Two Statutes, Two Channels, One Campaign
An ISO running both email nurture and SMS outreach is operating under two different federal statutes at the same time, not one compliance framework that covers both. CAN-SPAM governs commercial electronic mail specifically. The Telephone Consumer Protection Act governs calls and texts, already covered in VA Horizon’s own guide to TCPA for MCA shops. Treating one as a stand-in for the other is exactly the conflation this guide exists to prevent.
MCA Rocket’s own published glossary of industry terms lists CAN-SPAM directly among the compliance concepts it references for MCA email marketing, confirming this is already a real, live term this industry’s own vendors treat as relevant, not an abstract federal statute with no practical bearing on an ISO’s day-to-day campaigns.
What CAN-SPAM Requires in an Email
Per the FTC’s own CAN-SPAM Act compliance guide for business, the law requires accurate “From,” “To,” and routing header information that identifies the person or business who initiated the message, and a subject line that “accurately reflects the content of the message,” not a misleading hook designed purely to generate an open. The message itself has to include clear and conspicuous disclosure that it is an advertisement, and a valid physical postal address for the sender.
None of these four requirements is unusual by modern email-marketing standards, but each one is a specific, checkable line item, not a vague good-practice suggestion, and each carries the same penalty exposure below if it is missing.
The Opt-Out Rule, in Detail
CAN-SPAM’s opt-out requirement is more specific than “include an unsubscribe link.” Per the FTC’s compliance guide, the opt-out mechanism has to remain able to process a recipient’s request for at least 30 days after the email is sent, and the sender has to honor that opt-out within 10 business days. The mechanism cannot charge a fee, and it cannot require the recipient to supply any personal information beyond an email address to process the request.
An opt-out link that quietly stops working after a week, or a form that asks for a phone number and reason for leaving before it will process the request, is a real violation under this rule, not a minor UX shortcut.
What a Violation Costs
Per the FTC’s guide, each separate email sent in violation is subject to civil penalties of up to $53,088, the FTC’s current inflation-adjusted figure, and that number applies per message, not per campaign. A single non-compliant send to a list of any size multiplies that exposure by the number of messages delivered. Aggravated violations, unauthorized access to someone else’s computer to send spam, false header information, or harvesting email addresses without consent, can additionally carry criminal penalties including imprisonment.
Confirm the exact current penalty figure before repeating it in any external communication, since the FTC updates this amount by rule periodically, and the number above is only current as of this guide’s own research pass.
Where SMS Fits, and Where It Does Not, Under This Law
SMS and MMS marketing is not governed by CAN-SPAM’s specific header, subject-line, and opt-out mechanics described above; it runs under TCPA, a separate statute with its own consent requirements already covered in the site’s dedicated TCPA guide. The mistake worth guarding against is assuming a CAN-SPAM-compliant email footer, or a CAN-SPAM-trained compliance habit, automatically covers a text campaign as well. It does not, and a shop that only trains its team on one of the two statutes has a real, uncovered gap on the other channel.
The reverse mistake is just as real: a shop confident in its TCPA consent process for texting can still be running CAN-SPAM-noncompliant email campaigns in parallel, since the two compliance programs do not automatically overlap just because the same marketing team runs both.
Building One Checklist That Covers Both Channels
The practical fix is not a single unified policy document that pretends the two statutes are the same law. It is two short checklists, run against every campaign before it sends: a CAN-SPAM checklist for anything landing in an inbox, and a TCPA consent checklist for anything landing on a phone as a call or text. Running the wrong checklist against the wrong channel is how a compliant-feeling shop ends up with real exposure on the channel nobody was checking.
Human + AI SDRs run consent-checked SMS conversations by design, which keeps the texting side of an ISO’s outreach inside TCPA’s rules without asking a broker’s team to also become CAN-SPAM experts on the email side of the exact same campaign.
What this means for you
- CAN-SPAM governs commercial email specifically, with accurate headers, a non-deceptive subject line, an ad disclosure, a physical postal address, and an opt-out honored within 10 business days.
- Penalties run up to $53,088 per separate email in violation, the FTC’s current inflation-adjusted figure, with aggravated conduct carrying additional criminal exposure.
- SMS and calls fall under TCPA, a separate statute with its own consent rules, so a CAN-SPAM-compliant email program does not automatically cover an ISO’s texting campaigns.
Sources
The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.
