Email marketing runs on top of real law. Depending on where your recipients live, a single campaign can touch the United States CAN-SPAM Act, Canada's Anti-Spam Legislation (CASL), the EU's GDPR and ePrivacy rules, and a growing set of national statutes beyond them. An email compliance checklist is the practical antidote to that sprawl: rather than memorising every regime, you work through a short set of habits that nearly all of them share, grouped so you can see what each one is actually asking of you. This guide walks the email compliance checklist group by group — permission, identification, honest content, unsubscribe, data handling, and list hygiene — and links to the deeper article on each law wherever the specifics diverge. For the wider jurisdiction-by-jurisdiction map, start with the overview of email marketing laws by country.
How to use this email compliance checklist#
The good news is that the major regimes rhyme. CAN-SPAM, CASL, and the GDPR were written by different legislatures for different reasons, but they converge on a small number of ideas: people should know who is emailing them, should have agreed to it (or at least be able to stop it easily), should not be deceived, and should be able to walk away and have their data respected. Almost everything below is a variation on those themes.
The practical rule when more than one law reaches a single send is straightforward: follow the strictest requirement that applies to any recipient on the list. If part of your audience sits in the EU, the consent and data-handling bar for those addresses is higher than it is for a purely US send, so meeting the higher bar keeps the whole campaign clean. You rarely need a separate programme per country — you need one programme built to the highest standard your list demands. The table below maps the six checklist areas to the core question each answers and the regimes that lean on it hardest.
| Checklist area | Core question it answers | Emphasised by |
|---|---|---|
| Permission and consent | Did this person agree to hear from you? | CASL, GDPR |
| Accurate identification | Is it obvious who sent this and how to reach them? | CAN-SPAM, CASL |
| Honest content | Do the From line and subject tell the truth? | CAN-SPAM, all |
| Unsubscribe | Can they leave in one step, and did you honour it? | CAN-SPAM, CASL, mailbox providers |
| Data handling | Is the data stored, transferred, and deleted responsibly? | GDPR |
| List hygiene | Are you only mailing real, engaged addresses? | Deliverability, and the spirit of all |
1. Permission and consent#
Consent is where the regimes differ most, so it is worth getting right first. CASL generally requires some form of consent — express or implied — before you send a commercial electronic message, and it puts the burden on the sender to prove that consent exists. The GDPR requires a lawful basis for processing personal data, and for marketing email that basis is very often consent, which must be freely given, specific, informed, and recorded. CAN-SPAM is more permissive at the point of collection, but it still expects the rest of the checklist to hold once you have someone's address.
The habit that satisfies all of them is the same: collect permission cleanly and keep a record of it. Log when someone signed up, how, and what they agreed to receive, so you can show the trail later. Where you can, prefer confirmed (double) opt-in, which asks the subscriber to click a link in a confirmation email before they are added. It is not mandatory everywhere, but it produces the strongest evidence of consent and it quietly improves list quality — the trade-offs are laid out in the guide to single versus double opt-in. For the EU-specific detail on lawful basis and consent, see the deeper piece on GDPR email marketing; for the Canadian rules on express and implied consent, see CASL compliance.
2. Accurate identification#
Every major regime insists that recipients can tell who is emailing them. CAN-SPAM prohibits false or misleading header information — the From, To, and routing details must accurately identify the sender — and it requires a valid physical postal address in the message. CASL likewise requires clear identification of the sender and working contact information. The GDPR approaches it from the transparency angle, expecting people to know who is processing their data and why.
In checklist terms: send from a real, consistent From name and a domain you actually control and authenticate, not a spoofed or throwaway address. Include a genuine physical mailing address in the footer — a street address or a registered post-office box works for the US requirement. Make your contact details easy to find, so a recipient who wants to reach a human can. None of this is exotic; it is mostly a matter of not disguising who you are. The specific US wording on headers and the postal-address requirement is covered in CAN-SPAM compliance.
3. Honest content#
Once the envelope is honest, the message has to be too. CAN-SPAM prohibits deceptive subject lines: the subject must not misrepresent the contents of the message. It also requires that a commercial message be identifiable as an advertisement, unless the recipient gave prior affirmative consent to receive it. The other regimes share the underlying expectation — content should not mislead — even where the wording differs.
The checklist item is short but easy to fumble under deadline pressure: make the subject line reflect what is actually inside, and do not dress a promotion up as a transactional notice, a reply, or a personal message when it is not. If the message is an ad and your recipients did not explicitly ask for advertising, make its commercial nature clear. Honest subjects also happen to be good for deliverability, since misleading ones draw complaints and train mailbox providers to distrust your domain long after a single campaign is over.
4. A working, prompt unsubscribe#
The right to leave is the most universal item on the list. CAN-SPAM requires a clear and conspicuous way to opt out in every commercial message, and the opt-out mechanism must stay able to process requests for at least 30 days after you send. Opt-out requests must be honoured promptly — within 10 business days under CAN-SPAM. CASL similarly requires a functioning unsubscribe mechanism that is given effect without delay and, in any event, within 10 business days. On top of the law, the major mailbox providers now expect bulk senders to offer one-click unsubscribe and to process those requests quickly.
So the checklist here has a few parts. Put a clear unsubscribe link in every marketing message. Do not force people to log in, re-enter their address, or answer questions to leave — a single action should do it. Support one-click unsubscribe (the list-unsubscribe header) so it works directly from the inbox; the mechanics are covered in the guide to one-click unsubscribe. And then actually honour the requests fast, and suppress those addresses for good rather than letting them drift back onto a future import. Prompt suppression also keeps your spam complaint rate down, because people who cannot find the exit reach for the "report spam" button instead.
5. Responsible data handling#
For any list with EU or UK recipients, the addresses themselves are personal data, and the GDPR governs how you hold and move them. That brings a set of obligations beyond the send itself: store the data securely, keep it only as long as you have a reason to, and be ready to honour data-subject rights such as access and erasure when someone asks. Where a vendor processes the data on your behalf, that relationship is usually governed by a data processing agreement, and where the processing happens outside the EEA, data residency and international transfers come into play.
The checklist items are practical. Keep your consent and unsubscribe records somewhere secure and durable. Have a route to delete someone's data — not just unsubscribe them — when they exercise the right to erasure. Know where your tools store and process your list, because a processor in another region can reintroduce a transfer question you thought you had avoided. The EU-specific detail — lawful basis, data-subject rights, and the data-residency angle that matters when a processor handles your list — sits in GDPR email marketing. Any tool that touches your list, including a verification service like Qualisend, should be able to tell you where it processes data and how you delete it.
6. List hygiene and verification#
The last group is not a statute so much as the thing that keeps the rest honest. No law requires you to verify addresses, but every regime is built on the idea that you are mailing people who want to hear from you — and a stale list quietly undermines that. Old addresses turn into hard bounces and, worse, into spam traps that signal you are not maintaining consent. People who never engage are the ones most likely to complain. Cleaning the list is how you keep the population you actually send to aligned with the people who actually opted in.
In practice that means a recurring routine rather than a one-off: verify new addresses at the point of capture, re-verify before large sends, remove hard bounces, and suppress the unengaged instead of pushing them harder. The full routine is laid out in the guide to cleaning an email list, and the mechanics of what a check actually does to each address are in what email verification is. This is the part of the checklist Qualisend is built for: verifying and cleaning so that the addresses you keep are real ones, and pairing that with honoured unsubscribes and solid consent records so your list reflects the permission behind it.
Frequently asked questions#
What should an email compliance checklist include?#
At minimum, six things: permission and consent (collected and recorded, ideally via confirmed opt-in); accurate identification (a real From name, an authenticated sending domain, and a physical postal address where required); honest content (no deceptive subject lines); a clear, promptly honoured unsubscribe; responsible data handling (secure storage, honouring erasure, and minding data residency); and ongoing list hygiene so you only mail real, engaged addresses. The specifics of each vary by law, which is why the checklist links out to CAN-SPAM, CASL, and GDPR detail for the fine print.
Does one checklist cover CAN-SPAM, CASL, and GDPR?#
Largely, because the regimes overlap on the fundamentals — identify yourself, tell the truth, let people leave, and respect their data. The practical approach is to build to the strictest requirement that reaches any recipient on your list, since meeting the higher bar generally satisfies the lower ones for that send. Where they genuinely diverge is consent (CASL and the GDPR are stricter at the point of collection than CAN-SPAM) and data handling (the GDPR adds obligations that CAN-SPAM does not). Confirm the details that apply to you with a qualified lawyer.
How quickly do I have to honour an unsubscribe request?#
Under CAN-SPAM, opt-out requests must be honoured within 10 business days, and the unsubscribe mechanism must keep working for at least 30 days after the message is sent. CASL similarly requires that an unsubscribe be given effect without delay and, in any event, within 10 business days. Separately, the major mailbox providers expect bulk senders to process one-click unsubscribes quickly. The safe habit is to suppress the address immediately and permanently rather than waiting out the window.
Where does list cleaning fit into email compliance?#
List cleaning is not a legal requirement, but it supports the spirit every regime is built on: sending only to people who want your email. Verifying and cleaning removes dead addresses, reduces bounces and spam-trap hits, and lowers complaint rates — all of which keep your active list aligned with the permission behind it. Combined with honoured unsubscribes and good consent records, hygiene is the operational backbone that makes the rest of the checklist hold up over time.
Two of the six items above are pure list hygiene — verifying real addresses and honouring unsubscribes so you only mail people who want to hear from you. That is what Qualisend does: run a sample through the free email checker to see the results in your browser, or start with the 100 free credits on the free plan to clean a real list before your next send.