What Can Spam Penalties Cost You in 2026? Fines & Rules

CAN-SPAM penalties can hit roughly $53,000 per email. Here's what triggers fines in 2026, how the FTC enforces the law, and the checklist that keeps you safe.

Jun 23, 2026 10 min read 2,206 words
What Can Spam Penalties Cost You in 2026? Fines & Rules

What Can Spam Penalties Cost You in 2026? Fines & Rules

Most senders never stop to ask what can spam penalties actually cost a business. Sending commercial email in the U.S. without knowing CAN-SPAM is like driving with no idea of the speed limit. You may be fine for years. Then one enforcement action wipes out a quarter of your revenue. The fines are charged per email. So a single bad campaign to a small list can expose you to seven-figure liability.

This guide breaks down what CAN-SPAM penalties look like in 2026. You'll see what triggers them, who actually gets sued, and the checklist that keeps your cold email and marketing out of trouble.

TL;DR#

  • CAN-SPAM penalties are assessed per individual email — up to roughly $53,000 per message under the FTC's inflation-adjusted 2026 figure.
  • The most common triggers are deceptive subject lines, missing physical addresses, no working unsubscribe, and ignoring opt-out requests within 10 business days.
  • You are liable even if a vendor sends for you — "the marketer made me do it" is not a defense, and both parties can be held responsible.
  • There is no private right to sue for most individuals; enforcement comes from the FTC, state attorneys general, and ISPs.
  • Compliance is cheap insurance: a clean sender setup, accurate headers, and a verified list cost far less than one settlement.

What are CAN-SPAM penalties?#

CAN-SPAM penalties are civil fines for breaking the CAN-SPAM Act of 2003, the U.S. law for commercial email. The Federal Trade Commission and other enforcers impose them. The number that scares people is the per-email amount. With the FTC's inflation adjustments, each email in violation can cost up to about $53,000 in 2026.

That "per email" structure is what makes the math scary. Send one bad blast to 5,000 prospects, and each message is a separate violation. Courts rarely stack penalties to the maximum. But the exposure is real. It gives the FTC huge leverage in any settlement.

Think of CAN-SPAM as a checklist of duties, not a single rule. Break any one of them and the email becomes a violation. Good intentions don't matter.

What can spam penalties look like: no opt-out vs compliant
What can spam penalties look like: no opt-out vs compliant

The core duties CAN-SPAM imposes#

The law is built around a handful of obligations. Miss any of these and you have created exposure:

  1. Don't use false or misleading header information. Your "From," "To," "Reply-To," and routing details must accurately identify who sent the message.
  2. Don't use deceptive subject lines. The subject must reflect the actual content of the email — no bait-and-switch.
  3. Identify the message as an ad where required, clearly and conspicuously.
  4. Include a valid physical postal address. A current street address, registered PO box, or commercial mail-receiving agency all qualify.
  5. Offer a clear way to opt out, and honor every opt-out request within 10 business days.
  6. Monitor what others do on your behalf. If you hire an agency or use a sending tool, you remain responsible.

Diagram: What are CAN-SPAM penalties
Diagram: What are CAN-SPAM penalties

How much can spam penalties cost in 2026?#

How much can spam penalties cost? Short answer: up to roughly $53,000 per email, adjusted each year for inflation by the FTC. The figure keeps climbing. It was about $43,792 in 2020 and has risen every year since. So always check the current FTC notice before you quote an exact number in a contract.

But the per-email maximum is only one layer. Here is how the financial picture actually stacks up.

Penalty layer What triggers it Typical exposure
Per-email civil penalty Each non-compliant message Up to ~$53,000 per email (2026)
Aggravated violations Harvesting addresses, dictionary attacks, automated account creation Additional damages on top of base penalty
State AG actions Same conduct, pursued under state law Varies; often statutory per-email amounts
ISP/mailbox lawsuits Provider whose system you abused Negotiated damages, often large settlements
Criminal liability Fraud, falsified headers, hacking-style sending Fines plus prison in egregious cases
Reputation + deliverability loss Blocklisting, domain damage Lost revenue, hard to quantify

Founders often miss the cost in that last row. Even if you never pay a fine, a blocklisted domain can cripple your pipeline for months. That's what happens when you send like a spammer. So list hygiene and a clean setup matter as much as the legal text. Pair both with solid email deliverability habits.

Diagram: How much are CAN-SPAM penalties in 2026
Diagram: How much are CAN-SPAM penalties in 2026

What actually triggers CAN-SPAM penalties?#

Enforcement actions almost never come out of nowhere. They cluster around a few predictable mistakes. If you audit your own program against this list, you will catch the vast majority of risk.

  • Broken or missing unsubscribe. The opt-out link 404s, requires a login, or asks for more than an email address. The mechanism must work for at least 30 days after sending and process requests within 10 business days.
  • Ignoring opt-out requests. Someone unsubscribes and still gets mail two weeks later. This is one of the easiest violations for regulators to prove because the evidence is in the recipient's inbox.
  • No physical address. A surprising number of cold emails simply omit it. There is no excuse — a registered PO box is enough.
  • Deceptive subject lines and "From" names. "Re: our call yesterday" when there was no call, or a "From" name impersonating a colleague.
  • Selling or transferring an opted-out address. Once someone opts out, you cannot pass their address along.
  • Address harvesting. Scraping addresses indiscriminately or using software to generate combinations is an aggravated violation that increases penalties.

That last point is where how you source contacts becomes a compliance issue, not just a productivity one. Harvesting raw addresses off the open web is exactly the behavior the statute punishes harder. Using a permission-aware tool that returns verified, business-context email addresses — rather than a scraper that grabs everything — keeps your top of funnel on the right side of the line.

Sender choosing verified Tomba leads over a spam list
Sender choosing verified Tomba leads over a spam list

Diagram: What actually triggers CAN-SPAM penalties
Diagram: What actually triggers CAN-SPAM penalties

Who enforces CAN-SPAM, and who gets sued?#

A common myth is that any annoyed recipient can sue you under CAN-SPAM. For most individuals, that is false — the Act does not create a broad private right of action. Enforcement instead comes from a defined set of players:

  • The Federal Trade Commission (FTC) — the primary enforcer, and the agency that publishes the penalty amounts. The FTC's own CAN-SPAM compliance guide is the canonical reference.
  • State attorneys general, who can bring actions on behalf of residents.
  • Internet service providers and mailbox providers adversely affected by violations — these are the lawsuits that have produced some of the largest settlements, because providers have standing and resources.
  • Other federal agencies for entities they regulate (banking regulators, for example).

The pattern in real cases is instructive: enforcers tend to go after repeat, deliberate, high-volume senders, or businesses whose practices are flagrant — falsified headers, deceptive offers, or willful disregard of opt-outs. A small team sending honest, well-labeled outreach with a working unsubscribe is a low-priority target. The senders who get burned are the ones treating volume as a substitute for relevance.

Is cold email illegal under CAN-SPAM?#

No — and this is the single most misunderstood point. CAN-SPAM does not require prior opt-in consent. Unlike the EU's GDPR or Canada's CASL, the U.S. law permits sending commercial email to people who never asked for it, provided you follow the rules: truthful headers, honest subject lines, a physical address, a working opt-out, and prompt honoring of opt-outs.

In other words, cold B2B outreach is legal in the United States when done correctly. The law is about honesty and respect for opt-outs, not about consent. That is a meaningfully different bar than the one many marketers assume.

That said, "legal" and "deliverable" are not the same thing. Mailbox providers apply their own spam filters that are far stricter than the statute. You can be perfectly CAN-SPAM compliant and still land in spam if your sender reputation is weak or your list is full of dead addresses. Compliance is the floor; deliverability is the ceiling.

CAN-SPAM vs GDPR vs CASL at a glance#

Dimension CAN-SPAM (US) GDPR (EU) CASL (Canada)
Consent model No opt-in required Opt-in / legitimate interest Express or implied consent
Max penalty ~$53,000 per email Up to €20M or 4% global revenue Up to C$10M per violation
Unsubscribe Required, honor in 10 days Required, easy withdrawal Required, honor in 10 days
Physical address Required Identity disclosure required Sender identification required
Private lawsuits Generally no Yes Limited

If you send across borders, you must satisfy the strictest law that applies to each recipient — not just CAN-SPAM. A single international list can pull you under all three regimes at once.

Diagram: Is cold email illegal under CAN-SPAM
Diagram: Is cold email illegal under CAN-SPAM

How do you avoid CAN-SPAM penalties? (Compliance checklist)#

Staying compliant is mostly operational discipline. Work through this checklist before any commercial send, and bake it into your sending tooling so it is automatic rather than a thing you remember.

  • Use accurate header and "From" information. Your sending domain and name must truthfully identify you.
  • Write subject lines that match the body. No clickbait that misrepresents content.
  • Include your physical postal address in every commercial email's footer.
  • Add a one-click, no-login unsubscribe and keep it live for at least 30 days.
  • Process opt-outs within 10 business days — automate suppression so it is instant, not manual.
  • Suppress globally. An unsubscribe from one campaign should suppress the address across all of them.
  • Verify your list before sending. Bouncing into dead and spam-trap addresses is what damages reputation and draws scrutiny. Run addresses through an email verifier first.
  • Source contacts responsibly. Use a permission-aware email finder that returns verified business addresses instead of scraping the open web.
  • Document your process. If a regulator ever asks, you want evidence that compliance is systematic.

The thread running through all of this: the cleaner your data, the lower your risk. Most CAN-SPAM and deliverability problems trace back to bad lists — addresses that were harvested, never verified, or never wanted the mail. Fix the input and the rest gets dramatically easier. If you're sourcing at scale, a bulk email finder with built-in verification removes the temptation to cut corners.

What does a CAN-SPAM violation cost in practice?#

In theory, ~$53,000 per email. Reality is messier, because almost every case settles. Historic FTC settlements have ranged from tens of thousands of dollars for smaller operators to multi-million-dollar resolutions for large, deliberate offenders. The settlement amount typically reflects:

  • Volume — how many emails went out
  • Intent — accidental footer omission vs. willful header falsification
  • Cooperation — whether you fixed the problem when notified
  • Aggravating conduct — harvesting, fraud, or repeat behavior

For most legitimate businesses, the realistic worst case is not a record-breaking fine — it is the combination of legal fees, a consent decree that imposes ongoing monitoring, and the deliverability damage that follows public enforcement. None of that is worth saving the ten minutes it takes to add an unsubscribe link and verify a list.

For a sense of how authoritative sources frame the business risk, the U.S. Small Business Administration and industry analysts at G2 both treat email compliance as a baseline operational requirement rather than an optional nicety. Treat it the same way.

Frequently asked questions#

How much can spam penalties cost per email? Up to roughly $53,000 per message in 2026. The FTC adjusts that cap each year for inflation, so check the latest notice before you quote a figure.

Does CAN-SPAM apply to B2B email? Yes. The law applies to any "commercial electronic mail message," and there is no blanket exemption for business-to-business mail. Transactional or relationship messages have lighter requirements, but promotional B2B email is fully covered.

Is one missing physical address really a violation? Yes — the physical address requirement is one of the bright-line rules. It is also one of the easiest to fix, which is why omitting it looks careless to enforcers.

Can I be penalized for what my email vendor does? Yes. CAN-SPAM holds both the company whose product is promoted and the party sending the mail responsible. You cannot fully outsource liability, so vet your tools and partners.

How fast must I honor an unsubscribe? Within 10 business days. Practically, automate it so suppression is immediate — manual processing is where deadlines slip.

Stay compliant by starting with clean, verified data#

CAN-SPAM penalties almost always start upstream, with a bad list. Scraped addresses, unverified contacts, and spam traps are what turn an ordinary campaign into an enforcement risk and a deliverability disaster. Fix the source and most of your compliance burden disappears.

That is exactly where Tomba's Email Finder earns its place in your stack. It returns verified, business-context email addresses with confidence scoring — so you build outreach lists from real, reachable people instead of harvesting the open web. Pair it with built-in verification and you ship campaigns that are both CAN-SPAM-friendly and far more likely to actually land in the inbox. You can start on the free tier (25 searches/month) and scale up through transparent Tomba pricing as your sending grows. Clean data is the cheapest compliance insurance you will ever buy.

Start your free trial

Ready to find emails that actually work?

Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.

Get the Tomba newsletter

Practical outbound tactics and product updates — once every two weeks.

Share
0 clapsEnjoyed it? Give a clap.
AU

About the author

Tomba Editorial Team

Was this helpful?

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.