A public company must finish two-factor identity before any campaign

The requirementstatement

A PUBLIC_PROFIT brand must complete its Authentication+ two-factor identity step before a campaign is created against it.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
brand.entity_type + brand.vetting + campaign submission
Where it liveslayer
Brand ↔ campaignCROSS
How Ekas settles itdetectability
DeterministicDETERMINISTIC
Settled in code from the values you submitted. No model involved, no judgement call, same answer every time.
What the fix involvesfailureClass
Wait on someone elseTERMINAL_EXTERNAL
Needs an external system or a waiting period, such as IRS propagation, a vetting result, or a carrier queue.
Who requires itauthorities
TCR
When it appliesapplicabilityText
Applies when the brand is a public company.

Why this rule existsrationale

Publicly traded brands carry an extra identity step that no other entity type has, and it is the one gate that produces no error while it is outstanding: the brand verifies, looks healthy, and every campaign against it is refused. The two-factor mail goes to the business contact address, so it is routinely missed by the person doing the registration, who is rarely the person on that mailbox.

How to fix itremediation

Order the Authentication+ vet explicitly after the identity check, watch the business contact mailbox for the two-factor mail, and hold the campaign until the vet is recorded on the brand. Done when the brand shows an Authentication+ vet before the campaign is submitted.

Only meaningful once these passdependsOn

  • XBC-006The brand must be verified before its campaign is submitted

Check this yourselfattestation

Ekas flags this from what you submit, but the fact that settles it sits somewhere only you can reach.

Do you know who receives mail at the business contact address, and that they are expecting the Authentication+ two-factor message?

  1. 1Name the person on the business contact mailbox out loud. It is rarely the person doing the registration.
  2. 2Tell them the two-factor mail is coming and what to do with it, then confirm the completed vet appears on the brand before submitting the campaign.

What wrong looks like: The brand verifies and looks healthy, every campaign against it is refused, and the two-factor mail is unopened in a shared inbox nobody watches.

Notesnotes

The vet is an action at the registry, not a field on the submission, and the PIN arrives by mail on the registry's schedule. What the user has to do is confirm who receives the business contact mail and that they know to expect it — BRD-225 covers ordering the vet, BRD-226 the window it must be completed in; this rule is the campaign-side consequence of either being outstanding.

Rules you will hit next

Other brand ↔ campaign rules at the same severity. A registration is judged as a whole, not rule by rule.

All brand ↔ campaign rules

XBC-007 is one of 13 brand ↔ campaign rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.