Send one commercial email that breaks the rules in the United States and the fine can reach $53,088. For that single message. So before you press send on your next campaign, it pays to know exactly what the law asks of you.
I have run email marketing programs for B2B teams for years, and the CAN-SPAM Act is the one rule set almost everyone half-remembers and half-ignores. The good news is that it is short, practical, and easy to follow once you see it laid out. Let’s break it down 👇
📌 On this page: What the CAN-SPAM Act is, who it covers, the seven rules it sets, the penalties for ignoring them, how it compares to GDPR and CCPA, and a compliance checklist you can reuse before every send.
What is the CAN-SPAM Act?
The CAN-SPAM Act is a 2003 United States federal law that sets the rules for sending commercial email and gives recipients the right to stop a business from emailing them. CAN-SPAM stands for Controlling the Assault of Non-Solicited Pornography And Marketing. The Federal Trade Commission (FTC) enforces it.
Here is the part people miss. The law does not only apply to bulk newsletters. It covers any email whose main purpose is to promote a product or service, including one-to-one cold outreach a sales rep sends to a single prospect. If the message sells something, CAN-SPAM applies.
The law does not require permission before you email someone, which is where it differs sharply from Europe. Instead, it sets standards for honesty and gives every recipient a clear exit.
How the CAN-SPAM Act works
CAN-SPAM sorts email into three buckets, and the rules change depending on the bucket.
Commercial email advertises or promotes a product or service. This is the category the full law targets, and it carries every requirement below.

Transactional or relationship email completes a transaction the recipient already agreed to, such as a receipt, a shipping update, or a warranty notice. These messages are mostly exempt, though the header and sender information still have to be accurate.
Mixed messages that carry both content are judged by their primary purpose. If the promotional part is the main point, the message is treated as commercial.
💡 Why it works: The primary-purpose test stops senders from hiding an ad inside a receipt. A shipping email with one small promo line stays transactional, but a receipt built around a discount offer becomes a commercial message and inherits every rule.
The 7 rules the CAN-SPAM Act requires
The FTC boils the law down to seven main requirements. Miss any one of them on a commercial email and you are out of compliance.
| Rule | What it means in practice |
|---|---|
| 1. Do not use false or misleading headers | The From, To, Reply-To, and routing details must identify the real sender. |
| 2. Do not use deceptive subject lines | The subject has to reflect what is actually inside the email. |
| 3. Identify the message as an ad | Disclose clearly that the email is an advertisement. The disclosure can be brief. |
| 4. Tell recipients where you are located | Include a valid physical postal address, which can be a registered PO box. |
| 5. Explain how to opt out | Give a clear, easy way to stop future email from you. |
| 6. Honor opt-outs promptly | Process any unsubscribe within 10 business days, and keep the mechanism live for at least 30 days after sending. |
| 7. Monitor what others do on your behalf | You stay legally responsible even when an agency or vendor sends the email for you. |
Two of these trip people up most often. Rule 6 means you cannot charge a fee, ask for extra information beyond an email address, or make someone log in to unsubscribe. Rule 7 means hiring a contractor does not transfer the liability. Both the brand and the sender can be held responsible.
Penalties for breaking the CAN-SPAM Act
Each separate email that violates the CAN-SPAM Act can draw a civil penalty of up to $53,088 (FTC, 2024 inflation adjustment). The count is per email, not per campaign, so a single non-compliant blast to a list of thousands multiplies fast.
The FTC has pursued real cases. Marketers, and in some cases the companies whose products were promoted, have paid six and seven-figure settlements for deceptive headers and ignored opt-out requests. Some aggravated violations, such as harvesting addresses or using automated scripts to create accounts, can add further liability.
🧠 Keep in mind: Beyond the legal fine, ignoring the rules quietly wrecks your inbox placement. Mailbox providers watch complaint signals closely, so the same behavior that breaks the law also drives your delivery down.
Why the CAN-SPAM Act matters for your email program
Compliance is not only about avoiding fines. The habits the law enforces are the same habits that keep email working.
A clean opt-out flow lowers your spam complaint rate because frustrated recipients hit unsubscribe instead of the spam button. That protects your sender reputation and your email deliverability. A healthy unsubscribe rate is a feature here, not a failure, because it removes people who would otherwise complain.
💡 Why it works: Every CAN-SPAM rule pushes you toward sending wanted mail to people who can easily leave. Mailbox providers reward exactly that behavior, so the law and your deliverability goals point in the same direction.
CAN-SPAM vs GDPR vs CCPA
If you email across borders, CAN-SPAM is only one layer. The big difference is consent. CAN-SPAM lets you email first and requires an easy opt-out, an opt-out model. Europe works the opposite way.
Under GDPR, you usually need a lawful basis before you process someone’s data or email them, and marketing consent is often collected up front through a double opt-in flow. California’s CCPA focuses on giving residents the right to know what data you hold and to opt out of its sale, which reaches beyond email alone.
The practical takeaway is simple. Meeting CAN-SPAM does not make you GDPR or CCPA compliant. If your list includes EU or California contacts, you have to satisfy the stricter rule that applies to each person.
A CAN-SPAM compliance checklist
Here is the checklist I run before any commercial send. It takes a couple of minutes and saves a lot of grief.
- Confirm the From, Reply-To, and routing fields name the real sender.
- Read the subject line and check it matches the actual content.
- Include a plain disclosure that the message is an advertisement when it is one.
- Add your valid physical postal address in the footer.
- Place a visible, one-click unsubscribe link that needs nothing more than an email address.
- Route opt-outs to a suppression list and honor them within 10 business days.
- Keep the unsubscribe link working for at least 30 days after the send.
- Audit any agency or platform sending on your behalf, since the liability is still yours.
- Suppress role addresses and stale contacts to keep complaints low.
One more habit that is not strictly required but worth adopting. Even though CAN-SPAM allows emailing without prior consent, sending to people who show real interest almost always beats blasting a cold list, both for results and for staying clear of complaints.
Where CUFinder fits
CUFinder is a B2B data provider, not a legal service, so it will not file your compliance paperwork. What it does help with is the input side. Accurate, verified contact data and B2B data enrichment mean you are emailing real people at real addresses, which lowers bounces and complaints and keeps your sending honest.
You still own the CAN-SPAM parts that matter most, meaning the disclosures, the opt-out, and the suppression list. Good data does not replace those steps. It just gives them a cleaner starting point.
Frequently asked questions about the CAN-SPAM Act
Does the CAN-SPAM Act require permission before emailing someone?
No. Unlike GDPR, CAN-SPAM does not require prior consent. You can send commercial email to a contact without opt-in, as long as the message has honest headers, a clear ad disclosure, a physical address, and a working opt-out that you honor within 10 business days.
Does CAN-SPAM apply to B2B emails and cold outreach?
Yes. The law covers any email whose primary purpose is commercial, including one-to-one sales emails to a single business prospect. There is no exemption for B2B, so cold outreach must follow the same seven rules.
How quickly do I have to process an unsubscribe request?
Within 10 business days. You also have to keep the opt-out mechanism working for at least 30 days after you send the message, and you cannot charge a fee or ask for information beyond an email address to opt out.
What is the maximum penalty for a CAN-SPAM violation?
Up to $53,088 per email as of the FTC’s 2024 inflation adjustment. Because the penalty is counted per individual email, a single non-compliant campaign to a large list can create very large exposure.
Is a physical address really required in every commercial email?
Yes. Every commercial email must include a valid physical postal address for your business. This can be your street address, a registered PO box, or a private mailbox registered with a commercial mail receiving agency.
Does following CAN-SPAM make me GDPR compliant?
No. CAN-SPAM is a US opt-out law, while GDPR is a consent-based EU regulation with stricter requirements. If your list includes EU contacts, you must meet GDPR separately, and California contacts add CCPA obligations on top.
The bottom line
The CAN-SPAM Act comes down to honesty and an easy exit: tell the truth in your headers and subject lines, say who you are, and let people leave when they want to. Follow the seven rules and you protect both your budget and your inbox placement.
Want to start from clean, verified B2B contacts so your compliant sends actually reach real people? Get started today 👇