Under the CAN-SPAM Act, transactional or relationship messages are emails whose primary purpose is servicing an existing transaction, account, or business relationship rather than promoting something new. Because of that purpose, they’re exempt from most of CAN-SPAM’s requirements: no opt-out link, no physical mailing address, no advertisement label. What they still owe is honesty at the top of the email. Header and routing information must be accurate, and misclassifying a commercial email as transactional can cost up to $53,088 per message.
What Actually Counts as Transactional or Relationship Content
The statute defines the term at 15 U.S.C. § 7702(17), and the FTC’s CAN-SPAM Rule at 16 CFR § 316.3(c) spells out the five content categories that qualify. To earn the classification automatically, an email must consist exclusively of content drawn from these categories.
- Messages that complete or confirm a transaction the recipient already agreed to — order confirmations, purchase receipts, booking confirmations, payment acknowledgments.
- Safety and warranty notices about a product or service the recipient has purchased or used, including recall alerts and security notifications.
- Notifications about changes in the terms, features, or the recipient’s standing in an ongoing subscription, membership, loan, or account, plus regular balance statements.
- Information directly related to a current employment relationship or an employee benefit plan the recipient is enrolled in.
- Delivery of goods or services the recipient is entitled to receive under an existing agreement, including shipping and tracking notifications, software updates, and digital product access.
That last category is the one businesses most often overlook. A shipping update qualifies because it’s fulfilling a transaction the customer already initiated, not opening a new sales pitch. The same reasoning covers software patches and digital content unlocks.
The word doing the real work in all of this is “primary.” An email doesn’t become transactional just because the sender and recipient have done business before. The specific content of the specific email has to be about servicing that existing relationship. The FTC has warned that a message sent to a current customer is still commercial if its real purpose is to sell.
Mixed Emails and the Primary Purpose Test
Most compliance problems come from hybrid emails: a shipping confirmation with a promo banner, an account statement with a coupon at the bottom. For these, the FTC applies the primary purpose test at 16 CFR § 316.3(a)(2), and two factors decide it.
The first is the subject line. If a reasonable recipient reading the subject line alone would conclude the email is an advertisement, the whole message is treated as commercial. It doesn’t matter what transactional content sits inside. A subject line like “Your Order Has Shipped + 20% Off Your Next Purchase” fails the test.
The second is placement. Transactional content must appear mainly at the beginning of the message body. If a promotional banner is the first thing the recipient sees, and the actual order confirmation is buried below it, the email is commercial. Whatever hits the eye first is treated as the email’s true purpose.
Once an email is classified as commercial, it picks up every CAN-SPAM obligation at once: a working opt-out mechanism, a valid physical postal address, clear identification as an advertisement, and a 10-business-day window to honor opt-out requests. This is where penalties accumulate quickly for businesses that assumed they were sending transactional mail.
What a Transactional Email Still Has to Do
Exemption from most of CAN-SPAM isn’t exemption from all of it. Under 15 U.S.C. § 7704(a)(1), no email — commercial or transactional — may use materially false or misleading header information. The “from” line must accurately identify the sender. The originating domain and email address must be authentic.
That rule exists largely because phishing thrives on transactional camouflage. Fraudulent password resets, fake shipping notices, spoofed bank alerts — these all masquerade as transactional messages. Keeping header accuracy mandatory across all email categories prevents the trust built into transactional communication from being weaponized through forged sender information.
Subject lines on transactional messages also can’t be engineered to mislead. The rule specifically banning deceptive subject lines applies to commercial messages, but the broader prohibition on materially misleading header information reaches subject lines that are designed to trick recipients into opening the email through false claims.
What a transactional message does not need: a physical mailing address, an opt-out link, or an advertising label. Including an unsubscribe option voluntarily, as a courtesy, does not reclassify the email as commercial.
Who Is Liable When Classification Goes Wrong
Liability doesn’t sit only with whoever pressed send. The FTC treats both the company whose product or service is promoted and the company that physically transmits the email as responsible for CAN-SPAM compliance. Hiring a third-party email vendor does not shift the legal obligation.
When an email promotes offerings from multiple businesses, they can designate one of them as the official sender, and that designated party takes on the full compliance load — accurate headers, opt-out processing, physical address. If the designated sender fails, every business promoted in the message can still be held liable.
This is why classification matters strategically. A genuinely transactional email shrinks the compliance obligation to header accuracy. A commercial email dressed up as transactional exposes both the business and its email vendor to enforcement.
Penalties and Who Enforces Them
Consumers cannot sue under CAN-SPAM. The law has no private right of action. Enforcement authority belongs to the FTC, other federal agencies with jurisdiction over particular industries, state attorneys general, and internet service providers.
The FTC treats CAN-SPAM violations as unfair or deceptive acts under Section 5 of the FTC Act. Civil penalties reach $53,088 per noncompliant email after the 2025 inflation adjustment, which remains in effect for 2026. Each misclassified email is a separate violation, so a single campaign can produce arithmetic that gets uncomfortable fast.
State attorneys general can bring civil actions on behalf of residents for header violations, opt-out failures, or a pattern of other CAN-SPAM violations. Internet service providers can sue senders whose messages traverse their networks in violation of the law. Egregious conduct — falsified headers, hijacked computers, accounts registered with false information — can also draw criminal charges under 18 U.S.C. § 1037.
A recipient who suspects a misclassified email can’t personally sue, but they can report the sender to the FTC or a state attorney general, and both have pursued companies that systematically dressed marketing emails as transactional to avoid opt-out obligations.
How State Law Fits In
CAN-SPAM preempts state statutes that expressly regulate commercial email under 15 U.S.C. § 7707(b), so businesses don’t face 50 different email-specific regimes. Two exceptions survive. State laws prohibiting fraud or deception in commercial email content or attachments remain enforceable, and general state laws that aren’t specific to email — contract, tort, trespass, computer crime — continue to apply. The federal classification framework controls whether your transactional message needs an opt-out link; state fraud law still reaches deceptive content inside it.