING

Where the provider ties the two fields together, declaring subscriberOptin true requires optinKeywords to be populated.

CMP-187The wider opt-out keyword set is required on some platformscampaign.optout_keywordsBlockingBLOCKING

Where the platform publishes a wider standard opt-out set, the declared keywords must cover HALT and STOPALL as well as the universal five.

CMP-AFFILIATEAffiliate marketing campaigns are refusedcampaign.affiliate_marketingBlockingBLOCKING

A campaign declaring affiliate marketing — sharing opt-ins with, or promoting, third parties — is rejected.

CMP-DESC-LENCampaign description must be 40–4096 characterscampaign.descriptionBlockingBLOCKING

The campaign description must be at least 40 and at most 4096 characters.

CMP-FLOW-LENMessage flow must be 40–2049 characterscampaign.message_flowBlockingBLOCKING

The opt-in / message-flow field must be at least 40 and at most 2049 characters.

CMP-HTTPSEvery URL must use HTTPScampaign.sample[] + campaign.message_flow + urlsBlockingBLOCKING

All URLs in the registration must use https://; plain http:// is rejected.

CMP-KEYWORD-FMTOpt-out and HELP keywords must be alphanumeric and under 255 characterscampaign.optout_keywords + campaign.help_keywordsBlockingBLOCKING

Opt-out and help keyword lists must contain only alphanumeric keywords and must not exceed 255 characters.

CMP-LINK-DECLembeddedLink must match whether samples actually contain linkscampaign.embedded_link + campaign.sample[]BlockingBLOCKING

The embeddedLink attribute must be true when any sample contains a URL, and a sample must contain a URL when it is declared true.

CMP-PLACEHOLDERRegistration fields must not contain placeholder textcampaign.* (all text fields)BlockingBLOCKING

No registration field may contain lorem-ipsum, obvious placeholder text, or unreplaced template tokens.

CMP-SAMPLE-COUNTAt least two sample messages are requiredcampaign.sample[]BlockingBLOCKING

A campaign must carry at least two, and at most five, sample messages.

CMP-SAMPLE-LENEach sample message must be 20–1024 characterscampaign.sample[]BlockingBLOCKING

Every sample message must be at least 20 and at most 1024 characters.

CMP-USECASE-ENUMUse case must be a recognised TCR valuecampaign.usecaseBlockingBLOCKING

The declared use case must be one of the recognised TCR use-case values.

CMP-023Declared embedded links must come with a sample URLcampaign.embedded_link_sampleHighHIGH

A campaign declaring embedded links must supply the example link, at most 255 characters and at most fifteen entries.

CMP-041The description must say how often the messages comecampaign.descriptionHighHIGH

The campaign description must disclose the messaging frequency.

CMP-042A programme that asks for money must say socampaign.descriptionHighHIGH

Where the campaign solicits donations, the description must state that donations are collected.

CMP-048Emergency framing requires the emergency use casecampaign.description ↔ campaign.usecaseHighHIGH

A campaign may not describe itself as sending emergency or public-safety alerts unless EMERGENCY is declared and genuinely applies.

CMP-051A first-party lender must use the phrase the reviewer looks forcampaign.descriptionHighHIGH

A campaign whose business performs first-party lending must contain the literal phrase "Direct Lending" in its description.

CMP-052A website that is not live yet must be declared as suchcampaign.description + brand.websiteHighHIGH

Where the brand website is not yet published, the description must say so explicitly.

CMP-057A platform registering its own product must say that it iscampaign.descriptionHighHIGH

Where the registrant is a platform registering a direct offering of its own, the description must state that explicitly.

CMP-062Declared opt-in methods must all actually be usedcampaign opt-in method declarationsHighHIGH

Opt-in methods selected on the registration must be methods the brand genuinely uses; unused selections must be deselected.

CMP-068Evidence links must keep working after approvalhosted evidence URLHighHIGH

Hosted evidence URLs must stay reachable for the life of the campaign, not only until it is approved.

CMP-069A URL mentioned in the CTA must also be given as a link fieldcampaign.message_flow ↔ campaign.privacy_url + terms_urlHighHIGH

Any URL referenced inside the message-flow text must also be supplied in the structured link fields.

CMP-080The disclosure must be reproduced in the registration, not only on the sitecampaign.message_flowHighHIGH

The CTA disclosure text must appear inside the registration itself even when it is also published on the website.

CMP-094Each declared opt-in method needs its own evidenceconsent artifacts + declared methodsHighHIGH

A screenshot or artifact is required for EACH opt-in method declared, not one artifact covering the set.

CMP-115A point-of-sale opt-in must show the sign the customer readhosted evidence URLHighHIGH

A point-of-sale opt-in must supply a hosted photo of the signage, kiosk or tablet screen carrying the disclosure.

CMP-116An email-activated opt-in must show the email that askedopt-in evidenceHighHIGH

Where the opt-in is solicited by email, a screenshot of that email must be supplied.

CMP-118A pop-up opt-in must be declared as onecampaign.message_flowHighHIGH

Where the opt-in is presented in a pop-up or modal, the message flow must say so.

CMP-122The opt-in screenshot must show the terms and privacy linksopt-in screenshotHighHIGH

A screenshot submitted as opt-in evidence must show the Terms and Privacy Policy links as the consumer sees them.

CMP-124A multi-step consent flow must be captured at every stepopt-in screenshotsHighHIGH

Where consent is collected across several screens, evidence must show each step rather than the final one.

CMP-127A consent surface a reviewer cannot reach must be declared as suchcampaign.message_flowHighHIGH

Where the opt-in sits behind a login, is unpublished, is spoken, or is on paper, the submission must say so explicitly.

CMP-131Evidence must travel by the route the submission target actually offersevidence channel + campaign.message_flowHighHIGH

Evidence must reach the reviewer through the channel the submission target provides, whether an upload field, a TCR attachment, or a URL inside the flow.

CMP-PHONE-DECLembeddedPhone must match whether samples contain phone numberscampaign.embedded_phone + campaign.sample[]HighHIGH

The embeddedPhone attribute must be true when any sample contains a phone number, and vice versa.

CMP-SAMPLE-DUPSample messages must not be duplicatescampaign.sample[]HighHIGH

Sample messages must be materially different from one another.

CMP-018Attributes that do not apply to the registration type must be emptycampaign attributesMediumMEDIUM

Conditionally-allowed fields must not be populated when they do not apply to the chosen registration type.

CMP-021Reference id must be 50 characters or fewercampaign.reference_idMediumMEDIUM

The campaign reference id must be at most 50 characters, and unique within the CSP.

CMP-050The description must not contain personal datacampaign.descriptionMediumMEDIUM

The campaign description must not contain individual names, account numbers or other personal data.

CMP-053A site a US reviewer cannot reach must be declared as suchcampaign.description + brand.websiteMediumMEDIUM

Where the website is geo-restricted so a US reviewer cannot open it, the description must disclose that and attach a screenshot.

CMP-188A non-standard opt-out keyword is honoured by nobody but youcampaign.optout_keywordsMediumMEDIUM

Opt-out keywords outside the standard monitored set are handled by the sending platform alone and must not be relied on as carrier-enforced.

CMP-019Policy link fields must be 255 characters or fewercampaign.privacy_url + campaign.terms_urlLowLOW

The privacy policy and terms links must each be at most 255 characters.

CMP-058Some programmes are better served by another channelcampaign.description + campaign.usecaseLowLOW

A campaign whose traffic does not need 10DLC should be told that toll-free or another channel fits it better.

CMP-128An evidence field with nothing to say should be left emptyevidence fieldsLowLOW

Evidence fields that do not apply must be omitted rather than filled with filler text.

The other 7 layers

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.