Cold Email Strategy

    CAN-SPAM Act Compliance for B2B Cold Email: The Rules

    The CAN-SPAM Act makes no exception for business-to-business email. Here are the seven requirements, the opt-out clocks, and where liability lands when an agency sends.

    Editorial illustration for CAN-SPAM Act Compliance for B2B Cold Email
    August 12, 2026Updated September 18, 202611 min read
    Share:
    The short answer

    The FTC's CAN-SPAM Act: A Compliance Guide for Business lists seven requirements for every commercial email: accurate headers, an honest subject line, identification as an ad, a valid postal address, a way to opt out, opt-outs honored within 10 business days, and monitoring what others do on your behalf. The law makes no exception for B2B email.

    Key takeaways

    • The FTC's guide states the law makes no exception for business-to-business email and does not apply just to bulk email, so a single cold email to one prospect is covered.
    • The guide's seven requirements are accurate headers, no deceptive subject lines, identifying the message as an ad, a valid physical postal address, an opt-out, honoring opt-outs promptly, and monitoring what others do on your behalf.
    • An opt-out mechanism must work for at least 30 days after the send and a request must be honored within 10 business days, with no fee, no extra information and no more than a reply or a single web page.
    • The guide states each separate email in violation is subject to penalties of up to $53,088, and that hiring an agency to send does not contract away the responsibility to comply.

    Reviewed and updated September 18, 2026

    The FTC's "CAN-SPAM Act: A Compliance Guide for Business" carries one sentence that settles most of the arguments that happen inside a sales team: "The law makes no exception for business-to-business email" (FTC, CAN-SPAM Act: A Compliance Guide for Business). There is no B2B carve-out, no exemption for one company writing to another, and no volume floor below which the rules switch off. A single cold email to a single prospect is covered by the same law as a million-address blast.

    What the Act does not do is require permission. It regulates how you send, and it gives every recipient the right to make you stop. That combination is why US outbound is legal and why the mistakes that get people caught are mechanical ones: a missing postal address, an opt-out link that fails, a suppression list that only covers one campaign.

    Deciding whether a message qualifies as legitimate outbound at all often starts earlier than compliance mechanics, with the distinction between cold email and spam.

    This is not legal advice. It is an operator's reading of the statute, the CAN-SPAM Rule and the FTC's published guidance, written for people who send B2B email for a living. Take your own advice before relying on any of it.

    What does the FTC's "CAN-SPAM Act: A Compliance Guide for Business" require?

    The FTC's guide lists seven main requirements: no false or misleading header information, no deceptive subject lines, identify the message as an ad, tell recipients where you are located, tell them how to opt out, honor opt-out requests promptly, and monitor what others are doing on your behalf. It states that each separate email in violation is subject to penalties of up to $53,088. That is the whole list, which is why the Act is easier to satisfy than its reputation suggests.

    What the Act actually is

    The full name is the Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003. It is a single piece of federal legislation, styled CAN-SPAM Act rather than CANSPAM or Can-Spam, and the FTC's implementing rule sits under it at 16 CFR Part 316, which the eCFR titles the CAN-SPAM Rule and grounds in the statute at 15 U.S.C. 7701 to 7713 (eCFR, 16 CFR Part 316).

    Coverage turns on a single phrase. The FTC guide describes a commercial message as "any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service", and adds that the Act "doesn't apply just to bulk email". Cold sales email is squarely inside that. So is a prospecting message that only links to a commercial website.

    Because platform rules can be stricter than federal law, HubSpot's anti-spam policy for cold outreach is worth understanding before sending commercial email through that system.

    The consent model is the thing US senders should understand before anything else, because it is the opposite of Canada's and it is the reason a lot of imported advice is wrong. Under CAN-SPAM you may email a business contact who has never heard of you. Under CASL you generally may not, and the burden of proving you were allowed to sits on you. For the wider view across regimes, the multi-regime overview covers the EU, the UK and Canada alongside this one, and the Canadian half of the cold email laws comparison is the one whose consent model runs the other way.

    It does not require

    • Prior consent of any kind
    • An existing business relationship
    • A B2B exemption, because there is none to claim
    • Double opt-in, confirmed opt-in or a signup record
    • A minimum send volume before the rules apply

    It forbids

    • Charging a fee to opt out
    • Demanding information beyond an email address and opt-out preferences
    • Making the recipient do more than reply or visit one web page
    • Selling or transferring the address of someone who opted out
    • Contracting your liability away to a vendor
    What the FTC's guide says the Act leaves alone, and what it says a sender may not do even with a working opt-out. Sourced from the compliance guide and 16 CFR Part 316.

    The seven requirements

    The FTC guide lists its main requirements as a seven-item rundown. Here they are placed on a message that meets all seven.

    From: Dana Cole, Northwind Outbound (dana@northwind-outbound.com) 1

    Subject: three open SDR roles on your careers page 2

    Saw the three SDR roles open in Austin, which usually means the pipeline target moved before the team did.

    Northwind runs outbound for B2B teams your size on a per-meeting basis. This is a commercial message from Northwind Outbound. 3

    Worth 15 minutes next week to see if the maths works for you?

    Northwind Outbound, 120 Market Street, Suite 4, San Francisco, CA 94105 4

    Reply "stop" or use the one-click unsubscribe link to opt out. 5 6 7

    1. 1FTC guide: do not use false or misleading header information. The From, Reply-To and routing data identify who initiated the message.
    2. 2FTC guide: do not use deceptive subject lines. The subject accurately reflects the content.
    3. 3FTC guide: identify the message as an ad, clearly and conspicuously, with a lot of leeway in how.
    4. 4FTC guide: tell recipients where you are located, with a valid physical postal address: a street address, a registered PO box or a registered private mailbox.
    5. 5FTC guide: tell recipients how to opt out, in a way an ordinary person can recognise, read and understand.
    6. 6FTC guide: honor opt-out requests promptly. The mechanism works for at least 30 days after the send and a request is honored within 10 business days, with no fee and no extra steps.
    7. 7FTC guide: monitor what others are doing on your behalf. Hiring an agency to send does not contract away the responsibility to comply.
    A cold email that meets all seven of the FTC guide's requirements, with each one numbered where it is satisfied. The sender and addresses are invented for the illustration.

    Two of those are worth expanding, because they are the ones B2B senders treat casually.

    The postal address is defined tightly. Part 316 defines a valid physical postal address as the sender's current street address, a Post Office box accurately registered with the United States Postal Service, or a private mailbox accurately registered with a commercial mail receiving agency established under Postal Service regulations. A city and a country in the footer is not an address.

    The advertisement disclosure is the requirement most cold email quietly skips. The FTC guide says the law "gives you a lot of leeway in how to do this", but the disclosure itself is not optional, and leeway in the form is not the same as an exemption from the substance.

    The primary purpose test

    Section illustration: The primary purpose test

    Whether a message has to comply at all depends on its primary purpose, and Part 316.3 sets out the test rather than leaving it to instinct.

    Primary purpose test: what the message consists of decides which rules apply What does the message consist of? 316.3 tests the content, not the intent Only commercial Every rule applies A mix of the two Ad-like subject: commercial Only transactional Truthful routing only Mixed: where is the transactional content? Not at the start, in whole or substantial part? Commercial The guide's own example Same subject, "Your Account Statement". Shipping and payment first: transactional. Discount offer first, delivery date last: commercial, every requirement applies.
    How 16 CFR 316.3 decides whether a message is commercial and has to meet every requirement. Cold outbound lands in the first box by construction.

    The five transactional or relationship categories in 316.3(c) are narrow: facilitating or confirming a transaction the recipient already agreed to, warranty and recall and safety information, notifications about an ongoing subscription or account, information about an employment relationship or benefit plan, and delivery of goods or services the recipient is entitled to under an existing transaction. The FTC's guide warns that the law "views these categories narrowly" and that having an ongoing relationship with someone does not convert a marketing message into a transactional one.

    The guide's own worked example makes the placement rule concrete. Two messages carry the identical subject line "Your Account Statement". The one that opens with shipping and payment details and closes with a one-line product plug is most likely transactional. The one that opens with discount pricing and a summer offer, then mentions the delivery date at the end, is most likely commercial and subject to every requirement. Same subject, same parties, different obligations, decided by which content comes first.

    None of this rescues a cold email, which has no prior transaction to facilitate and is commercial by construction. The test earns its keep on the mail around a campaign: booking confirmations, onboarding notes and account updates, which stay transactional only while they consist exclusively of transactional content.

    The opt-out rules are stricter than most senders assume

    The headline numbers are 30 days and 10 business days. The mechanism has to keep working for at least 30 days after the message goes out, and a request has to be honoured within 10 business days of arriving.

    Two clocks: mechanism live 30 days after send, request honored in 10 days Clock 1: from the send Day 0: sent Day 30: opt-out still working Clock 2: from the request Request arrives 10 business days honored by here House practice: suppress on the first request, across every campaign and sending domain
    The two opt-out clocks the FTC guide states, drawn from the day a message is sent. The mechanism stays live for at least 30 days; a request is honored within 10 business days of arriving.

    The detail sits in 316.5, which prohibits a sender, or anyone acting for a sender, from requiring that a recipient pay a fee, provide any information beyond their email address and opt-out preferences, or take any step other than sending a reply email or "visiting a single Internet Web page" in order to opt out. A preference centre that demands a login, or that asks why someone is leaving before it will accept the request, sits badly against that text.

    Three more points from the FTC guide that come up constantly in outbound:

    • You may offer a menu of message types to opt out of, but the menu must include an option to stop all marketing messages from you.
    • Once someone has opted out, you may not sell or transfer their address, including as part of a list. The only exception is transferring it to a company you have hired to help you comply.
    • The guide says explicitly to make sure your own spam filter is not blocking opt-out requests. An unsubscribe reply that lands in a junk folder is still an opt-out request you received.

    Our own practice is narrower than the law requires, deliberately. We run one-click unsubscribe in every message, we suppress on the first request rather than inside a ten-day window, and a suppression list applies across every campaign and every sending domain rather than per campaign. We also send one message per campaign and never bump a thread, which removes the situation where an opt-out arrives while three follow-ups are already queued behind it.

    Who counts as the sender when an agency sends for you

    Section illustration: Who counts as the sender when an agency sends for

    This is the question every client asks, and the Act answers it in two places.

    Part 316.2(m) says that when more than one person's products, services or website are promoted in a single message, each of them is deemed a sender, with one exception: a single person can be deemed the sender if they meet the statutory definition, are identified in the "from" line as the sole sender, and comply with the initiator obligations covering deceptive transmission information, deceptive subject headings, the postal address, the opt-out mechanism and the sexually explicit labelling rule.

    The FTC guide adds the part that matters commercially. If the designated sender does not comply, all marketers in the message may be held liable as senders. And separately: "even if you hire another company to handle your email marketing, you can't contract away your legal responsibility to comply with the law". Both the company whose product is promoted and the company that originated the message may be legally responsible.

    Read that as an operating instruction rather than a legal risk to be papered over. When we run campaigns for a client, the client's identity and the client's postal address are what appear in the message, because the client is the sender in the Act's sense. The contract can allocate who pays for a mistake. It cannot move who the regulator can pursue.

    Penalties and enforcement

    The FTC enforces the Act, and its compliance guide states that "each separate email in violation of the CAN-SPAM Act is subject to penalties of up to $53,088".

    That figure is codified rather than editorial. 16 CFR 1.98 sets the FTC's inflation-adjusted civil penalty amounts and states that they "apply only to penalties assessed after January 17, 2025". Paragraph (d) puts Section 5(m)(1)(A) of the FTC Act at $53,088, and paragraph (p) routes civil penalties authorised by reference to the FTC Act under any other law within the Commission's jurisdiction back to those same amounts. The section carries the Federal Register citation 90 FR 5581, dated 17 January 2025 (eCFR, 16 CFR 1.98). That is the amount the current eCFR text carries as of this writing.

    The words that do the work are "each separate email". A 2,000-address send with a broken opt-out link is 2,000 separate violations, so exposure scales with list size, and the cheap moment to fix an opt-out link is before the send. Actual FTC outcomes are negotiated rather than multiplied.

    The guide also notes that more than one person may be held responsible, that aggravated violations can attract additional fines, and that the law provides criminal penalties including imprisonment for a specific set of behaviours: accessing someone else's computer to send spam, using false information to register multiple email accounts or domain names, relaying messages to disguise their origin, harvesting email addresses or generating them through a dictionary attack, and exploiting open relays or open proxies.

    That harvesting and dictionary-attack line is the one worth reading twice if you buy lists. The FTC guide defines a dictionary attack as "the practice of sending email to addresses made up of random letters and numbers in the hope of reaching valid ones", so the behaviour it describes is the sending, not the sourcing. Resolving a named person at a known company and confirming the address before anything goes out is a different activity, and it is the reason address verification belongs between sourcing and sending rather than after it. Our own waterfall runs MillionVerifier, then Prospeo, then Findymail, and an address that does not resolve and verify is dropped rather than mailed.

    Text messages are governed by a different rule

    Section illustration: Text messages are governed by a different rule

    Messages to wireless devices sit under a separate FCC rule, and the consent model flips. 47 CFR 64.3100 provides that no person or entity may initiate a mobile service commercial message unless they have "the express prior authorization of the addressee", with narrow exceptions, and it requires a sender to cease sending "within ten (10) days after receiving such a request". The rule takes its definition of a commercial electronic mail message straight from the statute, saying the term "means the term as defined in the CAN-SPAM Act" (eCFR, 47 CFR 64.3100). So the opt-out default that governs email does not carry across to text.

    The Australian Spam Act 2003 is a different law

    Australia has its own statute called the Spam Act 2003, and it is not a version of CAN-SPAM. Section 16 is headed "Unsolicited commercial electronic messages must not be sent" and prohibits a commercial electronic message with an Australian link unless the account holder "consented to the sending of the message", with the person relying on consent bearing "an evidential burden". Section 18 requires "a functional unsubscribe facility", and Part 3 prohibits harvested address lists (Federal Register of Legislation, Spam Act 2003). Sending into Australia, the consent question comes before the send rather than after a complaint.

    What compliant US outbound looks like in practice

    Section illustration: What compliant US outbound looks like in practice

    A real postal address in every message, matching the entity named as the sender. An honest subject line and honest headers. A clear opt-out one action deep: a reply or a single page, with no login, questionnaire or fee. Suppression that is global and immediate, so one request removes the address everywhere you send from. Addresses resolved and verified before they are mailed. One message per campaign, with no bumps and no thread replies, so nothing is queued behind an opt-out that has already arrived. And segmentation by jurisdiction before the send, because a process built for CAN-SPAM will not clear Canada, the EU, the UK or Australia.

    Every item on that list is a build-time decision. Compliance here is a property of how the sending system is configured rather than a judgment call someone makes per email, and the same choices that keep the FTC uninterested keep complaint rates low and inboxes reachable.

    Want US outbound run on infrastructure where the postal address, the opt-out and the global suppression are wired in before the first send? Get a free campaign plan and we will walk through how the compliance layer is built.

    Statutory and regulator text is taken from the sources linked above. This is an operator's summary and not legal advice. Verify current requirements, and take your own advice, before relying on it.

    Questions

    Frequently asked questions.

    Frequently asked questions
    What does the FTC's CAN-SPAM Act: A Compliance Guide for Business require?
    Seven things, in the FTC's own rundown: do not use false or misleading header information, do not use deceptive subject lines, identify the message as an ad, tell recipients where you are located with a valid physical postal address, tell them how to opt out, honor opt-out requests promptly, and monitor what others are doing on your behalf. The guide adds that each separate email in violation is subject to penalties of up to $53,088.
    Does the CAN-SPAM Act apply to B2B cold email?
    Yes. The FTC's guide states that the law makes no exception for business-to-business email and that it covers all commercial messages, defined as any email whose primary purpose is the commercial advertisement or promotion of a product or service. Cold sales email is inside that definition. What the Act does not require is prior consent, which is the opposite of Canada's CASL.
    How quickly do you have to honor a CAN-SPAM opt-out request?
    Within 10 business days, per the FTC guide, and the opt-out mechanism must keep working for at least 30 days after the message is sent. Under 16 CFR 316.5 a sender may not require a fee, any information beyond the email address and opt-out preferences, or any step other than a reply email or visiting a single web page. Once someone opts out, their address may not be sold or transferred.
    Who is liable under CAN-SPAM when an agency sends the email?
    Potentially both. The FTC guide states that even if you hire another company to handle your email marketing, you cannot contract away your legal responsibility to comply, and that both the company whose product is promoted and the company that originated the message may be legally responsible. In practice the client's identity and postal address appear in the message because the client is the sender.
    Cold EmailComplianceCAN-SPAMEmail LawB2B Sales
    Byline

    About the author.

    Ben Carden

    Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.

    Ben Carden · CRO

    Connect on LinkedIn →
    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.