Email marketing

What Is the CAN-SPAM Act? Requirements and Compliance Guide

CAN-SPAM Act cover with an envelope, legal documents, and a green approval check
Irene Dmitrieva
Irene Dmitrieva AI-free content
Updated: 22 July, 2026 / 1705 / 00 min

The CAN-SPAM Act is the main US federal law governing commercial email. It applies to more than bulk spam: a single promotional email, including a business-to-business message, can fall under the law. Senders must use accurate routing information and non-deceptive subject lines, identify advertising clearly, include a valid postal address, provide a working opt-out method, and honor unsubscribe requests on time.

Key takeaways

  • The CAN-SPAM Act regulates commercial emails in the US, covering single promotional emails, requiring accurate routing information, non-deceptive subject lines, clear advertising identification, valid postal addresses, working opt-out methods, and timely unsubscribe request handling.
  • CAN-SPAM applies to all commercial emails, not just bulk spam, including business-to-business messages.
  • The Act generally follows an opt-out model, not requiring prior permission for commercial emails.

What is the CAN-SPAM Act?

The Controlling the Assault of Non-Solicited Pornography and Marketing Act, better known as CAN-SPAM, became law in 2003 and took effect in 2004. It establishes rules for commercial email, gives recipients the right to stop future marketing messages, and authorizes enforcement and penalties for violations.

Despite the name, CAN-SPAM does not apply only to unsolicited bulk email. It covers any email whose primary purpose is the commercial advertisement or promotion of a product or service, including content on a commercial website. There is no general business-to-business exception.

CAN-SPAM generally follows an opt-out model, not an opt-in model. The federal law does not ordinarily require prior permission before a business sends a commercial email. Consent may still be required by another law, a platform policy, an industry rule, or the law of the recipient’s jurisdiction. Permission-based lists also remain the safer marketing practice.

Understanding the CAN-SPAM Act
Source: FTC

Which emails does CAN-SPAM cover?

Classification depends on the message’s primary purpose. The CAN-SPAM Rule and FTC guidance distinguish commercial content, transactional or relationship content, and other content.

Commercial messages

A message is commercial when its primary purpose is advertising or promoting a commercial product or service. These messages must follow the full CAN-SPAM requirements even if they go to one recipient or another business.

Transactional or relationship messages

A message may be transactional or relationship content when it completes or confirms an agreed transaction, provides warranty, recall, safety, or security information, reports changes to an account or ongoing relationship, gives employment or employee-benefit information, or delivers goods or services already agreed to. These messages remain subject to the rule against false or misleading routing information but are exempt from most commercial-message requirements.

Mixed-content messages

When an email mixes commercial and transactional content, the subject line and placement of the content matter. If the subject suggests a promotion, or the commercial material appears first while the transactional information is secondary, the message is likely commercial. Put the genuine transactional purpose first and do not disguise a promotion as an account notice.

Consent requirements in different countries
Source: Litmus

CAN-SPAM requirements for commercial email

Use this checklist for every commercial campaign sent to US recipients. It summarizes the core duties in the CAN-SPAM Rule, 16 CFR Part 316, and FTC business guidance.

Use accurate header information

The From, To, Reply-To, originating domain, email address, and routing information must be accurate and identify the person or business that initiated the message. Do not hide the real sender behind a misleading display name or domain.

pic

Use a subject line that matches the email

The subject line must accurately reflect the content. Avoid fake reply or forward prefixes, false urgency, or promises that the message does not fulfill. A promotional email can be persuasive without misrepresenting what the recipient will find inside.

CAN-SPAM non-compliant email subject line example
Source: Termly

A compliant subject line sets an accurate expectation. The example below describes the collection being promoted instead of pretending the message is a personal reply or guaranteed prize.

An example of CAN-SPAM compliant subject line
Source: Enzuzo

Identify advertising clearly

Commercial email must disclose clearly and conspicuously that it is an advertisement. The law allows flexibility in the wording and placement, so a literal “Ad” label is not the only possible approach. The disclosure should still be easy for an ordinary recipient to notice and understand.

Ad label in message subject line
Source: Termly

Include a valid physical postal address

Every commercial message must include the sender’s valid physical postal address. FTC guidance permits a current street address, a post office box registered with the US Postal Service, or a private mailbox registered with a commercial mail receiving agency established under Postal Service regulations.

An example of the sender's address in email

Provide a clear way to opt out

Explain clearly and conspicuously how the recipient can stop future marketing messages. You may offer preference options, but you must also provide a way to stop all marketing email from the sender. Make sure spam filters and other systems do not block opt-out requests.

An example of an unsubscribe link in an email
Source: Really Good Emails

Honor opt-out requests within 10 business days

The opt-out mechanism must be able to process requests for at least 30 days after the message is sent, and the sender must honor a request within 10 business days. You cannot charge a fee, demand personal information beyond the email address, or require more than a reply email or a visit to a single web page. After a person opts out, their address generally cannot be sold or transferred except to a vendor hired to help you comply.

Monitor vendors and partners

You cannot contract away responsibility by hiring another company to send campaigns. Both the company whose product is promoted and the company that sends the message may be held responsible. Establish approval, suppression-list, recordkeeping, and audit procedures with every vendor that sends on your behalf.

CAN-SPAM vs. other email laws

CAN-SPAM is a US federal rule and is comparatively permissive because it generally allows commercial email until a recipient opts out. That does not make it a universal standard for international campaigns.

  • Canada: Canada’s Anti-Spam Legislation generally relies on consent, identification, and unsubscribe requirements for commercial electronic messages, subject to defined exceptions.
  • European recipients: GDPR governs the processing of personal data, while electronic-marketing rules also depend on the EU ePrivacy framework and national implementation. GDPR alone is not a complete email-marketing rulebook.
  • Cross-border campaigns: Identify where recipients are located and apply the relevant jurisdiction’s rules. When requirements differ, permission-based sending and clear records provide a more defensible operating standard.

For a broader overview, see Selzy’s guides to email compliance and GDPR in email marketing.

CAN-SPAM pre-send compliance checklist

  1. Classify the message as commercial, transactional/relationship, mixed, or other content.
  2. Verify the sender name, domain, Reply-To address, and routing information.
  3. Check that the subject line accurately represents the email.
  4. Make the advertising nature clear and conspicuous when the message is commercial.
  5. Include the correct physical postal address.
  6. Display a clear, working opt-out method and a stop-all option.
  7. Test the unsubscribe route before sending and keep it working for at least 30 days.
  8. Process requests within 10 business days and suppress opted-out addresses from future marketing.
  9. Confirm vendors use the same suppression data and compliance procedures.
  10. Keep campaign, consent, suppression, and vendor records appropriate to your risk and jurisdiction.

CAN-SPAM penalties and enforcement

The FTC states that each separate email violating CAN-SPAM may be subject to civil penalties of up to $53,088. Civil penalty maximums can be adjusted for inflation, so verify the current figure in FTC guidance before relying on it for a legal or financial decision.

Federal enforcement

The FTC enforces CAN-SPAM for most businesses, while other federal agencies may enforce it for organizations within their jurisdiction. The Department of Justice may pursue criminal cases involving aggravated conduct such as unauthorized access to send spam, deceptive account or domain registration, address harvesting, dictionary attacks, or misuse of open relays and proxies.

State and internet service provider actions

State attorneys general may bring actions for specified violations. Providers of internet access service may also have a limited private right of action when they are adversely affected. Ordinary individual recipients generally do not receive a broad private right to sue under CAN-SPAM.

More than one party may be responsible for the same campaign, and misleading product claims can also trigger other consumer-protection laws. Treat the per-email maximum as a warning about scale, not as a prediction of the amount in a particular case.

Conclusion

CAN-SPAM compliance starts with correctly classifying the message and continues through sender identity, subject-line accuracy, ad disclosure, postal-address information, opt-out design, suppression processing, and vendor oversight. The law does not generally require prior consent for US commercial email, but permission-based marketing is usually better for trust, deliverability, and cross-border compliance.

Use the checklist before every campaign, document how opt-outs are processed, and review official guidance when penalty figures or operational rules change. This article is general information, not legal advice.

CAN-SPAM Act FAQ

What did the CAN-SPAM Act do?

The CAN-SPAM Act became law in 2003 and took effect in 2004. It set rules for commercial email, gave recipients the right to stop future marketing messages, and authorized enforcement and penalties for violations.

Does CAN-SPAM require permission before sending marketing emails?

Generally, no. CAN-SPAM follows an opt-out model rather than an opt-in model, so prior permission is not ordinarily required under federal law before sending a commercial email. Other laws, platform policies, industry rules, or the recipient’s local law may still require consent.

What emails must comply with the CAN-SPAM Act?

Any email whose primary purpose is advertising or promoting a commercial product or service must comply, even if it is sent to one recipient or to another business. Transactional or relationship emails are mostly exempt, but they still cannot use false or misleading routing information. When an email mixes commercial and transactional content, the overall purpose and the placement of the promotional material matter.

How quickly must a business honor an unsubscribe request?

Unsubscribe requests must be honored within 10 business days. The opt-out method must also keep processing requests for at least 30 days after the email is sent.

Who enforces the CAN-SPAM Act?

The FTC enforces CAN-SPAM for most businesses. Other federal agencies may enforce it within their jurisdictions, and state attorneys general may bring specified actions. Adversely affected internet access service providers have a limited private right of action, while ordinary recipients generally do not have a broad private right to sue.

Updated: 22 July, 2026

In this article
What is the CAN-SPAM Act CAN-SPAM Act requirements and international email spam laws CAN-SPAM compliance checklist Penalties for non-compliance Conclusion
Irene Dmitrieva

Written by Irene Dmitrieva

As a marketing copywriter, I have experience creating compelling content for websites and social media posts. My background in market research helps me ensure that my copy is both on-brand and data-driven. I am excited to bring my skills and experience to Selzy team and help drive success for this company.