All 915 10DLC rules

A2P 10DLC rule registry

10DLC operational rules

Registration-side twins of runtime obligations: STOP and HELP handling, quiet hours, suppression scope, consent record retention, and programme change management. These verify what was declared at registration, and record what falls due after approval.

139 rules· 48 blocking · 49 high · 36 medium · 6 low

OPS-026The universal opt-out keyword set must be declaredcampaign.optout_keywordsBlockingBLOCKING

STOP, END, CANCEL, UNSUBSCRIBE and QUIT must all appear in the declared opt-out keyword set.

OPS-027Opt-out keyword handling must be declared, not assumedcampaign.optout_keywordsBlockingBLOCKING

The campaign must declare an opt-out keyword set, and that set must be the one the sending platform is configured to honour.

OPS-029A revocation must survive punctuation, case and surrounding wordsinbound message normalisationBlockingBLOCKING

Opt-out keywords must be matched case-insensitively, tolerantly of punctuation, and when the keyword is surrounded by other text in the same message.

OPS-031A plainly-worded opt-out counts even with no keyword in itinbound message intent classificationBlockingBLOCKING

Revocations phrased in ordinary language — "take me off your list", "please opt me out" — must be honoured even though they contain no declared keyword.

OPS-033STOP must never come back as an errorSTOP response handlerBlockingBLOCKING

A consumer who sends STOP must never receive an error message in response.

OPS-037On a shared address, STOP must stop everythingsubscription registry keyed by number and application addressBlockingBLOCKING

Where several programmes share one application address, STOP must terminate every one of the consumer's active programmes on it, and any keyword menu must offer a STOP ALL option.

OPS-038Opt-out must not be reduced to one prescribed methodcampaign.message_flow + SMS terms + privacy policyBlockingBLOCKING

Published opt-out instructions must not designate an exclusive revocation method — a consumer may use any reasonable channel.

OPS-039A revocation on any channel must reach the SMS suppression listsuppression list ingestion across channelsBlockingBLOCKING

Revocations captured by an IVR key-press, a live agent, a designated website or number, an email or a voicemail must all be written into the same suppression list as a texted STOP.

OPS-043A revocation crosses mediasuppression list scope across voice and SMSBlockingBLOCKING

A revocation sent by text also stops robocalls to that number, and a revocation given on a call also stops texts.

OPS-045Sending stops on receipt, including on a political programmesend-time suppression checkBlockingBLOCKING

No message may be sent to a number after a valid opt-out is received, whatever the campaign type.

OPS-046The honouring clock starts when the revocation arrivessuppression latency, measured from receiptBlockingBLOCKING

The time taken to honour a revocation is measured from receipt of the revocation, not from the confirmation, and must never exceed ten business days.

OPS-056Opt-out records must keep the words the consumer actually sentcampaign.message_flow + privacy policyBlockingBLOCKING

Every opt-out transaction must be recorded with the raw inbound text, the channel it arrived on, and the normalisation that was applied to it.

OPS-066Watch the opt-out rate, and act at both thresholdsper-campaign opt-out rateBlockingBLOCKING

The per-campaign opt-out rate must be monitored, audited above roughly 0.5% on a send, and the campaign suspended with a root-cause analysis above 4% in 24 hours.

OPS-070A referral opt-out covers everything sent through the applicationsuppression scope across a viral applicationBlockingBLOCKING

In a viral or referral programme, an opt-out must be honoured across every message sent through that application, programme or software.

OPS-072The programme must not evade opt-out detectioncampaign.sample[] + campaign.message_flowBlockingBLOCKING

Content engineered to defeat opt-out or content detection — deliberate misspellings, non-standard phrasing — is prohibited.

OPS-078HELP is answered whoever asksHELP keyword handlerBlockingBLOCKING

A HELP request must always produce a response, whether or not the sender is currently subscribed and whether or not the programme is a subscription.

OPS-083Carrier deactivation files must be ingested dailydeactivation feed ingest jobBlockingBLOCKING

The carrier deactivation feeds must be processed every day and the listed numbers removed from every opt-in list.

OPS-085The programme must scrub deactivated numbers before sendingcampaign.message_flow + privacy policyBlockingBLOCKING

The programme must describe checking carrier deactivation data before each send, and logging each ingest.

OPS-102The national do-not-call registry must be scrubbed before any solicitationrecipient list against the national registryBlockingBLOCKING

Recipient lists must be scrubbed against the national do-not-call registry before any telephone solicitation, unless prior express written consent or an established business relationship applies.

OPS-105The internal do-not-call list is checked on every sendrecipient list against the internal do-not-call listBlockingBLOCKING

Every send must be scrubbed against the brand's own company-specific do-not-call list.

OPS-108A do-not-call request is recorded when it is madeinternal do-not-call write latencyBlockingBLOCKING

A do-not-call request must be recorded, with the name and number, at the time the request is made.

OPS-110Some states require the seller to register before texting residentsstate seller registrationBlockingBLOCKING

Before texting a state's residents, determine whether the seller must register with that state and post a bond.

OPS-123Every message needs a valid carrier message-class tagoutbound message class tagBlockingBLOCKING

Every 10DLC A2P message must carry a valid, authorised carrier message class tag.

OPS-135Do not spread one message across many numbersoutbound traffic distribution across numbersBlockingBLOCKING

Similar or identical content must not be distributed across many sending numbers to dilute per-number reputation or evade filtering.

OPS-137Do not burn numbers and replace themnumber provisioning and retirement patternBlockingBLOCKING

Numbers must not be cycled — used until deliverability degrades and then discarded, or freshly provisioned to escape a suspension.

OPS-138A blocked number must not be automatically replacedblocked-number remediation logicBlockingBLOCKING

A number blocked by a receiving network must never be auto-replaced with a fresh one, and a permanent block code must be treated as a programme defect rather than a replacement trigger.

OPS-139One number, one static routeroute configuration per numberBlockingBLOCKING

Each 10DLC, short code or toll-free number must use a single static route; dynamic routing is permitted only for major network outages.

OPS-140Grey routes are not a price advantagetermination path for A2P trafficBlockingBLOCKING

A2P traffic must not be carried over any path or setting not authorised by the service providers for non-consumer messaging.

OPS-141One approved number is controlled by one partynumber to content-provider mappingBlockingBLOCKING

Sub-aggregation is prohibited: no more than one party may control the content sent from, or the numbers receiving on, a single approved number.

OPS-144Do not rotate domains across a bulk senddomains used across a bulk sendBlockingBLOCKING

Multiple fully-qualified domains, or multiple public URL shorteners, must not be cycled across bulk messages carrying similar content.

OPS-149Live content has to keep matching the registrationlive traffic against the registered use case and samplesBlockingBLOCKING

Traffic must continue to match the registered use case and the registered samples, not merely have matched them at approval.

OPS-150Send only the message types the subscriber agreed tomessage type against the consent record scopeBlockingBLOCKING

Message types the subscriber did not consent to must not be sent — a survey to an OTP-only list, marketing to a transactional opt-in.

OPS-153The sender must be who the message says it isoutbound sender identityBlockingBLOCKING

The message number and sender name must not be spoofed or substituted in any way that misleads a consumer.

OPS-154Where the numbers came from mattersoriginating number provenanceBlockingBLOCKING

Volume must not originate from SIM boxes, SIM farms, or disposable, rental or temporary telephone numbers.

OPS-155Sending through a provider you have no relationship with is a red flagthe contractual chain behind the trafficBlockingBLOCKING

A message sender with no business relationship with the CPaaS or wireless provider carrying its traffic must be treated as a compromised-system indicator.

OPS-180Approved samples do not license prohibited contentlive message contentBlockingBLOCKING

Prohibited content must not appear in live traffic regardless of what the approved samples showed.

OPS-210Telemarketing consent must retain the request, its purpose and the answercampaign.message_flow + privacy policyBlockingBLOCKING

Where the Telemarketing Sales Rule applies, the programme must retain the consent request as it was presented, the purpose consent was sought for, and the consent actually given with its date and the consenting party.

OPS-214Telemarketing consent taken by phone must retain the recording of both halvescampaign.message_flowBlockingBLOCKING

Where the Telemarketing Sales Rule applies and consent was spoken, a recording of both the request and the consent given must be retained, making the purpose clear.

OPS-236An IVR opt-in must log the prompt, the keypress, the time and the callcampaign.message_flow + privacy policyBlockingBLOCKING

Every consent record must carry the prompt version played, the digit or spoken answer captured, the timestamp and the call identifier.

OPS-251Consent left unused for a month must be reconfirmedcampaign.message_flowBlockingBLOCKING

Where no message is sent within 30 days of collecting consent, the programme must reconfirm by double opt-in before its first send.

OPS-261Only the charity may use the numbers a charity collectscampaign.message_flow + privacy policyBlockingBLOCKING

A charitable programme must let no entity other than the charity use the collected subscriber data, and only for the campaign it was collected for.

OPS-323An identity appeal has a window, and it runs from brand creationbrand appeal submission vs brand creation dateBlockingBLOCKING

An identity-status appeal must be submitted within 45 calendar days of the brand being created, not of the decision being received.

OPS-324An appeal is void if you edit the identity you are appealingbrand.appeal + brand.brand_changesBlockingBLOCKING

Legal name, entity type, tax ID and tax ID issuing country must not be updated before an appeal is filed, and no brand update may be submitted while one is in flight.

OPS-344A brand carrying live work cannot have its identity edited at allbrand.brand_changes + brand.active_campaign_count + brand.vettingBlockingBLOCKING

Legal name, entity type, tax ID and tax ID issuing country cannot be edited while the brand has an active campaign or a vet in progress.

OPS-384Nothing goes out before the opt-insend-time consent checkBlockingBLOCKING

Messages may be sent only after the consumer has opted in; the single opt-out acknowledgement is the only permitted exception.

OPS-HELP-ONE-TIMEHELP must be supported even on one-time programmescampaign.help_keywordsBlockingBLOCKING

HELP keyword support is required regardless of whether the programme sends recurring messages.

OPS-OPTOUT-CONF-ONLYOpt-out confirmation must be the only message sent after revocationcampaign.optout_messageBlockingBLOCKING

The campaign must declare a single opt-out confirmation and nothing further after a consumer revokes.

OPS-034A programme in another language still owes the English keywordper-locale keyword tableHighHIGH

A programme messaging in a language other than English must honour STOP in that language, and must not return an error to the English keyword.

OPS-035The mandatory keywords must work over MMS tooinbound handler, per protocolHighHIGH

STOP, HELP and the rest of the mandatory keywords must be processed identically whether they arrive as SMS or MMS.

OPS-044Suppression is brand-wide, not per numbersuppression list scope across the brandHighHIGH

An opted-out consumer must be suppressed across every sending number and every campaign belonging to the brand, not only the number that received the STOP.

OPS-047A state may give you less time than the federal limitsuppression latency against the recipient stateHighHIGH

Where the recipient's state sets a shorter cure window for ceasing text solicitations, that window applies instead of the federal maximum.

OPS-052Silence after a scope question revokes everythingscope-clarification timeout handlingHighHIGH

Where a scope-clarification message is sent and the consumer does not reply, the revocation must be treated as covering all robocalls and robotexts from the sender.

OPS-053A STOP answering a scope question must not be answered with anotherscope-clarification loop guardHighHIGH

A STOP sent in reply to a scope-clarification message must not trigger a second clarification message.

OPS-054Revoking against an exempt message stops everything else toosuppression scope after a revocationHighHIGH

Where a consumer revokes in direct response to an exempted informational message, all further non-emergency robocalls and robotexts must stop.

OPS-058Re-read the inbound log for opt-outs the handler missedinbound log reviewHighHIGH

Inbound message logs must be reviewed on a schedule for revocations the keyword handler did not catch, and those subscriptions terminated.

OPS-061A later form fill does not undo an earlier opt-outconsent record against opt-out recordHighHIGH

A consumer who opted out must not be re-subscribed on the strength of a subsequent form submission without a fresh, separately documented opt-in.

OPS-065A carrier opt-out is authoritative even if your list has no recorddelivery error stream into the suppression listHighHIGH

A delivery rejection indicating the carrier holds an opt-out for the number must be treated as a suppression event in its own right.

OPS-068STOP and HELP volumes are a standing reportper-campaign keyword response metricsHighHIGH

STOP and HELP response volumes must be monitored per campaign as an ongoing obligation.

OPS-071Group messaging needs a member opt-out and anti-abuse controlscampaign.message_flow + campaign.descriptionHighHIGH

A group-messaging programme must let any member leave at any time, carry anti-abuse controls proportionate to the distribution size, and prevent recursive group messaging.

OPS-073Toll-free keyword behaviour cannot be customised, so do not promise itcampaign.message_flow + campaign.sample[] + auto-repliesHighHIGH

A toll-free programme must not tell consumers that STOP, UNSTOP or START will behave in any way other than the fixed carrier behaviour.

OPS-075Opt-out instructions must recur, not just appear at opt-inoutbound message cadenceHighHIGH

A recurring programme must carry opt-out instructions at opt-in and at regular intervals thereafter — at least monthly.

OPS-079HELP must work in every form it arrives inHELP keyword handlerHighHIGH

HELP must be case-insensitive, functional over both SMS and MMS, and functional in the programme's language without erroring on the English keyword.

OPS-081The HELP reply must send people somewhere that answerscampaign.help_messageHighHIGH

Every destination named in the HELP reply — a phone number, a URL or an email address — must actually reach help.

OPS-087The reassigned-numbers database is the only route to the safe harbourreassigned-numbers query, keyed on the consent dateHighHIGH

The FCC Reassigned Numbers Database must be queried using the date of consent, and re-queried at least every 30 days.

OPS-088Some states make reassigned-number screening mandatoryreassigned-number screening policyHighHIGH

Where a state requires it, reassigned-number screening is an obligation rather than a safe-harbour option.

OPS-092Local time is where the recipient is, not what their area code saysrecipient location resolutionHighHIGH

The recipient's local time must be derived from their actual location, not from the area code of their number.

OPS-093Several states set a narrower quiet-hours window than the federal onesend time against the recipient state windowHighHIGH

Where the recipient's state sets a narrower window than 8am–9pm, that window applies.

OPS-097Some states cap how often you may raise the same subjectper-recipient send count by subject, 24-hour windowHighHIGH

Where the recipient's state sets one, a per-subject frequency cap — commonly three messages per 24 hours on the same subject matter — must be enforced.

OPS-098There is a per-recipient daily ceiling even without a state ruleper-recipient 24-hour send countHighHIGH

No more than ten messages should reach one recipient in any 24-hour period without two-way engagement or explicit high-frequency consent.

OPS-100A national campaign needs a per-state matrix, evaluated against the strictest ruleper-state rule matrixHighHIGH

A per-state matrix of quiet hours, frequency caps, consent standards and retention windows must be maintained, and every national campaign evaluated against the most restrictive rule that applies to it.

OPS-103A registry snapshot older than a month is not a scrubregistry snapshot age at send timeHighHIGH

The national registry version used for a scrub must be no more than 31 days old at the time the message is sent.

OPS-104Several states run their own do-not-call registryrecipient list against state registriesHighHIGH

Where a state operates a registry that is not fully merged with the federal one, recipient lists must be scrubbed against it as well.

OPS-109The scrub process needs writing down, version dates includedscrub process documentationHighHIGH

The registry access and scrub process must be documented, including the registry version date used for each scrub.

OPS-113A state may impose its own opt-out and identification dutiesopt-out handling and sender identification, per stateHighHIGH

Where a state requires it, opt-out replies must be honoured and accurate sender identification maintained under that state's own rules.

OPS-114A programme relying on the delivery exemption still owes an opt-outcampaign.sample[] + campaign.message_flowHighHIGH

A campaign relying on the package-delivery exemption must offer an opt-out and honour it within six business days.

OPS-124Unregistered and P2P-classified traffic has a hard per-number ceilingper-number per-minute send rateHighHIGH

Traffic classified as P2P or unregistered is limited to roughly fifteen messages or segments per number per minute.

OPS-136The campaign must not duplicate another campaign on the accountcampaign fields across the accountHighHIGH

A campaign whose description, name, website, message flow and samples all match an existing campaign is a snowshoeing signal.

OPS-142A legitimately shared number needs a register of who sends on itshared-number sender registerHighHIGH

Where a number or short code is shared under an approved arrangement, documented records of every message sender operating on it must be immediately available.

OPS-143Distributing like content across several numbers needs an arrangementmulti-number distribution arrangementHighHIGH

Any use case that genuinely needs multiple numbers to distribute similar content requires special arrangements with the service providers.

OPS-156Watch for traffic that is being pumpedtraffic pattern and destination distributionHighHIGH

Content and traffic patterns consistent with artificially inflated traffic must be detected and rejected.

OPS-157A provider can block anything its risk assessment dislikesoverall sending postureHighHIGH

Service providers may block any message a reasonable risk assessment suggests is unwanted, and the triggers include compromised credentials, grey routes, missing authentication and a pattern of abusing best practices.

OPS-199Consent records must capture all seven required fieldscampaign.message_flow + privacy policyHighHIGH

The programme must retain a consent record holding the number, timestamp, medium, a capture of the consent experience, the campaign, an IP or call identifier, and the consenting party.

OPS-201The consent experience itself must be versioned and retainedcampaign.message_flowHighHIGH

A capture of the exact language and action used to secure consent must be retained and versioned per consumer.

OPS-215Express written consent must name the specific number and bear a signaturecampaign.message_flowHighHIGH

The retained consent agreement must identify the specific telephone number consented for and bear the consumer's signature.

OPS-217Consent must be tracked per consumer, not per listcampaign.message_flowHighHIGH

Consent must be recorded against the individual consumer rather than at list level.

OPS-219Opt-out records must be retained alongside opt-inscampaign.message_flow + privacy policyHighHIGH

Revocation requests must be retained for the same period as opt-ins, with the channel recorded.

OPS-221The retention period must clear the longest window that appliescampaign.message_flow + privacy policyHighHIGH

The stated retention period for consent and opt-out records must be the maximum of every applicable window, not the first one the brand found.

OPS-232A spoken opt-in needs a per-consumer artifact, not just a scriptcampaign.message_flowHighHIGH

Verbal consent must be evidenced per consumer by a recording, a transcript, or documented contemporaneous notes — never by the script alone.

OPS-235A spoken consent record must pin the script version that was readcampaign.message_flow + privacy policyHighHIGH

Every consent record must carry the version and effective date of the consent script read to the consumer.

OPS-239Declining to be recorded must not block the opt-incampaign.message_flowHighHIGH

A programme taking spoken consent must have a documented no-recording evidence path, and must never refuse a consumer the opt-in because they declined recording.

OPS-240Recordings must outlive the consent records they evidencecampaign.message_flow + privacy policyHighHIGH

Call recordings must be retained at least as long as the consent records they are the evidence for.

OPS-252Consent collected away from the handset should be confirmed on itcampaign.message_flow + campaign.optin_messageHighHIGH

Where consent is collected outside the SMS channel — web, phone, point of sale or paper — the programme should send a double opt-in confirmation before recurring messages.

OPS-FREQ-COHERENTDeclared frequency must be consistent everywhere it appearsconsent disclosure + terms + campaign.descriptionHighHIGH

The message frequency stated in the consent disclosure, the SMS terms, and the campaign description must agree.

OPS-POOL-DECLAREDNumber pooling must be declared consistently with the campaign scalecampaign.number_poolHighHIGH

The number-pool attribute must reflect whether the campaign will actually send from multiple numbers.

OPS-032A help request containing a stop-word is not an opt-outinbound message intent classificationMediumMEDIUM

An inbound message whose intent is a question must not be treated as a revocation merely because it contains a stop-word.

OPS-042Somebody has to own revocations that arrive in conversationwritten revocation-intake procedureMediumMEDIUM

A documented process must exist for capturing revocations conveyed to customer-service agents, in-store staff or social messages.

OPS-050The opt-out confirmation is worth sending inside five minutesopt-out confirmation latencyMediumMEDIUM

The single permitted opt-out confirmation should reach the consumer within five minutes of the revocation.

OPS-051Only ask which messages to stop when there is more than one kindcampaign.optout_message + campaign.sub_use_casesMediumMEDIUM

A scope-clarification question may appear in the opt-out confirmation only where the consumer consented to several distinct message categories.

OPS-057Log the sends you did not makesuppressed-send logMediumMEDIUM

Every send attempt suppressed because the number was opted out must be logged.

OPS-062An opted-out consumer must be able to come backcampaign.message_flow + campaign.optin_keywordsMediumMEDIUM

The programme must leave a published route back for a consumer who opted out and later wants the messages again.

OPS-063Opt-out records must not be shared onwardprivacy policy + SMS termsMediumMEDIUM

The published policy must not permit sharing or forwarding opt-out records to unaffiliated parties without the consumer's prior express permission.

OPS-074Toll-free opt-out language is appended for you, and billedoutbound toll-free message bodiesMediumMEDIUM

On toll-free traffic, expect the carrier to append opt-out language to outbound messages — it is billable, cannot be removed and can only be shortened.

OPS-076Customer-care contact details must recur toooutbound message cadenceMediumMEDIUM

Customer-care contact instructions must be promoted at opt-in and at regular intervals thereafter, at least monthly.

OPS-089A ported number is a new subscribersubscriber port event against consent statusMediumMEDIUM

A fresh opt-in must be obtained when a subscriber ports their number between carriers.

OPS-090Check the number is a live mobile before paying to send to itdestination number validationMediumMEDIUM

Destination numbers should be validated as real, active mobile numbers before sending, since platforms bill accepted requests regardless of delivery.

OPS-099A state may cap monthly volume and demand the logsmonthly solicitation volume and log productionMediumMEDIUM

Where a state sets monthly solicitation volume caps and log-production duties, both must be met.

OPS-101Default to daytime hours even where nothing requires itdefault scheduled send windowMediumMEDIUM

Sending should be restricted to normal daytime business hours in the recipient's local time as a platform default.

OPS-107Staff have to be trained on the internal list, and it has to be evidencedtraining recordsMediumMEDIUM

Personnel must be trained in the existence and use of the internal do-not-call list, and the training records retained.

OPS-115An exempt message must not cost the recipient anythingbilling treatment of exempt messagesMediumMEDIUM

Where an exemption requires it, exempted informational messages must not be charged to the called party or counted against their plan limits.

OPS-126A low-volume campaign has a ceiling, not a warningcampaign volume against the use-case ceilingMediumMEDIUM

Low-volume campaigns must stay under their published ceiling, or be upgraded to a standard registration.

OPS-127UCaaS low-volume carries restrictions beyond the volumeUCaaS traffic pattern against the tier conditionsMediumMEDIUM

A UCaaS low-volume registration is limited to a low daily ceiling, a restricted throughput class, one number per human user, and no API or automated traffic.

OPS-128Registering and vetting a brand does not raise the platform rate limitplatform account sending rateMediumMEDIUM

Brand registration and vetting alone do not raise the sending platform's own default per-number rate; a separate increase must be requested.

OPS-130Tax-exempt status is not a political vetpolitical vetting artefact against throughput termsMediumMEDIUM

Uncapped political throughput requires a valid political vetting artefact; 501(c) tax-exempt status alone yields only standard terms.

OPS-132The consumer-traffic thresholds are where P2P stopsper-number traffic shapeMediumMEDIUM

Traffic above the published consumer-operation reference thresholds is classified as non-consumer, whatever the sender intends.

OPS-133A P2P exemption has conditions, all of themP2P exemption applicationMediumMEDIUM

A P2P exemption may only be registered where every published condition holds — no business sending, not a cloud communications suite, human-written messages, traffic symmetry no worse than one to three, and a clean compliance history.

OPS-134The registry has API rate limits of its ownAPI request rate to the registryMediumMEDIUM

Integrations must stay within the registry's published API rate limits.

OPS-145Consecutive number ranges are a volume signalprovisioned number contiguityMediumMEDIUM

Consecutive number ranges must not be purchased to support higher-volume sending.

OPS-151Separate marketing traffic once volume matterscampaign and number segmentation by traffic typeMediumMEDIUM

At medium-to-high volume, marketing traffic should sit on its own campaign and number set, with a separate short code per brand and per message type.

OPS-152One recognisable number per programmeprogramme to source number mappingMediumMEDIUM

A business or programme should send from one primary, recognisable source number.

OPS-159A registered campaign must expect to carry trafficcampaign.descriptionMediumMEDIUM

A campaign should be registered only when it will actually send; sustained inactivity triggers dormancy suspension.

OPS-161Campaign auto-renewal must be set deliberatelycampaign.auto_renewalMediumMEDIUM

The autoRenewal setting must be chosen deliberately — true renews monthly, false deactivates at cycle end.

OPS-204Verbal consent records must substitute a call identifier for the IP addresscampaign.message_flowMediumMEDIUM

Where consent was verbal or via IVR, a call identifier must replace the IP-address field in the consent record.

OPS-209The consent record must say which act gave consentcampaign.message_flow + privacy policyMediumMEDIUM

Every consent record must carry the confirmation method used — a ticked box, a click, or a replied keyword.

OPS-223The retention clock starts at the last message, not the opt-incampaign.message_flow + privacy policyMediumMEDIUM

The retention period must be measured from the last message sent in reliance on the consent, not from the date the consent was collected.

OPS-233A spoken consent record must name the agent who took itcampaign.message_flow + privacy policyMediumMEDIUM

Every consent record must carry the identifier of the agent who read the consent script.

OPS-256A recurring programme should expire consent that has gone quietcampaign.message_flowMediumMEDIUM

A recurring programme should describe expiring an opt-in after a long period of subscriber inactivity, with one final notification permitted.

OPS-292Evidence screenshots must say when and where they were takencampaign.consent_artifact[]MediumMEDIUM

Every submitted evidence image must carry its capture timestamp, the source URL, and enough provenance to tie it to the live surface.

OPS-VOLUME-PLAUSIBLEDeclared volume must be plausible for the businesscampaign.description + brand websiteMediumMEDIUM

The message volume the campaign implies should be consistent with the size of the business described.

OPS-055Revoke-all across categories has a deadlinesuppression list data modelLowLOW

A suppression architecture that cannot revoke across every message category for a sender must be flagged before the federal revoke-all rule takes effect on 31 January 2027.

OPS-096A state may black out whole dayssend date against a state holiday calendarLowLOW

Where a state enacts holiday blackout dates for solicitations, no solicitation may be sent on them.

OPS-116Carrier approval is not legal covercompliance posture and risk modelLowLOW

Litigation exposure must be sized separately for state regimes with a private right of action, and carrier approval must not be treated as legal compliance.

OPS-131A validity period shorter than the queue drops messages silentlymessage validity period against queue depthLowLOW

The message validity period must be long enough for the message to survive queueing at the sender's actual throughput.

OPS-146Identical bodies across a bulk send fingerprint the campaignbody variance across a bulk sendLowLOW

Message body wording should vary across a bulk send rather than being byte-identical to every recipient.

OPS-208The consent record should carry the browser user agentcampaign.message_flow + privacy policyLowLOW

Every consent record must carry the device or browser user agent behind the submission.

The other 7 layers

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.