Strategy

CAN-SPAM Compliance: The 2026 Guide for US Email Marketers

The CAN-SPAM Act sets seven rules for commercial email sent to US recipients, from accurate headers to a working opt-out honored within 10 business days. This post is general information, not legal advice; the FTC can fine you up to $51,744 per offending email.

Sohail HussainSohail Hussain(Updated: )11 min read

CAN-SPAM compliance means meeting seven specific rules every time you send a commercial email to a US recipient: accurate headers, honest subject lines, ad disclosure, a valid physical address, a working opt-out, opt-outs honored within ten business days, and oversight of anyone sending on your behalf. The Federal Trade Commission can fine you up to $51,744 per email. Not legal advice.

The CAN-SPAM Act (Controlling the Assault of Non-Solicited Pornography And Marketing Act) became federal law in January 2004 and has been the baseline for commercial email in US inboxes ever since. According to the FTC's CAN-SPAM compliance guide, the seven rules below apply whether you send one email or a million.

This article is educational and not legal advice. Your specific situation, products, and recipient mix may add complications a qualified attorney should review.

What the CAN-SPAM Act covers

CAN-SPAM is the United States federal law governing commercial email. It applies to any electronic message whose primary purpose is the commercial advertisement or promotion of a product or service. Transactional and relationship messages such as order confirmations, account notices, and receipts are mostly exempt, though the boundary blurs; the FTC's primary purpose rule explains how to classify a mixed message.

A few things CAN-SPAM is not. It is not an opt-in law; you can legally send a cold commercial email to a US address with no prior consent, provided the message satisfies all seven rules. It does not displace stricter regimes like California's CCPA, Canada's CASL, or the EU's GDPR, and it preempts state law only where that law specifically regulates commercial email content, which leaves state fraud and deception statutes fully in play.

Scope is wide: every business or individual sending commercial email to a US recipient. No small-business exemption, no charity exemption, no B2B carve-out, and no distinction between a shared role address and a personal one. The B2B misconception causes the most confusion and is probably imported from Europe, where some member states allow a narrower legitimate-interest basis for business contacts. That is GDPR reasoning rather than CAN-SPAM reasoning, and jane@enterprise.com gets exactly the same protection as jane@gmail.com.

The statute uses two terms, sender and initiator, and both can be liable. The sender is whoever's product the message promotes; the initiator is whoever actually transmits it, sometimes an agency, an affiliate, or a partner. When more than one company fits the definition you may decide among yourselves who takes responsibility, and if nobody does, all of you remain on the hook. I have watched this go sideways twice on customer onboarding calls; both times the brand assumed the agency had compliance handled and the agency assumed the brand did. Sort it out in writing before the first send.

Penalties climb every year, because the FTC adjusts the per-email maximum for inflation. As of the 2024 adjustment, the cap sits at $51,744 per offending email.

The seven rules

The seven CAN-SPAM rules at a glance
RuleWhat it requires
1. Header honestyFrom, To, Reply-To, and routing info must accurately identify the sender
2. Subject honestySubject line must reflect the actual content
3. Ad disclosureMessage must be identifiable as an advertisement
4. Physical addressA valid postal address must appear in every commercial message
5. Opt-out mechanismRecipient must have a clear way to opt out of future mail
6. Opt-out timingOpt-outs honored within 10 business days; mechanism live for 30+ days
7. Oversight of sendersYou remain responsible for anyone sending on your behalf

Rules one through three are all about honesty. Your From line has to identify the person or business that initiated the email, on a domain you control, with a Reply-To that routes to a real inbox; authentication is what makes this auditable, and if DMARC is failing your headers may satisfy CAN-SPAM while Gmail and Yahoo block you anyway. Our SPF, DKIM, and DMARC setup guide has the records. The subject line then has to reflect the body. "RE: Your invoice" on a cold pitch is exactly the phrasing the FTC has cited in enforcement actions, and so is "FREE iPad inside" when there is no iPad; the test is whether a reasonable recipient would feel deceived. Persuasive is entirely allowed, and the B2B cold subject line library beats improvising under deadline. Ad disclosure is the loosest of the three: a promotional message that looks promotional, arriving from a brand the recipient recognizes, usually satisfies it implicitly, and the rule bites hardest when marketing email is dressed up as personal correspondence.

Rule four is the postal address, and it is the one cold outreach forgets. Every commercial email needs a valid physical address: a current street address, a registered post office box per USPS rules, or a private mailbox at a commercial mail receiving agency. A virtual office counts if mail is actually delivered there. The footer is the usual home for it, and it has to be visible rather than hidden behind dark-text-on-dark-background tricks.

Rules five and six govern the opt-out. Every commercial email needs a clear, conspicuous explanation of how to stop receiving mail, and the mechanism cannot demand a login, a fee, or any information beyond the address and the opt-out preferences. You then have ten business days to stop sending, the mechanism must stay functional for at least thirty days after the email went out, and you may not sell or transfer the address of anyone who opted out except to a provider helping you comply.

Ten business days is the legal ceiling, and you should treat it as seconds. Mailboxes that keep receiving mail after an unsubscribe generate complaints, and your spam complaint rate is what mailbox providers actually act on. Mailneo suppresses unsubscribed addresses globally within seconds of the click.

Rule seven is oversight. Outsourcing to an agency, an affiliate, or a partner does not move the liability; the FTC has fined brands for affiliate conduct the brand never directly authorized. The practical defense is a written agreement, documented approval of templates, and visibility into which lists are being used.

What violations cost

The current per-email civil penalty maximum is $51,744, per the FTC's 2024 adjustment, and penalties are not theoretical. ValueClick paid $2.9 million in 2008 over deceptive advertising and CAN-SPAM violations across its affiliate network, an early signal that the FTC would hold companies responsible for conduct they had outsourced (FTC press release).

State attorneys general can sue under CAN-SPAM, and so can internet service providers. For most legitimate operators, though, the realistic risk is smaller and slower: a state AG complaint, or an FTC inquiry triggered by a competitor or a run of consumer complaints. Either one eats months of legal time before anybody establishes you did nothing wrong.

CAN-SPAM vs GDPR vs CCPA

Most operators eventually send to more than one jurisdiction. Here is the working comparison.

CAN-SPAM vs GDPR vs CCPA/CPRA at a glance
DimensionCAN-SPAM (US)GDPR (EU/UK)CCPA/CPRA (California)
Consent modelOpt-out; no prior consent requiredOpt-in; freely given, specific, informed, unambiguousNotice at collection; opt-out of sale/share
Triggering jurisdictionRecipient in the United StatesData subject in the EU or UKBusiness meeting thresholds and California residents' data
Opt-out timing10 business daysImmediate (right to object is absolute)15 business days for opt-out of sale
Max penalty$51,744 per email20M EUR or 4% of global turnover$7,500 per intentional violation
Cold email allowed?Yes, with complianceEffectively noYes, with notice and opt-out

If you send to a mixed list, build to the strictest rule that applies to any address on it. Maintaining two signup flows and two unsubscribe systems costs more than running everything to GDPR's bar globally, and an opt-in record is easier to defend in every jurisdiction anyway. Our GDPR email marketing guide covers the European side.

Transactional and mixed-purpose messages

CAN-SPAM treats transactional or relationship messages differently. Order confirmations, shipping updates, password resets, and account notices are not commercial email. They still cannot carry false header information, but the ad disclosure, physical address, and opt-out rules do not apply.

Mixed-purpose messages are where it gets hard. A receipt carrying a "you might also like" cross-sell is the textbook case, and the FTC applies a primary purpose test: if a reasonable recipient would conclude the main point is commercial, the whole message is commercial.

I have watched that argument consume hours of legal review, and the clean answer never changes. Send the receipt as a pure transactional message and the cross-sell as a separate campaign with full compliance; the audit trail is cleaner and nobody has to litigate the word "primary." Our transactional vs marketing guide covers where to draw the line operationally.

Building an unsubscribe flow that holds up

One click should remove the recipient from all promotional mail by default. Granular preferences can appear afterward; do not make somebody complete a form to escape. Gmail and Yahoo force this anyway through the List-Unsubscribe-Post header, so CAN-SPAM is the legal floor and not the deliverability ceiling; the one-click unsubscribe entry has the header syntax.

The link must not require a login. The FTC has explicitly called out flows that bury an unsubscribe behind a password-protected portal. Use a tokenized link that authenticates the request implicitly.

Suppression also has to propagate. If a recipient unsubscribes from your newsletter and then signs up two weeks later through a different form, you are allowed to mail them, because they re-consented. But your suppression system has to catch the original opt-out in the first place, and mixing up sources, lists, and brands is one of the most common ways well-meaning operators end up with FTC complaints; our suppression list management guide covers the record structure that makes this survivable. Watch unsubscribe rate next to complaints, because a rising opt-out rate is the earlier and much friendlier of the two warnings.

Purchased lists

CAN-SPAM does not technically prohibit buying a list. It does prohibit harvesting addresses from public websites, generating them through dictionary attacks, and using addresses obtained either way. It also makes you fully responsible for everything else: header honesty, opt-out, postal address, complaint rates.

In practice, purchased lists are a trap, and the legal exposure is the smallest part of it. The acquisition cost is real, the deliverability is dismal because you will hit spam traps, and the complaint rate wrecks your sender reputation inside a week. If you have inherited one and you are stuck with it, the only defensible move is a re-permission campaign sent from a domain that is not your primary sending identity. Treat whoever responds as the new list; discard the rest.

Cold outreach to individually researched contacts is a different activity with a different risk profile. The cold outreach swipe file shows what that looks like when it is done properly.

Pre-send checklist

Working version, refined across several customer reviews. Run it before every campaign.

  1. From, To, and Reply-To fields point to identities you control
  2. SPF, DKIM, and DMARC pass on the sending domain
  3. Subject line accurately reflects the body
  4. Message reads as promotional or includes explicit ad disclosure
  5. Footer contains a current postal address (street, PO box, or registered CMRA)
  6. Unsubscribe link is visible, one-click, and does not require login
  7. List-Unsubscribe and List-Unsubscribe-Post headers are present
  8. Suppression list updates within seconds of the unsubscribe click
  9. Agency, affiliate, and partner sends are documented and approved
  10. Bounce and complaint feedback loops route into suppression automatically

Compliance and deliverability pull in the same direction here, which is convenient; almost every item on that list also improves inbox placement. The email deliverability guide covers the rest of that overlap, and Mailneo's CAN-SPAM tooling page documents what the platform enforces on your behalf.

can-spamcomplianceftcemail-lawunsubscribeopt-out
Share this article
Sohail Hussain

Sohail Hussain

Founder & CEO at Mailneo

Building Mailneo — AI-powered email marketing for growing businesses.

Ready to supercharge your email marketing?

Start sending smarter emails with AI-powered campaigns. No credit card required.

Get Started Free