{
  "id": "MSG-250",
  "slug": "msg-250",
  "title": "No simulated-phishing or security-testing programmes",
  "statement": "Campaign content must not promote simulated phishing and security-awareness test messaging.",
  "rationale": "A simulated phishing text is indistinguishable from a real one to every system that handles it, so it trains carrier filters on the sender, generates the same consumer complaints, and reaches the same people — including employees who left months ago and whoever now holds a recycled number. T-Mobile fines it at Tier 1, the same band as actual phishing, which surprises security teams badly because the intent is defensive and the programme was signed off internally. Intent is not a defence the network can see.",
  "layer": "MESSAGE_CONTENT",
  "layerSlug": "message-content",
  "object": "campaign.description + campaign.sample[] + campaign.message_flow",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "HARD_STOP",
  "authorities": [
    "Twilio",
    "T-Mobile"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30884",
      "remediable": false,
      "generation": "gen1"
    },
    {
      "provider": "Twilio",
      "code": "30007",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Move the simulation off SMS. Run the exercise on channels you control end to end — corporate email, an internal app, a managed device — where the deception never touches the public network. Where the awareness programme itself is worth texting about, register it on honest copy: reminders, enrolment and results, with nothing designed to be mistaken for something else.",
  "pitfalls": [
    "Internal authorisation and a signed engagement letter do not change the verdict: the carrier is assessing the traffic on its network, and the employer's consent is not the recipient's."
  ],
  "notes": "T-Mobile prices this at Severity-0 Tier 1, $2,000 per violation — the same band as real phishing, and assessed per message.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/message-content/msg-250/",
  "markdown": "https://ekas.io/rules/10dlc/message-content/msg-250.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
