Canada’s Anti-Spam Legislation (CASL) is the strictest commercial email regime in North America. It requires express or implied consent before the first message, mandates a working 60-day unsubscribe, and lets the CRTC assess up to CAD $10 million per violation against businesses and CAD $1 million against individual senders. The trigger is the recipient’s location in Canada, not the sender’s.
Canada’s Anti-Spam Legislation (CASL) · An Act to promote the efficiency and adaptability of the Canadian economy, S.C. 2010, c. 23 · In force since 1 July 2014 · Enforced by the Canadian Radio-television and Telecommunications Commission (CRTC), with the Office of the Privacy Commissioner and Competition Bureau for related conduct · Applies to every commercial electronic message (CEM) sent to a recipient in Canada, regardless of the sender’s country · Max administrative monetary penalty (AMP): CAD $10M per violation for businesses, CAD $1M for individuals · Directors and officers personally liable.
What CASL requires
Three requirements apply to every CEM. Miss any one and the message is non-compliant even if the other two are perfect.
- Prior consent. Express consent (an active opt-in you can document) or implied consent (existing business relationship within 24 months, or conspicuously published business address for a message related to that person’s role).
- Clear sender identification. Legal name of the sender or person on whose behalf the message is sent, current mailing address, and a working phone number, email address, or website URL for contact.
- Working unsubscribe. A prominent opt-out mechanism, valid for at least 60 days after the send, honored within 10 business days. No fee, no login required.
Consent: express vs implied
Who must comply
CASL applies to every commercial electronic message accessed by a computer system located in Canada, regardless of where the sender is based. A US company emailing a Canadian customer, a European SaaS pitching a Canadian prospect, and an Australian affiliate promoting to Canadian addresses are all in scope. Canadian courts have upheld this extraterritorial reach under the “real and substantial connection” doctrine.
CEMs cover far more than email. SMS, MMS, instant messages, social media direct messages, and app push notifications all qualify when the primary purpose is commercial. Vicarious liability extends to employers for employee conduct, and CASL expressly extends personal liability to corporate directors and officers.
Penalties and enforcement
CAD $10 million per violation, on the ceiling. Real-world settlements land far lower, $5,000 to $250,000 for typical SME cases through 2025, but the theoretical exposure has driven serious enforcement action. Compu-Finder was assessed $1.1M for sending CEMs without consent and with faulty unsubscribe mechanisms; Kellogg’s Canada settled for $60,000 for missing consent records; Rogers Media settled for $200,000 for CEMs to Canadian consumers without valid opt-in. The CRTC logged 152,603 spam complaints in the first six months of 2025 alone and continues an active enforcement pipeline.
Compliance checklist
- Document the consent source, timestamp, and exact language for every Canadian subscriber
- Refresh implied-consent records against the 24-month customer / 6-month inquiry clock quarterly
- Include your legal name, current mailing address, and one working contact channel in every CEM
- Provide a prominent unsubscribe link active for 60 days minimum, honored within 10 business days
- Maintain a suppression list shared across all business units, campaigns, and third-party senders
- Train staff and contractors: one rogue affiliate or salesperson can trigger corporate liability
- Audit list origin before importing purchased or referred contacts, if you cannot document consent, purge before sending
Common misconceptions
“CAN-SPAM covers us in Canada too.” No. CAN-SPAM is opt-out; CASL is opt-in. A cold email that is perfectly legal in the US is a CASL violation the moment it reaches a Canadian inbox.
“B2B is exempt.” No. CASL does not carve out business-to-business commercial messages. Cold prospecting to Canadian companies requires either express consent, a documented existing business relationship, or a conspicuously published business address paired with a role-related message.
“A conspicuously published address means anyone can email me.” No. The role-relevance requirement is strict, a marketing pitch to an accounts-payable inbox is not role-relevant. A posted do-not-contact notice also invalidates conspicuously-published-address consent.
“We deleted their email so we do not need to keep records.” No. CASL requires records of consent evidence, and the CRTC has assessed penalties on companies that could not produce documentation even when the underlying sends were arguably compliant.
Frequently asked questions
Does CASL apply to foreign senders?
Yes. CASL applies to any CEM accessed by a computer system in Canada. US, European, and other foreign companies emailing Canadian recipients must comply in full. Canadian courts have upheld the CRTC’s ability to investigate foreign senders under the “real and substantial connection” doctrine, though practical enforcement often relies on cooperation from foreign regulators.
How long does implied consent last?
Twenty-four months from the last purchase or written contract for an existing customer relationship, or six months from an inquiry or application for an existing business relationship. Both clocks reset with each qualifying transaction. Conspicuously-published-business-address consent has no expiry but requires role-relevance and no posted do-not-contact notice.
Are transactional emails exempt from CASL?
Some categories are excluded, including messages to an existing family or personal relationship, quotes or estimates requested by the recipient, transaction confirmations, warranty and safety notices, and factual information about an ongoing subscription or account. Promotional content stitched into an otherwise transactional message pulls the whole message back into CEM scope.
What triggers director and officer personal liability?
Section 31 of CASL extends liability to any director or officer who directed, authorized, assented to, acquiesced in, or participated in a violation, whether or not the corporation was proceeded against. Due diligence is a statutory defence but must be documented, policies, training records, audit trails.
Is there a private right of action under CASL?
The private right of action (PRA) originally scheduled for July 2017 was suspended indefinitely by the federal government and is not currently in force. Enforcement remains with the CRTC through administrative monetary penalties, warning letters, and compliance undertakings. The PRA remains on the statute book and could be activated by future government order.
Where to go next
- CAN-SPAM Act compliance guide, opt-out contrast with CASL’s opt-in regime for US recipients
- GDPR compliance guide, European opt-in regime with different consent standards
- Email unsubscribe laws worldwide, global overview of opt-out obligations
- Australian Spam Act 2003, comparable opt-in regime with per-day penalty structure
Sending to a Canadian list? Pre-validating recipient addresses with SMTPing before you press send catches disposables, catch-alls, and dead mailboxes that generate CASL complaints from recipients who never signed up. Thirteen validation types, twenty-five free checks daily, no card required. Try SMTPing free.
About the Author

Alaa · LinkedIn
Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.
About SMTPedia
SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.
We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.

