Almost every store we build eventually asks the same question: can we email our customer list before Yom Tov, and can we text them too? The email answer is usually "yes, with four things in the footer." The text answer is very different, and getting it wrong is one of the few marketing mistakes that can genuinely cost a small business real money.
Two laws, two very different levels of risk
Marketing email in the United States is governed by the CAN-SPAM Act of 2003, enforced by the Federal Trade Commission (FTC) through its rule at 16 C.F.R. Part 316. Marketing text messages are governed by the Telephone Consumer Protection Act (TCPA), a 1991 statute at 47 U.S.C. § 227, implemented through Federal Communications Commission (FCC) rules. People assume these are two versions of the same idea. The difference that matters is who is allowed to sue you.
| Email (CAN-SPAM) | Text (TCPA) | |
|---|---|---|
| Prior opt-in required? | No | Yes — prior express written consent for marketing |
| Who enforces it | FTC, state attorneys general, internet access providers | FCC, state AGs, and any individual recipient |
| Can a customer sue you personally? | No private right of action | Yes |
| Damages | Civil penalty per email, inflation-adjusted annually | $500 per message, up to $1,500 if willful or knowing |
Nobody is going to sue your bakery over an email footer. A plaintiff's firm absolutely will build a case out of 4,000 promotional texts sent to a list you bought.
What CAN-SPAM actually requires
Every commercial email — one whose primary purpose is advertising or promotion — has to satisfy all of this:
- Accurate header information. The "From," "Reply-To," and routing details must be truthful and identify who actually sent the message.
- A non-deceptive subject line. It must reflect what is really in the message. "Your order update" on a Yom Tov sale flyer is a violation — and the one owners commit most often.
- Identification as an advertisement, clearly and conspicuously. This requirement drops away if the recipient affirmatively opted in — a quiet benefit of building a real list.
- A valid physical postal address. A street address, a registered PO box, or a private mailbox from a commercial mail receiving agency. This is the most commonly missing item. If you run the business from home, get a PO box before the campaign, not after.
- A clear, working opt-out that keeps working at least 30 days after you send. No fee, no login, no reason required, nothing beyond the email address — and no more than a reply email or a single web page.
- Opt-outs honored within 10 business days. Once someone opts out you also may not sell or transfer that address, except to a vendor helping you comply.
- Responsibility for anyone acting for you. Hire a marketing person and both of you can be liable. Outsourcing does not hand off the risk.
The surprise: no opt-in required
CAN-SPAM does not require permission before the first email. If a caterer collects business cards at an expo and emails all of them a Sukkos menu, that is lawful as long as the seven items above are handled. This startles people who have absorbed European rules. Europe does effectively require consent for marketing email — though that consent rule comes from the ePrivacy Directive and its national implementations (in the UK, the Privacy and Electronic Communications Regulations), while the GDPR governs how you handle the personal data itself. Either way, those rules protect people in the EU and UK, and they would only reach a Brooklyn store that was deliberately marketing into those countries. They are not triggered by your customers in Boro Park. Legal and wise are different things: emailing people who never asked wrecks your deliverability. It just is not, by itself, a legal problem.
Why "per email" matters so much
The civil penalty attaches to each separate email in violation. The statutory maximum is inflation-adjusted every January and has sat above $50,000 per message in recent years; look up the FTC's current number rather than trusting one quoted in an article, including this one. And it is a ceiling available to a regulator in an enforcement action, not an automatic fine that arrives in the mail. The figure is not the point — no regulator is fining a grocery $50,000 an email. The structure is. A missing postal address on a list of 40 is a footnote; the same missing footer on a list of 12,000 is, on paper, an enormous number. Risk scales with list size, which is backwards from how owners think about it.
Transactional email, and the trap inside it
CAN-SPAM exempts "transactional or relationship" messages from almost everything except the accurate-header rule: order confirmations, shipping notices, safety and warranty information, account status, changes to terms.
Here is the trap. The FTC applies a "primary purpose" test to mixed messages: a message counts as commercial if a reasonable recipient reading the subject line would conclude it contains an ad, or if the transactional content does not appear at the beginning of the body. So dropping a "15% off Pesach wine" banner above the order details converts a transactional email into a commercial one — which now needs the ad identification, the postal address, and a working unsubscribe, none of which your store platform's confirmation template has. Either keep promotions out of confirmations, or put the full footer on the confirmation template and stop worrying about the line.
Gmail and Yahoo enforce more than the law does
Since February 2024, Google and Yahoo have required bulk senders to meet three requirements beyond CAN-SPAM. Google draws the bulk-sender line at roughly 5,000 or more messages a day to Gmail addresses from a single domain; Yahoo applied its rules to bulk senders without publishing that same number. Microsoft followed in May 2025 with comparable authentication rules for high-volume mail to Outlook.com, Hotmail and Live addresses. Day to day these matter more than the statute, because failing them means your Yom Tov email silently lands in spam.
- Email authentication — SPF, DKIM, and DMARC: three settings in your domain's DNS records (the internet's address book for your domain name) that let receiving servers verify a message really came from you. A one-time job for your developer.
- One-click unsubscribe on marketing mail, via a technical header (the standard is RFC 8058), honored within two days. Real email platforms handle this automatically.
- Spam complaint rate below 0.3%, with 0.1% as the level to aim for — which is why emailing people who do not remember you is self-defeating.
None of this works if you are blind-copying 600 customers from your own Gmail — and one slip from BCC to CC exposes every customer's address to every other customer. For a therapist or a medical billing office, whose client list is itself sensitive, that is a serious problem, not an embarrassing one.
Text messages: the one that actually bites
The FCC has long treated a text as a call, and that is how the great majority of courts have read the statute — though a few district courts have recently started questioning whether a text is a "call" at all. Treat it as the operating rule, not a closed question, and do not plan around the exception. For any message whose content includes advertising or telemarketing, the working standard is prior express written consent. Not implied consent. Not "he gave us his number at the counter." Written.
Strictly speaking, that written-consent requirement is written around messages sent using an autodialer or an artificial or prerecorded voice, and the separate Do-Not-Call rules require prior invitation or permission "in writing" — two different doors into the same room, which is why the compliance answer does not change. Nobody sensible builds an SMS program on the theory that one of those doors happens to be shut.
What valid written consent looks like
The FCC's definition (47 C.F.R. § 64.1200(f)(9)) requires a written agreement, signed by the consumer, that clearly authorizes you by name to send marketing messages to that specific number, discloses clearly and conspicuously that they are agreeing to receive them, and states that they are not required to agree as a condition of buying anything.
A signature can be electronic under the federal E-SIGN Act, so a website checkbox counts — provided it is not pre-checked, not bundled into "I agree to the terms," and separate from the purchase itself. A line on a paper signup sheet with the disclosure printed above it works in-store. A "text JOIN to 55555" sign can also work, because the customer's inbound text supplies the signature — but only if the sign itself carries the disclosures: who is sending, that they are agreeing to marketing texts, that consent is not required to buy anything, roughly how often you will message, that message and data rates may apply, and how to stop. Putting all that only in your automated reply is a common shortcut and a shaky one, because by then they have already "signed."
Then keep the record: date, time, number, the exact wording the person saw, and the source. Federal TCPA claims run under the four-year catch-all limitations period, and state statutes can run on their own clocks, so keep consent records at least five years. In litigation courts have generally put the burden of proving consent on the sender — you, not the customer. A consent you cannot document is a consent you do not have.
$500 per message, and the customer sues you directly
The TCPA gives individuals a private right of action with statutory damages of $500 per violation, which a court may increase to as much as $1,500 for a willful or knowing violation. No proof of actual monetary loss is required, though a plaintiff still has to show a real injury to get into federal court. Per message. Do the arithmetic on a purchased list of 3,000 numbers blasted once: 3,000 × $500 is $1.5 million of theoretical exposure from a single send. Blast it four times before Pesach and multiply by four. Your own platform's send logs are the evidence.
One thing has shifted in your favor. In Facebook v. Duguid (2021), the Supreme Court narrowed the definition of an "automatic telephone dialing system" to equipment using a random or sequential number generator, which excludes most platforms that send to a stored customer list. That did not make texting safe: the FCC's separate telemarketing and Do-Not-Call rules apply regardless of technology, and a growing list of states have their own "mini-TCPA" statutes. Florida's Telephone Solicitation Act and Washington's Commercial Electronic Mail Act are among the most litigated — though Florida narrowed its statute by amendment in 2023, adding a cure window for texts, which is a fair illustration of why you check the current text of a state law rather than a summary written a few years ago. New York General Business Law § 349, the state's deceptive-practices statute, carries its own private right of action. Which of these reaches you depends on where your customers are, not where your store is.
The rules also keep moving: an FCC rule that would have required consent to name one specific seller at a time, aimed at lead generators reselling consent, was vacated by a federal appeals court in January 2025, and the FCC has since removed the vacated language. The lesson stands regardless of where that fight lands next — do not rely on consent somebody else collected.
Why buying a phone list is reckless
Consent is not something you can purchase. A vendor's assurance that a list is "100% opted in" is worth nothing in court, where you will be asked to produce the specific consent record for the specific plaintiff, naming your business as the sender. You will not have it — and every number is an independent $500 claim that one motivated recipient can turn into a class. The same reasoning covers a list a friendly shop owner shares and numbers scraped from a community WhatsApp group. A customer list you inherited when you bought a business is genuinely murky; ask a lawyer first.
Quiet hours and handling STOP
FCC telemarketing rules (47 C.F.R. § 64.1200(c)(1)) prohibit telephone solicitations before 8 a.m. or after 9 p.m. in the called party's local time. Whether that reaches every business text is genuinely contested. "Telephone solicitation" is defined to exclude messages sent with the person's prior express invitation or permission, and messages to someone with an established business relationship — so senders argue a consented marketing text is not a solicitation at all and the clock does not apply. District courts have divided on it, a wave of quiet-hours class actions has been filed since late 2024, and the FCC asked for public comment on the question in 2025 without resolving it. Several states also set narrower windows than the federal one. Do not be the test case. A Brooklyn grocery scheduling an erev Pesach blast for 7 a.m. Eastern is texting a customer in Los Angeles at 4 a.m. Send between 9 a.m. and 8 p.m., segment by time zone if you have out-of-state customers, and keep scheduled sends off Shabbos and Yom Tov — the same discipline that applies to how your store handles orders over Yom Tov.
On opt-outs: FCC rules require honoring them within a reasonable time not to exceed 10 business days, and — the part people miss — consumers may revoke consent by any reasonable means. You cannot designate the exact word "STOP" as the only way out. "Stop texting me," "unsubscribe," "please remove me," and a reply in Yiddish all count. If a customer tells your cashier in person, that counts too, and somebody has to actually go remove the number. (The FCC has delayed part of this rule — the piece about how far one revocation reaches across your other message types — but the core any-reasonable-means requirement is in force, and the delayed piece is the direction things are heading anyway.) You may send a single confirmation acknowledging the opt-out, promptly and with no marketing in it — not a pitch, and not a "are you sure?"
Transactional versus marketing texts
This line matters more in SMS than anywhere else, because it is the difference between "the number they gave you is enough" and "you need signed written consent." Purely informational messages tied to a transaction the customer started — your order is ready, the driver is 10 minutes away, your appointment is Tuesday at 3 — rest on prior express consent, which giving you the number for that purpose supplies. No written agreement needed.
The moment you add promotional content, the whole message is marketing. "Your order is ready for pickup — and don't forget, 20% off honey cake this week" is a marketing text sent to someone who never gave marketing consent. One clause turned a compliant message into a $500 claim. So run two separate lists and two separate templates, and never let marketing copy leak into the transactional stream. If your store platform sends both, have your developer confirm they use different consent flags — a normal part of an online store's legal groundwork.
The plumbing: 10DLC, segments, and Yiddish
Registration is mandatory now. US carriers require businesses sending application-to-person messages from a standard 10-digit number to register their brand and campaign through The Campaign Registry. This is called 10DLC, and it involves a small one-time fee, a small monthly campaign fee, and per-message carrier surcharges. It is a carrier requirement rather than a law, which cuts both ways: no regulator will fine you, and there is no appeal when your messages stop arriving. Unregistered traffic gets filtered or blocked outright — meaning your Pesach blast quietly never arrives. It takes days, not hours, so do not start the week before Yom Tov. Carriers also filter content independently of the law, and alcohol is on the restricted list, which matters for a grocery advertising wine or a caterer promoting a bar package. Those campaigns need age-gating declared at registration.
Hebrew and Yiddish cost roughly two and a half times as much. SMS bills by segment. Plain Latin text fits 160 characters in a single segment, 153 per segment once a message spans several. A single Hebrew character forces the whole message into Unicode encoding, dropping that to 70 characters for one segment and 67 each thereafter. A 300-character English message is 2 segments; the same message in Yiddish is 5. At about a cent per segment before carrier fees, that is the difference between roughly $60 and roughly $150 on a 3,000-person send; at two cents, double both. Per-segment pricing varies a good deal by provider and volume, so treat those figures as the shape of the problem rather than a quote — but the ratio holds whatever you pay, which is why bilingual campaigns should be two sends rather than one message carrying both languages. The same encoding issues run through Yiddish and Hebrew websites generally.
WhatsApp broadcasts
The TCPA governs calls and texts delivered to a telephone number over the carrier network. Messages inside an app like WhatsApp travel over the internet, and courts have generally treated app-based messages as outside it. That is the prevailing view rather than a settled one, and state consumer-protection statutes still reach deceptive practices in any medium. "Probably not TCPA" is not "no rules." What actually constrains you here is Meta's own policy, enforced by suspension rather than lawsuit:
- Broadcast lists in the free WhatsApp Business app only deliver to recipients who have your number saved in their contacts. This defeats more campaigns than anything else — you send to 250 people, 60 receive it, and you never find out why. Lists also cap at 256 recipients.
- The WhatsApp Business Platform (the paid API route, through a provider) requires documented opt-in naming your business and stating messages will arrive on WhatsApp. Marketing templates need Meta's approval before use, and are billed per message.
- Quality rating. Meta scores your number on blocks and reports. Fall low enough and sending is throttled or the number banned. Losing the WhatsApp number your customers already have saved is a far more immediate disaster than a regulatory letter.
What we recommend you actually do
- Use a real email platform — Mailchimp, Klaviyo, Constant Contact, Brevo, MailerLite. All of them handle unsubscribes, the postal footer, list-unsubscribe headers, and complaint monitoring for you. Several have a free tier at small volumes, and most land somewhere around $20–$100 a month at a few thousand contacts — but plans and free tiers change often enough that you should check current pricing before committing.
- Get SPF, DKIM, and DMARC configured on your domain, or a perfectly compliant campaign still goes to spam.
- Put the CAN-SPAM footer on every promotional template, and re-check after any template change.
- For SMS, collect written consent deliberately — a separate, unchecked checkbox reading something like:
Text me offers and specials from [Store Name]. Message frequency varies. Message and data rates may apply. Consent is not required to purchase. Reply STOP to cancel.Store the timestamp and the exact wording shown. - Keep transactional and marketing SMS strictly separate — different lists, templates, and consent flags.
- Never buy a phone list. Not once, not "just to test it."
- Set a sending window of 9 a.m. to 8 p.m. local and check where out-of-state customers actually are.
- Honor every opt-out signal, in any wording, within days not weeks — including one said out loud at the counter.
- For an old list you are unsure about: for email, keep mailing with a proper footer and easy unsubscribe. For SMS you cannot, because a text asking permission is itself a marketing text. Re-permission by email, a sign at the register, a line on the receipt, or your website.
If your ordering system and your marketing tools were set up separately and you are not sure which messages carry which consent, that is worth untangling before your next big campaign. It is a normal thing to ask us to look at.
The short version
- Email is the forgiving one. CAN-SPAM requires no opt-in — just honest headers and subject lines, an ad disclosure (waived if the recipient opted in), a real physical postal address, and a working unsubscribe honored within 10 business days.
- Text is the dangerous one. Marketing texts need prior express written consent: a clear, separate, unchecked agreement naming your business, with records you can produce years later.
- $500 per text, up to $1,500 if willful, and the recipient sues you directly. That arithmetic is why buying a phone list is not a shortcut, it is a liability purchase.
- The transactional/marketing line is everything. "Your order is ready" is fine. "Your order is ready, and 20% off challah" is a marketing message to someone who never consented.
- Practical guardrails: a real email platform, SPF/DKIM/DMARC configured, 10DLC registered well before Yom Tov, sends between 9 a.m. and 8 p.m. local, every opt-out honored in any wording.
- WhatsApp mostly answers to Meta rather than the TCPA — the prevailing view, not a guarantee. Broadcast lists only reach people who saved your number, and unwanted blasts get that number banned.