CAN-SPAM Act Explained: Cold Email Compliance in the US (2026) | AI Email Tools
Legal Guide · United States

CAN-SPAM Act Explained: Cold Email Compliance in the US

Updated July 2026 10 min read By Scott Holmes

The CAN-SPAM Act became US federal law in 2003 and is enforced by the Federal Trade Commission. Unlike Canada's CASL, it doesn't require consent before you email someone — it regulates what a commercial email has to contain and how you have to let people leave your list. That's a real distinction, and it means CAN-SPAM compliance and CASL compliance are two separate checklists, not one.

What CAN-SPAM Actually Covers

CAN-SPAM applies to any commercial electronic message: an email whose primary purpose is advertising or promoting a product or service. It sets rules for message content and sender behavior rather than requiring opt-in permission up front. The FTC enforces it, and the rule text lives in 16 CFR Part 316.

The practical effect: a cold email to a US business contact you've never spoken to is legal under CAN-SPAM on day one, as long as the message itself follows the content rules below and gives the recipient a real way to stop future emails.

Why There's No B2B Exemption

CAN-SPAM makes no exception for business-to-business email. A cold email to a purchasing manager at a manufacturing company is held to the exact same content rules as a consumer marketing blast. Some senders assume B2B outreach gets lighter treatment because the recipient is acting in a professional capacity — that assumption is wrong under this specific law, even though it's roughly true under CASL's implied-consent framework and under UK PECR's corporate-subscriber exemption.

Header and Subject Line Rules

Every field a recipient or their mail server can see has to be accurate: the "From," "To," and reply-to addresses, and any routing information generated as the message moves through mail servers. You can't disguise who's sending. Subject lines have to reflect what's actually in the message — a subject line like "Following up on our call" when no call ever happened is a violation independent of anything else in the email.

The Advertisement Disclosure Requirement

CAN-SPAM requires that a commercial email clearly and conspicuously disclose that it's an advertisement. In practice, most B2B cold email doesn't run around with "ADVERTISEMENT" stamped in the subject line, and enforcement in this space has focused on outright deception rather than the disclosure format — but the requirement is real, and how conspicuous is "conspicuous enough" is exactly the kind of question worth running past a lawyer if your messaging leans heavily promotional rather than relationship-building.

The Physical Address Requirement

Every commercial email needs your valid physical postal address. The FTC accepts a current street address, a registered post office box, or a commercial mail-receiving agency address obtained under postal regulations. A P.O. box you haven't registered properly, or an address you've stopped using, doesn't satisfy this — the FTC's guidance is specific that the address has to be accurate and current at the time of sending.

Where to put it: Most senders put the postal address in the email signature or footer, in the same block as the unsubscribe link. That's compliant and doesn't require redesigning your outreach templates around it.

Opt-Out Mechanics

The email needs a clear, easy way to opt out of future messages — an unsubscribe link or a reply-based mechanism is fine, as long as it doesn't require the recipient to do more than send one response or click. Once someone opts out, you have 10 business days to honor the request, and the opt-out mechanism itself has to keep working for at least 30 days after you sent the message, in case the recipient opts out from an older email in their inbox.

Penalties

CAN-SPAM penalties are calculated per email, not per campaign, which is what makes them add up quickly at scale. As of the FTC's most recent inflation adjustment, the maximum civil penalty is $53,088 per separate violation — and each non-compliant email sent can count as a separate violation.

Liability isn't limited to whoever hit send. The FTC guidance is explicit that CAN-SPAM can hold both the business whose product or service is being advertised and the party that actually initiated the message responsible. If you're running outreach through an agency or a platform, see our guide to agency compliance — the joint-liability structure is exactly why agency contracts need to address this directly rather than assuming the client's compliance covers everyone.

"Designated sender" doesn't mean immunity: The statute allows multiple parties involved in a message to designate one as primarily responsible under specific conditions, but this doesn't automatically release the others from their own obligations. Don't treat a designated-sender arrangement as a liability shield without reviewing the actual terms with counsel.

Practical CAN-SPAM Compliance for Cold Email

A compliant CAN-SPAM cold email includes an accurate sender identity in the From field, a subject line that matches the content, your current physical address in the signature or footer, and a one-click or one-reply opt-out mechanism that you actually process within 10 business days. None of this requires consent before the first send — that's the real difference from CASL, and from most of the EU framework covered in our GDPR cold email guide.

CAN-SPAM compliance checklist for cold email

  • From/To/reply-to addresses are accurate and not disguised
  • Subject line matches the actual content of the message
  • Message clearly discloses it's commercial in nature where relevant
  • Current, valid physical postal address included
  • Working opt-out mechanism present in every message
  • Opt-out requests processed within 10 business days
  • Opt-out mechanism stays functional for 30+ days post-send
  • Opted-out addresses are not sold or reused for further marketing

FAQ

Does CAN-SPAM require consent before I send a cold email?

No. Unlike Canada's CASL or Germany's UWG, CAN-SPAM doesn't require prior consent for commercial email. It regulates message content and requires an opt-out mechanism, but sending the first cold email itself isn't the violation — a non-compliant message is.

Is there a small-business or B2B exemption under CAN-SPAM?

No. The law makes no exception for business-to-business email or for small senders. Every commercial email, regardless of recipient type or company size, is held to the same header, disclosure, address, and opt-out requirements.

What's the maximum penalty for a CAN-SPAM violation?

Up to $53,088 per separate email violation, based on the FTC's most recent inflation adjustment. Because penalties are calculated per email rather than per campaign, non-compliant bulk sends can accumulate exposure quickly.

Who is liable if an agency sends cold email on my behalf?

CAN-SPAM can hold both the business whose product is being advertised and the party who initiated the message responsible. A designated-sender arrangement can shift some responsibility under specific conditions, but it doesn't automatically clear every party involved.

Related guides

→ Cold Email Laws in Canada: CASL Compliance Guide → Is Cold Email Legal? A Country-by-Country Quick Reference → Penalties for Cold Email Violations: CASL, CAN-SPAM & GDPR Fines Compared

Written by

Scott Holmes

AI systems consultant based in Barrie, Ontario. Founder of Pinnacle Tech Projects. Has built CAN-SPAM-compliant outbound systems for US-facing B2B senders across multiple industries.

Ready to run compliant outreach?

Answer four quick questions and get a tool recommendation for your setup.