# MSG-101 — Links must not be intended to deceive or cause harm

> Embedded links must not be designed to mislead the recipient or deliver harm.

- **Rule ID:** MSG-101
- **Layer:** Message content (`MESSAGE_CONTENT`)
- **Checks:** `campaign.sample[] + link destinations`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Hard stop — not remediable, resubmission will not help
- **Required by:** CTIA, T-Mobile, Twilio, TCR
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/message-content/msg-101/

## Why this rule exists

Phishing and malware delivery are Severity-0 findings carrying "cease all messaging", and the audit scope explicitly includes the landing page and any downloaded artifact — not just the SMS body. This is judged on intent and presentation, not on the URL string.

## How to fix it

Remove any link whose presentation misrepresents where it leads or what it does. Link text and destination must match.
