CASL Email Compliance in 2026: The Complete Sender's Guide

CASL carries fines up to $10M per violation. Here's how express consent, identification, and unsubscribe rules actually work — and how to stay clean in 2026.

Jun 23, 2026 9 min read 1,986 words
CASL Email Compliance in 2026: The Complete Sender's Guide

CASL email compliance is not optional, even when you are based outside Canada. Canada's Anti-Spam Legislation (CASL) is one of the strictest commercial email laws on the planet. Most senders abroad do not realize it applies to them until a complaint lands. Email a single recipient in Canada, and you are inside CASL's reach. For an organization, the penalties run up to $10 million per violation.

This guide breaks down what CASL actually requires in 2026. It shows how the law differs from CAN-SPAM and GDPR. And it gives you the exact workflow that keeps your cold and marketing email compliant — without killing your pipeline.

TL;DR#

  • CASL is consent-first. Unlike the U.S. CAN-SPAM, you generally need express or implied consent before you send a commercial electronic message (CEM) to a Canadian recipient.
  • Three requirements, every message: valid consent, clear sender identification, and a working unsubscribe that's honored within 10 business days.
  • Fines are real and large: up to $10M per violation for businesses, $1M for individuals, and personal liability for directors and officers.
  • "I bought a list" is not a defense. Purchased lists almost never carry valid CASL consent, and the burden of proof is on you, the sender.
  • Hygiene protects you. Verifying addresses, documenting consent, and honoring opt-outs are the operational habits that keep you out of trouble and out of the spam folder.

What is CASL and who does it apply to?#

CASL is Canada's federal anti-spam law, in force since 2014 and enforced primarily by the Canadian Radio-television and Telecommunications Commission (CRTC). It governs any commercial electronic message — email, SMS, and some social messages — sent to or accessed from a computer in Canada.

The trap for international senders: CASL is jurisdiction-by-recipient, not jurisdiction-by-company. A SaaS founder in Berlin who emails a prospect in Toronto is bound by CASL the same as a Canadian company would be. There is no "we're not based in Canada" exemption.

A message is a CEM if one of its purposes is to encourage participation in a commercial activity. That includes cold outreach, newsletters, product announcements, and most "just checking in" sales follow-ups. Purely transactional or relationship messages (receipts, warranty info, responses to an existing request) have carve-outs, but they are narrow.

CASL vs CAN-SPAM vs GDPR consent showdown meme
CASL vs CAN-SPAM vs GDPR consent showdown meme

Wait — that's the meme below. Here's the first one:

Drake rejecting spam blasts and approving CASL-ready sending
Drake rejecting spam blasts and approving CASL-ready sending

What does CASL email compliance require for every email?#

Three things must be true for a compliant CEM. Miss any one and you have a violation.

  1. Consent — You have express or implied consent from the recipient before sending. This is the pillar that separates CASL from looser laws.
  2. Identification — The message clearly identifies who is sending it (legal or operating name) and includes a valid mailing address plus one other contact method (phone, email, or web form) that stays live for at least 60 days after sending.
  3. Unsubscribe — Every CEM contains a working unsubscribe mechanism that's easy to use, costs the recipient nothing, and is processed within 10 business days.

Those three are non-negotiable. The hard part — and where most violations start — is consent.

CASL recognizes two kinds of consent. Knowing which one you have determines what you can send and for how long.

Consent type How you get it How long it lasts Typical use
Express consent Recipient actively opts in (checkbox they tick, form they submit) for CEMs Indefinite, until withdrawn Newsletter signups, gated content opt-ins
Implied consent (existing business relationship) A purchase, contract, or inquiry in a defined window 24 months from a purchase; 6 months from an inquiry Following up with recent customers or leads
Implied consent (published address) Recipient conspicuously published a business email without a "no unsolicited mail" notice, and your message is relevant to their role Until they opt out B2B outreach to a published role-based contact
No consent Cold list, scraped emails, purchased data with no documented opt-in Not permitted Sending anyway = violation

The published-address path is the one B2B senders lean on for cold outreach — and it is legitimate, but conditional. The address must be conspicuously published (not behind a login or scraped from a spam-protected page). There must be no statement refusing unsolicited messages. And your message must be relevant to the recipient's business role. Emailing a CFO about your accounting tool can qualify; emailing that same CFO about a fitness product does not.

CASL also puts the burden of proof on the sender. If a complaint is filed, you must show you had consent. That means documentation — when, how, and what the recipient agreed to — is not optional paperwork. It is your legal defense.

Diagram: Express vs implied consent: what's the difference
Diagram: Express vs implied consent: what's the difference

How is CASL different from CAN-SPAM and GDPR?#

If you only know U.S. rules, CASL will surprise you. CAN-SPAM is opt-out: you can email first and stop when asked. CASL is opt-in: you generally need a lawful basis before the first send. GDPR overlaps on consent and data rights, but it is a privacy law, not an anti-spam law.

Dimension CASL (Canada) CAN-SPAM (USA) GDPR (EU)
Consent model Opt-in (express or implied) Opt-out Opt-in / legitimate interest
Applies based on Recipient location Sender + message Data subject location
Cold email to published B2B address Conditional (relevance + no refusal notice) Allowed with opt-out Legitimate interest, documented
Max penalty $10M per violation (org) ~$53,000 per email €20M or 4% global revenue
Burden of proof On the sender On the regulator On the data controller
Unsubscribe window 10 business days 10 business days Without undue delay

The practical takeaway: if you build your program to satisfy CASL, you are most of the way to CAN-SPAM and GDPR compliance too. CASL is effectively the strict ceiling for North American sending. For the privacy-law side, the GDPR overview on Wikipedia is a solid primer, and the official rules live at the Government of Canada's Fight Spam portal.

Diagram: How is CASL different from CAN-SPAM and GDPR
Diagram: How is CASL different from CAN-SPAM and GDPR

What are the penalties for getting CASL wrong?#

The headline number is $10 million per violation for a business and $1 million for an individual. The CRTC has issued multi-million-dollar penalties, and "violation" is counted aggressively — patterns of sending, not just single emails.

Three details make the risk worse than the sticker price:

  • Director and officer liability. Individuals who direct or acquiesce to violations can be held personally responsible.
  • Vicarious liability. You can be on the hook for what your agency, affiliate, or contractor sends on your behalf. "Our vendor did it" is not a shield.
  • No safe harbor for ignorance. Not knowing CASL applied to you is not a defense. The published guidance from the CRTC makes the obligations explicit.

A private right of action was drafted into CASL but remains suspended as of 2026. So class-action lawsuits aren't currently a vector, but regulatory enforcement absolutely is.

Sender tempted away from a bad purchased list toward Tomba
Sender tempted away from a bad purchased list toward Tomba

Diagram: What are the penalties for getting CASL wrong
Diagram: What are the penalties for getting CASL wrong

How do you keep cold and marketing email CASL-compliant?#

Compliance is mostly operational discipline. Here's the workflow that holds up.

1. Source contacts you can defend. Stop buying lists. A purchased list almost never carries documented consent, and CASL puts the proof on you. Build your list from inbound opt-ins and from accurate, role-relevant B2B data you can justify under the published-address path. A quality email finder that returns professional, role-based addresses with source attribution beats a scraped dump every time.

2. Verify before you send. Sending to dead or wrong addresses inflates bounce rates, wrecks your sender reputation, and increases the odds you're hitting someone who never should have been on your list. Run addresses through an email verifier so your list is both legal and deliverable.

3. Document consent at the moment you get it. Store the timestamp, the method (form URL, checkbox text), and the scope of what the person agreed to. If you rely on an existing business relationship, log the purchase or inquiry date so you can prove you're inside the 24-month or 6-month window.

4. Identify yourself in every message. Legal/operating name, a valid physical mailing address, and at least one more contact channel. Put it in the footer of every CEM — including the first cold email.

5. Make unsubscribe effortless and instant-ish. One click or one reply, no login wall, no "log in to manage preferences" maze. Process it within 10 business days — but tooling that honors it immediately is safer and looks better.

6. Suppress and audit continuously. Maintain a master suppression list across all sending tools. Re-verify aging lists, and keep consent records for at least three years in case of a complaint.

Here's a fast self-check before any campaign goes out:

  • Consent: Do I have express or implied consent for every recipient, and can I prove it?
  • Relevance: For published-address sends, is my message tied to the recipient's business role?
  • Identification: Is my legal name + mailing address + contact channel in the footer?
  • Unsubscribe: Is there a working, free, one-step opt-out?
  • Hygiene: Has this list been verified and de-duplicated recently?
  • Records: Is my consent documentation stored and retrievable?

If you can answer yes to all six, you are in strong shape under CASL.

CASL email compliance checklist diagram for cold and marketing email
CASL email compliance checklist diagram for cold and marketing email

Does verifying emails actually help with compliance?#

Yes — indirectly but meaningfully. CASL doesn't mandate verification, but verification supports nearly every requirement around it.

Clean data means fewer messages to invalid or abandoned addresses, which lowers complaint and bounce rates. Low complaint rates keep you off blocklists and protect email deliverability. A sender with strong deliverability and clean lists looks nothing like a spammer to a regulator or a mailbox provider. Documentation, verification, and suppression are the same habits that keep you out of the junk folder and out of a CRTC file.

This is also where good tooling pays for itself. Manually maintaining consent records, suppression lists, and verification across thousands of contacts is error-prone. Platforms that combine accurate sourcing with built-in verification — and transparent data sources — reduce the surface area where a compliance mistake can creep in. Compare what that costs against a single CASL penalty and the math is not close; you can review Tomba pricing to see where verification fits your volume.

What are the most common CASL mistakes?#

  • Assuming CASL doesn't apply because you're not Canadian. It applies by recipient, full stop.
  • Treating "implied consent" as permanent. The 6-month and 24-month clocks expire. Re-confirm or stop.
  • Relying on pre-checked boxes. Express consent must be an active opt-in; a pre-ticked box is not valid.
  • Forgetting identification on cold emails. Even your very first outreach email needs the sender identification block.
  • Slow or broken unsubscribe. A link that 404s or a process that takes weeks is a violation in itself.
  • No records. Without documentation, you cannot meet the burden of proof — which means you lose by default.

Final word: build the program, not just the campaign#

CASL email compliance isn't a checkbox you tick before a single send. It's a standing operating system for how you collect, verify, document, and retire contacts. Senders who treat consent and hygiene as core infrastructure send less spam, land in more inboxes, and never have to scramble when a complaint arrives.

Start with the data. If your list is built from accurate, role-relevant, verifiable contacts instead of bought rows of guesses, every downstream CASL requirement gets easier. The Tomba Email Finder returns professional email addresses by name, domain, or company with source attribution and built-in verification — so the list you build is the list you can defend. Try it free with 25 searches a month, and keep your outreach both compliant and in the inbox.

Start your free trial

Ready to find emails that actually work?

Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.

Get the Tomba newsletter

Practical outbound tactics and product updates — once every two weeks.

Share
0 clapsEnjoyed it? Give a clap.
AU

About the author

Tomba Editorial Team

Was this helpful?

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.