Consent and the suppression list
A suppressed address is unreachable by every send path — checked before a send is even proposed.
Consent is per channel and structural. Every contact carries email and SMS opt-in with the source and date it was given, so it can be evidenced later.
The suppression list is global, and it is checked in the guardrail preflight that every send passes through — not inside each send function, where one of them would eventually forget. A suppressed address is therefore unreachable by a broadcast, a sequence, a one-off and the API alike.
Addresses are stored lowercased, so casing cannot smuggle one through.
Unsubscribing does both halves: it withdraws consent on the contact and adds the global suppression. Either one alone leaves a path by which the person can be mailed again.
A bulk email with no unsubscribe link is blocked outright. CAN-SPAM is not optional.
Before any send, the proposal states exactly who will receive it and how many were excluded — silent truncation is a lie.