Skip to content
Learn · Updated September 2026

CAN-SPAM Act

The CAN-SPAM Act is the U.S. federal law governing commercial email. It does not require prior opt-in, but it does require accurate From and header information, non-deceptive subject lines, identification of the message as an ad where applicable, a valid physical postal address, and a working opt-out that is honored promptly. Violations carry substantial per-email penalties.

How it works

Every commercial email must let recipients unsubscribe and must honor that request within ten business days, must not use false headers or misleading subjects, and must include a legitimate physical mailing address. The rules apply to each message, and liability can reach the company whose product is promoted.

Why it matters

CAN-SPAM sets the legal floor for U.S. email. It is more permissive than GDPR (no prior consent needed), but the opt-out, honest-header and physical-address requirements are strict and enforced, with penalties that can run into thousands of dollars per non-compliant email.

CAN-SPAM checks on one commercial email: 1. Apply the primary purpose test; 2. Check honest From and subject line; 3. Include postal address and opt-out; 4. Honor opt-out within 10 business days; 5. Keep the opt-out working 30 days.
CAN-SPAM checks on one commercial email

How do you tell whether an email is commercial under CAN-SPAM?

The FTC applies a primary purpose test. A message whose main purpose is to advertise or promote a product or service is commercial and carries the full set of requirements. A transactional or relationship message, such as an order confirmation, an account notice or a meeting you already scheduled, is largely exempt apart from the rule against false or misleading routing information.

Mixed messages are where teams slip. A renewal notice that spends most of its space pitching an upgrade can tip into commercial. If the subject line or the opening would lead a reasonable reader to see an ad, treat the message as commercial and include the opt-out and postal address anyway.

What does a working opt-out mechanism have to do?

The opt-out must be clear and easy to find, and it must keep working for at least 30 days after the message is sent. You cannot charge a fee, require any personal information beyond an email address and opt-out preferences, or make the person visit more than a single page to opt out. Requests must be honored within 10 business days, and you cannot sell or transfer the address afterwards.

A hypothetical timeline shows the risk. A prospect replies "remove me" on a Monday in week one. Ten business days runs to the Friday of week two. If step four of your sequence was scheduled for week three, it must never go out. Plain reply-based opt-outs count too, so parse replies as well as link clicks. Separately, Gmail and Yahoo expect bulk senders to support one-click unsubscribe per RFC 8058 and honor it within 2 days, which is stricter than the law.

Who is liable when an agency or vendor sends on your behalf?

Both can be. The FTC's guidance says the company whose product is promoted and the company that sends the message may each be held responsible. Outsourcing a campaign to an agency does not move the obligation away from you, so contracts with lead-generation vendors should require CAN-SPAM compliance and give you access to their opt-out records.

Sync those opt-outs into your own suppression list. Otherwise a prospect who unsubscribed from the agency's campaign can receive your in-house sequence a week later, and from their side there is no difference. The solutions page for agencies describes how client workspaces keep lists separate.

Which checks should a sequence pass before the first send?

Read the From name and address as the recipient will; they must identify you honestly. Compare the subject line with the body and remove anything the body does not deliver. Confirm the footer carries a valid postal address. Click the unsubscribe link from a test inbox and verify the suppression lands. Run the copy through the cold email spam checker as a separate deliverability pass, since legal compliance and inbox placement are different tests.

How Autocloz handles it

Autocloz supports CAN-SPAM compliance with unsubscribe handling, a global cross-channel suppression list that honors opt-outs immediately, and an audit log of every outbound touch — so the required opt-out and record-keeping are enforced by the system.

Free tools for this

No signup required — they run in your browser.

FAQ

Does CAN-SPAM require opt-in before sending?

No. Unlike GDPR, CAN-SPAM permits sending commercial email without prior consent, provided you use honest headers and subject lines, include a valid physical address, and offer a working opt-out that you honor within ten business days.

Does CAN-SPAM apply to B2B email?

Yes. It covers commercial email broadly, including business-to-business messages. Every commercial email — B2B or B2C — must meet the identification, physical-address and opt-out requirements to be compliant.

Related terms

Sources

CAN-SPAM Act — explained by Autocloz