{
  "id": "OPS-153",
  "slug": "ops-153",
  "title": "The sender must be who the message says it is",
  "statement": "The message number and sender name must not be spoofed or substituted in any way that misleads a consumer.",
  "rationale": "Sender identity is the only thing a recipient has to judge a message by, and misrepresenting it is the mechanic behind every smishing campaign — which is why the prohibition is absolute rather than proportionate. Legitimate substitution exists, for failover or for a shared brand, and it requires an arrangement with the provider rather than a configuration change.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "outbound sender identity",
  "severity": "BLOCKING",
  "detectability": [
    "UNDETECTABLE_PRE_SUBMISSION"
  ],
  "failureClass": "HARD_STOP",
  "authorities": [
    "CTIA",
    "all MNOs"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Send from the numbers registered to the campaign, presented as themselves. Where a substitution is genuinely needed, arrange it with the provider in advance rather than configuring it.",
  "notes": "Wire-level behaviour. What the user has to confirm is that no part of their stack rewrites the originator — some aggregation layers do it for routing reasons, and the sender is accountable for the result either way.",
  "phase": "post",
  "automated": false,
  "attestation": {
    "question": "Does any part of your stack rewrite the originating number or sender name?",
    "howToCheck": [
      "Ask your provider and check any aggregation layer between your application and the carrier — some rewrite the originator for routing reasons.",
      "Confirm messages arrive from the numbers registered to the campaign, presented as themselves.",
      "Where a substitution is genuinely needed, arrange it with the provider in advance rather than configuring it."
    ],
    "failureLooksLike": "A routing layer substitutes the originator without anybody choosing it. Sender identity is the only thing a recipient can judge a message by, and the sender is accountable for the result either way."
  },
  "url": "https://ekas.io/rules/10dlc/operational/ops-153/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-153.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
