No malware or insecure downloads served from the site
The requirementstatement
The brand website must not host or promote malware, or application downloads served from non-secure locations.
- Severityseverity
- BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- crawled website content
- Where it liveslayer
- WebsiteWEBSITE
- How Ekas settles itdetectability
- AI · crawlCRAWL
- Needs your live site or policy page fetched and read. Ekas crawls it the way a reviewer would.
- What the fix involvesfailureClass
- Fix the websiteTERMINAL_WEBSITE
- The fix lives on your site. No amount of rewording the form clears it.
- Who requires itauthorities
- CTIAAT&T
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
Scan and clean the site, update the platform and plugins, and serve every download over https from your own domain. Done when a safe-browsing check on the domain comes back clear and no download link points at a plain-HTTP host.
A compliant exampleexample
App links point at https://apps.apple.com/... and https://play.google.com/... rather than at a self-hosted APK.
Common mistakespitfalls
- Cleaning the site does not clear the blocklist entry. Request a review with the safe-browsing service as well, or the domain reputation rules keep failing after the malware is gone.
Notesnotes
Rules you will hit next
6 other rules read crawled website content. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.
WEB-136 is one of 93 website rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.