A provider can block anything its risk assessment dislikes

The requirementstatement

Service providers may block any message a reasonable risk assessment suggests is unwanted, and the triggers include compromised credentials, grey routes, missing authentication and a pattern of abusing best practices.

Severityseverity
HighHIGHRejected by at least one carrier or provider, and a common cause of failure at the rest.
When it bitesphase
After you are livepostFalls due once you are sending: STOP handling, quiet hours, suppression, record retention.
What is checkedobject
overall sending posture
Where it liveslayer
OperationalOPERATIONAL
How Ekas settles itdetectability
Post-submissionUNDETECTABLE_PRE_SUBMISSION
The subject does not exist yet at submission time: a reply window, an expiring PIN, a queue position. Reported with its deadline.
What the fix involvesfailureClass
Wait on someone elseTERMINAL_EXTERNAL
Needs an external system or a waiting period, such as IRS propagation, a vetting result, or a carrier queue.
Who requires itauthorities
CTIAall service providers
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

This is the discretion behind every other rule in the folder, and it matters because it is not appealable in the way a rejection is: the traffic simply stops. Understanding that the assessment looks at posture rather than at individual messages is what makes the rest of the family worth acting on before anything goes wrong.

How to fix itremediation

Treat the posture as the thing being judged: authenticated sending, one static route, credentials under control, complaint and opt-out rates monitored. Done when nothing about your traffic requires explaining.

Check this yourselfattestation

No tool can settle this one for you. Here is the check, and what wrong looks like.

Do you know who to call at your provider before traffic is blocked, rather than after?

  1. 1Get the name and escalation path now. There is no threshold to comply with here — the assessment looks at posture, not at individual messages, and the traffic simply stops.
  2. 2Work the posture instead: authenticated sending, one static route, credentials under control, complaint and opt-out rates monitored.
  3. 3Done when nothing about your traffic requires explaining.

What wrong looks like: Not appealable in the way a rejection is. Delivery stops, no code explains it, and the conversation starts from scratch with somebody you have never spoken to.

Notesnotes

A judgement made by somebody else about traffic we cannot see. What the user has to accept is that there is no threshold to comply with here — the mitigation is the rest of this folder, and the practical step is knowing who to call at the provider before it happens.

Rules you will hit next

Other operational rules at the same severity. A registration is judged as a whole, not rule by rule.

All operational rules

OPS-157 is one of 139 operational rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.