The CAN-SPAM Act is the main US federal law governing commercial email. It applies to more than bulk spam: a single promotional email, including a business-to-business message, can fall under the law. Senders must use accurate routing information and non-deceptive subject lines, identify advertising clearly, include a valid postal address, provide a working opt-out method, and honor unsubscribe requests on time.
Key takeaways
- The CAN-SPAM Act regulates commercial emails in the US, covering single promotional emails, requiring accurate routing information, non-deceptive subject lines, clear advertising identification, valid postal addresses, working opt-out methods, and timely unsubscribe request handling.
- CAN-SPAM applies to all commercial emails, not just bulk spam, including business-to-business messages.
- The Act generally follows an opt-out model, not requiring prior permission for commercial emails.
What is the CAN-SPAM Act?
The Controlling the Assault of Non-Solicited Pornography and Marketing Act, better known as CAN-SPAM, became law in 2003 and took effect in 2004. It establishes rules for commercial email, gives recipients the right to stop future marketing messages, and authorizes enforcement and penalties for violations.
Despite the name, CAN-SPAM does not apply only to unsolicited bulk email. It covers any email whose primary purpose is the commercial advertisement or promotion of a product or service, including content on a commercial website. There is no general business-to-business exception.
CAN-SPAM generally follows an opt-out model, not an opt-in model. The federal law does not ordinarily require prior permission before a business sends a commercial email. Consent may still be required by another law, a platform policy, an industry rule, or the law of the recipient’s jurisdiction. Permission-based lists also remain the safer marketing practice.
Which emails does CAN-SPAM cover?
Classification depends on the message’s primary purpose. The CAN-SPAM Rule and FTC guidance distinguish commercial content, transactional or relationship content, and other content.
Commercial messages
A message is commercial when its primary purpose is advertising or promoting a commercial product or service. These messages must follow the full CAN-SPAM requirements even if they go to one recipient or another business.
Transactional or relationship messages
A message may be transactional or relationship content when it completes or confirms an agreed transaction, provides warranty, recall, safety, or security information, reports changes to an account or ongoing relationship, gives employment or employee-benefit information, or delivers goods or services already agreed to. These messages remain subject to the rule against false or misleading routing information but are exempt from most commercial-message requirements.
Mixed-content messages
When an email mixes commercial and transactional content, the subject line and placement of the content matter. If the subject suggests a promotion, or the commercial material appears first while the transactional information is secondary, the message is likely commercial. Put the genuine transactional purpose first and do not disguise a promotion as an account notice.
CAN-SPAM requirements for commercial email
Use this checklist for every commercial campaign sent to US recipients. It summarizes the core duties in the CAN-SPAM Rule, 16 CFR Part 316, and FTC business guidance.
Use accurate header information
The From, To, Reply-To, originating domain, email address, and routing information must be accurate and identify the person or business that initiated the message. Do not hide the real sender behind a misleading display name or domain.
Use a subject line that matches the email
The subject line must accurately reflect the content. Avoid fake reply or forward prefixes, false urgency, or promises that the message does not fulfill. A promotional email can be persuasive without misrepresenting what the recipient will find inside.
A compliant subject line sets an accurate expectation. The example below describes the collection being promoted instead of pretending the message is a personal reply or guaranteed prize.
Identify advertising clearly
Commercial email must disclose clearly and conspicuously that it is an advertisement. The law allows flexibility in the wording and placement, so a literal “Ad” label is not the only possible approach. The disclosure should still be easy for an ordinary recipient to notice and understand.
Include a valid physical postal address
Every commercial message must include the sender’s valid physical postal address. FTC guidance permits a current street address, a post office box registered with the US Postal Service, or a private mailbox registered with a commercial mail receiving agency established under Postal Service regulations.
Provide a clear way to opt out
Explain clearly and conspicuously how the recipient can stop future marketing messages. You may offer preference options, but you must also provide a way to stop all marketing email from the sender. Make sure spam filters and other systems do not block opt-out requests.
Honor opt-out requests within 10 business days
The opt-out mechanism must be able to process requests for at least 30 days after the message is sent, and the sender must honor a request within 10 business days. You cannot charge a fee, demand personal information beyond the email address, or require more than a reply email or a visit to a single web page. After a person opts out, their address generally cannot be sold or transferred except to a vendor hired to help you comply.
Monitor vendors and partners
You cannot contract away responsibility by hiring another company to send campaigns. Both the company whose product is promoted and the company that sends the message may be held responsible. Establish approval, suppression-list, recordkeeping, and audit procedures with every vendor that sends on your behalf.
CAN-SPAM vs. other email laws
CAN-SPAM is a US federal rule and is comparatively permissive because it generally allows commercial email until a recipient opts out. That does not make it a universal standard for international campaigns.
- Canada: Canada’s Anti-Spam Legislation generally relies on consent, identification, and unsubscribe requirements for commercial electronic messages, subject to defined exceptions.
- European recipients: GDPR governs the processing of personal data, while electronic-marketing rules also depend on the EU ePrivacy framework and national implementation. GDPR alone is not a complete email-marketing rulebook.
- Cross-border campaigns: Identify where recipients are located and apply the relevant jurisdiction’s rules. When requirements differ, permission-based sending and clear records provide a more defensible operating standard.
For a broader overview, see Selzy’s guides to email compliance and GDPR in email marketing.
CAN-SPAM pre-send compliance checklist
- Classify the message as commercial, transactional/relationship, mixed, or other content.
- Verify the sender name, domain, Reply-To address, and routing information.
- Check that the subject line accurately represents the email.
- Make the advertising nature clear and conspicuous when the message is commercial.
- Include the correct physical postal address.
- Display a clear, working opt-out method and a stop-all option.
- Test the unsubscribe route before sending and keep it working for at least 30 days.
- Process requests within 10 business days and suppress opted-out addresses from future marketing.
- Confirm vendors use the same suppression data and compliance procedures.
- Keep campaign, consent, suppression, and vendor records appropriate to your risk and jurisdiction.
CAN-SPAM penalties and enforcement
The FTC states that each separate email violating CAN-SPAM may be subject to civil penalties of up to $53,088. Civil penalty maximums can be adjusted for inflation, so verify the current figure in FTC guidance before relying on it for a legal or financial decision.
Federal enforcement
The FTC enforces CAN-SPAM for most businesses, while other federal agencies may enforce it for organizations within their jurisdiction. The Department of Justice may pursue criminal cases involving aggravated conduct such as unauthorized access to send spam, deceptive account or domain registration, address harvesting, dictionary attacks, or misuse of open relays and proxies.
State and internet service provider actions
State attorneys general may bring actions for specified violations. Providers of internet access service may also have a limited private right of action when they are adversely affected. Ordinary individual recipients generally do not receive a broad private right to sue under CAN-SPAM.
More than one party may be responsible for the same campaign, and misleading product claims can also trigger other consumer-protection laws. Treat the per-email maximum as a warning about scale, not as a prediction of the amount in a particular case.
Conclusion
CAN-SPAM compliance starts with correctly classifying the message and continues through sender identity, subject-line accuracy, ad disclosure, postal-address information, opt-out design, suppression processing, and vendor oversight. The law does not generally require prior consent for US commercial email, but permission-based marketing is usually better for trust, deliverability, and cross-border compliance.
Use the checklist before every campaign, document how opt-outs are processed, and review official guidance when penalty figures or operational rules change. This article is general information, not legal advice.
CAN-SPAM Act FAQ
What did the CAN-SPAM Act do?
The CAN-SPAM Act became law in 2003 and took effect in 2004. It set rules for commercial email, gave recipients the right to stop future marketing messages, and authorized enforcement and penalties for violations.
Does CAN-SPAM require permission before sending marketing emails?
Generally, no. CAN-SPAM follows an opt-out model rather than an opt-in model, so prior permission is not ordinarily required under federal law before sending a commercial email. Other laws, platform policies, industry rules, or the recipient’s local law may still require consent.
What emails must comply with the CAN-SPAM Act?
Any email whose primary purpose is advertising or promoting a commercial product or service must comply, even if it is sent to one recipient or to another business. Transactional or relationship emails are mostly exempt, but they still cannot use false or misleading routing information. When an email mixes commercial and transactional content, the overall purpose and the placement of the promotional material matter.
How quickly must a business honor an unsubscribe request?
Unsubscribe requests must be honored within 10 business days. The opt-out method must also keep processing requests for at least 30 days after the email is sent.
Who enforces the CAN-SPAM Act?
The FTC enforces CAN-SPAM for most businesses. Other federal agencies may enforce it within their jurisdictions, and state attorneys general may bring specified actions. Adversely affected internet access service providers have a limited private right of action, while ordinary recipients generally do not have a broad private right to sue.






