# WEB-019 — The site must stay live for the whole vetting window, not just at submission

> The brand website must remain live and publicly reachable for the entire vetting period, which runs weeks after submission.

- **Rule ID:** WEB-019
- **Layer:** Website (`WEBSITE`)
- **Checks:** `brand.website over the review window`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** Not knowable before submission — reported with its deadline
- **Fix type:** Wait on an external system or a required interval
- **Required by:** AWS, Bandwidth, Klaviyo, Postscript
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/website/web-019/

## Why this rule exists

Vetting re-fetches the site days or weeks later, so a site that was up when the form was filled in is not the thing being judged. The named failure is a password-protected storefront: a shop put into maintenance mode for a redesign, or a trial plan that lapses, takes the brand down with it and the rejection arrives with no hint that timing was the cause.

## How to fix it

Keep the site public and unchanged until the brand and campaign are approved. Do not schedule a migration, a password gate or a plan downgrade during the window; AWS states 10DLC review takes at least four to six weeks and toll-free three to ten business days.

## Check this yourself

**Is any redesign, migration, password gate or hosting downgrade scheduled between now and approval?**

1. Ask whoever runs the site what is planned for the next six weeks. AWS states 10DLC review takes at least four to six weeks and toll-free three to ten business days.
2. Hold the site public and unchanged until the brand and campaign are approved.
3. Check any trial plan or hosting subscription that could lapse mid-review.

*What wrong looks like:* A shop is put into maintenance mode for a redesign three weeks after submission. Vetting re-fetches the site, finds a password-protected storefront, and the rejection gives no hint that timing was the cause.

## Notes

Nothing at submission time can settle this — the failure happens after we stop looking. Surfaced as a warning with the deadline: the user has to hold the site up, and to hold off any redesign or hosting change, until approval lands.
