CAN-SPAM is the US federal law governing commercial email. It does not require permission before you send. It requires honest headers and subject lines, a physical postal address, a working opt-out honored promptly, and clear identification of advertising. Compliance is mostly about transparency, and it applies to every commercial message you send.
This is a plain-English explainer, not legal advice. Enforcement details, penalties, and how the rules apply to your specific business are questions for a qualified attorney. Use this as a working checklist and a starting point for that conversation.
Who the law actually covers
The scope is broader than most people assume. CAN-SPAM applies to commercial electronic mail whose primary purpose is advertising or promoting a product or service. There is no small-business exemption, no exemption for B2B mail, and no exemption for a one-off email to a list you bought. If the message promotes something, it counts.
The law splits messages into three types, and the obligations differ:
| Message type | Example | Opt-out required? | Postal address required? |
|---|---|---|---|
| Commercial | Newsletter with product promotion, sales campaign, webinar invite | Yes | Yes |
| Transactional or relationship | Order confirmation, shipping notice, password reset, account balance | No | No |
| Mixed purpose | Receipt with a promotional banner and cross-sell block | Depends on primary purpose — treat as commercial if promotion dominates | Same |
Every message type, including transactional, must still have accurate routing information and non-deceptive headers. You never get to lie about who sent something.
The mixed-purpose row is where most companies drift out of compliance without noticing. A shipping notification is transactional. A shipping notification with three recommended products, a discount banner, and a promotional subject line is arguably commercial, and it now needs an opt-out and an address. The safe practice is to keep transactional messages clean and put promotion in separate campaigns.
The seven-point compliance checklist
Work through this before any commercial send:
- Accurate From, To, and routing information. The sender name, from address, reply-to, and originating domain must truthfully identify who is sending. No spoofed domains, no borrowed identities.
- Non-deceptive subject line. The subject must reflect what is in the message. "Re: our conversation" on a cold promotional email to a stranger is the classic violation.
- Advertising identified as advertising. The message must be recognizable as an ad. This does not require the word "advertisement" in most contexts, but the commercial nature must be clear from the message.
- A valid physical postal address. Your current street address, a registered PO box, or a private mailbox registered with a commercial mail receiving agency. Include it in every commercial message.
- A clear, conspicuous opt-out mechanism. An unsubscribe link a normal person can find and use. Not hidden in a 6px light-gray footer, not requiring a login.
- Opt-outs honored promptly. The law allows a window measured in days; the operationally correct answer is immediately and automatically. Your platform's suppression list should handle this without human involvement.
- Responsibility for what others do on your behalf. Hiring an agency or affiliate does not transfer liability. Both the company whose product is promoted and the party sending can be held responsible.
The opt-out rules people get wrong
Unsubscribe handling generates more violations than anything else, usually through well-intentioned friction. Things you cannot do: charge a fee to unsubscribe, require any information beyond an email address and opt-out preferences, require the recipient to create an account or log in, or make them visit more than a single page to complete the request.
Things you also cannot do after the fact: sell, lease, or transfer an address that has opted out, or transfer it to another list to keep mailing. An opt-out is a suppression, not a segment change. And it must remain functional for at least 30 days after the message is sent, which means unsubscribe links in old campaigns need to keep working.
Two practices worth adopting beyond the minimum. Add a List-Unsubscribe header so mailbox providers can offer one-click unsubscribe natively — major providers now expect this from bulk senders regardless of the law. And offer a preference center as an option alongside, never instead of, a plain unsubscribe link.
CAN-SPAM versus GDPR, CASL, and the rest
The single biggest misunderstanding is that complying with CAN-SPAM makes you compliant everywhere. It does not, because CAN-SPAM is an opt-out regime and most of the world runs on opt-in.
| Regime | Region | Consent model | Distinctive requirement |
|---|---|---|---|
| CAN-SPAM | United States | Opt-out — permission not required to send | Physical postal address in every commercial message |
| GDPR / ePrivacy | EU and EEA | Opt-in — freely given, specific, informed | Records of consent, data subject rights, lawful basis |
| CASL | Canada | Express or implied consent, with expiry on implied | Sender identification and consent record-keeping |
| UK GDPR / PECR | United Kingdom | Opt-in with a narrow existing-customer exception | Soft opt-in conditions must be met precisely |
If any portion of your list sits in Europe, the stricter standard governs those contacts, and our guide to GDPR email marketing for EU contacts covers what consent, records, and data rights look like in practice. The workable policy for most companies with any international reach is to run opt-in globally. It costs you some list volume and eliminates an entire category of risk.
State laws add another layer
CAN-SPAM preempts most state anti-spam statutes, but not all of them, and it does not preempt state privacy laws at all. Several US states now have comprehensive privacy laws with their own obligations around data collection, disclosure, and deletion requests that touch email marketing directly. Those are separate from CAN-SPAM and worth reviewing with counsel if you operate at any scale.
Build compliance into the system, not the checklist
A checklist someone runs manually before each send will fail eventually. Automate the parts that can be automated:
- Put the postal address in a locked global footer so it cannot be deleted from an individual campaign.
- Make the unsubscribe link a required template element rather than something copied between drafts.
- Use platform-level suppression so an opt-out applies across every list, segment, and automation instantly.
- Authenticate with SPF, DKIM, and DMARC. Authentication is not a CAN-SPAM requirement, but it is what makes your header accuracy verifiable — and it is what mailbox providers actually check.
- Keep transactional and marketing streams separate so a promotional block never quietly turns a receipt into a commercial message.
IGSendMail handles most of this by default — automatic SPF, DKIM, and DMARC setup, required footer fields, and account-wide suppression that applies the moment someone unsubscribes. The platform is built for GDPR, CAN-SPAM, and CASL compliance, which removes the mechanical failures and leaves you free to focus on the judgment calls.
What to audit quarterly
Set a recurring review. Send yourself a live copy of each active automation and campaign template and confirm the footer, address, and unsubscribe link all render and work. Actually click the unsubscribe link and verify the address lands in suppression. Confirm your postal address is current — companies move and forget. Check that no transactional template has quietly acquired a promotional block. And review who else sends on your behalf, because affiliate and agency mail is your exposure too.
Frequently asked questions
Does CAN-SPAM require permission before I email someone?
No. CAN-SPAM is an opt-out law, so prior consent is not required for commercial email to US recipients. Permission is still the better practice, and it is legally required in the EU, Canada, and the UK, where opt-in regimes apply.
Do transactional emails need an unsubscribe link?
Not under CAN-SPAM, provided the primary purpose is genuinely transactional — receipts, shipping notices, password resets, account alerts. Adding promotional content to those messages can shift their classification and bring the commercial requirements with it.
Can I use a PO box for the required physical address?
Generally yes. A valid registered PO box or a private mailbox registered with a commercial mail receiving agency is typically acceptable in place of a street address. Confirm your specific arrangement with counsel if you are unsure.
How quickly must I honor an unsubscribe request?
The law provides a window measured in days, but the correct operational answer is immediately and automatically through platform-level suppression. Manual handling is where companies fall behind, and the unsubscribe link must keep working for at least 30 days after the send.
Am I liable if an agency sends non-compliant email for me?
Potentially, yes. Both the party whose product is promoted and the party doing the sending can be held responsible. Hiring a vendor does not transfer the obligation, so review what anyone sends on your behalf.
Want compliance handled by the platform instead of a pre-send checklist? Launch with IGSendMail — GDPR, CAN-SPAM and CASL compliant, automatic SPF/DKIM/DMARC, account-wide suppression, and free 24-hour migration. From $19/mo, free up to 2,500 contacts.

