CAN-SPAM when your tenants send the email, not you
A platform that sends email for its customers sits between the business being advertised and the provider that delivers the message. This page sets out what the US CAN-SPAM Act and the FTC say about who answers for that email — in their own words.
This is not legal advice. Whether a particular platform is responsible for a particular message depends on facts this page cannot know. It covers the US federal law only; other countries' laws work differently. If the question is live for you, ask a lawyer.
The FTC's own summary
The FTC's compliance guide answers the shared-responsibility question directly:
“Both the company whose product is promoted in the message and the company that actually sends the message may be held legally responsible.” FTC: CAN-SPAM Act: A Compliance Guide for Business
The same guide says you cannot contract that responsibility away, makes no exception for business-to-business email, requires opt-outs to be honoured within 10 business days, and currently lists penalties of up to $53,088 for each email in violation.
What the statute's words turn on
Whether a platform is treated as one of the parties that “initiates” a message depends on definitions in the Act itself. Three matter here:
- Initiate — to originate or transmit a message, or to procure its origination or transmission, but not including “routine conveyance”.
- Routine conveyance — “the transmission, routing, relaying, handling, or storing, through an automatic technical process, of an electronic mail message for which another person has identified the recipients or provided the recipient addresses.”
- Sender — someone who initiates a message and whose product, service or website it advertises.
Where a given platform falls against those words is exactly the question to take to counsel. The definition of routine conveyance is statutory text, not a ruling that any particular platform meets it. For comparison, Amazon states its own position in its SES terms:
“AWS is not the "sender" as defined in the CAN-SPAM Act or similar applicable law.” AWS Service Terms, section 15.6
Enforcement belongs to the FTC and other federal agencies, state attorneys general and internet access providers, and some of those remedies turn on whether a party had “actual knowledge, or by consciously avoiding knowing” what was happening (15 U.S.C. § 7706).
CAN-SPAM is an opt-out law
This is the point to be clear on. In general, CAN-SPAM does not require a recipient's permission before commercial email is sent; the FTC's guide sets out what a message must contain and how opt-outs must work, not a prior-consent rule. The consent requirement a platform answers to sits somewhere else: its email provider's own terms, which do require consent and can require you to prove it — see what SendGrid, Mailgun and SES ask for.
So a consent record is not a CAN-SPAM defence, and nothing on this page suggests it is one. What it gives a platform is an honest account, per recipient and per tenant, of how an address arrived — which is what a provider asks for, and useful context in any conversation about what your platform knew.
Why your provider asks
Your provider isn't the villain here. It answers to the people who receive the mail, and it carries every sender on its service, including you. The asking exists because of marketers who will mail anyone, at any cost. Because of them, everyone else has to be able to show their work. Being asked is part of sending at scale; what matters is how long your answer takes.
Where Redoubt Vault fits
Redoubt Vault is an API that records how your tenants' recipients opted in, as it happens, and produces that record per recipient when you are asked. It does not decide whether anyone is liable for anything, and it never sits between you and your provider. You can read a sample evidence packet first.
What this can and can't do. It shows what your platform told us, and when, for signups recorded from the day you start. It can't rebuild what was never recorded, it doesn't see your sign-up form, it never sends messages, and it doesn't record an IP address. It doesn't show that a person clicked. And nobody can promise your provider will accept an answer.
Make a key and record your first consent event
Or read the API reference first. Pricing is on one page.
What this is based on
- FTC: CAN-SPAM Act: A Compliance Guide for Business: “Both the company whose product is promoted in the message and the company that actually sends the message may be held legally responsible”, and penalties of up to $53,088 per email.
- 15 U.S.C. § 7702, definitions: “routine conveyance”.
- 15 U.S.C. § 7706, enforcement: “actual knowledge, or by consciously avoiding knowing”.
- AWS Service Terms, section 15.6: AWS “is not the "sender" as defined in the CAN-SPAM Act or similar applicable law”.
Related
- A story: a recipient escalated a complaint, and your email provider wants to know how you got their address
- When you're asked to prove someone opted in: all the stories
- Your email provider asked for your tenants' consent records
- ESP tenant vetting requirements: SendGrid, Mailgun, Amazon SES
Last checked against the sources below: 6 October 2026. Redoubt Vault is not affiliated with the FTC or Amazon Web Services.