
What law covers unsolicited emails?
Key Facts
- The CAN-SPAM Act of 2003 is the primary U.S. federal law governing unsolicited commercial email, enforced by the FTC with rules at 16 CFR Part 316 per the Federal Trade Commission
- CAN-SPAM uses an opt-out model — no prior consent required — unlike GDPR or Canada's CASL which require consent before sending according to compliance guidance
- Each violating email can carry penalties up to $53,088 (inflation-adjusted effective January 2025), with a 1,000-email non-compliant campaign theoretically exceeding $53 million per UnsubCentral's breakdown
- The FTC extracted a record $2.95 million penalty from Verkada for emails with no opt-out mechanism, no postal address, and ignored unsubscribe requests per compliance reporting
- 33 states have their own commercial email laws, and Washington's 2025 Brown v. Old Navy ruling triggered eight class actions in six months over 'false urgency' subject lines per legal analysis
- Spam complaint rates above 0.3% trigger filtering or blocks from Gmail and Yahoo, silently killing deliverability for legitimate messages per deliverability research
- Canada's CASL requires express or implied consent before the first send and carries penalties up to $10 million per violation — far stricter than CAN-SPAM per international compliance guidance
The Law You're Actually Up Against
If you've ever sent a cold email to a potential customer and wondered whether it was legal, the answer lives in one place: the CAN-SPAM Act of 2003. According to the Federal Trade Commission, this is the primary federal law governing unsolicited commercial email in the United States, with its implementing rules codified at 16 CFR Part 316.
The first thing to understand is that CAN-SPAM runs on an opt-out model, not opt-in. Unlike Europe's GDPR or Canada's CASL, it does not require prior consent before you hit send. As compliance guidance from UnsubCentral explains, businesses may legally email prospects until the recipient unsubscribes — which means cold outreach is permitted, provided you follow the rules.
Those rules are non-negotiable, and they apply to every commercial message you send:
- Honest headers: Your "From" and "Reply-To" fields must accurately identify who is sending the message.
- Truthful subject lines: No deceptive or misleading subject lines — a requirement that's become a legal flashpoint, as recent class action reporting shows.
- Clear commercial identification: The message must be identified as an advertisement or commercial communication.
- A valid physical postal address: A street address, P.O. Box, or registered private mailbox all qualify.
- A working unsubscribe mechanism: Opt-outs must be honored within 10 business days, and the mechanism must stay functional for at least 30 days after sending.
Here's what catches many businesses off guard: there is no B2B exemption and no volume threshold. As analysis of B2B email compliance confirms, CAN-SPAM covers all commercial email — a single one-off prospecting message, a nurture sequence, a follow-up after a form fill. If the primary purpose is commercial, the rules apply.
The stakes are real. Each violating email can carry penalties of up to $53,088 (the inflation-adjusted figure effective January 2025, per UnsubCentral's breakdown; some sources cite the earlier $50,120 figure). Enforcement isn't theoretical either — the FTC extracted a record $2.95 million penalty from Verkada for sending emails with no opt-out mechanism, no postal address, and ignored unsubscribe requests.
There's also a practical angle beyond the fines. Compliance and deliverability are linked — deliverability research shows spam complaint rates above 0.3% trigger filtering or blocks from Gmail and Yahoo, so sloppy email practices can quietly kill your ability to reach anyone at all.
For businesses running automated lead follow-up, this is where process matters. Every nurture email in a sequence needs the same disclosures and instant opt-out handling as a manual send — which is why CallMyLeads builds immediate, automatic opt-out honoring into its follow-up system rather than treating compliance as an afterthought.
What Non-Compliance Costs: Penalties and Enforcement
A single non-compliant email can now cost more than most small businesses spend on marketing in a year — and the FTC has already proven it will collect.
Under the CAN-SPAM Act, penalties are inflation-adjusted annually, and as of January 17, 2025, the maximum fine sits at $53,088 per violating email. Some sources still cite the older $50,120 figure, but the dated, adjusted amount is the one to plan around.
The critical detail most businesses miss: each individual message counts as a separate violation. A 1,000-email nurture campaign with a broken unsubscribe link isn't one mistake — it's a thousand violations, with theoretical exposure exceeding $53 million. One-off lead-response emails count too, since CAN-SPAM covers all commercial email with no B2B exemption.
Enforcement is real, not theoretical. Two FTC actions show how quickly violations add up:
- Verkada — $2.95 million. The record CAN-SPAM penalty, imposed for sending commercial email with no opt-out mechanism, no physical postal address, and ignored unsubscribe requests, according to compliance reporting on the case.
- Experian — $650,000. Fined for failing to provide any opt-out mechanism at all in its marketing messages.
- Third-party senders don't shield you. Brands can be held liable for non-compliant emails sent by agencies, affiliates, or vendors on their behalf.
Liability also extends beyond the FTC. With 33 states enforcing their own email laws and class actions multiplying after Washington's Brown v. Old Navy ruling, a misleading subject line can trigger private lawsuits even where federal regulators never get involved.
Then there's the quieter cost: deliverability. Email compliance research shows bounce rates above 2% damage sender reputation, and spam complaint rates above 0.3% trigger filtering or outright blocks from Gmail and Yahoo. Once mailbox providers flag your domain, even your legitimate messages — appointment confirmations, quote follow-ups, booking reminders — start landing in spam.
For businesses that depend on email to respond to and nurture leads, that turns compliance into a revenue-protection issue. A blocked domain means paid leads never see your reply, and the fastest follow-up in the world is worthless if it never reaches the inbox. This is why done-for-you lead response systems like CallMyLeads build opt-out handling and consent capture directly into every nurture sequence — opt-outs are honored immediately and automatically, keeping complaint rates low and sender reputation intact.
The math is straightforward. Compliance costs almost nothing: honest subject lines, a postal address, a working unsubscribe. Non-compliance costs up to $53,088 per message, plus the silent loss of every lead your emails no longer reach.
The State-Law Trap: Why Federal Compliance Isn't Enough
Passing your CAN-SPAM checklist used to mean you were done. In 2025, that assumption started costing major retailers real money — because federal law is only half the story.
According to legal analysis of recent state anti-spam litigation, 33 states now have their own commercial email or spam-specific laws on the books. Most sat dormant for years. Then, in April 2025, the Washington State Supreme Court changed the math.
In Brown v. Old Navy LLC, the court held that Washington's Commercial Electronic Mail Act (CEMA) applies to any false or misleading information in a subject line — not just the narrow technical deceptions federal law targets. That interpretation opened the door to claims over marketing language most compliance teams never flagged.
The response was immediate. Eight putative class actions were filed within six months of the decision, targeting retailers including Macy's, Discount Tire, Skechers, Nike, and Ulta Beauty. The common thread: "false urgency" subject lines — phrases like "ends tomorrow" when the promotion kept running.
CAN-SPAM does preempt state email laws — but with a critical carve-out. Under 15 U.S.C. § 7707, preemption does not apply to state laws that prohibit falsity or deception in any portion of a commercial email. Whether a subject line like "ends tomorrow" counts as actionable deception or harmless puffery is now the central unresolved question in email law.
Courts have historically split on this. The 4th and 9th Circuits read the exception narrowly, while later decisions suggest materially deceptive practices survive preemption. Critically, no court has yet ruled on CEMA preemption since Old Navy — meaning every business sending promotional email is operating in legal gray space.
The practical takeaway: subject-line honesty is now a state-law compliance requirement, not a copywriting best practice. Teams running automated follow-up and nurture sequences should audit for:
- Urgency claims ("ends tonight," "last chance") that don't match the actual offer window
- Discount language implying scarcity when promotions routinely renew
- Subject lines that promise content the email body doesn't deliver
- Vendor or affiliate emails sent on your behalf — brands can be held liable for third-party sends
The stakes compound with federal exposure. With CAN-SPAM penalties reaching $53,088 per violating email as of January 2025, a single non-compliant campaign layered with state class action risk can turn a marketing shortcut into a seven-figure problem. And because CAN-SPAM covers all commercial email with no B2B exemption, even one-off lead-response messages fall within scope.
This is one reason done-for-you lead response systems matter: when follow-up emails run automatically, the copy rules baked into them carry real legal weight. At CallMyLeads, nurture sequences honor opt-outs immediately and keep messaging consistent with what a business actually offers — because in the post-Old Navy landscape, "we'll only email you about real availability" isn't just good manners. It's a compliance position.
Third-Party Liability and the Done-for-You Risk
You can follow every CAN-SPAM rule to the letter and still face enforcement if the vendor sending email on your behalf doesn't. The FTC has made clear that brands are liable for non-compliant messages sent by affiliates, agencies, or done-for-you providers acting on their behalf — a point directly relevant to any business using an outsourced response system. The UnsubCentral compliance guide and Usercentrics analysis both confirm this third-party liability standard, meaning your compliance posture is only as strong as your vendor's weakest link.
A practical vendor-vetting checklist keeps exposure in check. Confirm the provider honors opt-outs immediately — not within the 10-business-day window CAN-SPAM allows, but instantly — and that every message includes a valid physical postal address as the law requires. Subject lines must be honest; the Washington Supreme Court's Old Navy ruling triggered eight class actions in six months against retailers using "false urgency" language like "ends tomorrow" when promotions continued. Complaint rates should stay below 0.3% to avoid Gmail and Yahoo filtering thresholds that deliverability research identifies as the de facto block line.
- Opt-outs processed instantly, not just within the legal minimum
- Valid physical address in every commercial message
- Subject lines free of false urgency or deceptive claims
- Spam complaint rates maintained below 0.3%
- A2P 10DLC registration for any SMS channel tied to the same outreach
CallMyLeads built its done-for-you system around these requirements from day one — instant opt-out handling, A2P 10DLC registration, and spam screening that keeps complaint rates near zero. When your leads get a response in seconds, the compliance infrastructure behind that speed is what keeps the entire program defensible.
Cross-Border Compliance: CASL Exposure for Canadian Operations
If your business operates in Canada — or sends email from Canadian soil — CAN-SPAM compliance alone won't protect you. Canada's anti-spam legislation flips the American model on its head, and the penalties reflect that.
Canada's Anti-Spam Legislation (CASL) is among the strictest email laws in the world. Where CAN-SPAM lets you send commercial email until someone opts out, CASL requires express or narrowly-defined implied consent before the first send. According to compliance research comparing global email laws, corporations face penalties of up to $10 million per violation under CASL — a figure that dwarfs even CAN-SPAM's inflation-adjusted $53,088 per email.
Implied consent has a hard expiry date. A prior transaction creates implied consent, but only for two years. After that window closes, you need express consent or the emails stop. Compare that to the U.S. model, where no prior relationship is required at all.
CASL also tightens the unsubscribe rules. While CAN-SPAM requires an opt-out mechanism to function for at least 30 days after sending, international cold email guidance notes that CASL requires unsubscribe links to work for at least 60 days — double the American standard.
For a Halifax-based company serving U.S. clients, this creates a dual-compliance reality. The practical approach:
- Segment Canadian-sourced sends under CASL rules — express or valid implied consent before any message goes out
- Track the two-year implied-consent clock on every Canadian contact with a prior transaction
- Keep unsubscribe mechanisms functional for at least 60 days on CASL-governed sends
- Maintain full CAN-SPAM compliance for U.S. recipients — accurate headers, honest subject lines, postal address, opt-outs honored within 10 business days
This is exactly the environment CallMyLeads operates in from Halifax, Nova Scotia. When follow-up emails run automatically as part of lead nurture, the segmentation between CASL-governed and CAN-SPAM-governed sends has to be built into the system — not bolted on after a complaint arrives.
The stakes justify the effort. A single non-compliant campaign under CASL can reach eight figures in exposure, and enforcement analysis shows regulators on both sides of the border actively pursue violations. The safest posture is simple: treat consent as the default everywhere, and let the stricter law set your floor.
Frequently Asked Questions
What law actually covers unsolicited emails in the US?
Is it legal to send cold emails to people who never opted in?
What are the main requirements to comply with CAN-SPAM?
How much can you actually be fined for violating CAN-SPAM?
Does CAN-SPAM protect me from state anti-spam lawsuits?
Am I liable if my agency or vendor sends non-compliant emails for me?
The Law Is the Floor — Your Follow-Up Has to Clear It
So here's where you land: the CAN-SPAM Act of 2003 governs unsolicited commercial email in the U.S., and it applies to every commercial message — even a single lead-response email — with no B2B exemption and fines up to $53,088 per violating message. But federal compliance is only the floor. Thirty-three states have their own email laws, the Washington Supreme Court's Old Navy ruling has already triggered eight class actions over "false urgency" subject lines, brands can be liable for what vendors send on their behalf, and Canada's CASL requires consent before the first send with penalties up to $10 million. Meanwhile, spam complaints above 0.3% get you filtered by Gmail and Yahoo — meaning even compliant emails stop reaching anyone. The takeaway is simple: audit your subject lines for honest claims, confirm every unsubscribe is honored instantly, and vet any provider sending on your behalf. When follow-up runs automatically, compliance has to be built in, not bolted on. That's how CallMyLeads approaches it — opt-outs honored immediately, honest messaging, and every lead answered in seconds. Want to see what that looks like on your lead flow? Book a free ~15-minute scoping call at callmyleads.app.