Are Cold Emails Legal in 2026? CAN-SPAM, GDPR & CASL Rules
Cold email is legal in most countries—if you follow the rules. Here's how CAN-SPAM, GDPR, and CASL actually work, plus a compliance checklist for 2026.

TL;DR
- Cold email is legal in the United States, the EU, the UK, Canada, and most other markets—but each region attaches conditions, and "legal" is not the same as "unregulated."
- In the US, CAN-SPAM permits unsolicited B2B email as long as you identify yourself, tell the truth, and honor opt-outs. There is no prior-consent requirement.
- In the EU and UK, GDPR and the ePrivacy rules are stricter: you need a lawful basis (usually legitimate interest for B2B), data minimization, and an easy opt-out.
- Canada's CASL is the toughest of the big three—it generally requires consent and carries penalties up to CA$10 million per violation.
- The fastest way to stay legal is operational, not legal: target real people at real companies, keep lists clean and verified, and make unsubscribing trivial.
This article is a practical compliance overview, not legal advice. For decisions that affect your business, consult a qualified attorney in the relevant jurisdiction.
Are cold emails legal at all?#
Short answer: yes, cold email is legal in nearly every major market—provided you follow that market's rules. Cold email is not the same as spam. Spam is unsolicited and deceptive, sent in bulk with hidden senders, fake subject lines, and no way to opt out. A targeted, honest, single message to a business contact who plausibly cares about your offer is a different animal, and the law treats it that way.
The confusion comes from lumping three separate questions together:
- Is sending the message legal? (Usually yes.)
- Is the way you collected the contact data legal? (Depends on the jurisdiction.)
- Will the message actually land in the inbox? (A deliverability question, not a legal one.)
Most "is cold email illegal?" panic is really about questions 2 and 3. Get your data sourcing and your sending hygiene right, and the legal question mostly takes care of itself. The sections below walk through the three regimes that cover the majority of B2B senders.
What does CAN-SPAM require in the United States?#
The US CAN-SPAM Act of 2003 is the governing law for commercial email, and it is surprisingly permissive. It does not require recipients to opt in before you contact them. You can legally send a cold email to a business prospect you have never spoken to. What CAN-SPAM regulates is how you send it.
The core duties are straightforward:
- Don't use false or misleading header information. Your "From," "To," "Reply-To," and routing details must identify the real sender.
- Don't use deceptive subject lines. The subject must reflect the content of the message.
- Identify the message as an ad where applicable (B2B outreach framed as a genuine 1:1 inquiry has more latitude here, but transparency is safest).
- Include a valid physical postal address.
- Provide a clear opt-out mechanism, and honor opt-outs within 10 business days. Once someone unsubscribes, you may not sell or transfer their address.
Penalties are real: the FTC can pursue statutory damages of up to $53,088 per individual email in violation (the figure is inflation-adjusted). You can read the official compliance guidance directly from the FTC's CAN-SPAM guide. The practical takeaway: in the US, cold email is legal by default, and compliance is mostly about honesty and a working unsubscribe link.
Is cold email legal under GDPR in Europe?#
This is where most senders get nervous, and where the nuance matters. GDPR does not ban cold email. It regulates the processing of personal data—and a work email address like jane.doe@company.com is personal data. So the question becomes: do you have a lawful basis to process that contact's data for outreach?
For B2B prospecting, the lawful basis is almost always legitimate interest (GDPR Article 6(1)(f)). Direct marketing is explicitly recognized as a potential legitimate interest in Recital 47. To rely on it, you should be able to show:
- A genuine business relevance—you're contacting someone whose role plausibly connects to your offer (a VP of Sales about a sales tool, not a random consumer).
- A balancing test: your interest doesn't override the person's rights and reasonable expectations.
- Transparency and easy opt-out in every message.
- Data minimization: you only hold what you need, and you can delete on request.
The wrinkle is the ePrivacy Directive, which individual EU states implement differently. Some countries (e.g., Germany, with stricter UWG rules) lean toward requiring consent even for B2B; others are comfortable with legitimate interest for role-based business contacts. The UK's PECR, post-Brexit, generally allows B2B cold email to "corporate subscribers" (companies and LLPs) without prior consent, while sole traders and partnerships get consumer-level protection.
If you want the primary source, the official GDPR text and summaries at gdpr.eu lay out the lawful-basis framework. The operational rule of thumb for Europe: target by role, keep messages relevant, never email consumer/personal addresses, document your legitimate-interest reasoning, and honor every opt-out instantly.
How do CAN-SPAM, GDPR, and CASL compare?#
The three regimes differ most on one axis: do you need consent before the first email? Here's the side-by-side.
| Attribute | CAN-SPAM (US) | GDPR / PECR (EU/UK) | CASL (Canada) |
|---|---|---|---|
| Prior consent required? | No | No for B2B (legitimate interest); document it | Generally yes (implied or express) |
| Lawful basis needed? | No | Yes — usually legitimate interest | Consent or a recognized exemption |
| Opt-out required? | Yes, honor within 10 business days | Yes, immediate and easy | Yes, honor within 10 business days |
| Sender identification | Required | Required | Required (name, address, contact info) |
| Physical address in email | Required | Best practice | Required |
| Max penalty | ~$53,088 per email | Up to €20M or 4% global revenue | Up to CA$10M per violation |
| Applies to B2C and B2B? | Both | Both (B2B contacts still personal data) | Both |
The pattern is clear: the US is the most permissive, the EU/UK sit in the middle (allowed but conditional on lawful basis and minimization), and Canada is the strictest. If you operate across all three, build to the highest standard—consent-aware, relevance-driven outreach with frictionless opt-outs—and you'll be compliant everywhere.
What does Canada's CASL demand?#
CASL (Canada's Anti-Spam Legislation) is the regime that turns cold email from "legal by default" into "legal with conditions." It applies to any commercial electronic message (CEM) sent to or accessed from a computer in Canada, so a US sender emailing a Canadian prospect is on the hook.
CASL generally requires one of two forms of consent before you send:
- Express consent — the recipient actively agreed to receive your messages.
- Implied consent — a recognized relationship exists, e.g., an existing business relationship, or the recipient conspicuously published their business email without a "no unsolicited mail" notice and your message relates to their role. This is the lane most B2B cold emailers use, and it has time limits.
On top of consent, every CEM must identify the sender, include valid contact information that stays live for at least 60 days, and provide a working unsubscribe that you honor within 10 business days. Penalties run up to CA$10 million per violation for organizations. The Canadian government's official CASL FAQ is the authoritative reference. Practically: if you email into Canada, lean on the conspicuously-published-business-address basis, keep messages tightly role-relevant, and treat opt-outs as sacred.
Does buying email lists make cold email illegal?#
Buying or scraping bulk lists is the single fastest way to turn a legal activity into a liability. Purchased lists collide with the law on multiple fronts at once:
- GDPR/CASL: you have no lawful basis or consent for contacts you didn't source yourself, and you can't honor data-subject rights you can't trace.
- CAN-SPAM: technically you can still send, but bought lists are riddled with spam traps, role accounts, and dead addresses that wreck deliverability.
- Accuracy: stale lists mean bounces, and high bounce rates get your domain throttled or blacklisted regardless of legality.
The compliant alternative is sourcing your own contacts—finding the right person at a target company and verifying that the address is real before you send. That's a data-quality discipline as much as a legal one. Using an email verifier to scrub addresses before a campaign protects both your compliance posture and your sender reputation. And building lists with a precise email finder—targeting named roles rather than spraying a purchased database—keeps your legitimate-interest argument defensible.
How do you send compliant cold email in 2026?#
Compliance is mostly a checklist you run before every campaign. Here's the operational version that satisfies CAN-SPAM, GDPR, and CASL simultaneously.
| Step | What to do | Why it matters |
|---|---|---|
| Target by role | Email named decision-makers whose job relates to your offer | Establishes legitimate interest / relevance |
| Source first-party data | Find and verify addresses yourself; never buy lists | Lawful basis + deliverability |
| Verify before sending | Run addresses through verification to cut bounces | Protects domain reputation, reduces spam-trap hits |
| Identify yourself | Real name, company, working reply-to, physical address | Required by CAN-SPAM and CASL |
| Be honest | Truthful subject line and body, no deception | Core of every anti-spam law |
| Make opt-out trivial | One-click unsubscribe in every message | Required everywhere; honor within 10 days |
| Suppress and document | Keep a do-not-contact list; log your reasoning | Proves compliance if challenged |
A few details that trip people up:
- An unsubscribe link is non-negotiable, even for B2B. "It's just a 1:1 email" is not a defense at scale.
- Honor opt-outs across your whole stack, not just one campaign. Maintain a global suppression list.
- Keep volumes human. Blasting thousands of identical messages from a cold domain is a deliverability problem that quickly becomes a reputation problem.
- Warm your domain and keep bounce rates low. Mailbox providers like Google and Microsoft increasingly treat high-bounce, high-complaint senders as spammers regardless of legal status. (For more on this, see how email deliverability interacts with list quality.)
If you're choosing tools or want benchmarks on accuracy, third-party review sites like G2's email-finder category are a neutral place to compare vendors before you commit.
What are the biggest cold email legal myths?#
A few persistent misconceptions are worth killing directly:
- "Cold email is illegal." False. It's legal in the US, EU, UK, Canada, and most markets when you follow the rules.
- "GDPR bans emailing Europeans." False. GDPR requires a lawful basis (usually legitimate interest for B2B) and good data hygiene—not silence.
- "If it's B2B, no rules apply." False. B2B contacts are still personal data under GDPR, and CASL covers business addresses too.
- "A purchased list is fine if I only email once." False on data-sourcing grounds in the EU/Canada, and a deliverability disaster everywhere.
- "An unsubscribe link is optional for personal-looking emails." False. Opt-out duties apply regardless of formatting.
The throughline: the law punishes deception, bulk indiscriminate sending, and ignoring opt-outs—not thoughtful, relevant, well-sourced outreach.
Cold email compliance, in one sentence#
Cold email is legal when you contact the right people, with honest messages, using data you sourced and verified yourself, and you make leaving easy. Everything else—CAN-SPAM, GDPR, CASL—is detail layered on top of those four habits. The senders who get into trouble are almost never the ones with a borderline legitimate-interest argument; they're the ones blasting bought lists with fake headers and broken unsubscribe links.
The compliant path also happens to be the effective one. Targeted, verified, role-relevant outreach gets better reply rates and keeps you on the right side of the law. That starts with building clean lists instead of buying dirty ones.
Ready to source contacts the compliant way? Use the Tomba Email Finder to find verified, role-specific business emails by name, company, or domain—so every message you send is targeted, accurate, and defensible. Pair it with verification before each campaign, keep your opt-outs clean, and your cold email program stays legal and lands in the inbox. See Tomba pricing to start on the free tier.
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author