{
  "id": "WEB-073",
  "slug": "web-073",
  "title": "The brand website must serve a certificate that verifies",
  "statement": "The brand website must present a valid TLS chain — not expired, not self-signed, and issued for the hostname actually submitted.",
  "rationale": "A vetting crawler stops at a certificate error and never reads a word of the site, so the rejection arrives as \"the website could not be verified\" rather than as anything about a certificate. Browsers hide this: the people who work at the business have been clicking through the warning for months, and a certificate valid for the bare domain but not for the www form fails only for whoever submitted the other one.",
  "layer": "WEBSITE",
  "layerSlug": "website",
  "object": "brand.website TLS chain",
  "severity": "BLOCKING",
  "detectability": [
    "DETERMINISTIC"
  ],
  "failureClass": "TERMINAL_WEBSITE",
  "authorities": [
    "Bandwidth",
    "TCR",
    "Twilio",
    "Plivo"
  ],
  "codes": [
    {
      "provider": "Bandwidth",
      "code": "1103",
      "remediable": true
    },
    {
      "provider": "Bandwidth/DCA",
      "code": "2103",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Reissue the certificate for the exact hostname in brand.website, covering both the www and bare-domain forms, and renew before expiry. Done when an external SSL checker — not your own browser — reports a complete, valid chain for the URL you are about to submit.",
  "pitfalls": [
    "A certificate valid for acmecoffee.com and not for www.acmecoffee.com fails whenever the submitted URL uses the other form. Submit the form the certificate actually covers.",
    "An expired intermediate is invisible in Chrome, which caches the issuer, and fatal to a strict crawler that does not. Test from outside your own network."
  ],
  "notes": "Absorbs BRD-128, which states the same certificate requirement from the brand-record side. Severity divergence in the catalog: website-evidence-012 and CARR-008 grade a TLS failure HIGH; Bandwidth, Plivo and Twilio grade it BLOCKING. Strictest kept.",
  "catalogIds": [
    "BRD-128"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/website/web-073/",
  "markdown": "https://ekas.io/rules/10dlc/website/web-073.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
