Evidence and testimony
Abstract horizontal band illustration representing Email Marketing

EvidenceParty-heldThe record sits in the parties' own systems, and its completeness is itself contested.

Email Marketing

Short answer
The decisive records sit with the sender and its service provider, not with a platform
The record
Send and bounce logs, full internet headers, SPF, DKIM and DMARC results, consent records
Who holds it
The sender and its email service provider; the receiving provider holds the rest
What it cannot settle
Nothing in a sender's records shows whether a message reached an inbox

An email program records what was sent and what the receiving server said back, and since 2021 little about what a reader did

What an email program records, in order of how much weight it bears

An email service provider — the platform a sender uses to transmit bulk mail — keeps a layered record, and the layers are not equally reliable. Ranked from strongest to weakest: the send record, showing that the provider accepted a message for a given address at a given time; the SMTP result, meaning the receiving server's 2xx acceptance or 4xx/5xx rejection; bounces, split between hard bounces (permanent, the address does not exist) and soft bounces (temporary, mailbox full or server unavailable); clicks, recorded when something requests a tracking redirect; and opens, recorded when a one-by-one pixel is fetched.

The first three are machine-generated records of a handoff and they carry real weight. They are also the natural subject of a certification under FRE 902(13) as records generated by an electronic process. The last two are where email evidence goes wrong. Corporate mail security products fetch and detonate URLs in inbound mail to check for malware, and at the log level those fetches are indistinguishable from human ones. A click-through rate in an email report is not a count of people. Bounce data, by contrast, is the single best available evidence of list quality, and it is rarely the thing anyone asks for.

Why open rates stopped being evidence in June 2021

Apple announced Mail Privacy Protection on 7 June 2021, shipping with iOS 15, iPadOS 15 and macOS Monterey. Apple's own description is that it helps prevent senders from learning “when they open an email, and masks their IP address so it can't be linked to other online activity or used to determine their location.” The mechanism as the industry understands it — Apple documents the outcome rather than the mechanism — is that Mail pre-fetches remote content, including tracking pixels, through a proxy for messages delivered to the device, whether or not anyone reads them.

Three distortions follow, and an opposing expert will raise all three. Opens are inflated, because they are recorded for unread mail. Timing is corrupted, because the recorded time is a proxy fetch rather than a human action, which makes time-of-day and time-to-open analysis unreliable on post-2021 data. Geography is corrupted, because the recorded address belongs to Apple's relay. The break is a step change at a known date, so any exhibit comparing 2020 open rates to 2022 open rates is measuring the measurement change rather than the campaign. Apple is not the only actor here; other providers proxy and cache images in ways that decouple a pixel request from a read. Whether open data retains diagnostic value within the post-2021 period, compared across segments, is genuinely contested among practitioners, and a report should present it as contested rather than declare the metric dead.

The headers are the evidence; the rendered message is not

A produced “email” with no headers is a document of unknown provenance. The evidentiary content sits in the full internet headers — the Received chain, the Message-ID, Authentication-Results and DKIM-Signature — and any production that omits them has discarded most of what makes the item verifiable. That belongs in the ESI protocol, negotiated before production rather than argued about after it.

Three DNS-published mechanisms answer the question of whether a message came from who it says it came from. SPF, Sender Policy Framework, is a record listing which sending addresses are authorized for a domain. DKIM, DomainKeys Identified Mail, is a cryptographic signature over selected header fields and the body, verifiable against a public key in DNS — which makes a message whose signature still verifies far stronger evidence of integrity and origin than a forwarded copy or a screenshot of an inbox. DMARC builds on both by requiring alignment with the visible From domain and letting the domain owner publish a policy of none, quarantine or reject plus addresses for reports. One citation trap is worth flagging: DMARC's original specification, RFC 7489, was Informational and has been obsoleted by RFC 9989, published on the Standards Track in May 2026, with reporting moved into companion documents. A 2026 report citing RFC 7489 as the current standard is citing an obsoleted document.

DMARC aggregate reports are an under-used discovery source. Receiving providers send them daily to the domain owner as XML, showing volumes by source address with authentication results, and they can corroborate or contradict claims about who was sending mail as a domain — directly relevant in spoofing, brand-impersonation and rogue-affiliate matters.

What CAN-SPAM requires, and the opt-in error that appears in most briefs

The Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003, 15 U.S.C. §§ 7701–7713, is implemented by the FTC's CAN-SPAM Rule at 16 C.F.R. Part 316. The FTC's own compliance guide states seven requirements: do not use false or misleading header information; do not use deceptive subject lines, since “the subject line must accurately reflect the content of the message”; identify the message as an advertisement; include a valid physical postal address; tell recipients how to opt out; honor an opt-out request within 10 business days; and monitor what others do on the sender's behalf, because responsibility is not delegated by hiring an agency.

The single most commonly misstated point in marketing writing is that CAN-SPAM is an opt-out statute, not an opt-in one. Prior consent is not required to send a commercial email under it; truthful headers, a working opt-out and an address are. Other regimes — Canada's CASL, the EU and UK ePrivacy rules — are opt-in, and a compliance analysis under one does not transfer to the other. Enforcement runs through the FTC, state attorneys general and, in a limited category, providers of internet access service, rather than through a general consumer private right of action. On penalties, the figure in circulation is the FTC Act amount and it moves: the FTC's 2025 inflation adjustment set it at $53,088 per violating message effective 17 January 2025, and the Commission adjusts annually each January. Print the figure only with its year attached, or check the current notice first.

The SMS consent rule that was vacated and never took effect

This is the item most likely to be stated wrongly, because a large volume of 2024 legal-alert content describes a rule that never came into force. The FCC's December 2023 order imposed two restrictions on prior express written consent for marketing robocalls and robotexts: consent could authorize no more than one identified seller at a time — the “one-to-one consent” rule — and the calls had to be logically and topically associated with the interaction that prompted the consent.

On 24 January 2025 the Eleventh Circuit granted the petition for review, vacated Part III.D of the 2023 Order and remanded, in Insurance Marketing Coalition Ltd. v. FCC, No. 24-10277, reported at 127 F.4th 303. The court reasoned that “prior express consent” is a common-law term the agency does not get to redefine, and that authority to implement the TCPA does not extend to altering the choices Congress made. The FCC subsequently issued a final rule removing the one-to-one language from its regulations. As of now the pre-2023 standard governs: marketing texts sent with an automatic telephone dialing system or an artificial or prerecorded voice require prior express written consent, meaning a signed written agreement clearly authorizing the seller to send such messages to a designated number, with clear and conspicuous disclosure and no condition of purchase. There is no one-to-one requirement and no topical-relatedness requirement in force. Separately, the revocation provisions of the same 2023 Order were not vacated, and their current terms and dates are a live question that should be checked rather than recited.

The marketing expert is not the person who opines on TCPA liability. What the marketing expert can establish is the record: what consent language was displayed, in what layout, at what time, on which version of the page, and what the system logged about the submission.

Deliverability, sender reputation, and the February 2024 requirements

Where the dispute is about whether a mailing program was competently run — or whether an agency damaged a client's ability to reach inboxes — the useful records are external. Google's published sender guidelines state that “starting February 1, 2024, email senders who send more than 5,000 messages per day to Gmail accounts must meet the requirements in this section,” which include SPF and DKIM authentication for the sending domain, a DMARC policy for that domain, keeping “spam rates reported in Postmaster Tools below 0.30%,” and, for marketing and subscribed messages, one-click unsubscribe support through the List-Unsubscribe-Post: List-Unsubscribe=One-Click and List-Unsubscribe headers plus a clearly visible unsubscribe link in the body.

Read as evidence rather than as compliance guidance, that regime produces something unusual: Google Postmaster Tools gives the domain owner a timestamped, third-party-generated measure of how recipients actually treated a sender's mail. In a dispute over list practices or reputation damage it is among the most probative records available, and it is very rarely collected. Its retention window is short, so it has to be pulled early. Yahoo announced parallel requirements on the same timeline, commonly described as matching Google's; a report should confirm Yahoo's own terms rather than assume they are identical.

What the email record does not settle

Acceptance by a receiving mail server is not delivery to an inbox. A 2xx response records a handoff to the recipient's provider, which may then place the message in spam, quarantine it, or apply a rule. Nothing in the sender's records shows where it landed; that knowledge sits with the receiving provider and the recipient.

An open is not a read, and since June 2021 may not even involve a device the recipient touched. A click is not necessarily a human click, because security scanners fetch URLs in inbound mail; absent server-side corroboration such as a session, a form submission or an order, it is weak evidence of engagement.

Authentication results answer a narrower question than they are often asked to answer. SPF, DKIM and DMARC passes indicate authorized sending, not legitimacy — a phishing message sent from a domain the phisher controls passes all three. A DMARC pass says nothing about inbox placement either. And none of this speaks to whether a recipient was persuaded by anything, which is a separate question requiring a separate design and is almost never answerable from the mail record alone.

Frequently Asked Questions

Can an email service provider's report show that a recipient read a message?

No. An open is recorded when a tracking pixel is requested, and since Apple's Mail Privacy Protection shipped in 2021 that request is routinely made by a proxy pre-fetching remote content whether or not anyone reads the message. The recorded time is the fetch, not a read, and the recorded address belongs to the relay. Clicks are somewhat better evidence, but corporate mail security scanners fetch URLs in inbound mail and those fetches look identical in the log. Evidence that a person engaged normally requires server-side corroboration such as a session, a form submission or an order.

Is a printed copy of an email sufficient, or are the full headers needed?

The headers are where the evidentiary value sits. A printed or forwarded copy shows text; the full internet headers show the Received chain, the Message-ID, the authentication results and the DKIM signature. A message whose DKIM signature still verifies carries a cryptographic assertion by the sending domain that specified headers and the body were not altered in transit, which is far stronger than any rendering of the message. A production that strips headers has discarded most of what makes the item verifiable, which is why header preservation belongs in the ESI protocol rather than in a later motion.

Does CAN-SPAM require consent before a marketing email is sent?

No. CAN-SPAM is an opt-out statute. It requires truthful header information, a subject line that accurately reflects the content, identification of the message as an advertisement, a valid physical postal address, a working opt-out mechanism, honoring opt-out requests within 10 business days, and monitoring anyone sending on the sender's behalf. Prior consent is not among the requirements. Other regimes, including Canada's CASL and the EU and UK ePrivacy rules, are opt-in, and an analysis under one does not carry over. Describing US commercial email as requiring opt-in consent is the most common error in this area.

Did the FCC's one-to-one consent rule for marketing texts ever take effect?

No. The FCC's December 2023 order would have limited prior express written consent to one identified seller at a time and required the messages to be logically and topically associated with the interaction that prompted the consent. On 24 January 2025 the Eleventh Circuit vacated that part of the order in Insurance Marketing Coalition Ltd. v. FCC, No. 24-10277, reported at 127 F.4th 303, and the FCC then formally removed the language. A great deal of 2024 commentary describes the rule as if it were in force. The pre-2023 prior express written consent standard governs instead.

What evidence shows that an agency damaged a client's sending reputation?

The most probative records are held outside both parties. Google Postmaster Tools reports a spam-complaint rate for the sending domain, timestamped and generated by the receiving provider rather than by either side of the dispute. Alongside it sit the bounce record, which is the best measure of list quality, the DMARC aggregate reports showing what was sent as the domain and from where, and the authentication records themselves. The Postmaster retention window is short, so this evidence has to be collected early. It is among the least frequently requested material in email disputes.

Can open rates from before 2021 be compared with open rates after?

Not as a like-for-like comparison. Apple's Mail Privacy Protection, announced 7 June 2021, introduced proxy pre-fetching of remote content for protected users, which records opens for messages nobody read, at times that reflect the fetch rather than any human action. A before-and-after comparison spanning mid-2021 measures that change at least as much as it measures anything about the campaign. Whether comparisons within the post-2021 period retain diagnostic value across segments is genuinely contested among practitioners, and an exhibit that relies on them should say which side of that debate it sits on.
Keep reading

Read the guides

An entry names the record that exists for one channel or one claim. A guide covers what is done with it, and how long there is before a retention window closes.

Top