CAN-SPAM Compliance for Online Businesses: What the Law Requires for Every Marketing Email You Send

CAN-SPAM regulates commercial email whose primary purpose is advertising or promoting a commercial product or service. The law covers individual messages and bulk campaigns alike, including messages to business contacts, existing customers, subscribers, and consumers.

Federal law generally permits sending a commercial email without first collecting the recipient's opt-in consent. The law requires truthful sender information, an accurate subject line, an appropriate advertising disclosure, a valid postal address, and a usable way to stop future marketing. Each noncompliant email can support a separate violation.

The harder compliance questions usually arise outside the email template. Enforcement often focuses on how a company classified mixed messages, synchronized suppression lists, identified the legal sender, and controlled agencies and affiliates that sent on its behalf.

Commercial and Transactional Messages

Under the CAN-SPAM Act, the full commercial-message rules apply when an email's primary purpose is the commercial advertisement or promotion of a commercial product or service. The CAN-SPAM Rule supplies the classification test.

A message containing only commercial content is commercial, and a message containing only qualifying transactional or relationship content is transactional. The transactional category covers content that completes or confirms an agreed transaction, provides warranty, recall, safety, or security information, reports on an account or ongoing commercial relationship, addresses a current employment relationship or benefit plan, or delivers goods, services, updates, or upgrades the recipient already has a right to receive, and the FTC reads those five categories narrowly.

Content and primary purpose control classification. In 2023, Experian Consumer Services agreed to pay $650,000 after the government alleged that emails described as important account information promoted products and omitted any opt-out mechanism. A customer's account or membership doesn't convert product promotion into account administration.

Mixed messages require a closer review, and the Rule provides two separate tests. When an email combines a promotion with transactional or relationship content, the message is commercial if a reasonable recipient would read the subject line as commercial or if the transactional content doesn't appear, in whole or substantial part, at the beginning of the body. When an email combines a promotion with other content that is neither commercial nor transactional, the applicable factors include the proportion of the message devoted to promotion, its placement, and how color, graphics, type size, and style highlight it.

The cleaner practice separates promotional content from receipts, security notices, shipping updates, and required account notices. A combined message should lead with the transactional content. The subject line and body then deserve review under the Rule's actual tests, because a promotion labeled as an account update keeps its commercial character and can add a separate deception issue.

The Federal Requirements

Header information comes first. The From, To, Reply-To, originating domain, email address, and routing information must be accurate and name a person or business that initiated the message, and this rule covers transactional and relationship messages too. A familiar display name can mislead when it names an unrelated company, conceals the sender, or uses a domain obtained through false pretenses. You should configure your marketing platform to preserve enough delivery data to establish who sent each message and connect it to the approved campaign.

Subject lines follow. A person can't send a commercial message with actual knowledge, or knowledge fairly implied from objective circumstances, that the subject line would likely mislead a reasonable recipient about a material fact concerning the message. A cold sales email labeled as a reply or an urgent account notice can cross that line when the recipient made no request and the message promotes a product. Preview text deserves review alongside the subject line, since CAN-SPAM governs the subject heading directly while the FTC Act and state deception laws can govern the email's broader presentation.

A commercial message must also identify itself clearly and conspicuously as an advertisement or solicitation. The statute prescribes no single label or location, and the disclosure must remain recognizable and readable in the delivered message. Prior affirmative consent removes only this identification requirement. The postal-address, opt-out notice, opt-out mechanism, and suppression duties all remain. Affirmative consent means express consent given in response to a clear and conspicuous request or at the recipient's initiative, and when another party will use the address, the consent request must disclose that transfer clearly and conspicuously.

Every commercial message must display a valid physical postal address, meaning the sender's current street address, a Post Office box accurately registered with the Postal Service, or a private mailbox accurately registered with a qualifying commercial mail receiving agency. A web address, an email address, or an unregistered mailbox doesn't satisfy the rule.

Commercial emails also require an opt-out mechanism. The message must explain clearly and conspicuously how the recipient can stop future commercial email from the sender, through a functioning reply address or another easy internet-based mechanism that remains capable of receiving requests for at least 30 days after transmission. A preference menu may let recipients stop selected categories, provided it also lets them stop all marketing from the sender, and the sender can't charge a fee, demand information beyond the email address and opt-out preferences, or require any step beyond a reply email or a visit to a single webpage.

A sender must honor an opt-out request within 10 business days. After that deadline, the sender and anyone acting for it can't send a commercial message covered by the request, and the sender can't sell, lease, exchange, or transfer the address after learning of the request except for compliance with CAN-SPAM or another law. A recipient can later give new affirmative consent. The statute allows the full 10 business days to process the request, while suppression as soon as the systems permit reduces the chance that a marketer, agency, or automated platform sends another message during that period.

Existing Customers and Purchased Lists

An existing customer, member, or subscriber can opt out of marketing. The relationship may support transactional messages, and it doesn't excuse promotional messages from the commercial-email rules.

CAN-SPAM generally follows an opt-out model, so a purchased list isn't automatically unlawful under federal law. Purchased lists can present substantial legal and operational risk. The Act imposes aggravated consequences on a sender who violates its rules using addresses harvested from sites that posted no-transfer notices or addresses generated through automated combinations, and state deception statutes, privacy laws, the seller's collection promises, contracts, and platform terms can impose separate restrictions.

Before using a third-party list, you should document the source, the collection notice, any consent language, transfer rights, the suppression process, and restrictions on use. You should verify independently how the vendor obtained the addresses.

Agencies, Affiliates, and Multiple Marketers

The promoted company can retain statutory exposure after hiring an email service provider, lead generator, agency, or affiliate. The FTC's current business guide states that regulators can hold both companies legally responsible, the one whose product a message promotes and the one that sends it.

Contracts help even though they don't eliminate statutory exposure. A complete vendor agreement identifies who approves campaigns, who maintains the suppression file, how quickly each party must transmit opt-out requests, which domains and sender names may be used, what records the vendor must retain, and what happens when a campaign fails review. Indemnity can allocate loss between contracting parties without barring government enforcement.

A single email can promote more than one company's products or websites. Under the CAN-SPAM Rule, each qualifying company counts as a sender unless one company qualifies for designation as the sole sender by meeting the Act's sender definition, appearing alone in the From line, and complying with the header, subject-line, opt-out, identification, and address requirements. Co-branded campaigns should settle that designation before launch, because when the designated sender falls short, every marketer in the message can face liability as a sender.

Enforcement and Penalties

Each separate email violating CAN-SPAM can result in a civil penalty of up to $53,088, the current inflation-adjusted maximum, and a court determines the penalty from the proven violations and applicable factors. Address harvesting, dictionary attacks, automated account creation, and unauthorized relaying can support aggravated penalties, and some conduct can also support criminal prosecution.

Ordinary recipients lack a general federal right to sue under CAN-SPAM. Section 7706 authorizes enforcement by the FTC and other specified regulators, state attorneys general in defined circumstances, and internet access services adversely affected by qualifying violations, while state laws can provide recipients with separate claims.

Verkada and Experian illustrate how enforcement can address email and consumer-protection allegations in the same case. In September 2024, Verkada agreed to pay $2.95 million to resolve allegations joining CAN-SPAM violations with separate data-security and deception claims under the FTC Act. The email allegations covered missing opt-out notices, missing valid postal addresses, and missed 10-business-day deadlines for honoring requests, and the penalty resolved the entire case rather than the email count alone. Experian's 2023 settlement addressed marketing messages sent to account holders without the required opt-out notice or mechanism. Together, the cases show that an established customer relationship and an account-themed wrapper leave all commercial-email duties in place.

State Email Deception Laws

CAN-SPAM preempts state laws written to regulate commercial email, except to the extent those laws prohibit falsity or deception, and it preserves generally applicable state laws, including contract, tort, trespass, fraud, and computer-crime rules. The falsity-or-deception exception can support private state claims that CAN-SPAM doesn't provide.

California's Business and Professions Code section 17529.5 applies to commercial email advertisements sent from California or to a California email address. It prohibits unauthorized use of a third party's domain, falsified or misrepresented headers, and subject lines the sender knows would likely mislead a reasonable recipient about a material fact. The Attorney General, an electronic mail service provider, or a recipient of an unsolicited commercial email advertisement may sue, and the statute authorizes actual damages or liquidated damages of $1,000 per unlawful email, subject to a $1 million per-incident cap and a reduction for defendants who implemented due-care practices.

Washington lawmakers rewrote the Commercial Electronic Mail Act this year after recent litigation. In Brown v. Old Navy (Wash. 2025), the Washington Supreme Court held that the statute covered any false or misleading information in a commercial email's subject line. The official Senate bill report summarized testimony reporting more than 100 CEMA lawsuits after June 2025, compared with eight lawsuits against retailers from enactment through June 2025. The legislature responded with amendments effective June 11, 2026. RCW 19.190.020 applies to commercial messages sent from a Washington computer or to an address the sender knows or has reason to know belongs to a Washington resident, and it now prohibits false or misleading subject-line information only when the sender has actual knowledge or knowledge fairly implied from objective circumstances. RCW 19.190.040 sets recipient damages at $100 or actual damages, whichever is greater, down from $500, and the amendments apply to actions filed on or after June 11, 2026, including actions based on earlier conduct.

Meeting the federal template requirements therefore sets only a baseline. State law separately covers deceptive acquisition, targeting, sender identity, and subject-line practices. After Brown, plaintiffs reportedly filed more than 100 CEMA lawsuits under the broader subject-line rule.

Compliance Operations and Evidence

Durable compliance depends on controls around the sender, the campaign, and the recipient rather than on a footer alone. Your approved templates should contain a fixed postal address, opt-out notice, and unsubscribe mechanism. Your sender identity and domain should match the promoted company. A campaign reviewer should examine the subject line, preview text, and body together before release.

A suppression process can cover the customer platform, email provider, sales tools, affiliates, and agencies, with defined timing for how quickly each system receives and applies a request. Testing the unsubscribe page without a logged-in account and checking whether spam filters block reply-based requests can expose failures before they generate complaints.

Evidence deserves the same discipline. Your records should include the campaign version, recipient source, send date, legal sender, From and Reply-To fields, subject line, body, postal address, opt-out steps, any consent record, the unsubscribe event, and the suppression timestamp, with vendor records showing the same facts.

Your team should classify recurring message types before use. Receipts, shipping notices, security alerts, account statements, newsletters, product announcements, renewal promotions, and win-back campaigns call for different treatment, and a coupon, cross-sell, referral offer, or product block added to a transactional template requires a fresh classification review. You should retest the whole chain after a platform migration or vendor change, since a compliant template can fail when an old integration bypasses the suppression file or a preference center stops recording requests.

CAN-SPAM compliance depends on truthful content and reliable operations together. An email can satisfy every visible requirement and violate the law because no one settled the sender designation, your team misclassified a mixed message, or one platform continued mailing after the legal deadline. You should connect campaign approval, recipient sourcing, vendor control, and suppression evidence before the first send.

This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.

Need advice tied to your business issue?

Share the issue. Get direct attorney review. Receive a concrete recommendation.

Submit an Inquiry