Sending through a provider you have no relationship with is a red flag

The requirementstatement

A message sender with no business relationship with the CPaaS or wireless provider carrying its traffic must be treated as a compromised-system indicator.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
After you are livepostFalls due once you are sending: STOP handling, quiet hours, suppression, record retention.
What is checkedobject
the contractual chain behind the traffic
Where it liveslayer
OperationalOPERATIONAL
How Ekas settles itdetectability
External recordEXTERNAL_DATA
The fact that settles it lives in a register we cannot query, such as the IRS file, a postal database, or another provider’s tenant. Reported as a warning with the evidence to check, not as a pass.
What the fix involvesfailureClass
Wait on someone elseTERMINAL_EXTERNAL
Needs an external system or a waiting period, such as IRS propagation, a vetting result, or a carrier queue.
Who requires itauthorities
CTIA
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

Every legitimate sender has a contract with somebody in the chain. Traffic arriving without one usually means compromised API credentials or a resold account, and the industry treats it as a compromise signal rather than as an unusual commercial arrangement — so a brand whose traffic reaches a carrier through an intermediary it has never heard of is indistinguishable from a breach.

How to fix itremediation

Know every party in your sending chain and hold a contract with the one you send through. Done when you can name the provider, the aggregator and the terminating carrier for your own traffic.

Check this yourselfattestation

No tool can settle this one for you. Here is the check, and what wrong looks like.

Can you name the provider, the aggregator and the terminating carrier for your own traffic — and do you hold a contract with the one you send through?

  1. 1Map the chain end to end. Resold accounts and white-labelled platforms make this genuinely unclear, and unclear is the state this rule is about.
  2. 2Confirm there is a contract with the party you send through.

What wrong looks like: Traffic reaching a carrier through an intermediary you have never heard of is indistinguishable from compromised API credentials, and it is treated as a compromise signal rather than as an unusual commercial arrangement.

Notesnotes

A commercial fact outside the registration. What the user has to do is map their own chain — resold accounts and white-labelled platforms make this genuinely unclear, and unclear is the state this rule is about.

Rules you will hit next

Other operational rules at the same severity. A registration is judged as a whole, not rule by rule.

All operational rules

OPS-155 is one of 139 operational rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.