{
  "id": "OPS-155",
  "slug": "ops-155",
  "title": "Sending through a provider you have no relationship with is a red flag",
  "statement": "A message sender with no business relationship with the CPaaS or wireless provider carrying its traffic must be treated as a compromised-system indicator.",
  "rationale": "Every legitimate sender has a contract with somebody in the chain. Traffic arriving without one usually means compromised API credentials or a resold account, and the industry treats it as a compromise signal rather than as an unusual commercial arrangement — so a brand whose traffic reaches a carrier through an intermediary it has never heard of is indistinguishable from a breach.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "the contractual chain behind the traffic",
  "severity": "BLOCKING",
  "detectability": [
    "EXTERNAL_DATA"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Know every party in your sending chain and hold a contract with the one you send through. Done when you can name the provider, the aggregator and the terminating carrier for your own traffic.",
  "notes": "A commercial fact outside the registration. What the user has to do is map their own chain — resold accounts and white-labelled platforms make this genuinely unclear, and unclear is the state this rule is about.",
  "phase": "post",
  "automated": false,
  "attestation": {
    "question": "Can you name the provider, the aggregator and the terminating carrier for your own traffic — and do you hold a contract with the one you send through?",
    "howToCheck": [
      "Map the chain end to end. Resold accounts and white-labelled platforms make this genuinely unclear, and unclear is the state this rule is about.",
      "Confirm there is a contract with the party you send through."
    ],
    "failureLooksLike": "Traffic reaching a carrier through an intermediary you have never heard of is indistinguishable from compromised API credentials, and it is treated as a compromise signal rather than as an unusual commercial arrangement."
  },
  "url": "https://ekas.io/rules/10dlc/operational/ops-155/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-155.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
