Quick answer: To comply with the US CAN-SPAM Act, every marketing email must use honest headers and subject lines, disclose that it is an ad, include a valid physical postal address, offer a clear opt-out, and honor that opt-out within 10 business days. Unlike Europe’s opt-in GDPR model, the US runs on opt-out — you can email first, but you must let people leave easily. Violations run up to $53,088 per email, assessed per recipient, per the FTC’s current penalty ceiling.
What is the CAN-SPAM Act, in plain English?
CAN-SPAM is the US federal law that governs commercial email. The most important thing to understand is that it is an opt-out law, not an opt-in one. You do not need prior consent to send a commercial email the way Europe’s GDPR requires — but you must give every recipient an easy, working way to stop hearing from you, and you must honor that request fast. The Federal Trade Commission enforces it, and the maximum civil penalty now stands at $53,088 per email after the FTC’s January 2025 inflation adjustment.
That per-email figure is what makes CAN-SPAM dangerous. The law treats every single recipient of a non-compliant message as a separate violation, and there is no cap tied to your revenue. A single 10,000-address blast with a broken unsubscribe link is, on paper, a multi-million-dollar liability. This guide is educational, not legal advice — for a specific situation, talk to a qualified attorney.
The 7 CAN-SPAM rules you must follow
The FTC boils the law down to seven requirements. Meet all seven on every commercial email and you are compliant.
- Don’t use false or misleading header information. Your From, To, Reply-To, and routing must accurately identify who sent the message.
- Don’t use deceptive subject lines. The subject must reflect the actual content of the email.
- Identify the message as an ad. You have latitude in how, but the commercial nature must be clear.
- Tell recipients where you are located. Include a valid physical postal address — a street address, a registered PO box, or a private mailbox.
- Tell recipients how to opt out. Include a clear, conspicuous way to unsubscribe from future email.
- Honor opt-outs promptly. Process any request within 10 business days, and keep the mechanism live for at least 30 days after you send.
- Monitor what others do on your behalf. If you hire an agency or use an affiliate, you are still legally responsible for compliance.
How is CAN-SPAM different from GDPR?
This trips up a lot of US marketers who read European advice. GDPR (and Canada’s CASL) require explicit opt-in consent before you email. CAN-SPAM does not — it lets you send first and requires a working exit. If you email people in the EU, UK, or Canada, you must follow their opt-in rules; for US recipients, opt-out is the standard. When in doubt, opt-in is the safer, more deliverable path even where it is not required.
| Requirement | US — CAN-SPAM | EU — GDPR |
|---|---|---|
| Consent model | Opt-out (email first, allow exit) | Opt-in (consent before sending) |
| Unsubscribe | Required, honored ≤ 10 business days | Required, plus consent records |
| Physical address | Required in every email | Required for identification |
| Max penalty | Up to $53,088 per email | Up to 4% of global revenue |
Why compliance and deliverability are the same fight now
Here is the part most compliance checklists miss: the rules that keep you legal are also the rules that keep you in the inbox. A missing or buried unsubscribe link is both a CAN-SPAM problem and a spam-complaint magnet. Litmus data found that 49% of consumers will mark a message as spam when there is no clear unsubscribe option — and spam complaints are exactly what tank your sender reputation at Gmail and Yahoo.
As AI intermediaries stand between brands and inboxes, sender reputation and relationship quality will replace surface-level engagement metrics as the things that actually determine results.
— Chad White, Head of Research at Zeta Global, at Litmus Live 2026
Google and Yahoo’s bulk-sender rules already require a one-click List-Unsubscribe header — yet analysis of a large email corpus found only about 14% of emails carried a compliant one-click unsubscribe, despite the requirement being public since mid-2024. Getting this right is a competitive edge, not just a legal box to tick. If you want the mailbox providers to trust you, treating the opt-out as sacred is step one.
A 10-minute compliance checklist before you hit send
- Does the From name and address clearly identify your business?
- Does the subject line honestly describe the email?
- Is your valid physical postal address in the footer?
- Is there a visible, one-click unsubscribe link?
- Is your unsubscribe automated so it processes within 10 business days?
- Are you enforcing the same rules on any agency or affiliate sending for you?
Enforcement is real but proportional. The FTC does not chase theoretical maximums; it negotiates settlements against conduct and scale. The largest CAN-SPAM penalty it has ever obtained was a $2.95 million proposed settlement with security-camera firm Verkada in 2024. The lesson is not “you will be fined tomorrow” — it is that sloppy list hygiene and broken opt-outs are what draw attention.
Compliance is only half the game — getting seen is the other half. The same “answer clearly, prove it, respect the reader” discipline that protects your email also wins in search: see our guide on how to rank in Google AI Overviews. If you want your email program audited and rebuilt for the inbox, explore our digital marketing services, grab a template from our free tools, or book a free strategy call.
Frequently asked questions
Does CAN-SPAM require opt-in consent before I email someone? No. The US runs an opt-out model — you may send commercial email without prior consent, as long as you provide a working opt-out and honor it within 10 business days. GDPR and CASL require opt-in, so consent rules apply if you email the EU, UK, or Canada.
How much is the CAN-SPAM penalty per email? Up to $53,088 per email as of the FTC’s January 2025 adjustment. It is assessed per recipient, with no revenue cap, which is why a single non-compliant blast can carry enormous theoretical liability.
How fast must I process an unsubscribe? Within 10 business days. You must also keep the opt-out mechanism working for at least 30 days after you send, and you cannot charge a fee or require more than an email address to unsubscribe.
Do transactional emails need to follow CAN-SPAM? Purely transactional or relationship messages (receipts, shipping notices) are exempt from most rules, but they still cannot contain false or misleading header information. If a message mixes transactional and promotional content, the promotional rules apply.
Related guides
References
- CAN-SPAM penalties in 2026: fines and how to avoid them
- CAN-SPAM Act violations: $53,088 per email
- Litmus Live 2026 recap (Chad White; one-click unsubscribe data)
- Litmus — 49% mark mail as spam without a clear unsubscribe
— Shivam
How this was made: written by the WiseGuyXL team from hands-on email work, with AI assistance for drafting and formatting. All statistics are linked to their original sources. Educational only, not legal advice.