Nothing goes out before the opt-in

The requirementstatement

Messages may be sent only after the consumer has opted in; the single opt-out acknowledgement is the only permitted exception.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
After you are livepostFalls due once you are sending: STOP handling, quiet hours, suppression, record retention.
What is checkedobject
send-time consent check
Where it liveslayer
OperationalOPERATIONAL
How Ekas settles itdetectability
Post-submissionUNDETECTABLE_PRE_SUBMISSION
The subject does not exist yet at submission time: a reply window, an expiring PIN, a queue position. Reported with its deadline.
What the fix involvesfailureClass
Hard stopHARD_STOP
Not remediable. Resubmitting will not help, and anyone offering to fix it is selling you a rejection.
Who requires itauthorities
CTIAFCCall MNOs
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

This is the obligation the whole framework exists to enforce, and it is worth stating separately because the failure is rarely a decision to send unsolicited messages — it is a list imported without provenance, a form that wrote consent before the box was ticked, or a test send to a colleague's number that went to the whole file. The consequence does not scale with the intent.

How to fix itremediation

Check consent at send time against a per-number record, never against list membership, and make an unconsented number impossible to include rather than unlikely.

Check this yourselfattestation

No tool can settle this one for you. Here is the check, and what wrong looks like.

Does your send path check a per-number consent record, or does it check list membership?

  1. 1Trace one send to the thing it actually reads. Segments are built by people; consent records are not.
  2. 2Make an unconsented number impossible to include rather than unlikely.
  3. 3The single opt-out acknowledgement is the only message permitted without a prior opt-in.

What wrong looks like: A list imported without provenance, a form that wrote consent before the box was ticked, or a test send to a colleague that went to the whole file. The consequence does not scale with the intent.

Notesnotes

The runtime form of everything the CONSENT_FLOW layer checks at registration. What the user has to verify is that their send path reads a consent record rather than a segment — segments are built by people and consent records are not.

Rules you will hit next

Other operational rules at the same severity. A registration is judged as a whole, not rule by rule.

All operational rules

OPS-384 is one of 139 operational rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.