// Infrastructure

What Is CAN-SPAM Act?

// definition

The CAN-SPAM Act is a 2003 US law that sets the rules for commercial email. It requires accurate headers and subject lines, a valid physical postal address, clear identification of ads, and a working opt-out honored within 10 business days. Violations can incur civil penalties of over $50,000 per email.

CAN-SPAM applies to commercial email sent to US recipients — including cold outreach and B2B email, not just bulk marketing. It does not require prior opt-in consent (unlike GDPR), but it does impose firm requirements on how every commercial message is sent and how recipients can stop receiving them.

The core obligations are straightforward: do not use false or misleading "From," "To," or routing information; do not use deceptive subject lines; identify the message as an advertisement where applicable; include your valid physical postal address; provide a clear way to opt out; and honor opt-out requests promptly. Each of these applies to every commercial email you send.

Enforcement is by the US Federal Trade Commission, and penalties are steep — each separate email in violation can draw a civil penalty (the FTC-adjusted maximum is over $50,000 per message). Beyond legal risk, ignoring these rules drives spam complaints, which directly damages deliverability.

CAN-SPAM requirements

The Act sets seven main requirements for commercial email. First, header information — the From, To, Reply-To, and routing details, including the originating domain and email address — must be accurate and identify who sent the message. Second, subject lines must not deceive recipients about the contents of the message. Third, if the message is an advertisement, it must disclose that clearly (though the law gives latitude in how).

Fourth, every commercial email must include a valid physical postal address for the sender — a street address, a registered post office box, or a private mailbox registered with a commercial mail receiving agency. Fifth, the message must tell recipients how to opt out of future email. Sixth, opt-out requests must be honored promptly: the mechanism must work for at least 30 days after sending, and you must stop mailing within 10 business days. Seventh, you remain responsible even if another company sends email on your behalf — you cannot outsource away liability.

CAN-SPAM vs GDPR

CAN-SPAM and the EU’s GDPR take fundamentally different approaches. CAN-SPAM is an opt-out regime: you may send commercial email to US recipients without prior consent, provided you follow the rules and let them unsubscribe. It regulates how you email, not whether you were permitted to start.

GDPR (and the related ePrivacy rules) is largely an opt-in regime for EU residents: you generally need a lawful basis — often prior consent — before sending marketing email, and recipients have broad rights over their personal data. B2B cold email has narrower allowances under legitimate interest in some cases, but the bar is far higher than CAN-SPAM. If you email across both regions, you must satisfy the stricter standard for each recipient — which in practice means GDPR-level consent and transparency for EU contacts and CAN-SPAM compliance for US ones.

CAN-SPAM vs GDPR at a glance

AspectCAN-SPAM (US)GDPR (EU)
Consent modelOpt-out (no prior consent required)Opt-in / lawful basis required
Physical addressRequired in every emailNot the core mechanism (transparency required)
Opt-outMust honor within 10 business daysRight to withdraw consent / object anytime
ScopeCommercial email to US recipientsPersonal data of EU residents
PenaltiesCivil penalty >$50,000 per emailUp to €20M or 4% of global turnover

Frequently asked questions

What is the CAN-SPAM Act?

The CAN-SPAM Act is a 2003 US law governing commercial email. It requires accurate headers and subject lines, a valid physical postal address, clear identification of advertisements, and a working opt-out that is honored within 10 business days. It applies to all commercial email — including cold B2B outreach — sent to US recipients.

What does CAN-SPAM require?

CAN-SPAM requires accurate From and header information, non-deceptive subject lines, disclosure that a message is an ad where applicable, a valid physical postal address, a clear opt-out mechanism, and honoring opt-out requests within 10 business days. Senders remain liable even when a third party sends the email on their behalf.

What are the penalties for violating CAN-SPAM?

The US Federal Trade Commission enforces CAN-SPAM, and each separate email in violation can incur a civil penalty — the inflation-adjusted maximum is over $50,000 per message. Because penalties apply per email, a single non-compliant campaign can carry substantial liability, on top of the deliverability damage from spam complaints.

Does CAN-SPAM require opt-in consent like GDPR?

No. CAN-SPAM is an opt-out law: you may send commercial email to US recipients without prior consent, as long as you follow its rules and let recipients unsubscribe. GDPR is largely opt-in for EU residents, generally requiring a lawful basis such as consent before sending. If you email both regions, meet the stricter standard for each.

// how mailpilot helps

MailPilot keeps your outreach mailboxes healthy so the compliant email you send — with accurate headers, a real address, and an easy opt-out — actually reaches the inbox instead of the spam folder.

Keep compliant email in the inbox

Start for free - no credit card required.

Get started freeBook a demo