Mailfois
Guides / US email marketing law
Guide

US email marketing law: the CAN-SPAM Act

US senders play by a very different rulebook to the UK. Here's what the CAN-SPAM Act actually requires — in plain English — plus how it compares to opt-in regimes and what it costs to get wrong.

Not legal advice. This is a general, plain-English overview for US email marketers, current as of 2026. It isn't legal advice and doesn't cover every situation. For the authoritative rules, see the FTC's CAN-SPAM compliance guide or take professional advice.

One federal law — and it's opt-out

Commercial email in the US is governed mainly by the CAN-SPAM Act of 2003, enforced by the Federal Trade Commission (FTC). The single biggest thing to understand — especially if you've read about UK or EU rules — is that CAN-SPAM is opt-out, not opt-in. You do not need a person's prior consent to send them a commercial email. What you do need is to be honest about who you are, tell people where you're based, and give them an easy, working way to stop hearing from you. The law sets a floor for honesty, not a permission gate.

The seven rules that matter

The FTC boils CAN-SPAM down to a short list. Every commercial email you send should satisfy all of these:

  • Don't use false or misleading header information. Your "From", "To", "Reply-To" and routing information must accurately identify who sent the message.
  • Don't use deceptive subject lines. The subject must reflect the actual content of the message — no bait-and-switch.
  • Disclose that the message is an ad. You have latitude in how, but if the email is an advertisement you must make that clear and conspicuous.
  • Include your valid physical postal address. A current street address, a registered PO box, or a private mailbox registered with a commercial mail-receiving agency all qualify.
  • Give a clear way to opt out. Every message needs an obvious, easy-to-understand way to decline future email.
  • Honor opt-outs promptly. Process requests within 10 business days. The opt-out link must keep working for at least 30 days after you send, and you can't charge a fee, ask for anything more than an email address, or make people take more than one step.
  • Stay responsible for what others do for you. If you hire an agency or tool to handle your email, both you and they can be held legally responsible — you can't outsource the liability.

Consent isn't required — but it's still smart

Because CAN-SPAM doesn't demand prior consent, cold commercial email to US recipients is lawful in a way it usually isn't in the UK. But "legal" and "effective" aren't the same thing. Mailbox providers like Gmail and Outlook judge you on engagement, complaints and spam-trap hits, not on the letter of CAN-SPAM. Sending to people who never asked to hear from you is the fastest way to wreck your deliverability, however compliant the footer is. Permission-based lists remain the right call — the law is a floor, not a strategy.

Transactional email is treated differently

CAN-SPAM distinguishes commercial messages (whose primary purpose is to advertise or promote) from transactional or relationship messages (order confirmations, receipts, account notices, warranty information). Transactional messages are exempt from most CAN-SPAM requirements — but they still can't contain false or misleading header information. If an email mixes the two, its "primary purpose" decides which rules apply, so don't smuggle a promotion into a receipt.

State laws layer on top

CAN-SPAM largely pre-empts conflicting state spam statutes, but it doesn't wipe the slate clean. States can still regulate falsity and deception, and several — California among them — have their own email and broader privacy rules (the CCPA/CPRA, for instance) that affect how you collect and handle personal data. Federal compliance is the baseline; if you have customers in specific states, check whether their rules add anything.

The penalties are per email

This is what makes CAN-SPAM bite. Each separate email in violation of the Act can carry a civil penalty of up to $53,088 — the FTC's inflation-adjusted maximum, effective January 2025. Because it's assessed per message rather than per campaign, a single non-compliant send to a large list is, in theory, multiplied by every address. In practice the FTC negotiates settlements against the conduct and the company's size rather than chasing the theoretical maximum, but the exposure is real. Aggravated practices — harvesting addresses, dictionary attacks, using open relays — increase liability, and the most egregious conduct can bring criminal penalties.

A practical CAN-SPAM checklist

  • Use accurate From, Reply-To and routing details, and a subject line that matches the content.
  • Put a valid physical postal address in every commercial email.
  • Include a clear, one-step unsubscribe and keep it working for at least 30 days after sending.
  • Process every opt-out within 10 business days, with no fee and no hoops.
  • Make sure any vendor or agency sending on your behalf is compliant too.
  • Prefer permission-based lists and keep them clean — it's what actually protects your inbox placement.

Good list hygiene is deliverability as much as compliance. Because the Mailfois list cleaner runs entirely in your browser, your subscriber data never leaves your device. And the spam checker flags a missing unsubscribe as part of its content review.

Frequently asked questions

Do I need consent to send marketing emails in the US?

No — CAN-SPAM is opt-out, not opt-in. You don't need prior consent, but you must identify yourself, include a physical address, and give a working opt-out you honor promptly. Permission-based sending is still strongly recommended for deliverability.

What are the main CAN-SPAM rules?

Accurate headers, honest subject lines, a disclosure that the message is an ad, your physical postal address, a clear opt-out, honoring opt-outs within 10 business days, and staying responsible for third parties.

How quickly must I honor an unsubscribe?

Within 10 business days. The opt-out mechanism must work for at least 30 days after sending, at no cost and in no more than one step.

What are the penalties?

Up to $53,088 per email (FTC figure, effective January 2025), assessed per message — so totals add up quickly.

Compliance and craft go together. Work through the pre-send checklist, or run the whole email through the Mailfois pre-send checker.

Everything you check before you send.

Open the pre-send checker
Mailfois
Website by LiamMail