The usual caveat. We build sending infrastructure, not legal advice. This is a practical summary; take proper advice for your situation.
CAN-SPAM is the United States rule for commercial email. It is often described as weak, which undersells it — it is permissive on consent and quite specific about everything else.
The headline difference from GDPR
CAN-SPAM does not require prior consent. You may send commercial email to someone who never asked for it, provided you meet the requirements and stop when they ask.
This is why cold outreach is a normal, legal business practice in the US and a considerably more constrained one in the EU and UK. It is also why "it's legal under CAN-SPAM" is an incomplete answer for anyone with international recipients — the applicable rules generally follow where the recipient is, not where you are.
What it actually requires
1. Accurate header information
The From, To, Reply-To and routing information must identify who actually sent the message. Falsifying any of it is a direct violation, and it is also the behaviour that domain authentication exists to make impossible.
2. A non-deceptive subject line
The subject must reflect the content. This is where prefixing a cold message with "Re:" to imply an existing conversation crosses from tacky into non-compliant — our subject line tester flags it as critical for exactly this reason.
3. Identify the message as an advertisement
Where the message is an advertisement and the recipient has not consented to receive it, that must be clear. The law allows flexibility in how, so an obviously promotional message that reads as one generally satisfies this.
4. A valid physical postal address
Every commercial message must include one — a street address, a registered PO box, or a private mailbox registered with a commercial mail receiving agency. This is the requirement most often missed, and the easiest for anyone to check.
5. A clear opt-out mechanism
Every message must explain how to stop receiving mail, in a way an ordinary recipient can find and use.
6. Honour opt-outs promptly
CAN-SPAM allows ten business days. Treat that as obsolete: Google and Yahoo require two days from bulk senders and enforce it by filtering your mail, which will hurt long before a regulator would. Process opt-outs automatically and immediately.
7. You remain responsible for work you outsource
Hiring an agency does not transfer liability. Both the business promoted and the party sending can be held responsible, so "our contractor did it" is not a defence.
What trips people up
The violations that occur in practice are rarely deliberate:
- No physical address, usually because a template was built without one and reused.
- Opt-outs processed manually in a weekly batch that slips.
- Opt-out honoured for one list but not others, so the recipient keeps hearing from you through a different campaign. Suppression must be account-wide.
- An opt-out that requires logging in or answering questions before it takes effect. It must work without conditions.
- A subject line that oversells to the point of being inaccurate.
Compliance and deliverability point the same way
Every CAN-SPAM requirement maps onto something that protects your sending reputation. Accurate headers are what authentication proves. Honest subject lines reduce complaints. A prominent opt-out means people unsubscribe instead of pressing the spam button — and an unsubscribe is invisible to mailbox providers while a complaint is a direct negative signal.
Treat the legal minimum as a floor rather than a target. The stricter standard, contacting only people plausibly interested and making it trivial to leave, is what actually keeps a domain sending.