Content must not solicit credentials or sensitive data

The requirementstatement

Messages must not ask recipients for passwords, full card numbers, SSNs, or account credentials.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
campaign.sample[]
How Ekas settles itdetectability
AI · formAI_FORM
A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
What the fix involvesfailureClass
Hard stopHARD_STOP
Not remediable. Resubmitting will not help, and anyone offering to fix it is selling you a rejection.
Who requires itauthorities
CTIAT-MobileTwilioTCR
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

Credential solicitation over SMS is indistinguishable from smishing from the carrier’s side, and it is filtered and fined accordingly. Legitimate businesses do not need it — verification belongs behind an authenticated session, not in a text reply.

How to fix itremediation

Remove any request for credentials or full financial identifiers. Link to an authenticated page on your own domain instead of collecting data by reply.

Rules you will hit next

6 other rules read campaign.sample[]. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.

All message content rules

MSG-PHISHING is one of 122 message content rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.