Educational Resource

What Is CAN-SPAM Compliance? (The Five Rules, and the $53,088 Per Message)

CAN-SPAM is short, specific and badly understood. It does not ban unsolicited email and it does not require consent. It sets five requirements for every commercial message, and it counts penalties per message.

Hamit Kaya
Hamit Kaya
Founder & CTO, aicente
9 min read

Key Takeaways

  • CAN-SPAM is opt-OUT. You may email someone who never asked, provided the message meets the five requirements. This is the single biggest difference from GDPR and CASL.
  • Penalties reach $53,088 per message. A 10,000-recipient send is 10,000 violations, not one.
  • Liability reaches the company whose product is advertised. Hiring an agency does not move it.
  • An unsubscribe must work for at least 30 days after the send and be honoured within 10 business days, with no fee, no login and no questions beyond the address.
  • There is no exemption for business-to-business email. The law covers commercial messages, not consumer ones.

What CAN-SPAM Actually Says

The Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003 governs commercial electronic mail sent to recipients in the United States. It is enforced by the Federal Trade Commission.

The name causes most of the confusion. People hear “CAN-SPAM” and assume the law bans unsolicited email. It does the opposite: it establishes the conditions under which unsolicited commercial email is lawful. There is no consent requirement anywhere in it. If you obtained an address legitimately and your message meets the requirements below, you may send it to someone who has never heard of you.

That is a genuinely permissive regime by international standards, and it is why a US sender expanding to European or Canadian recipients is often surprised to find their entire list practice unlawful there.

The Five Requirements

1. Do not use false or misleading header information. The From, the Reply-To and the routing information must identify who actually sent the message. The domain must not be one you do not control.

2. Do not use a deceptive subject line.The subject must reflect the content. This is the clause that makes a fake “Re:” or “Fwd:” on a message that is not a reply a violation rather than merely a cheap trick. It raises open rates and it is unlawful.

3. Identify the message as an advertisement.Required when the recipient did not give affirmative consent. The law does not prescribe wording, only that the disclosure be clear and conspicuous. A line reading “This is an advertisement” satisfies it.

4. Include your valid physical postal address. Your current street address, a post office box registered with the US Postal Service, or a private mailbox registered with a commercial mail receiving agency. A solo publisher does not have to publish their home address, which is the thing most people getting started are worried about.

5. Tell recipients how to opt out, and honour it. A clear, conspicuous explanation of how to stop receiving email. The mechanism has to keep working for at least 30 days after the message was sent. The request must be honoured within 10 business days. You may not charge a fee, require a login, require any information beyond the email address, or make the person state a reason.

The Part That Surprises People: How Penalties Are Counted

Each separate email in violation is a separate violation, with a civil penalty currently up to $53,088. The figure is adjusted for inflation and has risen steadily since the Act passed, which is worth knowing because almost every article online quotes an older number.

A campaign of 10,000 messages with a missing postal address is not one violation. It is ten thousand. This arithmetic is the reason compliance is not a judgement call about risk appetite: the exposure from a single careless send exceeds the lifetime value of most email programmes.

Who Is Liable

Both the company whose product is promoted and the company that actually sends the message can be held responsible. Hiring an agency, or using an email platform, does not transfer liability away from the business being advertised.

This matters practically. A marketing contractor who buys a list and sends on your behalf has created your exposure, not theirs alone, and the FTC has brought actions on exactly that basis.

Transactional Email Is Mostly Exempt, Until It Is Not

A message whose primary purpose is transactional or relationship content is exempt from most of the requirements. Receipts, shipping notifications, password resets, warranty information and account statements fall here. They still may not carry deceptive header information.

The trap is the word “primary”. Add a promotion to a receipt and the primary purpose can shift, at which point the full set of requirements applies to what you thought was a transactional message. The practical rule is that the moment a receipt starts selling something, treat it as commercial.

Business-to-Business Email Is Not Exempt

This is the most common misconception in B2B sales. CAN-SPAM covers commercial messages, and says nothing about whether the recipient is a consumer or a purchasing manager. A cold sales email to a work address needs the postal address and the working unsubscribe exactly as a consumer newsletter does.

What CAN-SPAM Does Not Cover

It is a floor, not a ceiling. Three things sit outside it and bite anyway.

State law. California and others have their own provisions, some stricter than the federal baseline.

The receivers’ own rules. Since 2026, Google, Yahoo and Microsoft require authenticated mail, a published DMARC record, a one-click List-Unsubscribe header and complaint rates under 0.3% from bulk senders, and they reject non-compliant mail with a permanent failure rather than filing it in spam. Nothing in CAN-SPAM requires any of that, and failing it means your mail does not arrive regardless of your legal position. Our free SPF, DKIM and DMARC checker tests that side.

Other countries. The moment one subscriber is in the EU, the UK or Canada, a different and stricter regime applies to that message. See GDPR email consent and CASL.

A Practical Checklist

Every commercial message you send should have a truthful From and subject, a visible unsubscribe link that still works a month later, your physical postal address, and an advertisement disclosure when the recipient did not opt in. Opt-outs should be processed automatically rather than by hand, because the 10-business-day clock does not pause for holidays.

You can generate a footer that covers the address and the unsubscribe with our free CAN-SPAM footer generator, and check an existing email against these rules with the free spam checker. Action BeeMail adds the footer automatically and refuses to send a campaign without one.

This is a description of the rules, not legal advice. If a decision turns on your specific circumstances, ask a lawyer.

Ready to Try Aicente?

Join 10,000+ businesses using aicente's 60+ AI tools to manage operations, win recognition, and grow. Platform Access starts at $19.99/month. Action Award entry is always free.