CAN-SPAM: What the Act and the Rule Require of Commercial Email
Key Takeaways
- The Act applies to any message whose primary purpose is commercial advertisement or promotion, with no exception for business-to-business mail and no bulk threshold
- 16 CFR 316.3 supplies the primary purpose test, which turns on the subject line and on where transactional content sits in the body of the message
- A sender has ten business days to stop sending after an opt-out request, and the opt-out mechanism must stay live for at least 30 days after the message went out
- There is no general private right of action; enforcement belongs to the FTC, other federal agencies, state attorneys general and internet access service providers
- Preemption is partial: state laws expressly regulating commercial email are superseded except to the extent they prohibit falsity or deception
A Conduct Statute, Not a Permission Regime
The Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 was enacted as Public Law 108-187 on December 16, 2003. It is routinely summarised as the statute that legalised commercial email, which is accurate as far as it goes: nothing in it requires a recipient's prior permission before a first message is sent. What it does instead is impose conduct rules on every message within its scope and attach civil penalties to each one that breaks them.
Two features of that design are widely misunderstood. The Act is not a bulk-mail statute — there is no message-volume threshold anywhere in it. And it contains no business-to-business exemption; the FTC's own compliance guide states that the law “makes no exception for business-to-business email,” so a single message to a former customer announcing a product line sits inside the same framework as a campaign to a purchased list.
The Primary Purpose Test
Everything turns on whether a message is a “commercial electronic mail message.” 15 U.S.C. 7702(2)(A) defines that as a message “the primary purpose of which is the commercial advertisement or promotion of a commercial product or service,” including content on a website operated for a commercial purpose. Subparagraph (B) excludes transactional or relationship messages, and subparagraph (D) adds that a mere reference or link to a commercial entity does not by itself make a message commercial.
Congress directed the Commission to define the criteria, and it did so at 16 CFR 316.3. The rule sorts messages into three cases:
- Exclusively commercial content. The primary purpose is deemed commercial, full stop.
- Commercial content mixed with transactional or relationship content. The purpose is deemed commercial if a recipient reasonably interpreting the subject line would likely conclude the message contains commercial promotion, or if the transactional content does not appear, in whole or in substantial part, at the beginning of the body.
- Commercial content mixed with other, non-transactional content. The purpose is deemed commercial on the same subject-line test, or if a recipient reasonably interpreting the body would likely conclude the primary purpose is commercial — with the rule naming placement, proportion, and the use of colour, graphics, type size and style as illustrative factors.
The second case is the one that catches ordinary marketing operations, because it makes physical placement dispositive. A receipt with a promotional block above it is a commercial message; the same two components in the opposite order may not be. Subsection (b) then completes the circle: a message is transactional or relationship in purpose only where it consists exclusively of the content listed in subsection (c).
That list at 16 CFR 316.3(c) is closed and short: facilitating, completing or confirming a transaction the recipient previously agreed to enter into; warranty, recall, safety or security information about a product the recipient used or purchased; notice of a change in terms or in the recipient's standing, or periodic account statements, in respect of an ongoing relationship; information directly related to an employment relationship or benefit plan the recipient is enrolled in; and delivery of goods, services or updates the recipient is entitled to under an existing transaction.
What the Act Makes Unlawful
Section 7704(a) contains five prohibitions. The first two reach deception and apply to transactional messages as well as commercial ones; the remaining three apply to commercial messages only.
| Provision | What it prohibits | State of mind |
|---|---|---|
| 7704(a)(1) | Header information that is materially false or materially misleading | None stated for the general bar |
| 7704(a)(2) | A subject heading likely to mislead a recipient acting reasonably about a material fact regarding the contents | Actual knowledge, or knowledge fairly implied on objective circumstances |
| 7704(a)(3) | Omitting a functioning, clearly and conspicuously displayed return address or Internet-based opt-out mechanism | None stated |
| 7704(a)(4) | Continuing to send more than 10 business days after an opt-out request, and transferring the address afterwards | Varies by clause |
| 7704(a)(5) | Omitting advertisement identification, opt-out notice, or a valid physical postal address of the sender | None stated |
The header rule has two clarifying provisions worth reading. Header information that is technically accurate is nonetheless materially misleading where the originating address, domain name or IP address was obtained “by means of false or fraudulent pretenses or representations.” And “materially” is defined at 7704(a)(6) to include alteration or concealment that would impair the ability of an internet access service, a person alleging a violation, or a law enforcement agency to identify or locate the initiator.
The identification requirement in 7704(a)(5)(A)(i) — clear and conspicuous notice that the message is an advertisement — does not apply where the recipient gave prior affirmative consent to receipt. The opt-out notice and physical address requirements carry no such exception.
Opt-Out Mechanics
Section 7704(a)(3)(A) requires a functioning return address or other internet-based mechanism, clearly and conspicuously displayed, that the recipient may use to request no further commercial mail from that sender, and that “remains capable of receiving such messages or communications for no less than 30 days after the transmission of the original message.” That thirty-day floor runs from each message, not from the campaign.
Subparagraph (B) permits a preference menu in place of a single link, but only where the list includes an option to decline all commercial messages from the sender. Subparagraph (C) forgives a mechanism that is “unexpectedly and temporarily” unable to receive requests because of a technical problem beyond the sender's control, if corrected within a reasonable period.
Once a request arrives, 7704(a)(4)(A) makes four things unlawful: sending a further in-scope commercial message more than ten business days later; doing so through a person acting on the sender's behalf with actual or implied knowledge; assisting in the initiation of such a message by supplying or selecting addresses; and — for the sender or anyone who knows of the request — selling, leasing, exchanging or otherwise transferring or releasing the recipient's address for any purpose other than compliance with the law. Subparagraph (B) lifts the prohibition where the recipient later gives affirmative consent.
The Rule adds a constraint on how the mechanism may be built. Under 16 CFR 316.5, neither a sender nor anyone acting on a sender's behalf may require a recipient to pay a fee, provide any information beyond an email address and opt-out preferences, or take any step other than sending a reply message or visiting a single web page, in order to submit an opt-out request or have it honoured. A multi-step flow, a login wall or a request for a reason falls outside that permission.
Who Counts as the Sender
Section 7702(16) defines the sender as a person who initiates a commercial message and whose product, service or website is advertised or promoted by it. Where an entity operates through separate lines of business or divisions and holds itself out throughout the message as that division rather than as the parent, the division is treated as the sender.
A single message can therefore have several senders. 16 CFR 316.2(m) addresses that directly: where more than one person's products, services or website are advertised in one message, each person within the statutory definition is deemed a sender — unless one of them is identified in the “from” line as the sole sender and is in compliance with the header, subject line, opt-out mechanism, identification and sexually-explicit-labelling provisions. That designated-sender mechanism is the rule's answer to co-branded and affiliate mail.
The FTC's guide states that responsibility for forward-to-a-friend messages turns on the facts, and specifically on whether the seller offered payment or another benefit — money, coupons, discounts, awards or sweepstakes entries — in exchange for forwarding, or for generating traffic or referrals.
Enforcement and Penalties
Section 7706(a) provides that the chapter is enforced by the Commission as if a violation were an unfair or deceptive act or practice proscribed under section 18(a)(1)(B) of the FTC Act. Subsection (b) allocates enforcement over regulated entities to banking and other federal regulators. The current maximum civil penalty per violation is set by the FTC's inflation adjustment rule at 16 CFR 1.98 at $53,088, a figure the Commission's compliance guide repeats and applies to each separate email.
Two other enforcers exist, and one notable category does not:
- State attorneys general, under 7706(f), may sue as parens patriae for violations of 7704(a)(1) or (a)(2), of 7704(d), or for a pattern or practice violating (a)(3), (4) or (5). Statutory damages are the number of violations — each separately addressed unlawful message counted separately — multiplied by up to $250, capped at $2,000,000 for violations other than false headers.
- Internet access service providers, under 7706(g), may sue where adversely affected, at up to $100 per message for header violations and up to $25 for others, capped at $1,000,000 outside the header provision.
- Individual recipients have no general private right of action under the federal statute. The enforcement provisions name the Commission, other federal agencies, state officials and access service providers, and stop there.
Both damages provisions allow trebling where the court finds the violation wilful and knowing or the conduct included one of the aggravated violations in 7704(b), which cover address harvesting, dictionary attacks, automated account registration and relaying through unauthorised computers. Both also permit the court to reduce damages where the defendant established and implemented commercially reasonable practices and procedures with due care.
The Aggravated Violations
Section 7704(b) sits apart from the five conduct rules and describes practices Congress treated as aggravating rather than merely non-compliant. They matter beyond their own prohibition, because both statutory damages provisions permit a court to treble an award where the defendant's conduct included one of them.
- Address harvesting. Initiating an unlawful commercial message, or assisting in its origination by supplying or selecting addresses, with actual or fairly implied knowledge that the recipient's address was obtained by automated means from a website or proprietary online service operated by a person who had given notice that it would not give, sell or transfer addresses.
- Dictionary attacks. The same, where the address was obtained by an automated means that generates possible addresses by combining names, letters or numbers into permutations.
- Automated account registration. Using scripts or other automated means to register for multiple email accounts or online user accounts from which to transmit unlawful commercial messages.
- Relaying through unauthorised computers. Knowingly relaying or retransmitting an unlawful commercial message from a protected computer accessed without authorisation.
The FTC guide notes that the statute also carries criminal exposure, listing imprisonment among the penalties for accessing someone else's computer to send spam without permission, using false information to register for multiple email accounts or domain names, and relaying or retransmitting multiple messages through a computer to mislead others about their origin.
The reduction provisions run the other way with the same structure. Under both 7706(f)(3)(D) and 7706(g)(3)(D), a court assessing damages may consider whether the defendant established and implemented, with due care, commercially reasonable practices and procedures designed to prevent the violations, and whether the violation occurred despite commercially reasonable efforts to maintain compliance with them. The statute makes those matters relevant to quantum; it does not make them a defence to liability.
Preemption Is Narrower Than It Looks
Section 7707(b)(1) supersedes any state statute, regulation or rule “that expressly regulates the use of electronic mail to send commercial messages, except to the extent that any such statute, regulation, or rule prohibits falsity or deception in any portion of a commercial electronic mail message or information attached thereto.” Subsection (b)(2) preserves state laws that are not specific to email — trespass, contract and tort — and other state laws going to fraud or computer crime.
The falsity-and-deception carve-out is what keeps state anti-spam statutes operative, and the practical consequence is that some of them supply the private remedy the federal statute withholds. California's Business and Professions Code section 17529.5 makes it unlawful to advertise in a commercial email advertisement sent from or to a California address where the message carries a third party's domain name without permission, carries falsified, misrepresented or forged header information, or has a subject line the sender knows would likely mislead a reasonable recipient about a material fact.
The remedy is what distinguishes it. Section 17529.5(b)(1)(A) permits an action by the Attorney General, by an email service provider, or by a recipient, and (b)(1)(B) allows actual damages or liquidated damages of $1,000 per offending message, capped at $1,000,000 per incident, plus fees and costs to a prevailing plaintiff. Paragraph (2) reduces liquidated damages to $100 per message and $100,000 per incident where the court finds the defendant established and implemented, with due care, practices reasonably designed to prevent violations. Subparagraph (D) excludes a service provider merely engaged in routine transmission.
The three prohibited circumstances in the California section all sound in falsity or deception, which is what places the statute inside the federal carve-out rather than outside it.
What This Guide Does Not Cover
Foreign commercial email regimes — Canada's anti-spam legislation and the consent rules that apply to electronic marketing in the European Union among them — impose consent architectures that differ from the American model in kind rather than in degree, and are not charted here. Neither is the separate body of federal law governing marketing calls and text messages, which turns on a different statute and a different consent standard.
16 CFR 316.4, the labelling rule for commercial email containing sexually oriented material, is summarised above only by reference. It sets out prescribed subject-line text and a constrained initially-viewable message body, and does not apply where the recipient gave prior affirmative consent.
Background
For the underlying law rather than this development: California privacy law, Retail & E-Commerce privacy law.
Frequently Asked Questions
Does CAN-SPAM apply to business-to-business email?
How is a transactional message distinguished from a commercial one?
How long does a sender have to honour an opt-out request?
Can a recipient sue under CAN-SPAM?
What is the maximum civil penalty for a CAN-SPAM violation?
Sources
Everything above is reported from these documents. Follow them to verify.
- 15 U.S.C. § 7702, Definitions (CAN-SPAM Act) statute
- 15 U.S.C. § 7704, Other protections for users of commercial electronic mail statute
- 15 U.S.C. § 7706, Enforcement generally statute
- 15 U.S.C. § 7707, Effect on other laws statute
- 16 CFR Part 316, CAN-SPAM Rule regulation
- 16 CFR § 1.98, Adjustment of civil monetary penalty amounts regulation
- FTC, CAN-SPAM Act: A Compliance Guide for Business agency guidance
- Cal. Bus. & Prof. Code § 17529.5, Unlawful commercial e-mail advertisements statute
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.