{
  "id": "CON-090",
  "slug": "con-090",
  "title": "The disclosure should say which number the messages come from",
  "statement": "The call-to-action should state the phone number or short code the programme will send from.",
  "rationale": "An unrecognised number is the most common reason a legitimate message gets reported as spam. Telling the consumer at signup which number to expect is what lets them recognise the first message instead of blocking it, and it is the cheapest protection a programme has against its own delivery rates.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "consent disclosure text + campaign number set",
  "severity": "MEDIUM",
  "detectability": [
    "CRAWL",
    "VISION"
  ],
  "failureClass": "TERMINAL_WEBSITE",
  "authorities": [
    "CTIA",
    "T-Mobile"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add the sending number or short code to the consent block, and update it if you change numbers. Where you send from a pool, say so and name the range or the short code rather than listing every number. Done when the consumer knows what will appear on their screen.",
  "example": "Messages come from short code 55512. Msg frequency varies. Msg & data rates may apply.",
  "pitfalls": [
    "Publishing a number you later migrate away from is worse than publishing none — treat the disclosure as something to keep current, not to set once."
  ],
  "notes": "Graded MEDIUM, matching the catalog. CTIA lists it as element (2) of the call to action but no provider rejects on it alone, so it is surfaced as an improvement rather than a blocker.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-090/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-090.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
