The CAN-SPAM Act became US federal law in 2003 and is enforced by the Federal Trade Commission. Unlike Canada's CASL, it doesn't require consent before you email someone — it regulates what a commercial email has to contain and how you have to let people leave your list. That's a real distinction, and it means CAN-SPAM compliance and CASL compliance are two separate checklists, not one.
CAN-SPAM applies to any commercial electronic message: an email whose primary purpose is advertising or promoting a product or service. It sets rules for message content and sender behavior rather than requiring opt-in permission up front. The FTC enforces it, and the rule text lives in 16 CFR Part 316.
The practical effect: a cold email to a US business contact you've never spoken to is legal under CAN-SPAM on day one, as long as the message itself follows the content rules below and gives the recipient a real way to stop future emails.
CAN-SPAM makes no exception for business-to-business email. A cold email to a purchasing manager at a manufacturing company is held to the exact same content rules as a consumer marketing blast. Some senders assume B2B outreach gets lighter treatment because the recipient is acting in a professional capacity — that assumption is wrong under this specific law, even though it's roughly true under CASL's implied-consent framework and under UK PECR's corporate-subscriber exemption.
Every field a recipient or their mail server can see has to be accurate: the "From," "To," and reply-to addresses, and any routing information generated as the message moves through mail servers. You can't disguise who's sending. Subject lines have to reflect what's actually in the message — a subject line like "Following up on our call" when no call ever happened is a violation independent of anything else in the email.
CAN-SPAM requires that a commercial email clearly and conspicuously disclose that it's an advertisement. In practice, most B2B cold email doesn't run around with "ADVERTISEMENT" stamped in the subject line, and enforcement in this space has focused on outright deception rather than the disclosure format — but the requirement is real, and how conspicuous is "conspicuous enough" is exactly the kind of question worth running past a lawyer if your messaging leans heavily promotional rather than relationship-building.
Every commercial email needs your valid physical postal address. The FTC accepts a current street address, a registered post office box, or a commercial mail-receiving agency address obtained under postal regulations. A P.O. box you haven't registered properly, or an address you've stopped using, doesn't satisfy this — the FTC's guidance is specific that the address has to be accurate and current at the time of sending.
Where to put it: Most senders put the postal address in the email signature or footer, in the same block as the unsubscribe link. That's compliant and doesn't require redesigning your outreach templates around it.
The email needs a clear, easy way to opt out of future messages — an unsubscribe link or a reply-based mechanism is fine, as long as it doesn't require the recipient to do more than send one response or click. Once someone opts out, you have 10 business days to honor the request, and the opt-out mechanism itself has to keep working for at least 30 days after you sent the message, in case the recipient opts out from an older email in their inbox.
CAN-SPAM penalties are calculated per email, not per campaign, which is what makes them add up quickly at scale. As of the FTC's most recent inflation adjustment, the maximum civil penalty is $53,088 per separate violation — and each non-compliant email sent can count as a separate violation.
Liability isn't limited to whoever hit send. The FTC guidance is explicit that CAN-SPAM can hold both the business whose product or service is being advertised and the party that actually initiated the message responsible. If you're running outreach through an agency or a platform, see our guide to agency compliance — the joint-liability structure is exactly why agency contracts need to address this directly rather than assuming the client's compliance covers everyone.
"Designated sender" doesn't mean immunity: The statute allows multiple parties involved in a message to designate one as primarily responsible under specific conditions, but this doesn't automatically release the others from their own obligations. Don't treat a designated-sender arrangement as a liability shield without reviewing the actual terms with counsel.
A compliant CAN-SPAM cold email includes an accurate sender identity in the From field, a subject line that matches the content, your current physical address in the signature or footer, and a one-click or one-reply opt-out mechanism that you actually process within 10 business days. None of this requires consent before the first send — that's the real difference from CASL, and from most of the EU framework covered in our GDPR cold email guide.
No. Unlike Canada's CASL or Germany's UWG, CAN-SPAM doesn't require prior consent for commercial email. It regulates message content and requires an opt-out mechanism, but sending the first cold email itself isn't the violation — a non-compliant message is.
No. The law makes no exception for business-to-business email or for small senders. Every commercial email, regardless of recipient type or company size, is held to the same header, disclosure, address, and opt-out requirements.
Up to $53,088 per separate email violation, based on the FTC's most recent inflation adjustment. Because penalties are calculated per email rather than per campaign, non-compliant bulk sends can accumulate exposure quickly.
CAN-SPAM can hold both the business whose product is being advertised and the party who initiated the message responsible. A designated-sender arrangement can shift some responsibility under specific conditions, but it doesn't automatically clear every party involved.
Related guides
Written by
Scott Holmes
AI systems consultant based in Barrie, Ontario. Founder of Pinnacle Tech Projects. Has built CAN-SPAM-compliant outbound systems for US-facing B2B senders across multiple industries.
Answer four quick questions and get a tool recommendation for your setup.