CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
TCPA And DNC Compliance

Does TCPA cover emails?

Back to InsightsDoes TCPA cover emails?

Does TCPA cover emails?

Key Facts

  • The TCPA regulates calls, texts, and faxes — email is absent from its scope and governed instead by CAN-SPAM per Law Ruler
  • CAN-SPAM penalties reach $43,280 per violating email, making email compliance comparably serious to TCPA's $500–$1,500 per call/text per Seyfarth
  • Under the FCC's Opt-Out Rule effective April 11, 2025, email is a legally recognized revocation channel — opt-outs must be honored across robocalls and robotexts within 10 business days per BCLP
  • April 2026 saw 330 TCPA cases and 255 class actions filed — a 40% year-over-year increase in litigation volume per Attentive
  • The largest TCPA damages award ever reached $925 million, with no cap on total statutory penalties per Drips
  • State email laws in Washington, California, and Maryland now fuel litigation over misleading subject lines like "Ends Tonight" — even when CAN-SPAM is satisfied per M&S Law Group
  • Opt-out records should be retained at least four years to match the TCPA's statute of limitations and serve as legal defense per BCLP

The Compliance Confusion: Why Businesses Assume Email Falls Under the TCPA

A reactivation campaign touches the same contact three ways: a call, a text, an email. Which rules govern which touch? Most operators assume the strictest rule — the TCPA — applies to all of them, and that assumption shapes consent decisions, list purchases, and campaign design.

The stakes of guessing wrong are real. TCPA statutory damages run $500 to $1,500 per violation with no cap on the total, and the litigation environment is accelerating: April 2026 saw 330 TCPA cases and 255 class actions filed, a 40% increase over April 2025. For a clinic running appointment reminders or a membership business working lapsed members, a single misclassified channel can multiply quickly across a contact list.

Here is the confusion in a nutshell. The TCPA regulates calls, texts, and faxes — prior express written consent is required for marketing texts, robocalls, and fax advertisements — but email never appears on that list. Commercial email follows a different statute entirely: as Law Ruler puts it, commercial email follows CAN-SPAM rather than the TCPA.

So why do businesses keep assuming email falls under the TCPA? A few reasons:

  • Multi-touch campaigns blur the channels together, so teams apply one consent standard across all of them for simplicity.
  • TCPA's reputation for brutal penalties makes "over-comply" feel like the safe default.
  • Email does have a TCPA connection — just not the one people think. Under the FCC's Opt-Out Rule effective April 11, 2025, an email can serve as a valid consent revocation channel, honored across robocalls and robotexts within 10 business days.
  • Email carries its own real risk that gets mislabeled as TCPA risk. CAN-SPAM penalties reach $43,280 per separate violating email, and state laws in Washington, California, and Maryland are fueling litigation over misleading subject lines and sender identity.

That last point matters most for clinics, franchises, and membership businesses running structured multi-touch reactivation campaigns. Treating email as "TCPA-covered" leads to over-conservatism on email while leaving the actual email risks — deceptive subject lines, missing physical addresses, broken unsubscribe handling — unaddressed. Meanwhile, the call and text touches, where TCPA exposure genuinely lives, may get less scrutiny than they deserve.

The fix is channel-specific thinking. Apply TCPA consent standards to calls and texts, CAN-SPAM requirements to email, and build one suppression system that catches opt-outs from any channel. That is the discipline we apply at My AI Call Center before any campaign launches — reviewing list source and consent records channel by channel, and flagging plainly when a list will not support the campaign. Guessing wrong about which rules apply is expensive; mapping them correctly is not.

The Clear Answer: Emails Are Governed by CAN-SPAM, Not the TCPA

If you've been scrubbing your email lists against TCPA requirements, you can stop — but don't relax just yet. The TCPA simply does not regulate email, and every credible legal source agrees on that point.

The statute's scope is explicitly limited to calls, texts, and faxes. BCLP's analysis of TCPA consent requirements frames the law around "prior express written consent" for marketing text messages, marketing robocalls, and fax advertisements — email never appears in the list. Other firms describe the same boundaries: telemarketing calls or texts to wireless numbers, and prerecorded-voice calls to landlines.

Email lives under a different statute entirely. Law Ruler states it directly: "Commercial email, including automated email campaigns sent by law firms, follows the CAN-SPAM Act rather than the TCPA." Seyfarth's compliance guidance draws the same line, separating "TCPA rules regarding texts and calls to consumers" from "CAN-SPAM Act rules with respect to emails."

Here's the critical nuance: not covered by the TCPA does not mean unregulated. CAN-SPAM carries penalties of up to $43,280 per separate violating email, according to Seyfarth — and a single campaign can generate thousands of "separate" emails. For context, TCPA statutory damages run $500–$1,500 per violation with no cap, so the two regimes are comparably serious even though they govern different channels.

CAN-SPAM's core requirements for commercial email include:

  • Accurate sender information and no deceptive subject lines
  • A valid physical postal address in every message
  • A working unsubscribe mechanism that stays active at least 30 days after sending
  • Opt-out requests processed within 10 business days

And CAN-SPAM is increasingly just the floor. M&S Law Group reports that plaintiffs are using state email laws in Washington, California, and Maryland to sue over misleading subject lines like "Ends Tonight" — even where the email body clarifies the terms and CAN-SPAM is technically satisfied.

Email also intersects with the TCPA in one important way: as a consent-revocation channel. Under the FCC's opt-out rule effective April 11, 2025, a consumer can revoke consent for robocalls and robotexts by email, and that revocation must be honored within 10 business days. Drips confirms the obligation applies "no matter how a consumer opts out — SMS, phone, email, or other channels."

This is why multi-touch campaigns need channel-specific compliance thinking. In a structured reactivation campaign that blends calls, texts, and emails, the call and text touches follow TCPA consent standards while the email touches follow CAN-SPAM — and an opt-out arriving through any channel suppresses the contact everywhere. That's the operating standard at My AI Call Center: opt-outs are logged and honored immediately across all campaigns, with records retained well beyond the TCPA's four-year statute of limitations.

The practical takeaway is simple. Run your emails under CAN-SPAM discipline, run your calls and texts under TCPA discipline, and treat every opt-out — regardless of how it arrives — as universal.

The One Place Email Does Matter Under the TCPA: Opt-Outs

While email sits outside the TCPA's regulated channels, it plays a surprisingly powerful role inside them: it is a legally recognized way for consumers to revoke consent to your calls and texts. Miss that email, and every robocall that follows can carry $500 to $1,500 per violation with no cap on total exposure.

Under the FCC's Opt-Out Rule, which took effect April 11, 2025, a consumer can revoke consent in any "reasonable manner" — and BCLP's analysis of the rule confirms that explicitly includes an email to any address where the consumer can reasonably expect to reach you. Once received, that revocation extends to both robocalls and robotexts, regardless of the channel it arrived through.

The deadline is firm. As Drips' compliance overview puts it, no matter how a consumer opts out — SMS, phone, email, or other channels — the revocation must be honored within 10 business days. Best practice is real-time suppression, not a weekly batch job.

For text programs, the FCC also designated specific keywords that automatically count as revocation:

  • STOP
  • QUIT and END
  • REVOKE and OPT-OUT
  • CANCEL
  • UNSUBSCRIBE

Here's the critical nuance: a consumer who replies "UNSUBSCRIBE" to a text, or emails your support inbox asking to be removed, has revoked consent across your entire calling operation — not just the one campaign that triggered the request. Cross-channel suppression is no longer optional.

Documentation is your defense. Because the TCPA carries a four-year statute of limitations, attorneys recommend retaining opt-out records for at least four years. With TCPA filings up 40% year-over-year in April 2026, the question in litigation is rarely whether someone opted out — it is whether you can prove when, how, and what you did next.

This is why documented opt-out and DNC logs are a legal defense, not just a service feature. At My AI Call Center, every campaign closes with a dispositioned contact list plus opt-out and DNC logs, and keyword opt-outs like STOP and REVOKE are honored immediately and carried into client DNC records across all campaigns. When consent records are reviewed before launch and revocations are logged the moment they arrive — by text, phone, or email — a revocation request becomes a routine event instead of a $1,500-per-call liability.

The takeaway: email may not be regulated by the TCPA, but an email sitting unread in your inbox can still trigger TCPA liability. Build email into your opt-out intake, suppress across every channel, and keep the records for four years.

Running Multi-Touch Campaigns Without Mixing Up the Rules

A multi-touch campaign that mixes calls, texts, and emails isn't running under one rulebook — it's running under two, and treating them as one is where campaigns get into trouble.

The split is straightforward. The TCPA governs calls, texts, and faxes — email is absent from its list of regulated channels. Commercial email follows the CAN-SPAM Act instead, which carries its own set of requirements. Seyfarth's attorney guidance makes the same distinction, separating TCPA rules for texts and calls from CAN-SPAM rules for emails.

For a Database Reactivation Blitz that touches a dormant list across all three channels, that means applying each regime to its own channel:

  • Call and text touches need prior express written consent under TCPA standards, with penalties of $500–$1,500 per violation and no cap on totals.
  • Email touches need accurate sender information, a physical address, a working unsubscribe honored within 10 business days, and subject lines that don't deceive.
  • An opt-out received by email must suppress that contact from calling and texting too — the FCC's Opt-Out Rule, effective April 11, 2025, recognizes email as a valid revocation channel that applies across robocalls and robotexts.

That last point matters more than most teams realize. A consumer who replies "stop emailing me" has, under the new rule, potentially revoked consent for your calls and texts as well. Opt-out intake needs to be cross-channel, and opt-out records should be kept at least four years, matching the TCPA's statute of limitations.

The email side carries a risk CAN-SPAM compliance alone won't cover. Plaintiffs are increasingly using state email laws in Washington, California, and Maryland to challenge misleading subject lines, sender identity, and undisclosed conditions on "free" offers — and many businesses wrongly treat email compliance as beginning and ending with CAN-SPAM, according to M&S Law Group. Courts have allowed claims based on subject lines alone — phrases like "Ends Tonight" or "Final Hours" — even when the email body clarifies the details and CAN-SPAM is otherwise satisfied.

The practical fix is accuracy in creative, not cleverness. As M&S attorney Aaron Parry puts it, businesses that prioritize transparency and accuracy in their email campaigns are generally best positioned to reduce risk. If an offer genuinely ends that night, "Ends Tonight" is fine. If it doesn't, no amount of fine print saves the subject line.

This is the discipline we build into every structured campaign at My AI Call Center: consent records checked before launch, TCPA standards on the call and text touches, and opt-outs logged and honored immediately across channels. When each channel runs under its own rulebook — cleanly separated — a multi-touch blitz stays aggressive and compliant at the same time.

How a Managed, List-Disciplined Approach Keeps Every Channel Clean

The legal landscape is fragmented by design — TCPA governs calls and texts, CAN-SPAM governs email, and state laws layer on top. The only practical way to manage that complexity is with a disciplined process that treats every channel's rules as non-negotiable before the first contact goes out.

That discipline starts with the list. Before any campaign launches, the list source and consent records get reviewed — and bought lists without clear permission records get flagged, and in most cases declined. This matters because the exposure is real: TCPA statutory damages run $500 to $1,500 per violation with no cap on total penalties, and the largest TCPA damages ever awarded reached $925 million.

With the FCC's one-to-one consent rule vacated and regional variation emerging on oral versus written consent, written, channel-specific consent records remain the most defensible standard. A consent record that specifies the number, the calling entity, the purpose, and the frequency protects the calling campaign — while email touches in a multi-touch campaign follow their own CAN-SPAM requirements: accurate sender information, non-deceptive subject lines, a physical address, and a working unsubscribe honored within 10 business days (Law Ruler's compliance analysis).

Opt-out handling is where channels collide. Because the FCC recognizes email as a valid revocation channel — and revocation extends across robocalls and robotexts regardless of the medium used — an opt-out received by email must suppress that contact from every calling and texting campaign. At My AI Call Center, opt-outs are logged and honored immediately across campaigns, not at the 10-business-day legal deadline. A structured campaign keeps this clean through:

  • List and consent review before launch, covering list source, consent records, and calling windows
  • AI voices treated as artificial voices under the TCPA, with prior express consent and AI disclosure on every call
  • Keyword opt-outs (STOP, REVOKE) and DNC requests carried into client DNC records across all campaigns
  • Opt-out and DNC logs delivered as campaign documentation — critical given the TCPA's four-year statute of limitations

Structure reduces risk in a second way: focus. Each campaign runs against an approved, permissioned, or reviewed list with one clear goal and a full quote before launch. That constraint prevents the scope creep that turns a compliant reminder campaign into an unconsented marketing blast — the kind of drift that fuels litigation. TCPA filings keep climbing, with 330 cases and 255 class actions filed in April 2026 alone, a 40% increase over the prior year, so the margin for sloppy lists keeps shrinking.

The free campaign review exists to surface these problems early. If a list cannot support the campaign — missing consent records, unclear provenance, contacts in regulated categories — that answer comes before any spend, not after a complaint. Campaign requirements vary by location, industry, contact type, and technology, so legal guidance before launch remains the client's responsibility. But a reviewed list beats a declined lawsuit every time.

Frequently Asked Questions

Does the TCPA cover emails?
No. The TCPA regulates calls, texts, and faxes — email is not on its list of covered channels. Commercial email is governed by the CAN-SPAM Act instead, as Law Ruler's compliance analysis states directly: commercial email follows CAN-SPAM rather than the TCPA.
If emails aren't under the TCPA, what law do I need to follow for email marketing?
Email falls under the CAN-SPAM Act, which requires accurate sender information, non-deceptive subject lines, a valid physical postal address, and a working unsubscribe honored within 10 business days. Penalties reach up to $43,280 per separate violating email, so 'not covered by the TCPA' does not mean unregulated.
Can a customer opt out of my calls and texts by sending an email?
Yes — this is the one place email matters under the TCPA. Under the FCC's Opt-Out Rule effective April 11, 2025, an email counts as a valid consent revocation, and it must be honored across robocalls and robotexts within 10 business days. Ignoring that email can expose every call that follows to $500–$1,500 per violation.
Do I need prior express written consent to send marketing emails?
No — prior express written consent is a TCPA standard that applies to marketing texts, robocalls, and fax advertisements, not email, per BCLP's analysis of TCPA consent requirements. Email runs on CAN-SPAM's opt-out model, though state laws in Washington, California, and Maryland add stricter rules around subject lines and sender identity.
Can I be sued over my email subject lines even if I follow CAN-SPAM?
Yes. Plaintiffs are using state email laws in Washington, California, and Maryland to sue over subject lines like 'Ends Tonight' or 'Final Hours' — even when the email body clarifies the terms and CAN-SPAM is technically satisfied, according to M&S Law Group. The safest approach is accuracy in your creative: if the offer doesn't genuinely end tonight, no fine print saves the subject line.
How do I keep a multi-touch campaign with calls, texts, and emails compliant?
Apply each rulebook to its own channel: TCPA consent standards for the call and text touches, CAN-SPAM requirements for the email touches, and one suppression system so an opt-out from any channel suppresses the contact everywhere. At My AI Call Center, list source and consent records are reviewed channel by channel before launch, and opt-out and DNC logs are retained given the TCPA's four-year statute of limitations.

Two Rulebooks, One Suppression List: The Bottom Line on Email and the TCPA

The answer is clear: email is not covered by the TCPA. Commercial email runs under CAN-SPAM — with penalties up to $43,280 per violating email, per Seyfarth's compliance guidance — plus a growing wave of state email laws in Washington, California, and Maryland. Meanwhile, the TCPA governs your calls and texts, where statutory damages of $500 to $1,500 per violation carry no cap. The one place the two worlds meet: an email can now serve as a valid consent revocation, and that revocation must suppress the contact across every calling and texting campaign within 10 business days. So run each channel under its own rulebook, honor every opt-out universally, and keep those records for at least four years. If you're planning a multi-touch reactivation campaign and want your list and consent records reviewed before you spend anything, My AI Call Center offers a free campaign review — one clear goal, quoted before launch, and a plain answer if your list won't support the campaign.

Get campaign planning tips