February 9, 20269 min read

What Is CAN-SPAM Compliance?

CAN-SPAM is a US law that sets requirements for commercial email. Compliance requires: accurate From/Reply-To headers, non-deceptive subject lines, identification as advertising (when applicable), physical postal address, clear unsubscribe mechanism, and honoring unsubscribes within 10 business days. Violations can result in penalties up to $51,744 per email.

The Seven CAN-SPAM Requirements

1. Accurate Header Information

2. Non-Deceptive Subject Lines

3. Identify the Message as an Advertisement

4. Include Physical Address

5. Provide Opt-Out Mechanism

6. Honor Opt-Outs Promptly

7. Monitor Third Parties

Penalties Are Serious

CAN-SPAM violations can cost up to $51,744 per violating email. A single non-compliant campaign to thousands of recipients creates massive liability. Compliance is not optional.

What CAN-SPAM Does Not Require

Prior Consent

Unlike GDPR, CAN-SPAM does not require opt-in consent before sending. You can email people who did not explicitly subscribe. However:

Transactional Email Exemptions

Transactional emails (order confirmations, password resets) are largely exempt from CAN-SPAM requirements—no unsubscribe needed, no advertisement disclosure. But they must still have accurate headers.

Unsubscribe Best Practices

Beyond Minimum Compliance

Preference Centers

Offer alternatives to full unsubscribe:

Physical Address Options

Acceptable Addresses

Remote Workers

If you work from home and do not want to share your address, use a registered business address service or PO Box.

Common Compliance Mistakes

Frequently Asked Questions

Does CAN-SPAM apply to B2B email?
Yes. CAN-SPAM applies to all commercial email sent to email addresses, whether B2B or B2C. The law does not distinguish between business and consumer recipients.
Can I send to purchased lists under CAN-SPAM?
Legally, yes—CAN-SPAM does not prohibit this. However, purchased lists generate high complaints, damage reputation, and often violate email platform terms of service. It is still a bad practice.
What if recipients are outside the US?
CAN-SPAM applies to commercial email sent from the US or by US companies. But international recipients may be protected by their own laws (GDPR, CASL) which are often stricter.
Are there exceptions for small businesses?
No. CAN-SPAM applies equally to businesses of all sizes. A one-person company sending commercial email must comply with all requirements.

Ensure Email Compliance

SortedIQ helps senders maintain compliance while maximizing deliverability.

Talk to Our Team