{
  "id": "CMP-116",
  "slug": "cmp-116",
  "title": "An email-activated opt-in must show the email that asked",
  "statement": "Where the opt-in is solicited by email, a screenshot of that email must be supplied.",
  "rationale": "The email is where the consumer was told what they were joining, so it carries the disclosures the web form usually would. Businesses treat it as marketing collateral rather than as consent evidence and often no longer have the exact version that was sent, which is why the screenshot is asked for at registration rather than at complaint time.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "opt-in evidence",
  "severity": "HIGH",
  "detectability": [
    "VISION"
  ],
  "failureClass": "TERMINAL_EVIDENCE",
  "authorities": [
    "Bandwidth"
  ],
  "applicability": {
    "consentMethods": [
      "email"
    ]
  },
  "applicabilityText": "Applies when consent was collected by email.",
  "universal": false,
  "remediation": "Send yourself the live activation email, screenshot it whole — subject line, body, and the link or button that starts the opt-in — and host it. Done when the image shows what the recipient saw, not a template preview.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-116/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-116.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
