Violating CAN-SPAM: Misleading Headers – NMP Skip to main content

Violating CAN-SPAM: Misleading Headers

Dec 17, 2014
Stop_Pic_12_17_14

Question: We were recently cited by our regulator for violations of CAN-SPAM. Specifically, the header of our email was considered to be misleading. How do we determine when a header is violating the CAN-SPAM requirements?

Answer: CAN-SPAM is the acronym for Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003. The Act governs the use of commercial email as a marketing tool as well as other activities relating to commercial email that is deemed to be abusive. It is unlawful to initiate a transmission to a protected computer of a commercial electronic mail message, or a transactional or relationship message, that contains, or is accompanied by, header information that is materially false or materially misleading.

Generally, a “protected computer” is a computer used in interstate or foreign commerce or communication, including a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States. [LVRC Holdings LLC v. Brekka, 581 F.3d 1127, 1131 (9th Cir. Nev. 2009)] Gradually this definition has been expanded to include all networked computers, inside the U.S. or outside. [Shurgard Storage Centers, Inc. v. Safeguard Self Storage, Inc., 119 FSupp2d 1121 (WD Wash 2000)] Briefly put, computers on the Internet are “protected computers.” [US v. Fowler, Case No. 8:10-cr-65-T-24 AEP (MDFL Oct. 25, 2010)]

Header information is considered materially misleading if the header:

1. Is technically accurate but includes an originating electronic mail address, domain name, or Internet Protocol address the access to which for purposes of initiating the message was obtained by means of false or fraudulent pretenses or representations; and,

2. Fails to identify accurately a protected computer used to initiate the message because the person initiating the message knowingly uses another protected computer to relay or retransmit the message for purposes of disguising its origin. [15 USC § 7704(a)(1)(A), (C)]

Furthermore, CAN-SPAM prohibits initiating a transmission of a commercial electronic mail message to a protected computer if there is actual knowledge, or knowledge fairly implied on the basis of objective circumstances, that a subject heading of the message would be likely to mislead a recipient, acting reasonably under the circumstances, about a material fact regarding the contents or subject matter of the message. [15 USC § 7704(a)(2)] 



Jonathan Foxx is president and managing director of Lenders Compliance Group, Brokers Compliance Group, Servicers Compliance Group and Vendors Compliance Group, national companies devoted to providing regulatory compliance advice and counsel to the mortgage industry. He may be contacted by phone at (516) 442-3456 or e-mail at [email protected]

About the author
Published
Dec 17, 2014
Insuring The Risk To Lenders At Closing

Traditional protections like title insurance and closing protection letters may leave lenders exposed to significant settlement, funding, and fraud-related losses

CHLA Uses Trump Mortgage Order To Renew Push For LO Comp Reform

Community lenders want more flexibility over employee compensation, closing-cost estimates, down payment assistance, and federal supervision of smaller IMBs

Servicers Begin Testing Systems Ahead of VA Partial Claim Deadline

VA lenders and servicers have until Nov. 28 to implement the new loss mitigation waterfall and Partial Claim Program

ROAD Act’s Housing Incentive May Be Too Small To Move Supply

Realtor.com finds the median city risks losing only about $84,000, although the policy could carry more weight in supply-starved Northeast and Midwest markets

CRA Proposal Could Reshape Bank Lending And Affordable Housing Investment

The OCC and FDIC would put more weight on lending while easing community development requirements for hundreds of banks

Fannie Mae AI Governance Deadline Arrives Aug. 6

Seller/servicers using artificial intelligence in origination or servicing must have formal policies, oversight, and vendor controls in place