Redoubt Vault

CAN-SPAM when your tenants send the email, not you

A platform that sends email for its customers sits between the business being advertised and the provider that delivers the message. This page sets out what the US CAN-SPAM Act and the FTC say about who answers for that email — in their own words.

This is not legal advice. Whether a particular platform is responsible for a particular message depends on facts this page cannot know. It covers the US federal law only; other countries' laws work differently. If the question is live for you, ask a lawyer.

The FTC's own summary

The FTC's compliance guide answers the shared-responsibility question directly:

“Both the company whose product is promoted in the message and the company that actually sends the message may be held legally responsible.” FTC: CAN-SPAM Act: A Compliance Guide for Business

The same guide says you cannot contract that responsibility away, makes no exception for business-to-business email, requires opt-outs to be honoured within 10 business days, and currently lists penalties of up to $53,088 for each email in violation.

What the statute's words turn on

Whether a platform is treated as one of the parties that “initiates” a message depends on definitions in the Act itself. Three matter here:

15 U.S.C. § 7702, definitions

Where a given platform falls against those words is exactly the question to take to counsel. The definition of routine conveyance is statutory text, not a ruling that any particular platform meets it. For comparison, Amazon states its own position in its SES terms:

“AWS is not the "sender" as defined in the CAN-SPAM Act or similar applicable law.” AWS Service Terms, section 15.6

Enforcement belongs to the FTC and other federal agencies, state attorneys general and internet access providers, and some of those remedies turn on whether a party had “actual knowledge, or by consciously avoiding knowing” what was happening (15 U.S.C. § 7706).

CAN-SPAM is an opt-out law

This is the point to be clear on. In general, CAN-SPAM does not require a recipient's permission before commercial email is sent; the FTC's guide sets out what a message must contain and how opt-outs must work, not a prior-consent rule. The consent requirement a platform answers to sits somewhere else: its email provider's own terms, which do require consent and can require you to prove it — see what SendGrid, Mailgun and SES ask for.

So a consent record is not a CAN-SPAM defence, and nothing on this page suggests it is one. What it gives a platform is an honest account, per recipient and per tenant, of how an address arrived — which is what a provider asks for, and useful context in any conversation about what your platform knew.

Why your provider asks

Your provider isn't the villain here. It answers to the people who receive the mail, and it carries every sender on its service, including you. The asking exists because of marketers who will mail anyone, at any cost. Because of them, everyone else has to be able to show their work. Being asked is part of sending at scale; what matters is how long your answer takes.

Where Redoubt Vault fits

Redoubt Vault is an API that records how your tenants' recipients opted in, as it happens, and produces that record per recipient when you are asked. It does not decide whether anyone is liable for anything, and it never sits between you and your provider. You can read a sample evidence packet first.

What this can and can't do. It shows what your platform told us, and when, for signups recorded from the day you start. It can't rebuild what was never recorded, it doesn't see your sign-up form, it never sends messages, and it doesn't record an IP address. It doesn't show that a person clicked. And nobody can promise your provider will accept an answer.

Make a key and record your first consent event

Or read the API reference first. Pricing is on one page.

What this is based on

Related

Last checked against the sources below: 6 October 2026. Redoubt Vault is not affiliated with the FTC or Amazon Web Services.