No simulated-phishing or security-testing programmes

The requirementstatement

Campaign content must not promote simulated phishing and security-awareness test messaging.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
campaign.description + campaign.sample[] + campaign.message_flow
How Ekas settles itdetectability
AI · formAI_FORM
A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
What the fix involvesfailureClass
Hard stopHARD_STOP
Not remediable. Resubmitting will not help, and anyone offering to fix it is selling you a rejection.
Who requires itauthorities
TwilioT-Mobile
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

A simulated phishing text is indistinguishable from a real one to every system that handles it, so it trains carrier filters on the sender, generates the same consumer complaints, and reaches the same people — including employees who left months ago and whoever now holds a recycled number. T-Mobile fines it at Tier 1, the same band as actual phishing, which surprises security teams badly because the intent is defensive and the programme was signed off internally. Intent is not a defence the network can see.

How to fix itremediation

Move the simulation off SMS. Run the exercise on channels you control end to end — corporate email, an internal app, a managed device — where the deception never touches the public network. Where the awareness programme itself is worth texting about, register it on honest copy: reminders, enrolment and results, with nothing designed to be mistaken for something else.

Common mistakespitfalls

  • Internal authorisation and a signed engagement letter do not change the verdict: the carrier is assessing the traffic on its network, and the employer's consent is not the recipient's.

Provider rejection codescodes

The code you get back when this rule is what failed, and whether that provider lets you resubmit.

ProviderCodeResubmit
Twiliogen130884No
Twilio30007Yes

Notesnotes

T-Mobile prices this at Severity-0 Tier 1, $2,000 per violation — the same band as real phishing, and assessed per message.

Rules you will hit next

6 other rules read campaign.description + campaign.sample[] + campaign.message_flow. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.

All message content rules

MSG-250 is one of 122 message content rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.