Consumer Protection
Electronic Mail Communications Act
Florida’s Anti-Spam Statute (Fla. Stat. §§ 668.60–668.610) — Deceptive E-mail, Per-Message Liquidated Damages & AI-Generated Marketing
Florida’s Electronic Mail Communications Act (FEMCA), Part III of Chapter 668, was enacted in 2004 as one of roughly three dozen state anti-spam laws passed to protect the integrity of electronic commerce. It targets unsolicited commercial e-mail sent from a computer in Florida or to a Florida address that uses another party’s domain name without permission, falsifies or hides its routing information, carries a false or misleading subject line, or is built to damage the recipient’s device. The statute has been lightly used since its enactment — the federal CAN-SPAM Act occupies most of the field — but the rise of AI tools that generate, personalize, and A/B-test subject lines at scale, and of mass-messaging platforms that send millions of messages from a single campaign, has the potential to bring it back into view. Its most striking feature is a liquidated-damages provision of $500 per message, which turns a single deceptive blast into an aggregation risk measured in the hundreds of thousands or millions of dollars.
Our Miami intellectual property attorneys counsel businesses on e-mail marketing compliance under FEMCA, CAN-SPAM, and FDUTPA, and defend senders, agencies, and platforms when a campaign — human-written or AI-generated — draws a demand, an Attorney General inquiry, or a suit.
The Federal Backdrop: CAN-SPAM and the Falsity Carve-Out
Why a 2004 Florida statute survives a 2003 federal law that preempts almost everything else
The CAN-SPAM Act of 2003, 15 U.S.C. § 7701 et seq., set the national rules for commercial e-mail: accurate header and subject-line information, identification as an advertisement, a working opt-out honored within ten business days, and a physical postal address. It expressly preempts state laws that regulate commercial e-mail — except to the extent a state law “prohibits falsity or deception in any portion of a commercial electronic mail message or information attached thereto” (15 U.S.C. § 7707(b)(1)). That carve-out is what keeps FEMCA alive. Like Washington’s Commercial Electronic Mail Act and the surviving anti-spam statutes of other states, FEMCA regulates only deception — false domains, forged routing, misleading subject lines — and leaves the rest of commercial e-mail to federal law. Where CAN-SPAM provides no private right of action for recipients and modest FTC penalties, FEMCA supplies per-message liquidated damages and attorney’s fees to the plaintiffs it authorizes to sue, a four-year limitations period, and a criminal provision with felony tiers.
What FEMCA Prohibits — and What It Pays
Four kinds of deception, a per-message remedy, and a private right of action that belongs to service providers, not recipients
Section 668.603(1) makes it unlawful for a person to initiate or assist in the transmission of an unsolicited commercial electronic mail message from a computer located in Florida, or to an electronic mail address the sender knows or has reason to know is held by a Florida resident, if the message uses a third party’s Internet domain name without permission or otherwise misrepresents the origin or transmission path; contains false or missing routing information; contains false or misleading information in the subject line; or contains deceptive content designed to damage the receiving device. Section 668.603(2) separately prohibits distributing software or systems designed to falsify routing information. An “unsolicited” message is one sent without the recipient’s affirmative or implied consent and outside a transactional or relationship context; a message the recipient opted into is not unsolicited, whatever its subject line — though the same subject line may still violate CAN-SPAM, FDUTPA, or § 817.41.
| Provision | What It Says | Why It Matters |
|---|---|---|
| Unauthorized domain — § 668.603(1)(a) | Using a third party’s Internet domain name without permission, or otherwise misrepresenting the message’s origin or transmission path. | The spoofing and impersonation provision — the basis for a brand’s claim against phishers using its domain. |
| Falsified routing — § 668.603(1)(b) | Containing falsified or missing routing information, or otherwise obscuring the point of origin. | Reaches forged headers and relay chains; rarely triggered by a legitimate marketer unless a vendor’s infrastructure hides the sender. |
| Misleading subject line — § 668.603(1)(c) | Containing false or misleading information in the subject line. | The provision with the greatest exposure for ordinary marketers: “Your free offer has arrived,” “Re: your account,” and “Order confirmation” on a promotional message are the classic examples. |
| Malicious content — § 668.603(1)(d) | Deceptive content designed to damage the recipient’s device, with an exception for messages spread by a virus without the sender’s knowledge. | Aimed at malware distribution. |
| Spoofing tools — § 668.603(2) | Distributing software or any system designed to falsify or omit routing information. | Reaches vendors of header-forging tools. |
| Who may sue — § 668.606 | The Department of Legal Affairs (damages, declaratory and injunctive relief, civil penalties) and an interactive computer service, telephone company, or cable provider that handles or retransmits the message. | Individual recipients are not among the authorized plaintiffs; their route is FDUTPA (below). |
| Remedies — § 668.606 | For a prevailing service-provider plaintiff: an injunction; actual damages or liquidated damages of $500 for each unsolicited commercial e-mail message; and attorney’s fees and litigation costs. | Per-message liquidated damages are the aggregation risk — a single blast to a large list can generate six- or seven-figure exposure. |
| Limitations — § 668.606 | Four years from the prohibited activity. | Long enough to sweep in years of campaigns. |
| Service-provider immunity — § 668.606 | No cause of action lies against an interactive computer service, equipment provider, communications provider, or cable provider whose equipment merely transports, handles, or retransmits the message. | The platform is not liable for carrying a message it did not initiate or knowingly assist. |
| FDUTPA — § 668.6075 | A violation of FEMCA is an unfair and deceptive trade practice under Part II of Chapter 501. | The recipient’s private path: actual damages and discretionary prevailing-party fees under FDUTPA, but not the $500 per-message figure. |
| Criminal violations — § 668.608 | A first-degree misdemeanor, rising to a third-degree felony where the violation reaches more than 2,500 recipients in 24 hours, 25,000 in 30 days, or 250,000 in a year; generates more than $1,000 from one message or $50,000 in total; involves a minor; or follows a conviction within five years. | Volume thresholds that an automated campaign can cross in an afternoon. |
The identity of the plaintiff is the point most often misunderstood. In 2019 a consumer filed a putative class action in the Middle District of Florida, George v. Defenders, Inc., No. 6:19-cv-1822, alleging that a home-security marketer’s e-mails bearing the subject line “Your ADT Monitored free* offer has arrived” were misleading because the body disclosed continuing subscription payments, and demanding $500 in liquidated damages for each of thousands of messages. The case illustrates the exposure a few words in a subject line can create — and also the limit of the statute’s private remedy, because § 668.606 confers the $500-per-message action on service providers and the Department, not on recipients. The action was later dismissed. A recipient’s claim proceeds instead under FDUTPA through § 668.6075, for actual damages and discretionary fees; the per-message figure is available to the Attorney General and to the e-mail, telephone, and cable providers whose systems carried the campaign — plaintiffs with the resources and the message logs to pursue it.
FEMCA in the AI Arena
No “the AI wrote it” defense — and tools that optimize subject lines for clicks, not truth
More businesses now automate e-mail marketing with AI tools that draft copy, personalize subject lines, generate variants for A/B testing, and send at scale. The statute says nothing about artificial intelligence, but its structure makes it directly relevant to AI-generated and AI-assisted campaigns. Liability attaches to the person who initiates or assists the transmission of a message that is false or misleading; the statute does not ask who composed the words. A business that deploys an AI agent or marketing platform to write and send its e-mail is the “original sender” that initiated the transmission, and the AI vendor whose technology has a commercially significant use beyond violating the statute is excluded from “assisting” under § 668.602. There is no defense that a machine authored the subject line; the business directed the action and answers for it.
The per-message remedy makes AI optimization tools a particular hazard. Systems that auto-generate or auto-tune subject lines for engagement — testing variants, promoting the ones that win clicks, and scaling the winners across a list — are built to maximize opens, not accuracy. A subject line that implies a reply, a confirmation, an account problem, or a completed order will often outperform an honest one, and an optimizer left to itself will find that out. Multiplied across a campaign that an automated platform sends to hundreds of thousands of addresses in minutes, each misleading variant is a separate violation, and the volume thresholds of the criminal provision are crossed without anyone noticing.
| AI Marketing Practice | FEMCA Exposure | Control |
|---|---|---|
| AI-drafted or personalized subject lines | Actionable under § 668.603(1)(c) if false or misleading, regardless of authorship | Human review of every subject line variant before send; prohibit reply, confirmation, and account-status framing on promotional mail |
| Automated A/B testing that promotes winning variants | Scales a misleading variant across the list — one violation per message | Truthfulness screening as a gate before a variant is scaled; audit logs of variants and volumes |
| AI agent that composes and dispatches campaigns | The business is the initiator; the platform vendor is generally excluded | Contractual controls, approval workflows, and send caps in the platform |
| Look-alike or partner-branded “from” domains | § 668.603(1)(a) if the domain is used without permission or misrepresents origin | Written authorization for every sending domain; SPF, DKIM, and DMARC alignment |
| Third-party list sends and affiliate mailers | “Assisting” liability where the business knows the mailer’s messages violate the statute | Vendor due diligence; consent records; indemnity |
| Transactional or relationship messages with promotional content | Not “unsolicited” if within an existing relationship — but subject to CAN-SPAM and FDUTPA | Keep transactional and promotional streams separate; honest subject lines on both |
FEMCA Alongside CAN-SPAM, FDUTPA & the FTSA
Which law governs which message — and who can enforce it
| FEMCA — §§ 668.60–.610 | CAN-SPAM — 15 U.S.C. § 7701 et seq. | FDUTPA via § 668.6075 | FTSA — § 501.059 | |
|---|---|---|---|---|
| Channel | Commercial e-mail | Commercial e-mail | Any trade or commerce | Telephone calls, texts, and voicemail |
| Conduct regulated | Deception: unauthorized domains, falsified routing, misleading subject lines, malicious content | Header and subject accuracy, ad identification, opt-out, postal address | Any unfair or deceptive act, including a FEMCA violation | Autodialed or prerecorded solicitations without consent; do-not-call; hours and frequency |
| Who may sue | Department of Legal Affairs; interactive computer services, telephone and cable providers | FTC; state attorneys general; Internet access services — no recipient action | Consumers and businesses; the Attorney General | The called party |
| Damages | Actual damages or $500 per message; civil penalties | Statutory damages up to $250 per message in ISP and state actions, capped at $2 million (trebled for aggravated violations); FTC civil penalties | Actual damages only | $500 per violation, up to $1,500 if willful |
| Attorney’s fees | To a prevailing service-provider plaintiff | Discretionary in ISP and state actions | Discretionary, prevailing party (§ 501.2105) | Prevailing party (§ 501.059(11)) |
| Limitations | 4 years | None stated; general federal periods apply | 4 years | 4 years (§ 95.11(3)) |
| Criminal exposure | Misdemeanor to third-degree felony (§ 668.608) | 18 U.S.C. § 1037 for fraudulent spam | None | None |
Telephone and text-message marketing under the Florida Telephone Solicitation Act — the statute that does give recipients a per-message private action — is covered in our Telephone Solicitation Act materials; open-tracking pixels in marketing e-mail, which have drawn wiretap demands under Chapter 934, in our Security of Communications Act materials; and the content of the offer itself under § 817.41 and FDUTPA in our False Advertising Statute materials.
Key Considerations for Florida Businesses
Honest subject lines, authorized domains, consent records, and a human in the loop
- Write subject lines that describe the message. The subject line of a promotional e-mail must not imply that the message is a reply, a receipt, a confirmation, an account notice, or a personal message when it is an advertisement, and “free” must mean free. This single rule addresses the provision under which most FEMCA exposure arises.
- Use only domains you are authorized to use — and authenticate them. Written permission for every sending and reply domain, and SPF, DKIM, and DMARC alignment, defeat both the unauthorized-domain and falsified-routing provisions and improve deliverability.
- Keep consent and relationship records. Because the statute reaches only unsolicited messages, opt-in records and evidence of an existing transactional relationship are the first line of defense; segment lists so that promotional content goes only to consenting recipients.
- Put a human gate on AI-generated copy and variants. Require review of subject lines before send and before an optimizer scales a winning variant; log variants, volumes, and approvals so the campaign can be reconstructed.
- Contract with platforms, agencies, and affiliates. Require honest-subject-line and authorized-domain warranties, approval workflows, send caps, and indemnity, and audit affiliate mailers whose messages the business could be found to have assisted.
- Comply with CAN-SPAM in parallel. Ad identification, a functioning opt-out honored within ten business days, and a physical address are federal requirements that FEMCA does not replace; a campaign that satisfies both is the goal.
- Treat a demand from a service provider or the Attorney General seriously. Those are the plaintiffs with the per-message remedy; preserve campaign records, retrieve consent logs, and evaluate the subject-line and domain facts before responding.
Full Capability