Quick answer: The CAN-SPAM Act is the US law governing commercial email. It requires honest headers and subject lines, a valid physical postal address, clear ad identification, and a working opt-out you honor within 10 business days. It covers all commercial email — including business-to-business — and each violating message can cost up to $53,088 (FTC).
If you send marketing email to anyone in the United States, one law sets the floor: CAN-SPAM. It is not complicated, but the penalties for ignoring it are steep and the rules catch a lot of senders who assume “it’s just a newsletter” exempts them. Here is what the FTC actually requires.
Disclosure: Bluey Email, mentioned near the end, is my own product. This article is general information, not legal advice — consult a lawyer for your specific situation.
What is the CAN-SPAM Act?
CAN-SPAM (the Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003) is enforced by the Federal Trade Commission. As the FTC explains, it “sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have you stop emailing them, and spells out tough penalties for violations.” A common myth is that it only applies to bulk email. It does not: “Despite its name, the CAN-SPAM Act doesn’t apply just to bulk email. It covers all commercial messages … The law makes no exception for business-to-business email.” A single message to former customers about a new product line must comply.
What are the main CAN-SPAM requirements?
The FTC boils it down to a short list of rules. Get these right and you are compliant:
- Don’t use false or misleading header information. Your From, To, Reply-To and routing details must be accurate and identify who sent the message.
- Don’t use deceptive subject lines. The subject must reflect the content of the message.
- Identify the message as an ad. You have leeway on how, but it must be clear and conspicuous.
- Tell recipients where you’re located. Include a valid physical postal address — a street address, registered PO box, or registered private mailbox.
- Tell recipients how to opt out, in a way an ordinary person can easily find and use.
- Honor opt-outs promptly. Process them for at least 30 days after sending and act within 10 business days; you can’t charge a fee or demand extra information.
- Monitor what others do on your behalf. Hiring an agency doesn’t transfer your legal responsibility.
Which emails does it apply to?
The test is the message’s “primary purpose.” Purely commercial messages (advertising or promoting a product or service) must meet every requirement above. Purely transactional or relationship messages — order confirmations, shipping updates, account notices, warranty or safety information — are exempt from most provisions but still can’t use false routing information. The FTC warns that these categories are read narrowly: don’t assume a message to existing customers is transactional. If the subject line reads like an ad, or the promotional content isn’t clearly secondary, it counts as commercial. Our transactional vs marketing email guide covers the distinction in practice.
What are the penalties?
They are per-message, which is what makes them dangerous. Per the FTC, “Each separate email in violation of the law is subject to penalties of up to $53,088.” Send one non-compliant blast to a few thousand people and, in principle, each message is a separate violation. More than one party can be liable, too — both the company whose product is promoted and the company that sent the message. Aggravated conduct such as harvesting addresses or using false registration data can add further fines and even criminal penalties. In short: the cost of compliance is a footer and an unsubscribe link; the cost of non-compliance is open-ended.
How do you stay compliant?
Most of CAN-SPAM is handled for you by any reputable email platform: a compliant unsubscribe link, opt-out processing, and a physical-address footer are standard features. Your job is to only mail people appropriately, keep your From and subject lines honest, and actually honor opt-outs. Note that CAN-SPAM is an opt-out regime — it doesn’t require prior consent to send — which is the big difference from Europe’s opt-in rules; see our GDPR email marketing guide if you also mail EU or UK recipients. For building a permission-based list the right way regardless, see how to build an email list and double opt-in. Bluey Email, like other compliant platforms, includes one-click unsubscribe and address-footer handling out of the box, so staying inside the law is mostly a matter of good sending habits.
Frequently asked questions
Does CAN-SPAM require opt-in consent? No. Unlike GDPR, CAN-SPAM is opt-out: you may send commercial email without prior consent, but you must give recipients a clear way to opt out and honor it within 10 business days.
Does CAN-SPAM apply to B2B email? Yes. The law makes no exception for business-to-business messages — all commercial email must comply.
How much can a CAN-SPAM violation cost? Up to $53,088 per individual email, per the FTC, plus possible additional fines for aggravated violations and criminal penalties in serious cases.
Do transactional emails need an unsubscribe link? Not under CAN-SPAM, if their primary purpose is genuinely transactional or relationship content. But they still can’t contain false or misleading header information.
References
- U.S. Federal Trade Commission — CAN-SPAM Act: A Compliance Guide for Business: https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business
— Shivam