Cold Email Strategy

    CAN-SPAM Act Compliance for B2B Cold Email: What the Law Requires

    The CAN-SPAM Act makes no exception for business-to-business email. Here are the seven requirements, the opt-out clocks, and where liability lands when an agency sends.

    August 13, 202611 min read
    Share:
    The short answer

    The CAN-SPAM Act regulates how you send commercial email rather than whether you may, and it makes no exception for business-to-business messages. No consent is required. Every commercial email needs accurate headers, an honest subject line, an advertisement disclosure, a valid physical postal address and a working opt-out honoured within 10 business days.

    Key takeaways

    • The FTC's compliance guide states the law makes no exception for business-to-business email, so a single cold message to one prospect carries the same obligations as a bulk send.
    • An opt-out mechanism has to keep working for at least 30 days after a message goes out, and a request has to be honoured within 10 business days of arriving.
    • 16 CFR 316.5 forbids charging a fee, demanding information beyond an email address and opt-out preferences, or making the recipient do more than reply or visit a single web page.
    • The FTC's guide puts the maximum at $53,088 for each separate violating email, and 16 CFR 1.98 codifies that amount for penalties assessed after 17 January 2025.

    Reviewed and updated August 13, 2026

    The FTC's compliance guide for the CAN-SPAM Act carries one sentence that settles most of the arguments that happen inside a sales team: "The law makes no exception for business-to-business email" (FTC, CAN-SPAM Act: A Compliance Guide for Business). There is no B2B carve-out, no exemption for one company writing to another, and no volume floor below which the rules switch off. A single cold email to a single prospect is covered by the same law as a million-address blast.

    What the Act does not do is require permission. It regulates how you send, and it gives every recipient the right to make you stop. That combination is why US outbound is legal and why the mistakes that get people caught are mechanical ones: a missing postal address, an opt-out link that fails, a suppression list that only covers one campaign.

    This is not legal advice. It is an operator's reading of the statute, the CAN-SPAM Rule and the FTC's published guidance, written for people who send B2B email for a living. Take your own advice before relying on any of it.

    What the Act actually is

    The full name is the Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003. It is a single piece of federal legislation, styled CAN-SPAM Act rather than CANSPAM or Can-Spam, and the FTC's implementing rule sits under it at 16 CFR Part 316, which the eCFR titles the CAN-SPAM Rule and grounds in the statute at 15 U.S.C. 7701 to 7713 (eCFR, 16 CFR Part 316). Two surfaces matter in practice: the FTC's compliance guide, which lists the requirements in plain English, and Part 316, where the definitions live and which is the one to read when the guide is loose about something.

    Coverage turns on a single phrase. The FTC guide describes a commercial message as "any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service", and adds that the Act "doesn't apply just to bulk email". Cold sales email is squarely inside that. So is a prospecting message that only links to a commercial website.

    The consent model is the thing US senders should understand before anything else, because it is the opposite of Canada's and it is the reason a lot of imported advice is wrong. Under CAN-SPAM you may email a business contact who has never heard of you. Under CASL you generally may not, and the burden of proving you were allowed to sits on you. For the wider view across regimes, the multi-regime overview covers the EU, the UK and Canada alongside this one.

    It requiresEvery commercial message
    • Accurate From, To, Reply-To and routing information
    • A subject line that reflects the content
    • Clear and conspicuous disclosure that the message is an advertisement
    • A valid physical postal address
    • A clear explanation of how to opt out
    • Opt-outs honoured within 10 business days
    • The opt-out mechanism working for at least 30 days
    It does not requireCommon misreadings
    • Prior consent of any kind
    • An existing business relationship
    • A B2B exemption, because there is none to claim
    • Double opt-in, confirmed opt-in or a signup record
    • A minimum send volume before the rules apply
    It forbidsEven with a working opt-out
    • Charging a fee to opt out
    • Demanding information beyond an email address and opt-out preferences
    • Making the recipient do more than reply or visit one web page
    • Selling or transferring the address of someone who opted out
    • Contracting your liability away to a vendor
    What the CAN-SPAM Act requires of a commercial email, what it leaves alone, and what it specifically forbids a sender from doing. Sourced from the FTC compliance guide and 16 CFR Part 316.

    The seven requirements

    The FTC guide lists the main requirements as a numbered rundown. Here they are as a sending checklist.

    Every commercial email you send
    • Yes: Header information is accurate. From, To, Reply-To and routing data, including the originating domain and address, identify whoever initiated the message.
    • Yes: The subject line accurately reflects the content of the message.
    • Yes: The message discloses clearly and conspicuously that it is an advertisement.
    • Yes: The message carries a valid physical postal address: a street address, a registered PO box, or a registered private mailbox.
    • Yes: The message explains how to opt out, in a way an ordinary person can recognise, read and understand.
    • Yes: The opt-out mechanism can process requests for at least 30 days after the message is sent.
    • Yes: Opt-out requests are honoured within 10 business days, with no fee and no extra hoops.
    The CAN-SPAM requirements as the FTC's compliance guide states them, in the order a sender meets them.

    Two of those are worth expanding, because they are the ones B2B senders treat casually.

    The postal address is defined tightly. Part 316 defines a valid physical postal address as the sender's current street address, a Post Office box accurately registered with the United States Postal Service, or a private mailbox accurately registered with a commercial mail receiving agency established under Postal Service regulations. A city and a country in the footer is not an address.

    The advertisement disclosure is the requirement most cold email quietly skips. The FTC guide says the law "gives you a lot of leeway in how to do this", but the disclosure itself is not optional, and leeway in the form is not the same as an exemption from the substance.

    The primary purpose test

    Whether a message has to comply at all depends on its primary purpose, and Part 316.3 sets out the test rather than leaving it to instinct.

    1. Step 1Only commercial content

      If the message consists exclusively of the advertisement or promotion of a commercial product or service, its primary purpose is commercial. Every requirement applies. This is where cold outbound lands.

    2. Step 2Only transactional or relationship content

      If it consists exclusively of content in the five listed categories, its primary purpose is transactional or relationship. It must still carry truthful routing information, and it is otherwise outside most of the Act.

    3. Step 3A mix of the two

      It is commercial if a recipient reading the subject line would likely conclude the message is an advertisement, or if the transactional content does not appear in whole or in substantial part at the beginning of the body.

    4. Step 4Commercial plus other content

      It is commercial if the subject line or the body would lead a reasonable recipient to conclude the primary purpose is advertising. Placement, proportion, colour, graphics and type size all count.

    How 16 CFR 316.3 decides whether a message is commercial and therefore has to meet every requirement.

    The five transactional or relationship categories in 316.3(c) are narrow: facilitating or confirming a transaction the recipient already agreed to, warranty and recall and safety information, notifications about an ongoing subscription or account, information about an employment relationship or benefit plan, and delivery of goods or services the recipient is entitled to under an existing transaction. The FTC's guide warns that the law "views these categories narrowly" and that having an ongoing relationship with someone does not convert a marketing message into a transactional one.

    The guide's own worked example makes the placement rule concrete. Two messages carry the identical subject line "Your Account Statement". The one that opens with shipping and payment details and closes with a one-line product plug is most likely transactional. The one that opens with discount pricing and a summer offer, then mentions the delivery date at the end, is most likely commercial and subject to every requirement. Same subject, same parties, different obligations, decided by which content comes first.

    None of this rescues a cold email, which has no prior transaction to facilitate and is commercial by construction. The test earns its keep on the mail around a campaign: booking confirmations, onboarding notes and account updates, which stay transactional only while they consist exclusively of transactional content.

    The opt-out rules are stricter than most senders assume

    The headline numbers are 30 days and 10 business days. The mechanism has to keep working for at least 30 days after the message goes out, and a request has to be honoured within 10 business days of arriving.

    The detail sits in 316.5, which prohibits a sender, or anyone acting for a sender, from requiring that a recipient pay a fee, provide any information beyond their email address and opt-out preferences, or take any step other than sending a reply email or "visiting a single Internet Web page" in order to opt out. A preference centre that demands a login, or that asks why someone is leaving before it will accept the request, sits badly against that text.

    Three more points from the FTC guide that come up constantly in outbound:

    • You may offer a menu of message types to opt out of, but the menu must include an option to stop all marketing messages from you.
    • Once someone has opted out, you may not sell or transfer their address, including as part of a list. The only exception is transferring it to a company you have hired to help you comply.
    • The guide says explicitly to make sure your own spam filter is not blocking opt-out requests. An unsubscribe reply that lands in a junk folder is still an opt-out request you received.

    Our own practice is narrower than the law requires, deliberately. We run one-click unsubscribe in every message, we suppress on the first request rather than inside a ten-day window, and a suppression list applies across every campaign and every sending domain rather than per campaign. We also send one message per campaign and never bump a thread, which removes the situation where an opt-out arrives while three follow-ups are already queued behind it.

    Who counts as the sender when an agency sends for you

    This is the question every client asks, and the Act answers it in two places.

    Part 316.2(m) says that when more than one person's products, services or website are promoted in a single message, each of them is deemed a sender, with one exception: a single person can be deemed the sender if they meet the statutory definition, are identified in the "from" line as the sole sender, and comply with the initiator obligations covering deceptive transmission information, deceptive subject headings, the postal address, the opt-out mechanism and the sexually explicit labelling rule.

    The FTC guide adds the part that matters commercially. If the designated sender does not comply, all marketers in the message may be held liable as senders. And separately: "even if you hire another company to handle your email marketing, you can't contract away your legal responsibility to comply with the law". Both the company whose product is promoted and the company that originated the message may be legally responsible.

    Read that as an operating instruction rather than a legal risk to be papered over. When we run campaigns for a client, the client's identity and the client's postal address are what appear in the message, because the client is the sender in the Act's sense. The contract can allocate who pays for a mistake. It cannot move who the regulator can pursue.

    Penalties and enforcement

    The FTC enforces the Act, and its compliance guide states that "each separate email in violation of the CAN-SPAM Act is subject to penalties of up to $53,088".

    That figure is codified rather than editorial. 16 CFR 1.98 sets the FTC's inflation-adjusted civil penalty amounts and states that they "apply only to penalties assessed after January 17, 2025". Paragraph (d) puts Section 5(m)(1)(A) of the FTC Act at $53,088, and paragraph (p) routes civil penalties authorised by reference to the FTC Act under any other law within the Commission's jurisdiction back to those same amounts. The section carries the Federal Register citation 90 FR 5581, dated 17 January 2025 (eCFR, 16 CFR 1.98). That is the amount the current eCFR text carries as of this writing.

    The words that do the work are "each separate email". As an invented illustration, purely to show the shape of the arithmetic: a 2,000-address send with a broken opt-out link is 2,000 separate violations, which at the codified maximum multiplies into a nine-figure theoretical exposure. No enforcement action works out that way, and actual FTC outcomes are negotiated. The point is that exposure scales with list size, so the cheap moment to fix an opt-out link is before the send.

    The guide also notes that more than one person may be held responsible, that aggravated violations can attract additional fines, and that the law provides criminal penalties including imprisonment for a specific set of behaviours: accessing someone else's computer to send spam, using false information to register multiple email accounts or domain names, relaying messages to disguise their origin, harvesting email addresses or generating them through a dictionary attack, and exploiting open relays or open proxies.

    That harvesting and dictionary-attack line is the one worth reading twice if you buy lists. The FTC guide defines a dictionary attack as "the practice of sending email to addresses made up of random letters and numbers in the hope of reaching valid ones", so the behaviour it describes is the sending, not the sourcing. Resolving a named person at a known company and confirming the address before anything goes out is a different activity, and it is the reason address verification belongs between sourcing and sending rather than after it. Our own waterfall runs MillionVerifier, then Prospeo, then Findymail, and an address that does not resolve and verify is dropped rather than mailed.

    Text messages are governed by a different rule

    Messages to wireless devices sit under a separate FCC rule, and the consent model flips. 47 CFR 64.3100 provides that no person or entity may initiate a mobile service commercial message unless they have "the express prior authorization of the addressee", with narrow exceptions, and it requires a sender to cease sending "within ten (10) days after receiving such a request". The rule takes its definition of a commercial electronic mail message straight from the statute, saying the term "means the term as defined in the CAN-SPAM Act" (eCFR, 47 CFR 64.3100). So the opt-out default that governs email does not carry across to text. We run email and LinkedIn and do not do SMS outbound at all, but it is worth knowing the boundary exists before anyone suggests adding it.

    The Australian Spam Act 2003 is a different law

    Australia has its own statute called the Spam Act 2003, and it is not a version of CAN-SPAM. Section 16 is headed "Unsolicited commercial electronic messages must not be sent", and it prohibits sending a commercial electronic message with an Australian link, subject to an exception where the relevant electronic account holder "consented to the sending of the message". A person relying on that exception "bears an evidential burden" in relation to it. Section 18 is headed "Commercial electronic messages must contain a functional unsubscribe facility", and Part 3 separately prohibits supplying, acquiring or using harvested address lists (Federal Register of Legislation, Spam Act 2003). If you are sending into Australia, none of the US analysis above applies, and the consent question has to be answered before the send rather than after a complaint.

    What compliant US outbound looks like in practice

    • A real postal address in every message. A street address or a properly registered box, matching the entity named as the sender.
    • An honest subject line and honest headers. The From name and domain identify who actually sent it, and the subject describes what is inside.
    • A clear opt-out, one action deep. A reply or a single page, no login, no questionnaire, no fee.
    • Suppression that is global and immediate. One request removes the address everywhere you send from, not just from the campaign that prompted it.
    • Addresses resolved and verified before they are mailed. Verification sits between sourcing and sending, so nothing goes out to an address nobody has confirmed exists.
    • One message per campaign. No bumps and no thread replies, so nothing is queued behind an opt-out that has already arrived.
    • Segment by jurisdiction before you send. A process built for CAN-SPAM will not clear Canada, the EU, the UK or Australia, and the differences are structural rather than cosmetic.

    Every item on that list is a build-time decision. Compliance here is a property of how the sending system is configured rather than a judgment call someone makes per email, and the same choices that keep the FTC uninterested keep complaint rates low and inboxes reachable.

    Want US outbound run on infrastructure where the postal address, the opt-out and the global suppression are wired in before the first send? Get a free campaign plan and we will walk through how the compliance layer is built.

    Statutory and regulator text verified against the sources linked above as of August 2026. This is an operator's summary and not legal advice. Verify current requirements, and take your own advice, before relying on it.

    Questions

    Frequently asked questions.

    Frequently asked questions
    Does CAN-SPAM apply to B2B cold email?
    Yes. The FTC's compliance guide states that the law makes no exception for business-to-business email, and that the Act does not apply only to bulk mail. Coverage turns on the primary purpose of the message rather than on who the recipient is, so a first-touch prospecting email to a work address is a commercial message and has to meet every requirement.
    Do I need consent before sending a cold email in the US?
    No. CAN-SPAM works on an opt-out model, so no prior consent, signup record or existing business relationship is needed before a first message. What the Act requires instead is honest identification, a valid physical postal address, a clear way to opt out and prompt suppression once someone asks. Canada, the EU and Australia work differently.
    How fast do I have to process an unsubscribe?
    The FTC's guide gives two clocks. The opt-out mechanism must be able to process requests for at least 30 days after the message is sent, and a request has to be honoured within 10 business days. Ten business days is the legal ceiling rather than a target, and suppressing on the same day costs nothing and removes the risk entirely.
    If an agency sends the email, who is liable?
    Potentially both parties. The FTC's guide says hiring another company to handle email marketing does not let you contract away your legal responsibility, and that the company whose product is promoted and the company that originated the message may each be legally responsible. A contract can allocate who pays for a mistake, not who a regulator can pursue.
    Cold EmailComplianceCAN-SPAMEmail LawB2B Sales
    Byline

    About the author.

    Ben Carden

    Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.

    Ben Carden · CRO

    Connect on LinkedIn →
    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.

    Cold Email Strategy

    GDPR for B2B Outbound: What Emailing Contacts in Europe Actually Requires

    Territorial scope, the assessment behind a legitimate interest send, the national ePrivacy layer that decides whether you may send, and what the first message carries.

    11 min readRead →
    Cold Email Strategy

    Is Cold Email Legal? CAN-SPAM, GDPR, and CASL in Plain English

    Cold email is legal in the US without consent, restricted in Canada, and conditional in the EU and UK. Here is what each regime requires and what it costs.

    6 min readRead →
    Cold Email Strategy

    CCPA Compliance for Cold Outreach: The B2B Exemption That Lapsed

    CCPA's business-to-business exemption went inoperative on 1 January 2023, so a B2B prospect record for a California resident carries full consumer rights.

    11 min readRead →
    Cold Email Strategy

    CASL Compliance for Cold Email: What Canadian Law Actually Requires

    Express versus implied consent, the conspicuous publication route, the narrow B2B exemption, and the 60-day and 10-business-day rules CASL imposes on senders.

    6 min readRead →
    Cold Email Strategy

    11 Cold Email Agencies: What Each One Publishes About Price

    Eight of eleven cold email agencies publish a rate and three publish only terms. Four publish what they count as a qualified lead, and those definitions differ sharply.

    7 min readRead →
    Cold Email Strategy

    How to Write a Cold Email When It Is the Only One You Send

    Cold email writing is mostly deciding, and the deciding happens before the drafting. The order the work runs in, from one verifiable fact to a message worth sending.

    7 min readRead →