# WEB-135 — No site impersonating another service to collect credentials

> The brand website must not host or promote impersonation of a legitimate service in order to capture credentials, identity numbers or other sensitive data.

- **Rule ID:** WEB-135
- **Layer:** Website (`WEBSITE`)
- **Checks:** `crawled website content`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Hard stop — not remediable, resubmission will not help
- **Required by:** Twilio, CTIA
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/website/web-135/

## Why this rule exists

This is the phishing pattern the whole landing-page review exists to catch: a page that looks like a bank, a carrier or a delivery service, reached from a text message, collecting whatever the real one would ask for. It is judged from design and form fields together, because the copy alone is by construction indistinguishable from the genuine article.

## How to fix it

This cannot be registered. Where the brand is an authorised partner using another company's marks legitimately, state the relationship in visible page content and expect the registration to be reviewed by a person.

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio (gen2) | `30960` | no |

## Notes

CTIA A65-03 extends the same prohibition to brand impersonation on any message landing page or download, and A65-04 to promotion of illegal activity. Both are discharged here.
