{
  "id": "OPS-OPTOUT-CONF-ONLY",
  "slug": "ops-optout-conf-only",
  "title": "Opt-out confirmation must be the only message sent after revocation",
  "statement": "The campaign must declare a single opt-out confirmation and nothing further after a consumer revokes.",
  "rationale": "One final confirmation is permitted; anything after it is messaging someone who has revoked consent, which is both the clearest TCPA violation available and a carrier fee event. Declaring a confirmation is fine — declaring a follow-up sequence is a self-reported violation.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "campaign.optout_message",
  "severity": "BLOCKING",
  "detectability": [
    "DETERMINISTIC"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "FCC",
    "CTIA",
    "TCR"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Configure exactly one opt-out confirmation, keep it non-promotional, and make sure no other automation can fire at a revoked number afterwards.",
  "example": "Acme Coffee: you have been unsubscribed and will receive no further messages. Reply HELP for help.",
  "catalogIds": [
    "OPS-048"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-optout-conf-only/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-optout-conf-only.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
