Sales representative checking an email and report before prospect outreach
Sales representative checking an email and report before prospect outreach

An MSP can send an unsolicited security report as commercial outreach only with the applicable email and advertising controls in place. A representative's manual send and a diagnostic attachment do not create an exemption when the message's primary purpose is promoting services.

Evidence before outreach · Part 3. Research date: October 6, 2026. Educational information, not legal advice or approval of a particular email campaign.

TL;DR
  • An unsolicited security report email can be commercial even when sent individually by a representative.
  • CAN-SPAM covers B2B commercial messages; a report attachment does not create an exemption.
  • Use truthful sender information and subjects, advertising identification, a valid postal address and a clear opt-out.
  • Honor opt-outs within 10 business days; keep the mechanism working for at least 30 days after sending.
  • SCOUTz public-source observations must not become claims of verified vulnerabilities or compromise.

When does a security report become commercial outreach?

A technical report can make a sales email feel like an urgent security notification. If the underlying purpose is to introduce the MSP's services, that impression does not remove the commercial-email obligations. It can also raise a separate accuracy problem if the subject suggests an incident the evidence does not establish.

Read the email and attachment together. The report may carefully distinguish indexed evidence from verified facts while the representative's first sentence discards that distinction. A compliant footer cannot repair an unsupported claim in the body.

Can MSPs email an unsolicited security report?

The federal starting point is the message's primary purpose under 15 U.S.C. § 7702(2)(A). The transactional categories are in § 7702(17)(A)(i)–(v); a company reference alone does not control classification under § 7702(2)(D).

Federal source limit: statutory links use GovInfo's official 2024 edition, effective January 6, 2025. Later amendments and current regulations have not been fully compared; these are not described as verified current 2026 code. The FTC CAN-SPAM guide, consulted October 6, 2026, states that commercial messages are covered, including B2B messages and messages that are not sent in bulk.

A report sent to introduce services is not automatically a transactional message. The FTC describes transactional or relationship categories narrowly, including communications related to an already agreed transaction. A cold prospect report does not become an existing customer security notice just because it discusses security.

Federal CAN-SPAM is not a blanket advance-opt-in rule for every commercial message. That is not permission to ignore other applicable laws, platform policies, contracts or a recipient's objection. Have counsel assess the actual audience, jurisdictions and message purpose.

Send scenarioQuestion to resolveOperational approach
Representative sends a report and offers MSP servicesIs the primary purpose commercial?Treat prospecting as commercial and use the required controls
Report is delivered under an agreed assessmentDoes the message fit a transactional category?Examine the agreement, subject and body rather than assuming exemption
Genuine security disclosure with no promotionWhat is the actual purpose and disclosure process?Keep disclosure separate from sales pressure
A later promotional follow-upIs this a new commercial message?Apply outreach controls and check suppression before sending

A genuine disclosure can require its own careful process. Do not use a security-notification label to disguise a service offer.

Evidence: the federal pre-send checklist

The FTC guide identifies the following requirements. This is a working checklist for commercial prospecting, not an exhaustive opinion on every rule that could apply.

Identify the real sender

15 U.S.C. § 7704(a)(1) prohibits materially false or misleading transmission information. Use accurate From, To, Reply-To and routing information. The person or business initiating the message must be identifiable. A representative should not impersonate the prospect's IT provider or an official security authority.

If the representative works for an MSP using SCOUTz evidence, the message should identify the MSP as the sender. Do not imply that the product vendor issued an independent incident alert unless that is what actually happened.

Make the subject truthful

Under 15 U.S.C. § 7704(a)(2), the subject must not mislead a reasonable recipient about a material fact under the stated knowledge standard. The subject must reflect the content. A line such as urgent breach detected claims more than a dated public-source observation can support.

An illustrative subject is Public-domain observations for your team's review. It describes the material without pretending a breach occurred or a live vulnerability was confirmed. Use it only if that is an accurate description of the attachment.

Identify the commercial message

15 U.S.C. § 7704(a)(5)(A)(i) requires clear and conspicuous advertisement or solicitation identification; § 7704(a)(5)(B) provides an exception to that identifier requirement for prior affirmative consent. The FTC guide explains how to disclose the commercial purpose. The exception is not a general exemption from the other duties. For an unsolicited MSP introduction, do not hide the commercial nature behind a report-only subject and a barely visible footer.

A direct line such as This is a commercial introduction to our MSP services makes the purpose explicit. Counsel should approve the wording and placement for the actual send process.

Include a valid postal address

15 U.S.C. § 7704(a)(5)(A)(iii) requires the sender's valid physical postal address. The FTC guide permits a current street address, a registered USPS post office box or an appropriately registered private mailbox. Use the sender's actual valid address.

A website link or phone number alone is not the postal address requirement. Do not reuse a product vendor's address as if it were the sending MSP's location.

Provide an easy opt-out

Explain clearly how the recipient can stop future marketing. 15 U.S.C. § 7704(a)(3)(A)–(B) specifies a functioning, clearly displayed return address or internet-based mechanism, with a stop-all option if a preference menu is offered.

If you offer reply-based opt-out, someone must receive and act on replies. A mailbox that discards responses does not support the process. A representative's departure should not make requests disappear.

Meet the timing requirements

15 U.S.C. § 7704(a)(3)(A)(ii) specifies no less than 30 days of receipt capability. Section 7704(a)(4)(A)(i)–(iii) prohibits covered sending after more than 10 business days following the request; § 7704(a)(4)(A)(iv) addresses transferring opted-out addresses, subject to the stated compliance exception. Honor opt-outs within 10 business days, as the FTC guide explains.

The recipient cannot be charged or required to provide information beyond an email address. The process cannot demand extra steps beyond sending a reply email or visiting a single website page.

Make these deadlines visible to the person responsible for the sending workflow. Do not leave compliance dependent on each representative remembering an old email thread.

Insight: collection and communication remain separate

Sending a report does not authorize its collection retroactively. Conversely, the recipient's lack of advance email permission does not by itself prove that collecting public evidence was unauthorized computer access.

SCOUTz's free domain review, as described by the team, relies on public records and passive enumeration. Its reports state that indexed means publicly discoverable and that no request was sent to verify an indexed observation. That supports a narrow description of the material, not a claim that the prospect's network was tested.

The deeper Microsoft 365 assessment requires prospect authorization and full sign-up. Do not imply the first unsolicited attachment includes internal tenant evidence if that authorized assessment has not taken place.

Accurate wording is not concealment

Avoid saying we scanned your network and found vulnerabilities when the evidence came from public sources and unverified indexes. The phrase suggests direct probing and confirmed findings that your team may not have performed or established.

But do not use public-source wording to conceal direct tests. If the workflow sent target requests, describe them accurately. The solution is to keep conduct, evidence and wording aligned.

Evidence in handSupported statementUnsupported escalation
Published DNS answerThe report records the published answer on the stated dateYour organization is compromised
Indexed resource referenceA source indexed this reference; current availability was not verifiedWe accessed sensitive data
Authorized tenant configuration evidenceThe agreed review retrieved these settingsEvery part of your tenant is secure or insecure
Unknown internal evidenceThis public review does not assess the internal controlWe found no internal risk

Unknown is not clean. Unverified is not confirmed. Those distinctions should survive every summary the representative writes.

Proof: substantiate the claim before sending

The FTC advertising-substantiation policy, consulted October 6, 2026, requires a reasonable basis for objective advertising claims before dissemination. It covers express claims and reasonable implied claims.

For an MSP report email, review what the recipient would reasonably understand. A dramatic subject and a screenshot can imply current compromise even if a technical appendix contains a disclaimer. Do not depend on the recipient reading every page to discover the limitation.

Keep an evidence record containing the source, relevant dates, exact observation, verification status and supported wording. Where a claim requires deeper access, obtain appropriate authorization before making the claim rather than testing first to improve the pitch.

What can a representative say without overstating the report?

The following language illustrates the structure. It is not ready to send without the real sender identity, a valid address, a functioning opt-out and review of the actual report.

We prepared dated observations from publicly discoverable sources associated with your domain. The attached report identifies the sources and marks indexed observations that were not independently verified.

This is a commercial introduction to our MSP services. If useful, we can discuss whether the observations are relevant to your current environment. The public-source report does not establish a breach or assess your internal Microsoft 365 configuration.

If you do not want further marketing emails from our business, reply asking us to stop.

The sample deliberately does not invent a sender name, address, signature or findings. Add truthful information rather than copying a fictional identity. If reply-based opt-out is used, test it before the representative sends a real email.

What should the representative check before sending?

  1. Match the attachment to the intended organization and recipient.
  2. Confirm that the report date does not obscure older source evidence.
  3. Check the subject and first paragraph for unsupported urgency or compromise claims.
  4. Identify the real sender and commercial purpose.
  5. Include the valid postal address and conspicuous opt-out instructions.
  6. Confirm that the recipient has not opted out of marketing from the sender.
  7. Test the opt-out route and identify its responsible owner.
  8. Preserve the sent version and supporting evidence under your approved retention policy.

These are suggested operating steps. The platform's ability to send an email is not proof that the message or collection method is lawful.

Keep disclosure away from purchase pressure

The team's described SCOUTz reports are diagnosis only, without a built-in remediation upsell or threatened disclosure. Preserve that boundary in the representative's message.

Do not condition silence, notification or disclosure handling on the recipient buying a service. A helpful observation becomes a different kind of interaction when the seller introduces a threat. Route a genuine security issue through an appropriate disclosure process rather than treating it as negotiation leverage.

FAQ

Does CAN-SPAM apply to one-to-one MSP emails?

Yes, when the primary purpose is commercial. The FTC says coverage is not limited to bulk mail.

Is B2B email exempt from CAN-SPAM?

No. The FTC guide expressly says there is no B2B exception for commercial messages.

Does attaching a security report make the message transactional?

No. The primary purpose and the narrow transactional categories control, not the attachment's subject matter.

How quickly must the sender honor an opt-out?

Within 10 business days under the FTC guide. The offered mechanism must accept requests for at least 30 days after sending.

Can an MSP use reply-based opt-out?

The FTC guide permits a return email address or another easy internet-based mechanism. The reply route must work and requests must be honored.

Can an indexed finding be called a verified vulnerability?

Not without evidence supporting that conclusion. Keep the index source, date and lack of independent verification visible.

Does avoiding the word scanner remove legal risk?

No. Accurate wording matters, but the underlying collection and access still require their own analysis.

Who handles opt-outs when representatives send manually?

The sending business needs a reliable process and responsible owner. Manual sending does not remove the obligation.

One last thing

The footer is only one part of the message. Before sending, ask whether the subject, first sentence and attachment make the same factual claim. If they do not, fix the inconsistency before the recipient sees it.

Before outreach, resolve the collection-permission question and check the methods behind the observations. Protected tenant work needs its own authorization scope. SCOUTz's methodology and trust boundary support the distinction between indexed observations, verified findings and unknowns.

Does a sales purpose excuse access or threats?

No. 18 U.S.C. § 1030(a)(2)(C), (a)(5) and (a)(7) address different computer-access, damage and extortion conduct with separate elements. A threatening disclosure message is not automatically a completed § 1030(a)(7) offense; counsel must assess the exact threat and statutory conditions. Never use purchase-conditioned silence as an outreach technique.

The DOJ Justice Manual § 9-48.000 B.3(8), C excludes extortion-motivated conduct from its good-faith research guidance. It is charging policy, not immunity from civil claims, state law or federal offenses.

Sources

Statutes: 15 U.S.C. § 7702(2), (17); § 7704(a)(1)–(5); and 18 U.S.C. § 1030(a)(2)(C), (a)(5), (a)(7), linked near their claims. Official federal 2024 edition, effective January 6, 2025; current-2026 amendment and regulatory comparison remains pending.

Court decisions: no judicial holding is asserted. Relevant decisions and state deceptive-marketing or privacy claims remain unreviewed.

Agency guidance: FTC CAN-SPAM business guide and advertising-substantiation policy, and DOJ Justice Manual § 9-48.000, linked above. These are guidance, not statutory exemptions. The opt-out fee, information and single-page/reply restrictions above are attributed to the FTC guide, not invented statutory wording.

Product sources: SCOUTz methodology and trust, plus the team's stated indexed-evidence and consent workflow. Sources consulted October 6, 2026; no legal reviewer or sign-off is claimed.