{
  "id": "OPS-037",
  "slug": "ops-037",
  "title": "On a shared address, STOP must stop everything",
  "statement": "Where several programmes share one application address, STOP must terminate every one of the consumer's active programmes on it, and any keyword menu must offer a STOP ALL option.",
  "rationale": "From the consumer's side there is one number sending them things, and stopping it means stopping it. A registry keyed per programme instead honours the opt-out for whichever one they last received and leaves the others running, so the messages keep coming from the same number they just unsubscribed from — which reads as deliberate evasion even when it is a data model.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "subscription registry keyed by number and application address",
  "severity": "BLOCKING",
  "detectability": [
    "UNDETECTABLE_PRE_SUBMISSION"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Key suppression on the pair of consumer number and application address, not on the programme, so one STOP clears every subscription on that address. Where a menu offers per-programme choices, put STOP ALL in it. Done when a subscriber to two programmes on one short code receives nothing after a single STOP.",
  "example": "Keyword menu: \"Reply 1 to stop offers, 2 to stop order updates, or STOP ALL to stop everything.\"",
  "notes": "Applies to shared short codes and multi-programme addresses, which no registration field identifies. What the user has to establish is whether their address carries more than one programme, and if so, how their platform scopes suppression — per programme is the common default and it is the wrong one.",
  "phase": "post",
  "automated": false,
  "attestation": {
    "question": "Does this application address carry more than one programme — and if so, does one STOP clear all of them?",
    "howToCheck": [
      "List the programmes sending from the address.",
      "Ask your platform how suppression is scoped. Per programme is the common default and it is the wrong one.",
      "Test it: subscribe to two programmes on the address, send one STOP, and confirm neither sends again."
    ],
    "failureLooksLike": "The messages keep coming from the same number the consumer just unsubscribed from. It reads as deliberate evasion even when it is only a data model."
  },
  "url": "https://ekas.io/rules/10dlc/operational/ops-037/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-037.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
