ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

Does TCPA cover emails?

Back to InsightsDoes TCPA cover emails?

Does TCPA cover emails?

Key Facts

The Short Answer: TCPA Covers Calls and Texts, Not Emails

The short answer is clear: the TCPA (47 U.S.C. §227) governs telephone calls and text messages only, while commercial email is regulated separately under the CAN-SPAM Act (15 U.S.C. §§7701–7713). This distinction trips up business owners running multi-channel outreach because the two regimes operate under fundamentally different rules. For a service like CallMyCustomers that coordinates calls, texts, and emails for reactivation campaigns, applying the wrong framework can trigger significant liability.

Under the TCPA, marketing calls and texts generally require prior express written consent, and violations carry statutory damages of $500 per violation, up to $1,500 if willful or knowing. In contrast, CAN-SPAM follows an opt-out model: businesses can send commercial email without prior consent, but must honor unsubscribe requests within 10 business days and include accurate sender information, a physical address, and a clear unsubscribe method. CAN-SPAM penalties reach up to $43,280 per violating email per the FTC, or approximately $53,088 per email under current FTC guidance. These differences mean that consent practices valid for email could violate TCPA if applied to texts or calls, and vice versa.

For businesses managing outreach across channels, compliance requires treating each pathway separately. CallMyCustomers addresses this by applying consent-based rules to call and text campaigns while adhering to CAN-SPAM’s content and opt-out requirements for email. Crucially, opt-outs sent via email can validly revoke consent for texting, so suppression lists must sync across dialer, texting, and email systems within 24 hours. Email unsubscribe links must also remain functional for at least 30 days after each send, with no login, fee, or extra data required. Outsourcing does not shift liability under either regime — the business whose message is sent remains responsible, reinforcing the value of owner approval before any communication goes out. Missteps in either channel can quickly compound costs, especially when reactivating lists of past customers who may not recall opting in.

Most marketers assume every outreach channel requires permission before the first message. In reality, the two federal laws governing US outreach work on opposite philosophies — and applying the wrong playbook to the wrong channel is where compliance trouble starts.

The TCPA playbook: consent first. For texts and calls, marketing messages generally require prior express written consent, with statutory damages of $500 per violation — up to $1,500 if the violation is willful or knowing, according to Hunton's TCPA compliance guidance. Timing matters too: messages may only be sent during quiet hours of 8am–9pm in the recipient's local time, and some states are stricter — a 2025 compliance analysis notes Florida and Oklahoma cut off at 8pm. Recipients can revoke consent with any of seven FCC-recognized keywords: stop, quit, end, revoke, opt out, cancel, or unsubscribe.

The CAN-SPAM playbook: opt-out instead. Email operates under a completely different model. As business litigation attorney Matthew Fornaro explains, "you can send commercial email to an address without prior consent, as long as you honor the opt-out when it comes." That surprises many marketers who have heard "get permission first" as a blanket rule — it isn't one under US email law. What CAN-SPAM demands instead is honesty and an exit:

  • Accurate sender information and no deceptive subject lines
  • A valid physical postal address in every message
  • A clear, working unsubscribe mechanism honored within 10 business days
  • The same rules for B2B as for consumer email — there is no B2B exemption

The stakes on the email side are real, even without consent requirements. Penalties reach tens of thousands of dollars per violating email — Octillo Law's compliance advisory cites up to $43,280 per email, while FTC guidance cited by Fornaro puts the figure near $53,088, likely reflecting inflation adjustments over time. Unsubscribe links must also stay functional for at least 30 days after each send, per Law Ruler's compliance guidance.

One more wrinkle: outsourcing doesn't outsource liability. Under CAN-SPAM, liability extends to the initiator, the sender, and the party who procures the sending — so hiring a vendor to run your email doesn't shift responsibility if an opt-out goes ignored. That's why, at CallMyCustomers, the owner approves every script, offer, and message before anything goes out, whether the campaign mix includes calls, texts, or emails.

The practical takeaway for any service business reactivating past customers: keep the two regimes separate in your head. Consent-based rules govern your calls and texts; content and opt-out rules govern your email.

Where the Channels Collide: Opt-Outs, Outsourcing, and Shifting Rules

Where the Channels Collide: Opt-Outs, Outsourcing, and Shifting Rules

While email isn’t regulated by the TCPA, the practical reality for businesses running multi-channel outreach is that opt-outs received by email can validly revoke consent for text messages, requiring suppression lists to sync across email, texting, and dialer systems within 24 hours. This operational overlap means compliance isn’t siloed by channel — a customer who replies “STOP” to a promotional email must be suppressed from future texts and calls just as if they’d texted the keyword directly. For a service like CallMyCustomers that manages calls, texts, and emails together under a single reactivation campaign, this cross-channel synchronization is essential to avoid inadvertent violations.

Outsourcing doesn’t outsource liability — under CAN-SPAM, the business whose product is promoted remains liable even if a vendor sends the email or fails to honor an opt-out. This principle reinforces the importance of models where clients retain control, such as CallMyCustomers’ owner-approval workflow, ensuring every script, offer, and message is signed off before deployment. The evolving TCPA landscape adds further complexity: the FCC’s one-to-one consent rule was vacated by the Eleventh Circuit in January 2025 and formally removed by July 2025, while the McLaughlin Chiropractic decision affirmed that district courts are not bound by the FCC’s TCPA interpretations. Meanwhile, a February 2026 Fifth Circuit ruling created state-level inconsistency by holding that TCPA prior express consent can be given orally or in writing in Texas, Louisiana, and Mississippi. These shifts contribute to a busy litigation environment, with WebRecon recording 2,810 TCPA filings in calendar 2025, up 0.8% from 2024. For businesses navigating this terrain, maintaining centralized suppression lists and honoring opt-outs across all channels within 10 business days isn’t just best practice — it’s a necessity.

Running Compliant Reactivation Campaigns Across Every Channel

Knowing the rules is one thing; running a reactivation campaign that follows them across phone, text, and email is where most businesses slip. The good news: a channel-by-channel checklist keeps you compliant without slowing you down.

Treat each channel under its own framework. Calls and texts fall under the TCPA, which requires prior express written consent for many marketing messages and carries statutory damages of $500 per violation, up to $1,500 if willful, per Hunton's compliance guidance. Email runs on CAN-SPAM's opt-out model — no prior consent needed, but accurate sender info, a physical address, and a working unsubscribe are mandatory, as Law Ruler's TCPA guide explains. Keep the regimes separate in your head, as one business litigation attorney puts it.

Opt-outs are where channels intersect. An email reply like "unsubscribe" can validly revoke consent for a texting campaign, and suppression lists should propagate to every system holding that number within 24 hours, according to TCPA compliance research. Both regimes share a 10-business-day processing deadline — but "immediately" is the only safe policy.

Your practical reactivation checklist:

  • Apply consent-based rules to calls/texts; apply CAN-SPAM content and opt-out rules to email.
  • Honor opt-outs immediately and sync suppression across dialer, texting, and email systems.
  • Keep email unsubscribe links live at least 30 days after each send, single-step — no login, no fee, no extra data required.
  • Document consent at collection, including explicit consent captured in your booking flow.
  • Retain consent and opt-out records for at least five years, since TCPA claims can run four years.

One more rule matters: outsourcing doesn't outsource liability. Under CAN-SPAM, the business whose product is promoted can be liable even when a vendor sends the email, per Fornaro Legal's analysis. That's exactly why CallMyCustomers uses an owner-approval model — every script, offer, and message is signed off by you before anything is sent, so nothing goes out that you haven't seen.

The stakes are real: 2,810 TCPA filings landed in calendar 2025, up 0.8% from 2024, and plaintiffs keep testing the bounds of "reasonable" opt-out language. Compliance isn't a barrier to reactivation — it's the foundation that makes it repeatable.

Turn past customers, old quotes, and inactive members into booked work — approved by you, run by us. Get a free list review before you spend a dollar, and see exactly what your customer list can produce.

Frequently Asked Questions

Does the TCPA regulate marketing emails?
No. The TCPA (47 U.S.C. §227) governs telephone calls and text messages only, while commercial email is regulated separately under the CAN-SPAM Act (15 U.S.C. §§7701–7713). Multiple legal sources confirm that a marketing email itself doesn't trigger TCPA liability.
Do I need someone's permission before emailing them marketing messages?
Not under US federal law. CAN-SPAM uses an opt-out model — you can send commercial email without prior consent as long as you honor unsubscribe requests within 10 business days, include accurate sender info, and provide a physical address. This surprises many marketers, as business litigation attorney Matthew Fornaro notes.
What are the penalties for breaking TCPA vs. CAN-SPAM rules?
TCPA violations carry statutory damages of $500 per call or text, up to $1,500 if willful or knowing, per Hunton's compliance guidance. CAN-SPAM penalties are even steeper per message — Octillo Law cites up to $43,280 per violating email, with some FTC guidance putting the figure near $53,088 due to inflation adjustments.
If a customer replies "unsubscribe" to my email, do I have to stop texting them too?
Yes. Even though email isn't TCPA-regulated, an email opt-out can validly revoke consent for a texting campaign, so suppression lists should sync across your email, texting, and dialer systems within 24 hours, per TCPA compliance research. Both regimes share a 10-business-day processing deadline, but honoring opt-outs immediately is the only safe policy.
If I hire a vendor to send my emails or texts, are they responsible for compliance?
No — outsourcing doesn't outsource liability. Under CAN-SPAM, liability extends to the initiator, the sender, and the party who procures the sending, so the business whose product is promoted remains responsible even if a vendor fails to honor an opt-out, per Fornaro Legal's analysis. That's why CallMyCustomers has clients approve every script, offer, and message before anything goes out.
Are the rules different for B2B emails or texts to business customers?
There's no B2B exemption under CAN-SPAM — business-to-business email is regulated the same as consumer email if the primary purpose is commercial. On the TCPA side, the rules for calls and texts apply regardless of recipient type, and compliance guidance recommends documenting consent and retaining opt-out records for at least five years.

Your Reactivation Engine Runs on Compliance

Understanding that TCPA governs calls and texts while CAN-SPAM regulates email isn’t just legal trivia — it’s the backbone of a reactivation strategy that protects your business and unlocks repeat revenue. By treating each channel with its own rulebook — consent-based for phone and text, opt-out focused for email — you avoid costly missteps and build trust with every outreach. Sync suppression lists across systems, honor opt-outs immediately, keep unsubscribe links live for 30 days, and never let outsourcing erase your liability. With 2,810 TCPA filings in 2025 alone, compliance isn’t optional — it’s how you turn past customers into booked work, safely and consistently. See what your list can produce with a free list review before you spend a dollar.

Stay in the Loop