The brand website must serve a certificate that verifies

The requirementstatement

The brand website must present a valid TLS chain — not expired, not self-signed, and issued for the hostname actually submitted.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
brand.website TLS chain
Where it liveslayer
WebsiteWEBSITE
How Ekas settles itdetectability
DeterministicDETERMINISTIC
Settled in code from the values you submitted. No model involved, no judgement call, same answer every time.
What the fix involvesfailureClass
Fix the websiteTERMINAL_WEBSITE
The fix lives on your site. No amount of rewording the form clears it.
Who requires itauthorities
BandwidthTCRTwilioPlivo
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

A vetting crawler stops at a certificate error and never reads a word of the site, so the rejection arrives as "the website could not be verified" rather than as anything about a certificate. Browsers hide this: the people who work at the business have been clicking through the warning for months, and a certificate valid for the bare domain but not for the www form fails only for whoever submitted the other one.

How to fix itremediation

Reissue the certificate for the exact hostname in brand.website, covering both the www and bare-domain forms, and renew before expiry. Done when an external SSL checker — not your own browser — reports a complete, valid chain for the URL you are about to submit.

Common mistakespitfalls

  • A certificate valid for acmecoffee.com and not for www.acmecoffee.com fails whenever the submitted URL uses the other form. Submit the form the certificate actually covers.
  • An expired intermediate is invisible in Chrome, which caches the issuer, and fatal to a strict crawler that does not. Test from outside your own network.

Provider rejection codescodes

The code you get back when this rule is what failed, and whether that provider lets you resubmit.

ProviderCodeResubmit
Bandwidth1103Yes
Bandwidth/DCA2103Yes

Notesnotes

Absorbs BRD-128, which states the same certificate requirement from the brand-record side. Severity divergence in the catalog: website-evidence-012 and CARR-008 grade a TLS failure HIGH; Bandwidth, Plivo and Twilio grade it BLOCKING. Strictest kept.

Rules you will hit next

Other website rules at the same severity. A registration is judged as a whole, not rule by rule.

All website rules

WEB-073 is one of 93 website rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.