Answer

What is the CAN-SPAM Act?

CAN-SPAM applies to every commercial email a US company sends, including cold outbound to businesses. It is less strict than GDPR because it does not require prior consent, but every message still has to meet all seven rules.

Short answer

The CAN-SPAM Act is a 2003 US federal law that regulates commercial email, including business-to-business messages. It sets seven requirements: honest sender identification, truthful subject lines, clear advertisement labeling when applicable, a valid physical postal address, a working opt-out mechanism, honoring opt-outs within ten business days, and taking responsibility for third-party senders. The FTC enforces it with statutory per-email penalties for each violation.

Key points

What matters most.

What CAN-SPAM covers, what it does not, and the seven rules every commercial email has to pass before it goes out.

What it is

A US federal email law from 2003.

The Controlling the Assault of Non-Solicited Pornography And Marketing Act, signed into law in 2003 and enforced by the Federal Trade Commission. It governs commercial email sent to or from US recipients. The name is a backronym; the law itself is a short set of rules every sender has to pass, every send.

Who it applies to

Any commercial email, including B2B.

Unlike GDPR, CAN-SPAM does not carve out business addresses. A cold email from a sales rep to a buyer at another company is still a commercial message and still has to meet all seven requirements. Transactional and relationship messages (receipts, shipping notices, account updates) are exempt from most of the rules.

Opt-in or opt-out

Opt-out model, not consent-first.

CAN-SPAM is a notice-and-choice regime. A sender does not need prior permission to email a prospect, but every message must include a visible way to opt out, and the sender must honor that opt-out within ten business days. This is the single biggest difference from GDPR, which requires affirmative consent before the first message.

The seven rules

Honest headers, address, opt-out, timeliness.

No false or misleading headers. No deceptive subject lines. Identify ads as ads when the recipient has not opted in. Include a valid physical postal address. Provide a working opt-out mechanism. Honor opt-outs within ten business days. Monitor what others do on your behalf. Miss any one and the message is non-compliant, even if the other six are perfect.

The penalty

Statutory damages per email, per recipient.

The FTC can seek statutory penalties for each individual non-compliant message. The math scales badly: a single bad send list, measured in tens of thousands of recipients, becomes a very large exposure fast. Aggravating conduct (harvested addresses, dictionary attacks, misleading headers) raises the ceiling and opens the door to criminal liability.

Enforcement

FTC, state AGs, and ISPs.

The Federal Trade Commission is the primary enforcer. State attorneys general and internet service providers can also bring actions. The practical enforcement most senders feel first is not a government fine, it is deliverability: inbox providers downgrade reputation and start sending mail to spam long before a federal case is filed.

The seven requirements

Every commercial email has to pass all seven rules.

The CAN-SPAM Act does not read like a compliance framework. It reads like a short checklist a product manager would write. Each rule maps to a specific piece of the email itself: the from line, the subject line, the body, and the footer. Miss any one and the message is non-compliant, even if the other six are flawless. Below is the plain-language version of each rule and what it looks like in a real send.

Rule one

Honest "from" and routing information.

The From, To, Reply-To, and routing information (domain names, IP addresses) must accurately identify the person or business who sent the message. No spoofed from addresses, no routing through someone else's mail server to disguise origin, no borrowed domains that imply a relationship that does not exist.

Rule two

Truthful subject lines.

The subject line has to reflect the message content. "Re: our conversation" when there was no prior conversation is a violation. "Your invoice is attached" when the body is a cold pitch is a violation. The test is simple: would a reasonable recipient feel the subject accurately described what they opened?

Rule three

Identify the message as an ad.

If the recipient has not given prior affirmative consent, the message must disclose that it is an advertisement. The disclosure does not have to be loud, but it has to be clear and conspicuous. Transactional messages and messages to recipients who opted in are exempt from this specific rule.

Rule four

Include a valid physical postal address.

Every commercial message must include a valid physical postal address for the sender. A street address, a registered PO box, or a private mailbox at a commercial mail receiving agency all qualify. The address goes in the footer and is the one piece every legitimate marketing email has, no exceptions.

Rule five

A clear opt-out mechanism.

Every message needs a conspicuous way for the recipient to tell the sender to stop. The common pattern is an unsubscribe link in the footer, but a reply-to-opt-out instruction also qualifies. The mechanism must stay live for at least thirty days after the message was sent and cannot require the recipient to log in, pay a fee, or provide information beyond an email address.

Rule six

Honor opt-outs within ten business days.

Once a recipient opts out, the sender has ten business days to stop sending commercial messages to that address. Transferring the opted-out address to another sender for commercial use is also prohibited. The practical implementation is a suppression list the sending system checks before every send.

Rule seven

Responsibility for third-party senders.

If a company hires an agency, a reseller, or an affiliate to send on its behalf, both parties can be legally responsible for the message. A company that benefits from the send cannot blame a vendor who broke the rules. Procurement, contracts, and monitoring all have to assume shared liability.

CAN-SPAM vs GDPR

Different jurisdictions, different consent models.

The two laws come up in the same breath because both regulate email, but they operate from different starting points. CAN-SPAM is a notice-and-choice law: you can send until the recipient tells you to stop. GDPR is a consent-first law: you cannot send until the recipient tells you it is okay. A sender that targets both US and EU recipients has to meet the stricter of the two for the EU recipients, which in practice means operating the whole list under GDPR rules.

Jurisdiction

US law vs EU law.

CAN-SPAM applies to commercial email sent to or from the United States. GDPR applies to personal data of individuals in the European Union, regardless of where the sender is located. A US company emailing an EU resident is subject to GDPR for that message, even if CAN-SPAM would otherwise be the only US rule.

Consent

Opt-out vs opt-in.

CAN-SPAM lets a sender email a cold recipient first and asks only that the sender honor the opt-out afterward. GDPR requires a lawful basis before any processing of personal data, which for most marketing email means freely given, specific, informed, and unambiguous consent recorded before the first send.

B2B carve-out

None vs partial.

CAN-SPAM applies to B2B email the same way it applies to B2C. GDPR has no formal B2B carve-out either, but some EU member states (notably under the ePrivacy Directive) allow legitimate-interest sending to a business address if the content relates to the recipient's role. The practical safer path is treating B2B the same as B2C.

Penalties

Per-message vs percent-of-revenue.

CAN-SPAM penalties are calculated per non-compliant message. GDPR penalties scale with company global annual revenue and are measured in millions of euros at the top tier. A small US sender is more likely to feel CAN-SPAM. A global brand is more likely to feel GDPR.

Opt-out window

Ten days vs immediate.

CAN-SPAM gives the sender ten business days to process an opt-out. GDPR requires the sender to stop processing without undue delay once consent is withdrawn, which in practice means immediately. A compliance stack that targets both jurisdictions picks the stricter rule and applies it everywhere.

What travels well

The checklist either way.

The practical overlap is large. Clear sender identity, truthful subjects, honest content, a visible opt-out, a current suppression list, a documented physical address, and vendor contracts that pass compliance through to subcontractors satisfy both laws most of the time. The difference is where you start: with consent or without.

How a CRM enforces compliance

The four jobs a CRM has to do automatically.

Compliance is not a policy document, it is an operational rhythm. The reason senders violate CAN-SPAM is almost never intent, it is a gap between what the policy says and what the sending tool actually does on a Thursday afternoon. A modern CRM collapses that gap by making the compliant path the default path. The four jobs below are the ones that have to happen without anyone remembering to do them.

Job one

Unsubscribe link on every send.

Every email template includes an unsubscribe token the system resolves at send time, so no template can go out without it. One-click unsubscribe is the standard; the recipient clicks the link, the suppression list updates, no login or form required. The audit log records the opt-out event with a timestamp.

Job two

Suppression list, enforced at send.

The suppression list is checked at the moment of send, not at the moment of list build. A contact that opted out between the time the campaign was scheduled and the time it ships is skipped automatically. The suppression list is global across the tenant, so an opt-out from marketing also blocks the sales rep from sending the same address a sequence.

Job three

Sender name and verified domain.

Outbound email uses a verified sending domain with SPF, DKIM, and DMARC configured. The from name and from address are tied to the actual sender, not spoofed. Reply-to lands in the sender's inbox so the recipient can respond or opt out by reply. The headers do what rule one of CAN-SPAM says they have to do.

Job four

Physical address footer, every message.

The tenant's registered postal address lives in a single setting and renders into every email footer automatically. Updating the address in one place updates every template and every campaign. There is no manual copy-paste step, so no template can ship without the address, and no address change can leave old templates stale.

Supporting job

Honor the ten-day rule immediately.

A good system does not wait ten business days to process an opt-out, it processes it the moment the link is clicked. The ten-day window is a legal ceiling, not an operational target. Immediate suppression also protects deliverability, because inbox providers watch for senders who keep mailing people who tried to leave.

Supporting job

Audit log for every event.

Every opt-in, opt-out, bounce, complaint, and resend decision is recorded with a timestamp and a reason. When a regulator or an inbox provider asks why a recipient was emailed on a specific day, the answer is a database query, not a slack search. The log also makes it possible to prove third-party senders followed the same rules.

Run compliant outbound without a separate stack.

Strkr handles the CAN-SPAM mechanics for you: unsubscribe link on every send, global suppression list enforced at send time, verified sending domain, address footer baked into the template, and an audit log of every opt-in and opt-out. One tool, no bolt-on.

People also ask

Related questions.

Does CAN-SPAM apply to business-to-business email?

Yes. CAN-SPAM makes no distinction between personal and business email addresses. A cold outbound message from one business to another is a commercial message under the law and must meet all seven requirements, including the physical address footer and the working opt-out mechanism. This is a common blind spot for sales teams running cold-email sequences.

What is the difference between a transactional and a commercial email under CAN-SPAM?

A commercial email has the primary purpose of advertising or promoting a product or service. A transactional or relationship email facilitates an agreed-upon transaction or updates a customer about an existing relationship (receipts, shipping notices, account statements, warranty information). Transactional messages are exempt from most CAN-SPAM rules but still cannot have false or misleading header information.

How long does a sender have to honor an opt-out?

Ten business days. The law requires senders to stop sending commercial email to a recipient within ten business days of the opt-out request. Modern compliance tooling honors opt-outs immediately rather than waiting, because immediate suppression is both legally safer and better for inbox deliverability.

What are the penalties for violating CAN-SPAM?

The Federal Trade Commission can seek statutory penalties for each individual non-compliant email, which scales quickly across large send lists. Aggravating conduct like address harvesting, dictionary attacks, and open-relay abuse can increase the penalty ceiling and expose senders to criminal liability. State attorneys general and internet service providers can also bring their own actions.

How is CAN-SPAM different from GDPR?

CAN-SPAM is a US law that uses an opt-out model: a sender can email a cold recipient first and must honor the opt-out afterward. GDPR is an EU law that uses an opt-in model: a sender needs a lawful basis (usually documented consent) before the first send. GDPR penalties scale with global revenue and are substantially larger than CAN-SPAM penalties. Companies with EU recipients must meet GDPR for those recipients.

Does CAN-SPAM apply to SMS or just email?

CAN-SPAM covers commercial email, including email-to-text (SMS messages delivered through an email gateway). Standard mobile-to-mobile SMS and MMS are governed by the Telephone Consumer Protection Act (TCPA) instead, which has its own stricter consent and opt-out rules. A sender running both channels needs a compliance plan for each.

Who is responsible when an agency sends email on a company's behalf?

Both parties can be legally responsible. CAN-SPAM makes the company that benefits from the message as well as the sender who actually transmitted it liable for compliance. A vendor contract that disclaims responsibility does not remove the underlying legal exposure. Procurement teams should verify sending practices and keep audit rights on third-party senders.

What does a compliant CAN-SPAM email look like?

A compliant message has a from line that identifies the real sender, a subject line that honestly describes the content, a visible disclosure that it is an advertisement when the recipient has not opted in, a working one-click or reply-to opt-out, and a valid physical postal address in the footer. The sender also maintains a suppression list and processes opt-outs promptly.

Try it free. Bring your team next week.

No sales call, no migration consultant, no four-month implementation. Enter your card, get 14 days of the full Pro tier, cancel any time before day 14 with zero charge. Spin up a workspace, import your CSV, and have something useful before lunch.