If you send marketing or promotional email to anyone in the United States, CAN-SPAM compliance is the baseline the federal government expects you to meet. The CAN-SPAM Act sets rules for commercial email — how you identify yourself, what your subject lines may say, and how you let people stop hearing from you. What surprises many senders is what the law does not require: it does not ask for prior permission before you send. It regulates how you behave once you do. This guide walks through what the Act actually covers, the specific duties it places on senders, and why its opt-out design makes it the odd one out among the world's major email laws.
What the CAN-SPAM Act actually covers#
CAN-SPAM — short for Controlling the Assault of Non-Solicited Pornography And Marketing — is a US federal law that governs commercial electronic mail messages: email whose primary purpose is to advertise or promote a product or service. It applies to messages sent to recipients in the United States, and notably it covers business-to-business email just as much as consumer email. There is no exemption for a small list, a first message, or a "just checking in" sales note; if the primary purpose is commercial, the rules attach.
The Act draws a line between commercial content and other kinds of email. Transactional or relationship messages — a receipt, a shipping notice, an account update, information about something a person already bought — are treated differently and are not subject to the same set of requirements, though they still may not use false or misleading routing information. Messages that mix commercial and transactional content are judged by their primary purpose. Most newsletters, promotions, and cold outreach fall squarely on the commercial side.
Enforcement sits with the Federal Trade Commission (FTC), with a role for other regulators and state authorities as well. Violations can carry substantial civil penalties assessed on a per-email basis, so a single non-compliant blast to a large list is not a single infraction — each message can count. The figures are adjusted over time, so rather than fixate on a number, the practical takeaway is that penalties scale with volume and that the duties below are inexpensive to meet compared with the exposure of ignoring them.
The core duties CAN-SPAM sets out#
The Act's requirements are concrete and, for a well-run sender, mostly a matter of good hygiene. There are a handful of them, and they work together.
- No false or misleading header information. The "From," "To," "Reply-To," and the routing details that identify who sent the message must be accurate. The originating domain and email address have to genuinely represent the sender. You cannot disguise who you are.
- No deceptive subject lines. The subject must reflect the actual content of the message. A subject that promises one thing to get the open while the body delivers something else is exactly what this provision targets.
- Identify the message as an advertisement. Where it applies, the law requires that a commercial message be disclosed as an ad. The disclosure can be handled in a clear and conspicuous way; the point is that recipients should be able to tell they are looking at advertising.
- Include a valid physical postal address. Every commercial email must carry your real, current physical mailing address. A registered post office box or a private mailbox registered with a commercial mail-receiving agency can satisfy this, but the address has to be genuine.
- Provide a clear and conspicuous way to opt out. Every commercial message must give recipients an obvious method to tell you they want no more email — typically an unsubscribe link. It has to be easy to find and easy to use, and you may not charge a fee, require anything beyond an email address and opt-out preferences, or make people log in or hand over other information to get off the list.
- Honor opt-out requests promptly. Once someone opts out, you must stop sending them commercial email. The Act gives you 10 business days to process the request — a well-established deadline in the statute — and after that window the address should receive nothing further. You also cannot sell or transfer the email address of someone who has opted out.
- Monitor what others do on your behalf. You remain responsible for messages sent to promote your business even if you hire another company to send them. Both the business whose product is promoted and the party that actually transmits the message can carry legal responsibility, so outsourcing the send does not outsource the duty.
That last point deserves emphasis because it is the one most often assumed away. If an agency, an affiliate, or a lead vendor sends email advertising your product, CAN-SPAM does not treat that as somebody else's problem. The company being promoted can be on the hook alongside the sender. Building opt-out handling and honest headers into every path that mails on your behalf — not just your own platform — is the only reliable way to cover that exposure.
An opt-out regime: why CAN-SPAM compliance differs from GDPR and CASL#
Here is the defining feature, and the one most likely to trip up a sender who operates across borders. CAN-SPAM is an opt-out law. It does not require that you obtain a recipient's prior consent before sending commercial email. Under the Act, you may send a first commercial message to someone who never asked for it, provided the message itself follows the rules above and offers a working way to opt out. The obligation is to behave honestly and to stop when told — not to have permission in advance.
That is a genuinely different philosophy from the two other regimes senders most often deal with. Canada's Anti-Spam Legislation is built on the opposite default: it generally requires consent before you send, along with clear sender identification and a working unsubscribe. The requirements and how consent works are covered in the guide to CASL compliance. Europe's framework treats email addresses as personal data and leans on a lawful basis — often consent — for marketing, as the guide to GDPR and email marketing explains. In practice, a sender who builds for the stricter opt-in world of CASL and GDPR will usually clear the CAN-SPAM bar comfortably, because permission-first sending already implies honest identification and easy opt-out. Going the other way is where senders get caught: a program designed only for CAN-SPAM's opt-out standard can be non-compliant the moment it reaches a Canadian or European inbox.
| Dimension | CAN-SPAM (US) | CASL (Canada) / GDPR (EU) |
|---|---|---|
| Consent before sending? | Not required | Generally required |
| Model | Opt-out / conduct-based | Opt-in / permission-based |
| Honest sender identity | Required | Required |
| Working unsubscribe | Required | Required |
| Physical postal address | Required | Commonly expected |
| Applies to B2B? | Yes | Yes |
Because different countries draw these lines differently, senders with any international reach benefit from mapping which rules apply where. The overview of email marketing laws by country lays out how the opt-in and opt-out regimes compare, so you can design a single program that satisfies the strictest inbox you actually reach.
Making the opt-out work in practice#
The two operational duties that generate the most real-world trouble are the opt-out mechanism and the 10-business-day window to honor it. Both are simple in principle and easy to get subtly wrong.
An opt-out that technically exists but is hard to use is a common failure. The link has to be clear, conspicuous, and functional for a reasonable time after you send. Modern inbox providers have pushed senders further in the same direction: the major mailbox operators now expect bulk senders to support one-click unsubscribe in the message header, which both satisfies the spirit of CAN-SPAM's easy-opt-out rule and keeps you aligned with deliverability requirements. Treating unsubscribe as a first-class feature rather than a fine-print afterthought serves both goals at once.
Honoring requests within 10 business days means the plumbing behind the link has to actually suppress the address across every system that might mail it. If your unsubscribe writes to one platform but a separate cold-outreach tool keeps the contact active, you have not honored the request — you have merely recorded it in one place. This is where the "responsible for third parties" rule and the opt-out deadline meet: suppression has to be global across everything sending in your name.
There is a reputation dimension too. Recipients who cannot find an easy way out tend to reach for the "report spam" button instead, and a rising spam complaint rate hurts your deliverability regardless of whether any regulator ever looks at you. A clean, honest opt-out is simultaneously a legal duty and a deliverability asset — the interests line up.
Where list hygiene and record-keeping fit#
CAN-SPAM does not require the kind of consent records that CASL and GDPR do, but keeping good records still helps you demonstrate honest conduct and manage suppression reliably. Whatever your sending model, the operational side of compliance rests on the same list hygiene that keeps you out of spam folders.
Two habits matter most. First, maintain and respect your suppression list rigorously so that opt-outs stay opted out everywhere. Second, keep the list you mail accurate — routine email list cleaning removes dead and invalid addresses that inflate bounces and drag down reputation. Verification is where a tool like Qualisend fits: it confirms which addresses are deliverable before you send, so your honest, well-formed messages actually reach real inboxes rather than bouncing off abandoned mailboxes or spam traps. It does not decide who you are allowed to email — that is a matter of law and consent — but it keeps the list you are entitled to mail in good shape.
How you collect addresses in the first place shapes everything downstream. Even though CAN-SPAM permits opt-out sending, choosing a confirmed opt-in at signup gives you a cleaner, more engaged list and quietly moves you toward compliance with stricter regimes; the trade-offs are covered in the guide to single versus double opt-in. Good collection, accurate lists, and reliable suppression are the routine that makes the legal duties easy to meet rather than a scramble after the fact.
Frequently asked questions#
Does CAN-SPAM require opt-in consent before sending?#
No. CAN-SPAM is an opt-out law. It does not require prior permission to send a commercial email to a US recipient, which is its key difference from Canada's CASL and the EU's GDPR, both of which generally expect consent before you send. What CAN-SPAM does require is honest sender identification, a truthful subject line, a physical postal address, and a clear way to opt out that you honor promptly. A permission-first program built for CASL or GDPR will typically satisfy CAN-SPAM as well.
How quickly must I honor an unsubscribe under CAN-SPAM?#
The Act gives you up to 10 business days to process an opt-out request, after which you must stop sending that person commercial email. This deadline is set in the statute. In practice, most senders suppress the address immediately through their sending platform, which is both simpler and safer than tracking a countdown — and it avoids the situation where a separate tool keeps mailing a contact who already asked to leave.
Does CAN-SPAM apply to business-to-business email?#
Yes. Unlike some laws that focus on consumers, CAN-SPAM applies to commercial messages regardless of whether the recipient is a consumer or a business contact. A cold sales email promoting your product to another company is a commercial message and must follow the same rules — honest headers, a truthful subject, a physical address, and a working opt-out — as any consumer newsletter.
Am I responsible if a third party sends email for me?#
Yes. CAN-SPAM makes you responsible for commercial messages that promote your business even when another company sends them on your behalf. Both the business being advertised and the party transmitting the message can carry legal responsibility. That means opt-out handling and honest identification need to be built into every path that mails in your name — agencies, affiliates, and outsourced platforms included — not just your own sending tool.
Honest email starts with a list you can actually reach. Qualisend verifies your addresses so genuine, well-formed messages land in real inboxes and dead addresses stop dragging down your reputation. Try the free email checker or start with 100 free credits on the free plan — then keep your suppression list tight and your unsubscribes honored, and the rest of good sending follows.