Every business that sends commercial email to US recipients operates under the CAN-SPAM Act, whether or not the team handling the email has ever read the statute. The law has been in force since 2003, the Federal Trade Commission enforces it, and the penalties for violations run to tens of thousands of dollars per individual email. Most senders comply by accident — they use email deliverability that handles most of the requirements automatically. Some senders comply by ignorance and have never been caught. A few senders get hit with sender reputation and find that “we did not know” is not a defence.
CAN-SPAM is also one of the most misunderstood compliance frameworks in marketing. Common misconceptions include the belief that it applies only to bulk email, that it requires recipient opt-in, that it bans certain kinds of content, and that it covers transactional mail. None of these is true.
What CAN-SPAM actually is (and what it does not cover)
CAN-SPAM stands for the Controlling the Assault of Non-Solicited Pornography And Marketing Act. The name reflects its mixed origin — it was initially focused on adult content and evolved into a general framework for commercial email. The statute defines specific requirements for any “commercial electronic mail message,” which the FTC defines as any email whose primary purpose is the commercial advertisement or promotion of a commercial product or service.
The scope is broader than many senders realise. CAN-SPAM applies to one-to-one cold email deliverability as well as bulk marketing campaigns. It applies to small businesses as well as large ones. It applies to any sender, anywhere in the world, who sends commercial mail to a US recipient. There is no minimum volume threshold.
The scope also has clear limits. CAN-SPAM does not cover transactional mail — order confirmations, shipping notifications, account statements, password resets, receipts. It does not cover “relationship” mail like updates about an ongoing service the recipient is already using. It does not regulate the content of commercial mail (with limited exceptions for sexually-explicit content, which has separate labelling rules). It does not require opt-in consent before the first message. And it does not preempt stricter state laws — California’s CCPA and several other state frameworks apply on top.
The seven CAN-SPAM rules, with examples
The statute is structured around seven specific requirements. Every commercial email sent to US recipients must meet all seven.
Rule 1 — Accurate header information
The From, To, Reply-To, and routing information must accurately identify the person or business that initiated the message. The email authentication and the displayed sender name must correspond to the actual sender — not to a fictitious entity or a third party.
In practice, this rules out spoofed sender identities. It also rules out “From” lines that obscure the sender, like generic names (“Team Updates”) without a corresponding business identification elsewhere in the message.
Compliant example: From: Marketing Team <marketing@brandname.com> Non-compliant example: From: Special Offer <noreply@random-domain-not-associated-with-business.com>
Rule 2 — Honest subject lines
The subject line must accurately reflect the content of the message. Gmail email delivery factors that misrepresent what the recipient will find inside are explicit violations.
The classic violation patterns are: “Re:” or “Fwd:” prefixes implying an existing conversation that does not exist; promised content in the subject that the body does not deliver; false urgency or false benefit claims.
Compliant example: Subject: 25% off all running shoes through Sunday Non-compliant example: Subject: Re: your order — when the message is a cold marketing message and no order exists.
Rule 3 — Clear identification as an ad (when applicable)
If the message is an advertisement, the recipient must be able to recognise it as one. The statute does not require a specific format (“This is an ad” labelling), and the requirement is considered met if context makes the commercial nature obvious — for example, a message from a known brand with promotional content.
In practice, this rule is most relevant to messages that mix commercial and editorial content, or to outreach that disguises itself as personal communication. A cold outreach email that reads as a one-to-one personal note from a real person but is in fact a templated commercial message is at risk under this rule.
Rule 4 — Physical postal address
Every commercial message must include the sender’s valid email compliance checklist. The address can be a street address, a registered Post Office box, or a Commercial Mail Receiving Agency address registered with the USPS.
In practice, this is usually placed in the email footer. Most email platforms add it automatically based on the account’s registered address.
The requirement applies to every message. A campaign sent to 100,000 recipients with no postal address in the footer is 100,000 separate violations under the FTC’s enforcement framework.
Rule 5 — Clear opt-out mechanism
Every commercial message must include a conspicuous, easy-to-use mechanism for the recipient to email list hygiene from the sender. The opt-out must be functional, must not require the recipient to provide more than an email address, and must not require the recipient to take more than a single step beyond clicking the opt-out link.
The opt-out cannot charge a fee, cannot require account creation, cannot require disclosure of personally identifying information beyond the email address, and cannot impose any other obligation on the recipient.
In practice, this is the unsubscribe link in the email footer. The link must work — broken unsubscribe links are violations. It must lead to a page where the recipient can complete the opt-out with one click. Long opt-out funnels that ask “are you sure?” multiple times, or require login, or attempt to upsell on the opt-out page, are problematic.
Rule 6 — Honour opt-outs within 10 business days
Once a recipient opts out, the sender has 10 business days to learn how to clean an email list and stop sending commercial mail to that address. After 10 business days, continued commercial mail to the opted-out address is a per-message violation.
The opt-out must also be permanent. A sender cannot interpret an opt-out as applying only to one mailing list or one campaign — it applies to all commercial mail from the sender. The only exception is if the recipient explicitly opts back in.
The opt-out cannot be sold, transferred, or shared with other senders. Opt-out lists from one business cannot be used as marketing lists by another business.
Rule 7 — Monitor what others do on your behalf
A business is responsible for CAN-SPAM compliance not only for mail it sends directly but for mail sent on its behalf by third parties. If a brand hires an agency to send marketing email, both the brand and the agency are subject to CAN-SPAM. If the agency violates the law, the brand can be held liable.
In practice, this means brands must vet the email practices of any agency, ESP, affiliate program, or partner that sends mail referencing the brand. Contracts should require CAN-SPAM compliance, and brands should periodically audit the actual mail being sent.
Penalty structure (and who actually gets fined)
CAN-SPAM penalties are calculated per email. As of 2026, the maximum civil penalty per violation is approximately $51,744, adjusted annually for inflation. The FTC can assess penalties against the sender, against any person who initiated the email, and against the company that owns the product or service being promoted.
In practice, the FTC concentrates enforcement on patterns of substantial violation, not on individual technical mistakes. Enforcement actions typically involve millions of violating messages, deceptive practices, or repeated violations after warnings. A small business that misses a postal address in one campaign is not likely to face FTC action, but it is technically liable and could face action in extreme circumstances.
State attorneys general can also bring CAN-SPAM enforcement, and the law allows internet service providers to sue senders who violate the act and damage their networks. ISP lawsuits have produced some of the largest CAN-SPAM judgments.
CAN-SPAM vs CASL vs GDPR — a one-page comparison
CAN-SPAM is the most permissive of the major commercial email frameworks. Senders should be aware of the stricter ones if they have recipients in those jurisdictions.
CASL (Canada’s Anti-Spam Legislation, in force since 2014) requires email verification before sending commercial mail to Canadian recipients in most cases. CASL also requires identification of the sender, an opt-out mechanism, and accurate sender information — broadly similar to CAN-SPAM, but the consent requirement is fundamental. Penalties run to CAD $10 million per violation for businesses.
GDPR (the EU General Data Protection Regulation, in force since 2018) requires a lawful basis for processing personal data, which includes sending email to a person’s email address. The most common lawful basis for marketing email under GDPR is consent, though “legitimate interest” can apply in B2B contexts. GDPR’s penalties are up to 4% of global annual revenue or €20 million, whichever is higher.
The practical implication for senders: if any portion of the recipient list is Canadian, CASL applies and consent must be obtained. If any portion is in the EU, GDPR applies. If neither, CAN-SPAM is the baseline framework, but the cleaner approach used by most modern programs is to apply CASL/GDPR-style consent globally and exceed the CAN-SPAM baseline by default.
Common CAN-SPAM compliance mistakes
Several patterns produce CAN-SPAM violations in otherwise well-intentioned email programs.
Treating cold outreach as exempt. Cold outreach is commercial mail. Every CAN-SPAM rule applies to it. Cold outreach messages must have an opt-out mechanism, a postal address, and accurate sender identification.
Missing postal address on transactional emails that also contain promotional content. A confirmation email is transactional, but if it includes “see what’s new in our store” or a promotional banner, the entire message becomes mixed-purpose. Under FTC guidance, such messages are evaluated by their primary purpose, and a promotional secondary purpose pulls the message into CAN-SPAM scope.
Broken unsubscribe links. A link that returns a 404 error, a link that requires login, a link that produces an error page — all are functional violations of the opt-out requirement.
Slow opt-out processing. ESPs typically process opt-outs within hours, but custom-built systems or manual processes sometimes take longer than the 10-business-day window. Continued sending past that window is a per-message violation.
Re-permission emails to opted-out addresses. Sending “we noticed you unsubscribed — are you sure?” to an opted-out address is itself a violation. Once opted out, the sender cannot send commercial mail to that address without explicit re-opt-in.
A compliance audit checklist
A simple periodic audit catches most CAN-SPAM problems before they become enforcement issues.
– Test every commercial email template for: accurate From line, accurate Reply-To, honest subject, postal address in footer, functional unsubscribe link. – Test the email blacklist check end-to-end: click the link, complete the opt-out in one step, confirm the address is added to the suppression list. – Verify the opt-out suppression list is being honoured. Pull a sample of opted-out addresses and confirm no commercial mail has been sent to them within the past 30 days. – Review any agency, partner, or affiliate sending mail on the brand’s behalf. Confirm their templates are CAN-SPAM compliant. – Review transactional templates for promotional content that might pull them into CAN-SPAM scope.
This audit takes one to two hours and should be repeated quarterly.
Key takeaways
– CAN-SPAM applies to every commercial email sent to US recipients, including one-to-one cold outreach. – The seven specific rules cover: accurate headers, honest subjects, ad identification where applicable, postal address, clear opt-out, opt-out processing within 10 business days, and responsibility for mail sent on the business’s behalf. – Penalties are calculated per email, currently up to $51,744 per violation, with enforcement concentrated on patterns of substantial violation. – CAN-SPAM does not require opt-in consent. CASL (Canada) and GDPR (EU) do. – Common violations are missing postal addresses, broken unsubscribe links, slow opt-out processing, and treating cold outreach as exempt. – A simple quarterly audit covers the operational basics and prevents most enforcement risk.
No. The US framework is opt-out rather than opt-in. A sender can send a first commercial message to a US recipient without prior consent, provided all seven rules are followed and the recipient can easily opt out of further mail.
No. Transactional mail (order confirmations, shipping notifications, account notices, password resets) is exempt. The exemption is lost if the transactional message is mixed with promotional content where the promotional content becomes the primary purpose.
CAN-SPAM applies to email. Commercial text messages are regulated under the Telephone Consumer Protection Act (TCPA), which is stricter than CAN-SPAM and includes explicit opt-in consent requirements.
Sending to a purchased list is not categorically prohibited by CAN-SPAM, but every rule still applies. The sender must have accurate headers, honest subject, postal address, working opt-out, and must honour opt-outs within 10 business days. In practice, purchased lists generate high complaint rates that damage sender reputation severely, so the question is usually moot — by the time a purchased-list campaign reaches enough recipients to attract enforcement attention, deliverability has usually collapsed.
CAN-SPAM is the federal law. ESP terms of service are contractual rules set by the sending platform, typically stricter than CAN-SPAM. ESPs require opt-in consent, prohibit purchased lists, and enforce engagement thresholds — all of which exceed CAN-SPAM’s baseline. A sender can comply with CAN-SPAM and still violate ESP terms.
Conclusion
CAN-SPAM remains the foundation of commercial email compliance in the United States. While it is more permissive than regulations like CASL and GDPR, it still imposes clear obligations on every sender: use accurate sender information, write honest subject lines, provide a valid postal address, offer a simple unsubscribe option, and honor opt-out requests promptly. Most violations stem from operational oversights rather than intentional misconduct, making regular compliance audits essential for any email program.
The safest long-term approach is not simply meeting the email verification best practices, but adopting permission-based email practices that align with global standards and protect sender reputation. Compliance reduces legal risk, improves deliverability, and helps build lasting trust with subscribers.
