A2P 10DLC rule registry
Half of website vetting is decided before anyone reads a word: DNS, status codes, certificates, redirects, robots directives. The rest is what the page must show. These rules cover reachability, content, and whether the opt-in a reviewer can actually find matches the one you described.
Every brand registration must carry a website URL or an equivalent hosted online-presence artifact.
The submitted website URL must resolve to a live host and return a successful response.
A registrar placeholder, parked domain, or domain-for-sale page is rejected.
A "coming soon" or "under construction" page is rejected as the brand website.
Non-production hosts — staging, dev, preview, admin, internal — are not acceptable brand websites.
The site must be fetchable by an automated vetter — no robots.txt disallow, no noindex, no JS-only render, no geofence.
A geo-gate, bot challenge, captive portal, or app-install wall blocking the reviewer is rejected.
The brand website must be publicly reachable without authentication.
Where the brand's service genuinely sits behind a login, a public page describing the business and its messaging programme is required.
A site judged to be a shell, an unmodified template, scraped or fabricated content, or stock-imagery-only is rejected.
A URL resolving to a standalone lead form with no surrounding business site is rejected.
The name displayed on the website must match the registered legal name or DBA.
The website must carry enough information about the business, and ideally the messaging programme, for a reviewer to understand what is being registered.
An ISV or reseller must not submit its own platform website in place of the end customer's.
The business described on the website, the registered company name and the registered postal address must corroborate one another.
The brand website must link to a reachable privacy policy.
What the website shows the business doing must be consistent with the campaign use case.
The website, campaign description, message flow and sample messages must all identify the same sending business.
The website referenced inside the message flow must belong to the same business as the registered brand website.
Where the website, description, or samples solicit donations, the charity use case must be used.
Where the website, description, or samples carry political-campaign content, the political use case must be used.
Where lending content appears in the description, the message flow, or the website, directLending must be declared.
Where the programme sends shopping-cart reminders, the opt-in terms shown at the call to action must disclose it.
The call to action as described in the registration and the call to action as it appears live on the website must be audited as two separate passes.
Where consent is collected on the site, the call to action the registration describes must be findable on the crawled site.
The brand website must present a valid TLS chain — not expired, not self-signed, and issued for the hostname actually submitted.
Where a submitted URL redirects off the registered domain, the full content review applies to the destination, so the destination is what the registration must be able to survive.
Third-party reputation signals on the domain — prior compromise, complaint volume, adverse media, blocklist entries — block the registration.
The page a QR code opens must be fetchable by anyone — no login, geo-gate, app-install wall or captive portal in front of it.
The page a QR code opens must display the brand name as registered, so the consumer can see whose programme they are joining.
Where the site or the campaign carries age-restricted content, the site must present a functioning age gate in front of it.
The age gate must be presented before any age-restricted content is accessible, including on a page reached by a direct link.
An alcohol delivery brand must present the age gate on the ordering flow itself, not only on a marketing splash page.
Where the restricted content is alcohol, the age gate must enforce a 21+ threshold rather than 18+.
Any landing site collecting personal information must carry a conspicuously accessible privacy policy.
Prohibited-content screening must cover the entire website, not only the page the campaign points at.
The brand website must not host or promote adult, pornographic, escort or nudity content.
The brand website must not host or promote the identity, materials or fundraising of a hate group.
The brand website must not host or promote the sale of firearms, ammunition, explosives or fireworks.
The brand website must not host or promote tobacco, vape, e-cigarette or nicotine product content.
The brand website must not host or promote cannabis, CBD, hemp, kratom, dispensary or drug-paraphernalia content.
The brand website must not host or promote casino, sportsbook, lottery or online gambling content.
The brand website must not host or promote payday and short-term high-interest lending, third-party loan solicitation, debt collection, credit repair, debt forgiveness, crypto or retail investment content.
The brand website must not host or promote lead generation, affiliate marketing or SEO and marketing-agency services.
The brand website must not host or promote sweepstakes, prize-draw or contest-entry content that the registration does not declare.
The brand website must not host or promote multilevel-marketing or distributor-recruitment content.
The brand website must not host or promote impersonation of a legitimate service in order to capture credentials, identity numbers or other sensitive data.
The brand website must not host or promote malware, or application downloads served from non-secure locations.
The brand website must not host or promote unsubstantiated health or product claims, fabricated urgency, unverifiable guarantees, unauthenticatable testimonials or false endorsements.
The brand website must not host or promote counterfeit, replica or imitation designer goods, fake identification or falsified documentation.
The brand website must not host or promote SHAFT merchandise in the storefront catalog, where the destination platform refuses such merchants outright.
The brand website must not host or promote affiliate or lead-generation activity in the campaign combined with high-risk lending on the website.
A Charity campaign must supply the charity's own website URL and a listing URL at an accreditation organisation, and both must resolve.
A Political campaign must supply the candidate's or organisation's website URL alongside the FEC Committee ID, and that URL must resolve.
The website must be renderable in English, or an English version must be supplied.
The brand website must remain live and publicly reachable for the entire vetting period, which runs weeks after submission.
The website should show signs of being an operating business, not a shell created to pass vetting.
Where the business runs a main site, that site must be registered as the brand website rather than a single campaign landing page.
An e-commerce brand must show a real, populated product catalog rather than a placeholder store.
The business name or branding must be displayed in the logo, header or footer of the rendered page, not carried only in the title tag or metadata.
The support phone and contact shown on the website should match the brand registration.
An About page and a Contact page must exist on the brand domain.
The brand website must link to reachable Terms & Conditions or SMS Terms.
The website must display contact details — an address, phone number, or support email identifying the business.
The website should carry information about what the messaging programme sends, to whom, and why.
The website must display how to opt in and how to opt out.
The declared campaign attributes must be consistent with what the website shows, not only internally consistent with the form.
Where the website or description implies a message category the campaign has not declared, it must be flagged.
Where verbal opt-in is the only declared consent method, the registration must not supply a website opt-in URL that shows no SMS consent surface.
A URL submitted to TCR must resolve directly rather than returning a 30x redirect.
A brand website that redirects to a business other than the registered brand is rejected, whatever the submitted URL says.
A recently registered, disposable or short-lived domain raises the risk score on the brand, independently of what the site contains.
A domain that imitates a better-known brand through misspelling, homoglyphs or an added word is screened as a phishing indicator.
The URL given in the message flow must point at the page carrying the consent surface, not at the site root.
The age gate must not be defeatable by dismissing it, by loading a page directly, or by clearing a cookie.
Any landing site a message links to must publish contact information including a postal mailing address.
The brand website must not host or promote advertising that misrepresents or ridicules people by age, colour, national origin, race, religion, sex, sexual orientation or disability, or that trivialises a historic atrocity.
The brand website must not host or promote excessive or graphic violence.
The brand website must not host or promote content that infringes another party's intellectual property.
A social profile standing in for a website must be a business page carrying the business name, a description of what it does, and contact information.
A social-media profile is accepted as the online presence only where the brand genuinely has no website of its own.
Where the brand is registered as a sole proprietor, the website must not hold itself out as an LLC or incorporated entity.
The website URL must fit within the provider field cap (100 characters at the tightest).
The brand website should be on a domain the business owns, not a free platform subdomain.
Any page the registration references must load — no broken internal links, 404s, or links pointing at the wrong page.
The site footer should show a business phone number, an email address and a physical street address rather than a PO box.
Where the brand has a website, the privacy policy and terms URLs must serve an HTML page rather than a PDF or other downloadable file.
A page must not load sub-resources over, or redirect through, unencrypted HTTP — mixed content fails.
A domain resolving to an IP or ASN shared with known-malicious sites carries that reputation into the brand score.
The brand website must not host or promote law-evasion and protection-bypass products, or products of questionable legality.
Where the brand genuinely has no website, an established, active, public business profile is accepted as the online presence.
The social-profile route is available to small businesses and sole proprietors that have no established website, not to larger businesses choosing not to submit one.
When the business moves to a new domain, the registered brand website must be updated to match.
Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.