No site impersonating another service to collect credentials
The requirementstatement
The brand website must not host or promote impersonation of a legitimate service in order to capture credentials, identity numbers or other sensitive data.
- Severityseverity
- BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- crawled website content
- Where it liveslayer
- WebsiteWEBSITE
- How Ekas settles itdetectability
- AI · crawlCRAWL
- Needs your live site or policy page fetched and read. Ekas crawls it the way a reviewer would.
- What the fix involvesfailureClass
- Hard stopHARD_STOP
- Not remediable. Resubmitting will not help, and anyone offering to fix it is selling you a rejection.
- Who requires itauthorities
- TwilioCTIA
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
This cannot be registered. Where the brand is an authorised partner using another company's marks legitimately, state the relationship in visible page content and expect the registration to be reviewed by a person.
Provider rejection codescodes
The code you get back when this rule is what failed, and whether that provider lets you resubmit.
| Provider | Code | Resubmit |
|---|---|---|
| Twiliogen2 | 30960 | No |
Notesnotes
Rules you will hit next
6 other rules read crawled website content. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.
WEB-135 is one of 93 website rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.