CAN SPAM Penalties Per Email: The Real Cost in 2026

Each non-compliant message can cost more than $50,000. Here is how CAN-SPAM penalties per email actually work in 2026 — and how to avoid them.

Jun 23, 2026 9 min read 2,061 words
CAN SPAM Penalties Per Email: The Real Cost in 2026

TL;DR

  • CAN SPAM penalties per email are charged one message at a time, not per campaign. The FTC's inflation-adjusted maximum now sits above $50,000 per individual message in 2026.
  • The law treats every recipient of a non-compliant email as a separate violation. So a single 10,000-address blast becomes a liability bomb.
  • You don't need bad intent to get fined. A missing physical address, a broken unsubscribe link, or a misleading subject line is enough.
  • The cheapest control is simple: don't send to bad data. Bounces, spam traps, and recycled addresses raise both legal and deliverability risk.
  • Keep evidence. Suppression lists, opt-out timestamps, and verification logs separate a warning from a settlement.

What are CAN SPAM penalties per email?#

The short version: each non-compliant commercial email can trigger a civil penalty of more than $50,000. The law counts violations one message at a time. That per-email math turns a sloppy campaign into six- or seven-figure exposure.

The CAN-SPAM Act of 2003 is the U.S. federal law for commercial email. When Congress wrote it, the maximum was $16,000 per violation. That figure is adjusted for inflation every year. By recent Federal Trade Commission adjustments, it has climbed past $51,000 per email. The FTC publishes the current number each year in the Federal Register.

Think of it like a parking meter that keeps getting pricier. The rule never changed, but the cost of ignoring it keeps rising.

Here's the part most marketers miss. The penalty attaches to the message, not the send. Blast a non-compliant offer to 5,000 inboxes, and regulators can treat that as 5,000 violations. You will rarely see the full maximum applied, because the FTC settles based on intent, scale, and cooperation. But the ceiling is what gives the agency leverage at the table.

Marketer tempted to switch from spam blasts to a verified workflow
Marketer tempted to switch from spam blasts to a verified workflow

Diagram: What are CAN SPAM penalties per email
Diagram: What are CAN SPAM penalties per email

How much is the fine, really?#

Conclusion first: plan for the low-to-mid tens of thousands of dollars per violating email as your worst case. Assume real settlements land lower, but still hurt. The exact statutory maximum is set by the FTC and rises with inflation. Always check the current figure on ftc.gov before you quote a number in a contract or policy.

The table below shows how the structure of the penalty drives your total exposure — not just the headline number.

Factor What it means Effect on total penalty
Per-email basis Each recipient of a bad message is a separate violation Multiplies linearly with list size
Statutory maximum FTC inflation-adjusted ceiling (> $50,000/email in 2026) Sets the negotiating ceiling
Aggravated violations Harvested addresses, dictionary attacks, false headers Can stack additional damages
Knowing vs. unknowing Intent and pattern of conduct Reduces or inflates the settlement
Other laws in play State statutes, wiretap/TCPA overlap, GDPR for EU contacts Adds parallel liability

A few practical notes on reading that table:

  1. List size is the multiplier. A 200-contact founder campaign and a 2-million-record blast share the same per-email rate. But the totals are worlds apart. Scale is risk.
  2. Address harvesting is the aggravator. Scraping the open web for addresses, or guessing them with a dictionary attack, is called out in the statute. It invites the harshest treatment. Sourcing matters as much as sending.
  3. Settlements, not maximums, are the norm. Published FTC cases have ranged from tens of thousands to over $900,000, and into the multi-million-dollar range for repeat or egregious actors. You negotiate down from a ceiling, not up from zero.
  4. CAN-SPAM is a floor, not a ceiling. Other regimes — and aggressive state laws — can apply on top of it.

Diagram: How much is the fine, really
Diagram: How much is the fine, really

Who enforces CAN-SPAM and who can actually sue you?#

The Federal Trade Commission is the primary enforcer, but it is not alone. State attorneys general can act on behalf of residents. Certain federal regulators police email in their own industries, such as banking and transportation. Internet service providers you harmed also have a private right of action.

What you, as an individual recipient, generally cannot do is sue a sender directly under CAN-SPAM. The law routes private enforcement through ISPs and government bodies. That detail lulls many senders into complacency: "no individual can sue me, so I'm fine." That's the wrong framing. The entities that can sue — the FTC and large mailbox providers — have deeper pockets and far more patience than any annoyed recipient.

The reputational and deliverability damage usually arrives long before any legal letter. By the time spam complaints spike enough to attract regulators, your sending domain is often already throttled or blocklisted. For the mechanics, our primer on email deliverability and sender reputation explains how inbox providers score you in real time.

What actually counts as a violation?#

CAN-SPAM compliance comes down to a handful of concrete, checkable rules. Break any one, and the message is a violation — no matter how good your intentions were. Here are the load-bearing requirements:

  • No deceptive headers. Your "From," "To," "Reply-To," and routing information must accurately identify who sent the message. Spoofing or disguising the originating domain is a top-tier violation.
  • No misleading subject lines. The subject must reflect the content. "Re: your invoice" on a cold pitch to someone you've never billed is exactly the kind of deception regulators target.
  • Disclose that it's an ad. Commercial messages must be identifiable as advertising. The standard is flexible, but the intent must be clear.
  • Include a valid physical postal address. A real, current street address or registered P.O. box is mandatory in every commercial email. This is the single most commonly missed requirement.
  • Offer a working opt-out. Every message needs a clear, functioning unsubscribe mechanism.
  • Honor opt-outs within 10 business days. Once someone unsubscribes, you have a hard deadline to stop. You can't charge them or make them log in to do it.
  • Police your vendors. If you hire an agency or use a sending tool, you are still legally on the hook. Outsourcing the send does not outsource the liability.

Drake meme rejecting purchased lists and approving verified contacts
Drake meme rejecting purchased lists and approving verified contacts

That last point deserves emphasis. The statute holds both the company whose product is promoted and the company that physically sends the email responsible. Picking a clean sending stack and clean data is a legal control, not just an operational one.

Why does email verification reduce your CAN-SPAM exposure?#

Because the fastest way to rack up per-email violations is to send to addresses you never had permission to use. Bad data is where unauthorized, harvested, and trap addresses hide.

Think of your list like a guest list at a private event. Let in everyone standing outside, and you'll eventually admit someone who was never invited — and you're responsible for them being in the room. Verifying addresses before you send is the bouncer checking names against the list.

Here's how clean data maps to specific CAN-SPAM and deliverability risks:

Data problem Compliance / deliverability risk Mitigation
Harvested or scraped addresses Aggravated CAN-SPAM violation Source from permission-based, documented data
Spam-trap addresses on the list Blocklisting + ISP legal standing Verify and remove unknown/risky addresses
High hard-bounce rate Reputation collapse, complaint spikes Pre-send email verification
Catch-all domains Unverifiable recipients, blind sends Use a catch-all verifier
No suppression of past opt-outs Direct 10-day-rule violation Maintain a synced suppression list

This is why a verification step belongs in every outbound workflow. Confirm an address is real, deliverable, and not a trap before you hit send. That shrinks the pool of messages that could ever count as violations. A clean list is both your deliverability insurance and your compliance evidence. Tools like a dedicated email verifier and a catch-all verifier exist to keep questionable addresses out of the send.

Where the address came from matters too. Pulling a contact from a public company domain via domain search is a defensible, documented method. Scraping a forum signature with a bot is the harvesting the statute punishes. Provenance is part of compliance.

Diagram: Why does email verification reduce your CAN-SPAM exposure
Diagram: Why does email verification reduce your CAN-SPAM exposure

Yes — and this surprises people. CAN-SPAM does not require prior opt-in consent the way the EU's GDPR-aligned rules do. Cold B2B outreach is legal in the United States, as long as every message meets the rules above: honest headers, an honest subject, clear identification, a physical address, and a working, promptly-honored opt-out.

The catch is jurisdiction. The moment your list includes recipients in the EU, UK, or Canada, you've stepped into stricter regimes:

Region Governing law Consent model Headline penalty
United States CAN-SPAM Opt-out (no prior consent needed) > $50,000 per email
Canada CASL Opt-in (express or implied consent) Up to CA$10M per violation
EU / EEA GDPR + ePrivacy Opt-in for most marketing Up to €20M or 4% of global revenue
United Kingdom UK GDPR + PECR Opt-in for most marketing Up to £17.5M or 4% of turnover

So "is cold email legal?" has no single answer. It depends entirely on where your recipients sit. A campaign that's fine for a Texas SaaS buyer can be a four-comma fine in a German inbox. Segment your lists by geography before you build your sending rules, not after.

If your outbound motion mixes phone and email, the same care applies to dialing. B2B phone outreach follows its own web of rules. Verified contact data from a phone validator keeps that channel as clean as your email.

Diagram: Is cold B2B email even legal under CAN-SPAM
Diagram: Is cold B2B email even legal under CAN-SPAM

How do you keep cold email compliant in practice?#

Here's the operational checklist I'd put on the wall of any outbound team:

  1. Source addresses you can defend. Use documented, permission-aware data and email-finding methods tied to real public business identities — not bulk scrapes. Keep a record of how each contact entered your system.
  2. Verify before every send. Run new contacts and re-validate aging lists. Hard bounces and traps are where both fines and blocklisting begin.
  3. Hard-code the static requirements. Your physical address and unsubscribe link should be template-level. Don't let a rep accidentally delete them. Remove the chance for human error.
  4. Automate suppression. The 10-business-day opt-out rule is unforgiving. Sync unsubscribes across every tool instantly. A manual spreadsheet will fail you eventually.
  5. Tell the truth in headers and subjects. No spoofing, no fake "Re:" threads, no bait subject lines. If the subject promises something the body doesn't deliver, that's a violation.
  6. Log everything. Opt-out timestamps, suppression records, and verification results are your defense file. In an FTC inquiry, "we have records" is the difference between a warning and a settlement.
  7. Audit your vendors. Whoever sends on your behalf shares your liability. Read their compliance posture before you sign.

Most of this fits inside your existing stack. Connect verification and enrichment to your CRM through native integrations, so the clean-data step runs automatically. Don't depend on a rep remembering it. Compliance that relies on discipline fails; compliance that's built into the pipeline holds.

For the legal text itself, the FTC's own CAN-SPAM compliance guide is the authoritative source. The broader history and scope of the statute is well summarized on Wikipedia's CAN-SPAM Act entry. When the stakes are real, read the primary source — don't rely on a blog's paraphrase, including this one.

What's the bottom line on CAN SPAM penalties per email?#

The number to remember is simple: more than $50,000, multiplied by every non-compliant message. You will rarely face the maximum. But the per-email structure means risk scales with how carelessly you send and how dirty your list is. The two cheapest controls — clean, well-sourced data and an automated opt-out process — are also the two biggest drivers of deliverability. Compliance and inbox placement are the same discipline wearing different hats.

If you do one thing after reading this, make it this: stop sending to data you can't vouch for. Tomba's Email Finder sources professional addresses from real, public business domains. It pairs every result with built-in verification, so the contacts entering your campaigns are deliverable, traceable, and defensible from day one. Start on the free tier (25 searches a month). When you scale, the Starter plan at $49/mo keeps your list — and your legal exposure — clean. The best CAN-SPAM defense isn't a lawyer. It's never sending the bad email in the first place.

Start your free trial

Ready to find emails that actually work?

Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.

Get the Tomba newsletter

Practical outbound tactics and product updates — once every two weeks.

Share
0 clapsEnjoyed it? Give a clap.
AU

About the author

Tomba Editorial Team

Was this helpful?

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.