Shadow Inbox/blog
Subscribe
← back to indexblog / cold email / is-cold-email-legal-can-spam
Cold Email

Is Cold Email Legal? What CAN-SPAM Actually Requires

The FTC just handed out its largest cold email fine ever. Here's what CAN-SPAM actually requires, verified against the FTC's own compliance guide.

A
ArthurFounder, Shadow Inbox
publishedSep 24, 2026
read6 min
Is Cold Email Legal? What CAN-SPAM Actually Requires

You wrote the sequence, loaded two hundred prospects into it, and your thumb is hovering over "launch" when a slower, more paranoid part of your brain asks a question you can't quite answer: is this actually legal? You search it and get nin

You wrote the sequence, loaded two hundred prospects into it, and your thumb is hovering over "launch" when a slower, more paranoid part of your brain asks a question you can't quite answer: is this actually legal? You search it and get nine blog posts from email tools with a financial interest in the answer being yes, all citing "the CAN-SPAM Act" with the confidence of people who have never opened it. Somewhere in the same search results, someone swears a founder got sued for cold emailing. Nobody links the actual law. You close eleven tabs and hit send anyway, which is roughly how most people arrive at this.

Here's the part that gets buried under all the FUD: the United States never adopted an opt-in rule for commercial email. Unlike the EU's consent-first model, CAN-SPAM runs on opt-out, meaning you're allowed to email a stranger commercially without asking first, as long as you follow what the law requires on every message. Cold email isn't a loophole you're exploiting. It's the default the law was written around.

$53,088Maximum FTC penalty per non-compliant commercial email
10 business daysDeadline to honor an opt-out request once it comes in
$2.95MLargest CAN-SPAM penalty the FTC has ever obtained, against Verkada in 2024
0Exceptions CAN-SPAM makes for B2B email or single one-to-one messages

That default comes with conditions, which is where most of the internet's confusion actually lives. Being legal by default doesn't mean anything you type into an outbound tool and hit send on is automatically compliant.

The law was written with zero interest in your B2B excuse

Every founder eventually has the same thought: this is B2B, one operator emailing another about a real product, surely that's different from consumer spam. The FTC's own compliance guide closes that door directly: the law "makes no exception for business-to-business email." It doesn't matter that your prospect has a company email address and a job title. It doesn't matter that you'd frame the message as a warm, specific note instead of a blast. The same guide is just as direct about volume: CAN-SPAM "doesn't apply just to bulk email," and defines a covered message by its commercial purpose, not by how many other people got the same one. A single, hand-written email to one prospect is fully in scope if the primary purpose is commercial. Neither exemption you were hoping for exists.

What the law actually asks you to do isn't complicated

Strip away the legal reading and CAN-SPAM's requirements fit on an index card: your From, To, and Reply-To fields have to be honest and route to a real inbox, your subject line has to describe what's actually in the email, and you need a valid physical postal address somewhere in the message, a street address, a registered PO box, or a registered private mailbox all count. You need a working opt-out mechanism that doesn't require a phone call, a login, or more than one click, and you have to honor an opt-out request within 10 business days and keep that option live for at least 30 days after you send. None of that requires a lawyer. Most of it is a checkbox in whatever sequencing tool you're already paying for, if you haven't switched it off.

In August 2024, the FTC announced a settlement requiring the security camera company Verkada to pay $2.95 million, the largest CAN-SPAM penalty the agency has ever obtained. The complaint wasn't about Verkada cold emailing prospects; sending commercial email to people who hadn't asked for it was never the violation. It was about what Verkada didn't do around it: over roughly three years and more than 30 million commercial emails, the company failed to give recipients a way to opt out, failed to honor the opt-out requests it did receive, and left out a physical postal address entirely.

Thirty million emails over three years without a working way to opt out. Not a clever growth hack. Just the largest CAN-SPAM penalty the FTC has ever handed anyone.

The per-email math should change how you think about volume, not just compliance

$53,088 is a per-message ceiling, with no cap on the total once you multiply it across a sequence. That number lands differently once you connect it to something this blog has argued from a completely different angle: spray-and-pray volume outbound stopped converting for anyone years ago. Now the same instinct, blast a list of two thousand cold contacts with an identical template and no working unsubscribe, isn't just a bad growth strategy. It's a liability that scales with exactly the thing you were trying to scale. A sequence built around genuine timing and volume discipline was already the better play for reply rates. It also happens to be the version that never puts you within shouting distance of a six-figure exposure over a missing footer link.

A compliance pass takes five minutes, and most tools already do half of it

Before your next sequence goes out, check four things. Confirm your Reply-To address is real and matches the domain you're sending from, the same hygiene that gets a message rejected outright by Outlook when it's missing. Confirm there's a physical address somewhere in the footer, most cold email platforms add this by default, but plenty of founders strip it out chasing a cleaner-looking template. Click your own unsubscribe link and confirm it actually removes the contact rather than just logging a request nobody processes. And if an agency or a tool is sending for you, ask them directly how they handle opt-outs, because the actual CAN-SPAM playbook only works if every hop in that chain honors the same rule you'd honor yourself.

None of this touches what happens once your list includes prospects in the EU or Canada, where consent rules and their own penalty regimes sit on top of anything CAN-SPAM requires. The legal breakdown of scraping Reddit for leads covers exactly where GDPR's rules kick in for outbound, and it's worth reading before you assume a US-compliant sequence is compliant everywhere your prospect list reaches.

● FAQ

Is cold email actually legal in the United States?
Yes. CAN-SPAM runs on an opt-out model, not opt-in, so the FTC's own compliance guide confirms you don't need a prospect's consent before emailing them commercially. Legality is conditional, not automatic: you have to meet the law's requirements on sender honesty, disclosure, and opt-out on every message you send.
Does CAN-SPAM apply to B2B cold email, or just consumer spam?
It applies to both. The FTC's compliance guide states plainly that the law makes no exception for business-to-business email. There's no carve-out for SaaS outbound, no carve-out for a founder emailing another founder. If the primary purpose is commercial, CAN-SPAM applies.
Does CAN-SPAM cover a single email, or only bulk campaigns?
A single email is covered. Per the FTC's guide, the law "doesn't apply just to bulk email" and defines a commercial message by its purpose, not its volume. One hand-typed sales email to one prospect is fully in scope if its primary purpose is commercial.
What happens if I skip the unsubscribe link or the physical address?
Those are two of the four specific failures the FTC cited when it fined Verkada $2.95 million in 2024, the largest CAN-SPAM penalty the agency has ever obtained. The company had sent more than 30 million commercial emails over three years without honoring opt-outs or including a postal address.
How much can one non-compliant cold email actually cost?
Up to $53,088 per violating email, per the FTC's inflation-adjusted maximum, and that cap applies per message, not per campaign. There's no ceiling on the total across a sequence, which is the detail most outbound tools don't put in their onboarding flow.
— share
— keep reading

Three more from the log.