The CAN-SPAM Act is the US federal law that sets the rules for commercial email, including cold email, and it applies no matter how large or small the list. It requires honest sender information, a real postal address, and a working opt-out, and it does not require the recipient's consent before the first message.
This page covers what CAN-SPAM actually requires, whether it applies to B2B cold email, the seven main rules as a checklist, current penalties, and how the US approach differs from GDPR and CASL elsewhere. It sits under our guide to whether cold email is legal, which covers the UK, EU, Canada and Australia in full; this page goes deeper on the US law alone. This is a summary of public regulator guidance, not legal advice.
What is the CAN-SPAM Act, and does it cover cold email?
The CAN-SPAM Act is a 2003 US federal law, officially the Controlling the Assault of Non-Solicited Pornography and Marketing Act, that sets requirements for commercial email and gives recipients the right to stop receiving it. The Federal Trade Commission, known as the FTC, enforces the Act and publishes the CAN-SPAM Act compliance guide for business. The statute itself sits at 15 U.S.C. §§ 7701-7713.
The name is misleading on its own: despite "CAN-SPAM," the law covers every commercial email, not only bulk sends. The FTC's guide is explicit that it makes no exception for business-to-business messages.
Does CAN-SPAM apply to B2B cold email?
Yes. CAN-SPAM applies to any email whose primary purpose is commercial advertising or promotion. The FTC's guide states plainly that the law "makes no exception for business-to-business email." A cold email pitching your product to another company is a commercial message under the Act, covered the same as a consumer marketing blast.
The one narrow carve-out is for "transactional or relationship" messages, such as an order confirmation or an account update, which get lighter obligations. A cold outreach email selling something does not fall into that category, so it needs to meet every requirement below.
Is a cold email commercial content or a transactional message?
A message is commercial under CAN-SPAM when its main point is advertising or promoting a product or service, and transactional when its main point is completing or servicing a transaction the recipient already agreed to. The FTC's guide gives five narrow examples of transactional content:
| Transactional content type | Example |
|---|---|
| Completes an agreed transaction | A shipping confirmation for an order already placed |
| Gives warranty, recall or safety info | A product recall notice |
| Reports a change to an account or membership | A price change notice for an existing subscription |
| Covers an employment relationship | A benefits enrollment reminder |
| Delivers goods or services already agreed | A download link for a purchased file |
Cold outreach is not on this list. A message introducing your business to a stranger is commercial content by definition, so it needs every CAN-SPAM requirement, not the lighter transactional treatment.
What are the CAN-SPAM Act's 7 main requirements for cold email?
CAN-SPAM's main requirements, as set out in the FTC's compliance guide, cover honesty in the header and subject, a clear ad disclosure, a real address, and a working opt-out that is honored on time. Here is each one, in the order the FTC lists them:
- Don't use false or misleading header information. The "From," "To," "Reply-To" and routing information must be accurate and identify who actually sent the message.
- Don't use deceptive subject lines. The subject has to accurately reflect what is in the message.
- Identify the message as an ad. The FTC allows wide leeway in how this is done, but it must be clear and conspicuous.
- Give a valid physical postal address. A current street address, a registered PO box, or a registered private mailbox.
- Give a clear way to opt out. An easy, free mechanism that needs nothing more than an email address to use.
- Honor opt-out requests within 10 business days. The opt-out mechanism itself has to keep working for at least 30 days after the message was sent.
- Monitor what others do on your behalf. Hiring a vendor to send your email does not transfer away legal responsibility; both the company whose product is promoted and the company that sends the message can be held liable.
What does the postal address rule require in a cold email?
The physical address rule means every commercial email needs a real, checkable location for the sender, not a website or an email address alone. The FTC's guide accepts three forms:
- A current street address.
- A PO box registered with the US Postal Service.
- A private mailbox registered with a commercial mail receiving agency under USPS regulations.
A PO box or a registered private mailbox satisfies the rule exactly as well as a street address.
How fast do you have to honor a cold email opt-out under CAN-SPAM?
An opt-out request has to be honored within 10 business days of being received, and the opt-out mechanism itself must keep accepting requests for at least 30 days after the original message went out. You cannot charge a fee, demand information beyond an email address, or require more than a reply email or a single website visit to process the request. Once someone opts out, their address cannot be sold or transferred to anyone else, except to a company hired specifically to help with CAN-SPAM compliance.
Gmail and Yahoo add their own rule for bulk senders: see one-click unsubscribe.
What are the CAN-SPAM penalties for a non-compliant cold email?
Each separate email that violates CAN-SPAM carries a civil penalty of up to $53,088, and the FTC notes this figure is adjusted for inflation; the current number as published is on the FTC's compliance guide. More than one party can be held responsible for the same violation: both the company whose product is advertised and the company that actually sent the message.
Beyond civil penalties, the Act carries criminal penalties for more serious conduct, and these can include imprisonment. Covered conduct includes hacking into someone else's computer to send spam, registering domains or email accounts with false information, and harvesting addresses through a dictionary attack. Violators may also owe redress to recipients under the FTC Act, which can include the value of their lost time, not just money spent.
What does CAN-SPAM not require for cold email, compared with GDPR or CASL?
CAN-SPAM does not require the recipient's consent before you send the first email. It only requires honesty and an easy way to opt out afterward. That single difference is what separates the US approach from most other major markets:
- United States (CAN-SPAM): no consent needed first, opt-out only, after the fact.
- UK (GDPR / PECR): no consent needed for companies; sole traders and some partnerships need consent.
- EU (GDPR): usually relies on "legitimate interest" for B2B; some countries require consent.
- Canada (CASL): express or narrowly implied consent required.
- Australia (Spam Act 2003): express or inferred consent required.
If any part of your list includes contacts outside the US, the opt-out-only approach is not enough on its own. Our guide to whether cold email is legal covers the UK, EU, Canada and Australia rules in full, since each sets its own consent requirement that CAN-SPAM does not share.
Do Gmail and Yahoo require anything from cold email beyond CAN-SPAM?
Yes. Google's email sender guidelines require one-click unsubscribe from senders close to 5,000 messages or more a day to personal Gmail accounts. That means a List-Unsubscribe header plus List-Unsubscribe-Post: List-Unsubscribe=One-Click on marketing and subscribed messages, along with a clearly visible unsubscribe link in the message body. Yahoo applies a similar bulk-sender expectation without publishing an exact volume threshold. These are inbox-provider rules, not law, but failing them gets mail rejected or junked regardless of CAN-SPAM compliance.
A smaller cold email program sending well under that volume is not caught by the mandatory one-click rule. A clear, working unsubscribe link in every message is still good practice regardless of volume, and it is what CAN-SPAM requires anyway.
CAN-SPAM compliance checklist for cold email
| Requirement | What to check |
|---|---|
| Header accuracy | "From" name and domain are real and identify the actual sender |
| Subject line | Describes the message honestly, no bait-and-switch |
| Ad disclosure | Message is clearly identifiable as an ad or outreach, not disguised as something else |
| Postal address | A real street address, registered PO box, or registered private mailbox appears in the message |
| Opt-out mechanism | Free, needs only an email address, and stays working for 30+ days |
| Opt-out turnaround | Every opt-out honored within 10 business days |
| Vendor oversight | Any third party sending on your behalf is held to the same rules |
How does Pipefire handle CAN-SPAM in the cold emails it sends?
Every email Pipefire sends carries an unsubscribe option, and an unsubscribe request is honored automatically rather than needing a person to process it by hand. Each message includes a List-Unsubscribe header pointing at a one-click link, with List-Unsubscribe-Post: List-Unsubscribe=One-Click added whenever that https link is present. The sender's postal address appears in the message footer alongside the opt-out line.
Replies containing opt-out language such as "unsubscribe," "remove me" or "stop emailing" are detected automatically, in the subject or the body, across the common ways people phrase it. That detection applies even when the opt-out request arrives inside what looks like an automated reply, so a person does not have to catch it by hand. This describes what the product does; it is not a substitute for your own legal review. Our features page covers the rest of what is included.
CAN-SPAM Act cold email FAQ
Does the CAN-SPAM Act apply to B2B cold email?
Yes. The FTC's compliance guide states CAN-SPAM makes no exception for business-to-business email; any commercial message is covered regardless of who the recipient is.
Does CAN-SPAM require opt-in consent before sending a cold email?
No. CAN-SPAM only requires an opt-out mechanism that works after the message is sent, honored within 10 business days. This is the opposite of consent-first regimes like GDPR or CASL.
What is the penalty per cold email for violating the CAN-SPAM Act?
Up to $53,088 per violating email as a civil penalty, a figure the FTC adjusts for inflation, with the current number published on its compliance guide. Criminal penalties, including prison time, apply to more severe conduct like address harvesting or computer hacking.
What does CAN-SPAM require in every cold email?
Honest header and subject information, a clear ad disclosure, a real physical postal address, and a working, honored opt-out. These apply to every commercial email, cold or otherwise.
Is this cold email CAN-SPAM guide legal advice?
No. This page summarizes public FTC guidance and the statute's text for general understanding. Check current requirements with a lawyer before relying on this for compliance decisions, especially if your list includes contacts outside the US.