CAN-SPAM has an unfortunate name. It sounds like a ban on unsolicited email, and it is closer to the opposite: a set of conditions under which unsolicited commercial email is lawful in the United States.
This is general information rather than legal advice, and if your programme is large or your market is regulated, get a lawyer who works in this area.
The seven requirements
1. Do not use false or misleading header information
The From, To, Reply-To and routing information must accurately identify who sent the message. Sending as a domain you do not control, or disguising the origin, is a violation.
2. Do not use deceptive subject lines
The subject must reflect the content. "Re: our conversation" to someone you have never spoken to fails this, and it is a common pattern in cold email templates.
3. Identify the message as an advertisement
The law allows latitude in how, but a commercial message should be recognisable as one. A genuine one-to-one business email that reads as a person writing to a person is treated differently from a bulk advertisement, and most cold outreach sits in a grey area worth staying on the honest side of.
4. Include your physical location
Every commercial message must contain a valid physical postal address: a street address, a registered PO box, or a private mailbox from a commercial mail receiving agency.
This is the requirement almost everyone ignores. Look at the last cold email you received; the odds are it has no address in it.
5. Provide a clear way to opt out
An unsubscribe mechanism the recipient can find and use. A reply-to-unsubscribe instruction counts if you actually process those replies. A link is better, and a one-click unsubscribe header is better still, because it also satisfies Google and Yahoo's sender requirements.
6. Honour opt-outs promptly
Within ten business days. The mechanism must keep working for at least 30 days after the message was sent. You may not charge a fee, require any information beyond an email address, or make the recipient log in or visit more than one page.
7. Monitor what others do on your behalf
If you hire an agency, both you and they can be held responsible. Outsourcing the sending does not outsource the liability.
What CAN-SPAM does not require
It does not require consent. That is the whole architecture: it regulates the conduct of unsolicited commercial email rather than prohibiting it.
It does not distinguish B2B from B2C. Both are covered.
It does not cap volume, mandate double opt-in, or require you to prove a prior relationship.
This makes the US substantially more permissive than the EU, the UK or Canada, and it is why so much cold email advice written for a US audience is dangerous if you apply it in Europe.
How it compares
| US (CAN-SPAM) | EU (GDPR + ePrivacy) | UK (PECR + UK GDPR) | Canada (CASL) | |
|---|---|---|---|---|
| Consent needed first | No | Usually, or legitimate interest | B2B corporate has an exemption | Yes, express or implied |
| Opt-out required | Yes | Yes | Yes | Yes |
| Physical address | Required | Best practice | Best practice | Required |
| Identify sender | Required | Required | Required | Required |
| Penalty basis | Per email | Percentage of turnover | Per breach | Per violation |
The practical takeaway for a list spanning several countries: apply the strictest standard that touches your list, rather than sorting recipients by regime and hoping the sorting is right.
A compliant cold email, structurally
The message itself needs:
- A real name and a real company in the From line
- A subject that describes what the email is about
- A relevant, specific reason for writing to that person
- A clear statement of who you are and what you do
- A visible way to opt out
- Your physical postal address
- One-click unsubscribe headers
The address and the unsubscribe are usually what is missing. Both belong in your signature block and cost you nothing but two lines.
Practical notes that go beyond the law
Suppress opt-outs permanently and globally. Not per campaign. Someone who unsubscribed from one sequence and receives another from your other domain will complain rather than unsubscribe again, and the complaint costs you far more than the send earned.
Keep records. Which list, sourced when and how, sent what, when, and who opted out. If anyone ever asks, "we think it was fine" is not an answer.
Make unsubscribing easier than complaining. This is self-interest, not compliance. A spam complaint damages your ability to reach everyone else; an unsubscribe costs you one prospect who was never going to buy.
Do not use scraped personal addresses. Harvesting is treated as an aggravated violation and, separately, personal addresses are where the regimes outside the US get strict.
The five-minute audit
Open the last cold email you sent and check for: your physical address, a working unsubscribe, a subject line that matches the content, and honest header information.
If any of the four is missing, fix it before the next send. That is most of your CAN-SPAM exposure closed in an afternoon.
For non-US recipients, the picture is different and stricter. Our GDPR guide to cold outreach covers the European position, where consent and legitimate interest do most of the work.
