
Who is exempt from the spam act?
Key Facts
- Exemptions from CAN-SPAM depend entirely on message content — only purely transactional or relationship messages qualify, per the FTC's compliance guide.
- There is no business-to-business exemption — the FTC states the law makes no exception for B2B email, according to its official guidance.
- CAN-SPAM penalties reach up to $53,088 per violating email, per current enforcement figures.
- Experian Consumer Services paid $650,000 for disguising marketing emails as transactional messages, per FTC enforcement records.
- Tacking a promo onto an order confirmation can convert an exempt message into fully regulated commercial email, legal analysts warn.
- Texts fall under TCPA, where damages run $500 per violation — up to $1,500 for willful violations — with no class action cap, per this legal comparison.
- Since February 2025, major US carriers block 100% of unregistered 10DLC business texting traffic, with violations costing $10,000 each, per carrier rules analysis.
The Only Real Exemption: Transactional and Relationship Messages
If you're hoping your business qualifies for a pass under the CAN-SPAM Act, here's the honest answer: exemptions depend entirely on what's inside the message, not who sends it. According to the FTC's compliance guide, only messages containing purely transactional or relationship content escape most of the Act's requirements — and even those still can't carry false or misleading routing information.
The FTC defines five narrow categories that qualify. The agency is explicit that it views these categories narrowly, warning businesses not to assume that every message sent to someone with an ongoing commercial relationship is automatically exempt.
The five exempt categories are:
- Messages facilitating, completing, or confirming a commercial transaction the recipient already agreed to
- Warranty, recall, safety, or security information about a product or service the recipient purchased
- Notices about changes in terms, features, or standing in a membership, subscription, account, loan, or similar ongoing relationship, plus periodic account balance information
- Information about an employment relationship or employee benefits
- Delivery of goods or services as part of an already agreed-upon transaction
Here's where businesses get into trouble: mixed content can destroy the exemption. If a message blends commercial and transactional content, the FTC applies a "primary purpose" test — a promotional subject line or promo-heavy body makes the entire message fully commercial and fully regulated. Legal analysts call out the classic mistake of tacking a promotional offer onto an order confirmation and assuming the whole message stays exempt.
The consequences are real. Experian Consumer Services paid $650,000 after the FTC found it had disguised marketing emails as transactional messages. CAN-SPAM penalties now reach up to $53,088 per violating email, and liability cannot be contracted away — both the product-promoting company and the message-sending company can be held responsible.
This shared-liability rule matters for any business using a done-for-you lead response service like CallMyLeads. Because a vendor's compliance failures can land on the client, the booking flow collects explicit consent, opt-outs are honored immediately and automatically, and business texting runs under US carrier rules (A2P 10DLC). The exemption question also never extends to texting: texts are TCPA territory, where marketing messages require prior express written consent — a stricter standard than CAN-SPAM's opt-out model.
The takeaway is simple: if your message's main job is to sell something, treat it as fully commercial, no matter who you are or who the recipient is.
Why Text Messaging Falls Outside CAN-SPAM (and Into TCPA Territory)
If your business texts leads, the spam act you worry about probably isn't the one that applies to you. CAN-SPAM governs commercial email — but text messages live in different legal territory, and the rules there are far stricter.
CAN-SPAM does not generally apply to SMS or MMS marketing. Those messages fall under the Telephone Consumer Protection Act (TCPA), which requires prior express written consent before you send marketing texts to a cell phone. As one legal comparison puts it, "treat every message to a phone number as TCPA territory and you will rarely be wrong."
The contrast with email is stark. CAN-SPAM is an opt-out law: sending a marketing email without consent is legal if you honor unsubscribes, but sending a marketing text without consent violates federal law outright. Email consent doesn't transfer either — a customer who opted into your emails has not opted into your texts.
The stakes explain why. TCPA statutory damages run $500 per violation, up to $1,500 for willful violations, with no cap on class action exposure. By one estimate, 10,000 unauthorized texts could mean up to $15 million in potential liability.
The most common mistake is applying CAN-SPAM's email logic to texting — send first, offer unsubscribe later. That approach is precisely what generates TCPA liability. Texting has its own requirements:
- Explicit, separate SMS opt-in — email consent doesn't count
- Immediate opt-out handling when someone replies "STOP"
- Quiet hours: texts only between 8 am and 9 pm recipient local time
- A2P 10DLC registration — carriers now block unregistered business texting traffic
There are narrow exceptions. An existing business relationship can substitute for formal consent for limited windows — 18 months after a purchase, three months after an inquiry — unless the consumer opts out earlier, per the same consent rules analysis. And since the FCC's one-to-one consent rule took effect, blanket consent collected by lead generators no longer qualifies; each company receiving shared lead data must obtain its own separate, explicit consent.
One more thing: liability can't be outsourced. Both the company whose products are promoted and the company sending the messages can be held responsible, and the FTC is explicit that this responsibility cannot be contracted away. If you hire a texting vendor, you share the risk.
That shared-liability reality is why CallMyLeads builds compliance into every plan rather than treating it as an add-on. The booking flow collects explicit consent before any text goes out, opt-outs are honored immediately and automatically, quiet-hours rules are followed, and business texting runs on registered A2P 10DLC routes. For businesses where every missed lead is missed revenue, fast response and lawful response aren't competing priorities — they're the same system working correctly.
How CallMyLeads Built Compliance Into Its Done-For-You Service
Hiring a texting vendor doesn't shield you from the law — the FTC is explicit that legal responsibility cannot be contracted away. If you authorize a vendor to market on your behalf, you share the liability. That reality shaped how CallMyLeads built its done-for-you lead response service: compliance runs inside the system, not as an afterthought.
Because text messages fall under the TCPA rather than CAN-SPAM, the stakes are higher. TCPA statutory damages run $500 per violation — up to $1,500 for willful violations — with no cap on class action exposure. A batch of 10,000 unauthorized texts could theoretically mean up to $15 million in potential liability. So the guardrails matter as much as the speed.
Every business texting number is registered under A2P 10DLC, the US carrier framework for application-to-person messaging. This matters practically: since February 2025, major US carriers block 100% of unregistered 10DLC traffic, and violations can cost $10,000 each. Registered traffic also filters spam before it reaches your team — and screened spam numbers never touch your bill.
The consent piece is built into the flow itself. The booking process collects explicit consent before any texts go out, which aligns with the FCC's one-to-one consent requirement — blanket consent from lead generators no longer qualifies, so each business must capture its own. For practices buying shared leads in home services, dental, or legal, that distinction is the difference between a compliant campaign and a lawsuit.
Opt-out handling is automatic and immediate. CAN-SPAM allows up to 10 business days to honor an opt-out, but TCPA territory demands faster discipline — a nurture sequence that keeps texting someone who replied "STOP" is exactly the mistake that generates statutory damages. Quiet-hours rules are enforced the same way, keeping messages inside the 8 am to 9 pm recipient-local-time window.
For regulated clients, the layering goes further:
- HIPAA-aligned configuration for dental and medical practices — approved scripts only, no diagnosis or treatment advice.
- Honest AI disclosure on every call, so consent is informed from the first sentence.
- Nurture sequences that stop the moment a lead opts out, before the next message ever sends.
None of this makes the client's legal obligations disappear — CAN-SPAM is a baseline, not a complete program, and regulated firms must layer their own requirements on top. What it does is remove the most common failure points: unregistered numbers, missing consent records, ignored opt-outs, and texts sent at midnight. The speed advantage only counts if the message was legal to send.
Frequently Asked Questions
Is my business exempt from the CAN-SPAM Act if we only send transactional emails?
Does the CAN-SPAM Act apply to text messages I send to customers?
Can I use my email list to send marketing texts if customers opted in for emails?
What happens if I accidentally send a promotional text without consent?
Is there a CAN-SPAM exemption for business-to-business (B2B) emails?
If I hire a vendor to send texts or emails for my business, am I still liable for compliance mistakes?
The Short Answer: Almost Nobody Gets a Pass
If you were hoping for a loophole, here it is straight: exemptions from the spam act depend on what's in the message, not who sends it. Only purely transactional or relationship content escapes most CAN-SPAM rules — and the FTC reads those five categories narrowly. Tack a promo onto an order confirmation and the whole message becomes fully regulated, a mistake that cost Experian $650,000. If you text leads, the bar is even higher: texts fall under the TCPA, where marketing messages require prior express written consent and violations run $500 to $1,500 each with no class action cap. And since liability can't be contracted away, the vendor you hire matters as much as your own practices. That's why CallMyLeads builds compliance into every plan — explicit consent in the booking flow, immediate opt-out handling, quiet-hours enforcement, and registered A2P 10DLC texting — so fast lead response and lawful lead response are the same system. Your next step: audit every automated message you send. If its main job is selling, treat it as fully commercial. Then book a free 15-minute scoping call to see how every lead can get a compliant, instant reply — before interest disappears.