What is CAN-SPAM?

CAN-SPAM, defined
CAN-SPAM is the United States law governing commercial email, which permits sending without prior consent as long as the message identifies itself honestly and offers a working opt-out.

The requirements are short. Accurate headers and sender identity, a subject line that is not deceptive, a physical postal address, disclosure that the message is an advertisement, and an opt-out honored within ten business days.

Penalties are per message and large, and liability reaches the company whose product is being promoted even when an agency pressed send. Outsourcing the campaign does not outsource the exposure.

There is no consent requirement, which is the genuine difference from European law. That gap is why a list-buying strategy can be legal in the United States and commercially disastrous anyway.

Transactional mail is largely exempt. A receipt or a password reset does not need an unsubscribe link, but adding marketing content to one moves it back under the rules.

How ZapBounce reports it

Compliance is about who you mail and what you say, not about whether a mailbox exists, so no verdict of ours speaks to it. A verified address can be one you have no legal basis to contact.

One cold email, checked line by line

Say you run marketing at Acme and your agency sends this on your behalf. The subject is Re: our call last week and the sender name is Jen at Acme. Inside is a pitch for your payroll software, a link to unsubscribe, and nothing else. There was no call.

The subject line fails first, since it implies a conversation that never happened. There's no postal address, which the law requires in every commercial message. A street address works, and so does a post office box registered with the postal service or a private mailbox at a registered commercial mail receiving agency. The unsubscribe link is fine if it keeps working.

Fixing it takes five minutes: an honest subject, a footer address, and a line saying it's a solicitation. Penalties run to more than $50,000 for each separate email in violation, so a 2,000-message campaign with a misleading subject isn't one offense. You and the agency are both exposed.

Commercial or transactional? The primary purpose test

Many of the messages you send will mix the two, such as an order confirmation with a discount code. The FTC's rule looks at primary purpose. If a reasonable reader of the subject line would think the message is an ad, it's commercial. It's also commercial if the transactional part doesn't appear at the beginning of the body.

So Your order has shipped with tracking details up top and a small offer underneath stays transactional. 20% off your next order (and your shipping update) doesn't. You've sent the same content in a different order and earned a different legal treatment.

Two assumptions are worth dropping before your next campaign. One is that business recipients are exempt, and the FTC says directly that they aren't: the law covers mail to companies as well as consumers. The other is that a purchased list is safe if the seller says it's compliant. Compliance attaches to each message you send, and no list arrives with it built in.

CAN-SPAM: common questions

Does CAN-SPAM require opt-in?

No. It requires honest identification and a working opt-out. Consent requirements come from GDPR, CASL and similar laws elsewhere.

Do transactional emails need an unsubscribe link?

Generally not. Receipts and account notices are exempt, unless you add promotional content to them.

Who is liable when an agency sends?

Both. The law reaches the business being promoted as well as the party that sent the message.

See this on your own list

100 free checks a month, and the unknowns come back labeled.