The CAN-SPAM Act sets baseline rules for every commercial email sent to or from the United States. Truthful headers, a clear opt-out, a physical postal address, and no deception in the subject line. Miss any of them and the FTC can pursue up to $53,088 per non-compliant email under Section 5 of the FTC Act, with parallel state and ISP causes of action layered on top.
CAN-SPAM Act · Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 · 15 U.S.C. §§ 7701-7713 · Enforced by the FTC, with state Attorneys General and ISPs as parallel plaintiffs · Applies to commercial email sent to or from US recipients, including B2B and foreign senders · Max civil penalty $53,088 per email (FTC 2025 inflation adjustment; no 2026 change per OMB Memo M-26-11) · Aggravated criminal cases: up to $6M and 5 years imprisonment under 18 U.S.C. § 1037.
What CAN-SPAM requires
The FTC codifies seven obligations that apply to every commercial email:
- Truthful From, To, and routing headers. The sender domain, IP, reply-to, and From name must accurately identify the actual sender.
- No deceptive subject line. The subject must reflect the content of the message.
- Clear advertising identification. The recipient must be able to tell the message is an advertisement.
- Valid physical postal address. A current postal address, PO box, or Commercial Mail Receiving Agency address in every message.
- Clear opt-out mechanism. Working for at least 30 days after the send.
- Prompt honoring of opt-outs. Within 10 business days. No fee, no information required beyond the email address, no multi-step forms.
- Third-party accountability. If a marketing agency, affiliate, or ESP sends on your behalf, both parties can be held liable.
Who must comply
CAN-SPAM applies to any commercial email, a message whose primary purpose is commercial advertisement or promotion of a product or service, sent to or from a US recipient. That includes B2B email (the FTC has been explicit on this since 2005) and foreign senders whose messages reach US recipients. Transactional and relationship messages (order confirmations, account notifications, service alerts, receipt-of-purchase updates) are exempt from most requirements but still must carry accurate header information.
Both the initiator and the sender share liability. If you outsource sending to an ESP or affiliate network, the FTC can pursue both parties for the same violations. Contractual disclaimers between them do not extinguish either party’s exposure to the FTC.
Penalties and enforcement
Per-email liability. The FTC assesses civil penalties at up to $53,088 per individual email, not per campaign. A 100,000-recipient send that fails a single requirement has a theoretical exposure of over $5 billion. Settlements typically land far below the ceiling, Verkada paid $2.95M for disguising marketing emails as transactional, Experian paid $650,000 for similar violations, but the per-email structure gives the FTC leverage in every negotiation. Aggravated criminal cases (address harvesting, dictionary attacks, or falsifying header information) carry up to $6M in fines and 5 years imprisonment under 18 U.S.C. § 1037.
Compliance checklist
Common misconceptions
B2B is not exempt. CAN-SPAM applies to every commercial email including business-to-business marketing. The FTC has stated this explicitly since 2005. Sending cold outreach to work addresses does not remove any compliance obligation.
Transactional does not mean any email to a customer. Order confirmations, account updates, and service alerts qualify. A newsletter or promotional message to existing customers is commercial and must comply in full.
Consent is not required to start sending. Unlike CASL and GDPR, CAN-SPAM operates on an opt-out model rather than opt-in. Compliance means recipients can leave the list, not that they consented to join it.
Frequently asked questions
Does CAN-SPAM apply to cold outreach and B2B email?
Yes. The FTC’s official guidance is that CAN-SPAM makes no exception for business-to-business email. Every commercial email sent to or from a US recipient must satisfy all seven requirements, whether the recipient is a personal or work address.
Are foreign senders subject to CAN-SPAM?
Yes when the message reaches a US recipient. The FTC has pursued cases against foreign senders including affiliate networks based in Europe and Asia. Using a US-based ESP does not shift the compliance burden away from the initiator.
Can I add promotional content to a transactional email?
Only if the primary purpose remains transactional. The FTC uses a primary-purpose test: if the transactional content dominates the message (subject line, first screen, main body) the message stays transactional. If the promotional content dominates, the entire message is commercial and must comply in full. The Experian $650,000 settlement turned on exactly this distinction.
Is a link to an unsubscribe preference center enough?
Yes provided the preference center accepts opt-out with no more than one additional step, requires no login, and does not ask for information beyond the email address. Preference centers that require account creation, force users through multiple opt-out categories, or fail to include a global opt-out have all generated FTC enforcement.
How does CAN-SPAM interact with state laws like California CCPA or Colorado CPA?
CAN-SPAM preempts state statutes that would impose different or additional requirements for commercial email specifically. It does not preempt broader privacy statutes like CCPA that regulate data collection and sharing. State AGs retain enforcement authority under CAN-SPAM itself and can bring parallel actions alongside the FTC.
Where to go next
- CASL Canada compliance guide, opt-in model contrast with CAN-SPAM opt-out
- GDPR compliance guide, EU rules for senders reaching European recipients
- Email unsubscribe laws worldwide, global overview of opt-out obligations
- Australian Spam Act 2003, opt-in regime with per-day AUD 2.22M penalty ceiling
Pre-validating your list before you press send catches disposables, catch-alls, and dead mailboxes that generate CAN-SPAM opt-out complaints from recipients who never signed up. SMTPing gives you thirteen validation types with twenty-five free checks daily, no card required. Try SMTPing free.
About the Author

Alaa · LinkedIn
Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.
About SMTPedia
SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.
We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.

