CASL Cold Email Compliance: The 2026 Rules and Checklist
Sending cold email into Canada? CASL is stricter than CAN-SPAM and fines run to $10M. Here is what consent, ID, and unsubscribe rules actually require in 2026.

Canada's Anti-Spam Legislation (CASL) is one of the strictest email laws on the planet, and most cold email playbooks written for the US market quietly break it. If you send commercial email to anyone in Canada, CASL applies to you — regardless of where your company is based.
TL;DR#
- CASL is consent-first. Unlike the US CAN-SPAM, you generally need permission before you send a commercial email to a Canadian recipient — not just an opt-out afterward.
- Cold email is not automatically illegal in Canada, but it only works under narrow "implied consent" rules (existing business relationships, conspicuously published business addresses tied to a relevant role).
- Every message needs three things: valid consent, clear sender identification, and a working unsubscribe that you honor within 10 business days.
- Penalties are severe — up to CAD $10 million per violation for businesses, plus personal liability for directors and officers.
- Hygiene matters as much as law. Verified, role-relevant contacts reduce both legal risk and bounce-driven deliverability damage. Tools like the email verifier help you keep lists clean and targeted.
What is CASL and who does it apply to?#
CASL is Canada's federal anti-spam law, in force since 2014 and enforced by the CRTC (Canadian Radio-television and Telecommunications Commission). It governs "commercial electronic messages" (CEMs) — any message that encourages participation in a commercial activity, including the classic B2B cold email pitching your product.
The key trigger is the recipient's location, not yours. If a message is accessed by a computer in Canada, CASL is in play. A startup in Austin emailing a procurement lead in Toronto is subject to CASL even if it has never set foot in Canada.
Three obligations sit at the center of the law:
- Consent — you must have express or implied consent before sending.
- Identification — the recipient must be able to identify who sent the message and how to reach you.
- Unsubscribe — every CEM must include a functioning opt-out mechanism.
Miss any one of these and the message is non-compliant, even if the other two are perfect. You can read the official text and guidance directly on the Government of Canada's CRTC site.
How is CASL different from CAN-SPAM?#
This is where US-based senders get burned. CAN-SPAM (the US law) is permissive: you can email a cold prospect first, as long as you identify yourself, don't mislead, and offer an unsubscribe. CASL flips the default — no consent, no send.
| Attribute | CASL (Canada) | CAN-SPAM (United States) |
|---|---|---|
| Consent model | Opt-in (express or implied) required before sending | Opt-out — cold sending allowed |
| Cold email to new B2B prospect | Only under implied-consent exceptions | Generally permitted |
| Sender identification | Mandatory: name, mailing address, contact info | Mandatory: valid physical postal address |
| Unsubscribe deadline | Honor within 10 business days | Honor within 10 business days |
| Record-keeping | Must prove consent on request | No proactive consent records required |
| Max penalty | CAD $10M (business) / $1M (individual) per violation | ~USD $53,088 per email |
| Enforcement body | CRTC | FTC |
The practical takeaway: a campaign that is perfectly legal in the US can rack up six- and seven-figure exposure the moment it crosses into Canadian inboxes. If you run cold email across North America, you cannot treat the two countries as one list.
Is cold email legal under CASL?#
Yes — but only inside specific lanes. CASL recognizes two flavors of consent, and cold outreach lives entirely in the "implied" category.
Express consent is an active opt-in: the recipient checked a box, filled a form, or otherwise agreed to receive your messages. It does not expire on its own and is the gold standard. Pre-checked boxes do not count.
Implied consent is what makes B2B cold email possible. The two most useful forms for outreach are:
- Existing business relationship — the person bought from you, inquired, or had a contract with you within the last 24 months (or 6 months for an inquiry). This consent is time-limited.
- Conspicuous publication — the recipient has published their business email address publicly (on a company site, directory, or professional profile) without a statement saying they don't want unsolicited messages, and your message is relevant to their role or business.
That second exception is the legal backbone of compliant Canadian cold email. The relevance test is real: emailing a published cfo@company.ca about an accounting tool can qualify; blasting that same address about unrelated SEO services likely does not.
This is exactly why targeting precision matters. Pulling a generic scraped list and firing it at Canada is both legally risky and a deliverability disaster. Sourcing role-relevant, business addresses through structured domain search keeps your outreach inside the conspicuous-publication lane rather than outside it.
What must every CASL cold email contain?#
Beyond consent, the message itself has mandatory content. Treat this as a non-negotiable template skeleton for any email going to Canada.
- Sender identity. State who is sending on whose behalf. If you send for a client, name both parties.
- Physical mailing address. A current postal or street address, valid for at least 60 days after the message is sent.
- A second contact method. A working phone number, email, or web address.
- A functioning unsubscribe. It must be clearly worded, easy to use, and free. You then have 10 business days to stop sending.
- No misleading headers or subject lines. The "from," subject, and body must accurately represent the message.
Here is how the consent types and their requirements line up:
| Consent type | How you get it | Expires? | Cold email use |
|---|---|---|---|
| Express | Active opt-in (form, checkbox, signed agreement) | No (until withdrawn) | Best for nurture, not first touch |
| Implied — existing relationship | Purchase, contract, or inquiry | 24 months (6 for inquiry) | Re-engagement, upsell |
| Implied — conspicuous publication | Publicly posted business address + role relevance | While published & relevant | Primary lane for B2B cold email |
| No consent | — | — | Not permitted |
Keep the consent evidence. Under CASL the burden of proof is on the sender — if the CRTC asks why you emailed someone, "I assumed it was fine" is not a defense. Log where each address came from and why it qualified.
What are the penalties for getting CASL wrong?#
The numbers are designed to hurt. Maximum administrative monetary penalties run to CAD $10 million per violation for organizations and CAD $1 million for individuals. Crucially, CASL includes vicarious liability and director/officer liability — your company can be on the hook for an employee's or contractor's violations, and named executives can be personally liable.
Real enforcement has teeth. The CRTC has issued multi-hundred-thousand-dollar penalties against Canadian and foreign companies, including cases triggered by purchased lists and missing unsubscribe mechanisms. Settlements in the CAD $100,000–$200,000 range are common even for first offenses.
There is also reputational and deliverability fallout that never shows up in a fine. High complaint rates from unconsented sends tank your sender reputation, which mailbox providers like Google and Microsoft use to decide whether your compliant emails reach the inbox at all. One sloppy Canadian campaign can degrade an entire domain's deliverability.
How do you build a CASL-compliant cold email workflow?#
Compliance is a process, not a disclaimer line. Here is a practical sequence that keeps you inside the law while protecting deliverability.
- Segment by geography first. Tag Canadian recipients separately so they only ever receive CASL-treated campaigns. Never run a single blended North American blast.
- Qualify the consent basis for every contact. For cold prospects, confirm the address is conspicuously published and your offer is relevant to their role. Record the source URL.
- Verify before you send. Invalid and risky addresses inflate bounces and complaints — both of which draw regulatory and ISP attention. Run lists through an email verifier and screen catch-all domains so you are not guessing.
- Use a compliant template. Bake sender name, mailing address, second contact method, and unsubscribe into the footer of every send.
- Honor opt-outs fast and permanently. Process unsubscribes within 10 business days — automate it to be safe — and suppress those addresses across all future campaigns.
- Keep records. Maintain a consent log and an unsubscribe suppression list you can produce on demand.
For teams running outreach at scale, automating steps 2–4 through the Tomba API means consent-relevant sourcing and verification happen before a contact ever enters your sequencing tool — not after a complaint lands.
CASL cold email best practices for 2026#
The law hasn't loosened, and mailbox providers have only tightened. A few habits separate senders who scale cleanly from those who get throttled:
- Lead with relevance, not volume. The conspicuous-publication exception requires role relevance. Tightly targeted lists are both more compliant and higher-converting.
- Warm your domain and watch complaint rates. CASL exposure and deliverability damage travel together; a complaint spike is your earliest warning on both fronts.
- Refresh implied consent before it expires. A 24-month existing-relationship window quietly lapses — re-engage or convert to express consent before it does.
- Audit contractors and tools. Vicarious liability means your agency's shortcuts become your fines. Vet anyone sending on your behalf.
- Document everything. If you cannot prove consent, you do not have it.
Cold email into Canada is absolutely viable in 2026 — it just rewards precision over spray-and-pray. The senders who win treat CASL as a forcing function for better targeting rather than a wall.
Start with cleaner, more compliant lists#
CASL compliance begins long before you hit send — it starts with who is on your list and why they belong there. The fastest way to lower both your legal risk and your bounce rate is to source role-relevant, business email addresses and verify them before they enter a sequence. The Tomba Email Finder lets you find professional emails by domain, name, or company, so you can build targeted, conspicuous-publication-aligned lists instead of scraping indiscriminately. Pair it with verification, start free with 25 searches a month, and scale on a Tomba plan when your outreach grows. Compliant outreach and high deliverability are the same discipline — and it starts with a better list.
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author