All articlesCompliance

    CAN-SPAM Compliance: A Plain-English Checklist

    CAN-SPAM does not require permission to send — it requires honest headers, a real postal address, clear advertising identification, and an opt-out you honor fast. A seven-point checklist, the opt-out rules people get wrong, and how CAN-SPAM differs from GDPR and CASL.

    CAN-SPAM Compliance: A Plain-English Checklist
    Erin Moore
    Erin Moore
    September 12, 20269 min read
    Share:

    CAN-SPAM is the US federal law governing commercial email. It does not require permission before you send. It requires honest headers and subject lines, a physical postal address, a working opt-out honored promptly, and clear identification of advertising. Compliance is mostly about transparency, and it applies to every commercial message you send.

    This is a plain-English explainer, not legal advice. Enforcement details, penalties, and how the rules apply to your specific business are questions for a qualified attorney. Use this as a working checklist and a starting point for that conversation.

    Who the law actually covers

    The scope is broader than most people assume. CAN-SPAM applies to commercial electronic mail whose primary purpose is advertising or promoting a product or service. There is no small-business exemption, no exemption for B2B mail, and no exemption for a one-off email to a list you bought. If the message promotes something, it counts.

    The law splits messages into three types, and the obligations differ:

    Message typeExampleOpt-out required?Postal address required?
    CommercialNewsletter with product promotion, sales campaign, webinar inviteYesYes
    Transactional or relationshipOrder confirmation, shipping notice, password reset, account balanceNoNo
    Mixed purposeReceipt with a promotional banner and cross-sell blockDepends on primary purpose — treat as commercial if promotion dominatesSame

    Every message type, including transactional, must still have accurate routing information and non-deceptive headers. You never get to lie about who sent something.

    The mixed-purpose row is where most companies drift out of compliance without noticing. A shipping notification is transactional. A shipping notification with three recommended products, a discount banner, and a promotional subject line is arguably commercial, and it now needs an opt-out and an address. The safe practice is to keep transactional messages clean and put promotion in separate campaigns.

    The seven-point compliance checklist

    Work through this before any commercial send:

    1. Accurate From, To, and routing information. The sender name, from address, reply-to, and originating domain must truthfully identify who is sending. No spoofed domains, no borrowed identities.
    2. Non-deceptive subject line. The subject must reflect what is in the message. "Re: our conversation" on a cold promotional email to a stranger is the classic violation.
    3. Advertising identified as advertising. The message must be recognizable as an ad. This does not require the word "advertisement" in most contexts, but the commercial nature must be clear from the message.
    4. A valid physical postal address. Your current street address, a registered PO box, or a private mailbox registered with a commercial mail receiving agency. Include it in every commercial message.
    5. A clear, conspicuous opt-out mechanism. An unsubscribe link a normal person can find and use. Not hidden in a 6px light-gray footer, not requiring a login.
    6. Opt-outs honored promptly. The law allows a window measured in days; the operationally correct answer is immediately and automatically. Your platform's suppression list should handle this without human involvement.
    7. Responsibility for what others do on your behalf. Hiring an agency or affiliate does not transfer liability. Both the company whose product is promoted and the party sending can be held responsible.

    The opt-out rules people get wrong

    Unsubscribe handling generates more violations than anything else, usually through well-intentioned friction. Things you cannot do: charge a fee to unsubscribe, require any information beyond an email address and opt-out preferences, require the recipient to create an account or log in, or make them visit more than a single page to complete the request.

    Things you also cannot do after the fact: sell, lease, or transfer an address that has opted out, or transfer it to another list to keep mailing. An opt-out is a suppression, not a segment change. And it must remain functional for at least 30 days after the message is sent, which means unsubscribe links in old campaigns need to keep working.

    Two practices worth adopting beyond the minimum. Add a List-Unsubscribe header so mailbox providers can offer one-click unsubscribe natively — major providers now expect this from bulk senders regardless of the law. And offer a preference center as an option alongside, never instead of, a plain unsubscribe link.

    CAN-SPAM versus GDPR, CASL, and the rest

    The single biggest misunderstanding is that complying with CAN-SPAM makes you compliant everywhere. It does not, because CAN-SPAM is an opt-out regime and most of the world runs on opt-in.

    RegimeRegionConsent modelDistinctive requirement
    CAN-SPAMUnited StatesOpt-out — permission not required to sendPhysical postal address in every commercial message
    GDPR / ePrivacyEU and EEAOpt-in — freely given, specific, informedRecords of consent, data subject rights, lawful basis
    CASLCanadaExpress or implied consent, with expiry on impliedSender identification and consent record-keeping
    UK GDPR / PECRUnited KingdomOpt-in with a narrow existing-customer exceptionSoft opt-in conditions must be met precisely

    If any portion of your list sits in Europe, the stricter standard governs those contacts, and our guide to GDPR email marketing for EU contacts covers what consent, records, and data rights look like in practice. The workable policy for most companies with any international reach is to run opt-in globally. It costs you some list volume and eliminates an entire category of risk.

    State laws add another layer

    CAN-SPAM preempts most state anti-spam statutes, but not all of them, and it does not preempt state privacy laws at all. Several US states now have comprehensive privacy laws with their own obligations around data collection, disclosure, and deletion requests that touch email marketing directly. Those are separate from CAN-SPAM and worth reviewing with counsel if you operate at any scale.

    Build compliance into the system, not the checklist

    A checklist someone runs manually before each send will fail eventually. Automate the parts that can be automated:

    • Put the postal address in a locked global footer so it cannot be deleted from an individual campaign.
    • Make the unsubscribe link a required template element rather than something copied between drafts.
    • Use platform-level suppression so an opt-out applies across every list, segment, and automation instantly.
    • Authenticate with SPF, DKIM, and DMARC. Authentication is not a CAN-SPAM requirement, but it is what makes your header accuracy verifiable — and it is what mailbox providers actually check.
    • Keep transactional and marketing streams separate so a promotional block never quietly turns a receipt into a commercial message.

    IGSendMail handles most of this by default — automatic SPF, DKIM, and DMARC setup, required footer fields, and account-wide suppression that applies the moment someone unsubscribes. The platform is built for GDPR, CAN-SPAM, and CASL compliance, which removes the mechanical failures and leaves you free to focus on the judgment calls.

    What to audit quarterly

    Set a recurring review. Send yourself a live copy of each active automation and campaign template and confirm the footer, address, and unsubscribe link all render and work. Actually click the unsubscribe link and verify the address lands in suppression. Confirm your postal address is current — companies move and forget. Check that no transactional template has quietly acquired a promotional block. And review who else sends on your behalf, because affiliate and agency mail is your exposure too.

    Frequently asked questions

    Does CAN-SPAM require permission before I email someone?

    No. CAN-SPAM is an opt-out law, so prior consent is not required for commercial email to US recipients. Permission is still the better practice, and it is legally required in the EU, Canada, and the UK, where opt-in regimes apply.

    Do transactional emails need an unsubscribe link?

    Not under CAN-SPAM, provided the primary purpose is genuinely transactional — receipts, shipping notices, password resets, account alerts. Adding promotional content to those messages can shift their classification and bring the commercial requirements with it.

    Can I use a PO box for the required physical address?

    Generally yes. A valid registered PO box or a private mailbox registered with a commercial mail receiving agency is typically acceptable in place of a street address. Confirm your specific arrangement with counsel if you are unsure.

    How quickly must I honor an unsubscribe request?

    The law provides a window measured in days, but the correct operational answer is immediately and automatically through platform-level suppression. Manual handling is where companies fall behind, and the unsubscribe link must keep working for at least 30 days after the send.

    Am I liable if an agency sends non-compliant email for me?

    Potentially, yes. Both the party whose product is promoted and the party doing the sending can be held responsible. Hiring a vendor does not transfer the obligation, so review what anyone sends on your behalf.

    Want compliance handled by the platform instead of a pre-send checklist? Launch with IGSendMail — GDPR, CAN-SPAM and CASL compliant, automatic SPF/DKIM/DMARC, account-wide suppression, and free 24-hour migration. From $19/mo, free up to 2,500 contacts.

    Enjoyed this article?

    Get email marketing tips delivered to your inbox every week.