An artifact proving consent collection must be attached

The requirementstatement

The opt-in / message flow must reference a durable artifact evidencing how consent is collected — a screenshot of the opt-in screen, a PDF or scan of the paper form, the verbal script, or a capture of the QR landing page.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
campaign.message_flow + consent artifact
Where it liveslayer
Consent flowCONSENT_FLOW
How Ekas settles itdetectability
DeterministicDETERMINISTIC
Settled in code from the values you submitted. No model involved, no judgement call, same answer every time.
What the fix involvesfailureClass
Supply evidenceTERMINAL_EVIDENCE
Needs proof only you hold: a screenshot, a recording, a scan of the form people signed.
Who requires itauthorities
Ekas (product policy)CTIATCRTwilioBandwidth
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

Every provider reject list is dense with "opt-in could not be verified" reasons, and a reviewer who cannot see your consent surface has no way to distinguish a compliant one from a claim. CTIA MPBP 5.1.2 separately requires you to retain "a capture of the experience" used to secure consent — so the artifact is something you are obliged to hold anyway. Producing it at registration converts the single most common soft rejection into a solved problem.

How to fix itremediation

Attach proof of your opt-in and reference it in the message flow. For a web form, a full-width screenshot of the form with the consent text visible. For phone consent, the script your agents read. For paper, a scan of the signed form. For QR, a capture of the landing page. Host it somewhere publicly reachable — a reviewer must be able to open it without logging in.

A compliant exampleexample

Consent is collected at https://acmecoffee.com/signup via an unchecked checkbox. Screenshot of the live form: https://cdn.acmecoffee.com/compliance/optin-2026-07.png

Common mistakespitfalls

  • A Google Drive or Dropbox share link that shows a "request access" wall is treated as no evidence at all.
  • A viewer page is not an image — link the file directly so it opens as a picture.

Notesnotes

STRICTER THAN THE BASELINE BY DESIGN, per product policy. TCR does not universally demand an artifact; we do. That is also why CON-037 (a mockup or script for 2FA and OTP campaigns) and CON-039 (an opt-in description or screenshot on toll-free verification) are aliased here rather than written separately: both are this requirement narrowed to one path, and a rule that already demands the artifact from everyone discharges them outright.

Rules you will hit next

5 other rules read campaign.message_flow + consent artifact. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.

All consent flow rules

CON-ART-001 is one of 101 consent flow rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.