The CAN-SPAM Act — Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003 — is the US federal law that sets rules for every commercial email. It requires truthful headers, clear ad identification, a physical postal address, and a working opt-out. Enforced by the FTC, violations carry penalties up to $53,088 per email as of 2024.

Enacted
Dec 2003 (US)
Category
Email Marketing
Max penalty
$53,088 per email
Consent model
Opt-out

CAN-SPAM is often called "the polite law" — it does not require prior consent the way GDPR does. But treat it lightly and the FTC will treat you the same way. Every US commercial email must clear the same seven bars, whether you send one message or one million.

What is the CAN-SPAM Act?

The CAN-SPAM Act was signed into law by President George W. Bush on December 16, 2003, and took effect January 1, 2004. It's enforced by the Federal Trade Commission (FTC) with support from the Department of Justice and state attorneys general.

The law applies to every commercial electronic mail message — defined as any email whose primary purpose is advertising or promoting a commercial product or service. It covers B2C, B2B, transactional emails that also promote, and even individual sales-rep outreach from personal Gmail accounts.

CAN-SPAM pre-empts state anti-spam laws — one federal standard applies nationwide.

Common misconception

CAN-SPAM does not ban cold email. It regulates it. As long as your email is truthful, identifies itself as an ad, gives a physical address, and honors opt-outs, cold outreach to purchased or scraped lists is legal in the US — though ethically questionable and terrible for deliverability.

Why CAN-SPAM matters for marketers

Ignore CAN-SPAM and you invite three separate cost centers.

  1. FTC fines. Up to $53,088 per email in violation (2024 inflation-adjusted figure). Every non-compliant message is a separate violation. A single blast to 10,000 people can theoretically be a half-billion-dollar liability.
  2. ISP blocking. Gmail, Outlook, and Yahoo use CAN-SPAM compliance signals in their spam filters. A missing unsubscribe or fake sender name will land your entire domain on blocklists.
  3. Criminal charges. Aggravated violations — harvested addresses, dictionary attacks, or falsified headers — can bring prison sentences up to 5 years plus asset forfeiture.

The 7 CAN-SPAM requirements

Every commercial email must satisfy seven rules. Miss any single one and the email is non-compliant.

#RequirementWhat it means in practice
1Truthful "From" infoSender name, email address, and reply-to must accurately identify the business sending the message.
2Non-deceptive subject lineSubject cannot mislead the recipient about the message's contents. No "RE:" tricks on cold email.
3Identify as an adThe message must clearly and conspicuously disclose it's an advertisement.
4Physical postal addressEvery email must include a valid physical postal address — street address, PO box, or private mailbox registered with USPS.
5Clear opt-out mechanismEvery message must include a working unsubscribe link or reply-to method that is visible and easy to use.
6Honor opt-outs within 10 business daysOnce someone unsubscribes, stop emailing within 10 business days. The mechanism must stay live for at least 30 days after send.
7Monitor third partiesIf someone else sends email on your behalf (affiliate, agency, ESP), you are still responsible for their compliance.

CAN-SPAM compliance examples

1. Compliant email footer

# Standard compliant footer
You received this email because you subscribed at example.com.
Unsubscribe | Manage preferences

Example Inc., 123 Main Street, Suite 400,
San Francisco, CA 94103, United States

2. Non-compliant subject line (violation)

Subject: RE: Your invoice #4472 # deceptive — no prior thread
Subject: FREE iPhone (limited time) # deceptive if not actually free
Subject: 30% off summer skincare — this week only # truthful, ad-clear

3. Compliant "identify as ad" pattern

# Options that satisfy requirement #3
"[AD]" prefix in subject line
"Promotional" label in preheader
"You're receiving this promotional email because..." in footer

US marketers emailing internationally deal with three separate regimes. Pick the strictest law that applies to any recipient and comply with it globally.

CAN-SPAM (US)

  • Opt-out model — no prior consent needed
  • Truthful headers + physical address + unsubscribe
  • Max $53,088 per email
  • Enforced by FTC
  • Applies to commercial email only

GDPR (EU) & CASL (Canada)

  • GDPR — opt-in consent required, up to €20M or 4% global revenue
  • CASL — express consent required, up to CAD $10M per violation
  • Both apply based on recipient location, not sender
  • Both require documented consent records
  • Both cover far more than email

7 CAN-SPAM best practices

  1. Use verified sender domains. Authenticate with SPF, DKIM, and DMARC. Truthful "From" fields aren't just legal — they're a deliverability requirement.
  2. Put the physical address in every email. A PO Box works. A private mailbox registered with USPS works. Your home address does not need to be listed if you register a PMB.
  3. One-click unsubscribe. Gmail and Yahoo now require one-click unsubscribe for senders over 5,000 messages per day. This exceeds CAN-SPAM's minimum but is now the practical bar.
  4. Process opt-outs within 24-48 hours, not 10 days. The law gives 10 business days. Deliverability tools expect near-instant. Use your ESP's suppression list, not a manual export.
  5. Never sell or transfer opt-out addresses. Once someone unsubscribes, that address cannot be sold, rented, or shared for any purpose beyond suppression.
  6. Audit third-party senders. Affiliates, agencies, and partners emailing on your behalf create your liability. Contractually require compliance and monitor sending logs.
  7. Keep the opt-out live for 30+ days after send. A dead unsubscribe link is a violation even if the recipient stopped caring.
Common trap — "transactional" emails that promote

Order confirmations, shipping notifications, and receipts are exempt from most CAN-SPAM rules — but only if their primary purpose is transactional. Add a "Shop more like this" promo block and the FTC's primary-purpose test may reclassify the email as commercial. Keep promotional content out of transactional messages, or comply with CAN-SPAM in full.

Common CAN-SPAM mistakes to avoid

  • Using "no-reply@" as the only reply option — the FTC has warned that this can violate the "clear opt-out" requirement when combined with a broken unsubscribe link.
  • Requiring login to unsubscribe — illegal. Opt-out must not require the recipient to provide personal info beyond the email address.
  • Charging to unsubscribe — illegal. Opt-out must be free.
  • Ignoring third-party senders — the "on behalf of" clause makes both the sender and the beneficiary liable.
  • Forgetting the physical address — the single most common minor violation in FTC enforcement actions.
  • Purchasing email lists — legal under CAN-SPAM, but the vendor's original consent status is unverifiable. It's the fastest way to blacklist your sending domain.

Frequently asked questions

No. Unlike GDPR or CASL, CAN-SPAM is an opt-out law. You can email cold prospects legally in the US as long as the email includes a valid opt-out mechanism, a physical postal address, truthful headers, and clear ad identification.

Up to $53,088 per email in violation as of 2024 (adjusted for inflation). Each non-compliant email is a separate violation, and criminal penalties apply for aggravated cases involving harvested addresses or deceptive routing.

Within 10 business days of the request. The opt-out mechanism must remain functional for at least 30 days after the email is sent, and you cannot charge a fee, require login, or ask for personal information beyond the email address.

Yes. CAN-SPAM applies to any commercial electronic mail message, including B2B outreach and cold email. The primary purpose test looks at content, not the recipient type.

No. CAN-SPAM (US) is opt-out and applies to email content. GDPR (EU) requires prior opt-in consent, covers all personal data, and has far stricter penalties (up to 4% of global revenue). If you email EU residents, GDPR applies even from the US.

Sources

Akshay VR

Akshay VR

Marketing Head · theStacc · ex-Sr Marketing Specialist, ARKA 360 · Malappuram, Kerala

Akshay leads editorial and content operations at theStacc. He writes about the boring compliance work — CAN-SPAM footers, GDPR consent, DMARC records — that separates sustainable email programs from short-lived blasts.