The policy host must serve a valid certificate of its own
The requirementstatement
The host serving the policy pages must present a valid TLS chain, checked independently of the brand website host.
- Severityseverity
- BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- privacy policy + terms URL TLS chain
- Where it liveslayer
- Policy pagesPOLICY_PAGE
- How Ekas settles itdetectability
- DeterministicDETERMINISTIC
- Settled in code from the values you submitted. No model involved, no judgement call, same answer every time.
- What the fix involvesfailureClass
- Fix the policyTERMINAL_POLICY
- The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
- Who requires itauthorities
- BandwidthTCRAT&TT-MobileAWS
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
Renew or reissue the certificate for the policy host, including any subdomain the policy sits on, and test it from outside your network. Done when an external SSL checker reports a complete valid chain for both policy URLs.
Common mistakespitfalls
- A wildcard certificate for *.acmecoffee.com does not cover a policy hosted on a vendor domain. Check the host in the URL you actually submitted, not the one you think of as yours.
Provider rejection codescodes
The code you get back when this rule is what failed, and whether that provider lets you resubmit.
| Provider | Code | Resubmit |
|---|---|---|
| Bandwidth | 7105 | Yes |
| Bandwidth | 1103 | Yes |
Notesnotes
Rules you will hit next
Other policy pages rules at the same severity. A registration is judged as a whole, not rule by rule.
POL-015 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.