Email Compliance in 2026: Laws, Risks, and Real Fixes

CAN-SPAM, GDPR, CASL and the Gmail/Yahoo sender rules all hit the same inbox. Here's what email compliance actually requires in 2026 — and the shortcuts that get teams fined or blocked.

Jul 31, 2026 10 min read 2,379 words
Email Compliance in 2026: Laws, Risks, and Real Fixes

TL;DR

  • Email compliance is not one law. It's a stack: CAN-SPAM (US), GDPR/ePrivacy (EU), CASL (Canada), PECR (UK), plus the Gmail and Yahoo bulk-sender requirements that act like law because they control whether you land in the inbox.
  • The US runs on opt-out. Canada and most of the EU run on opt-in or documented legitimate interest. Sending one template to a mixed-geography list is the single most common violation.
  • "B2B is exempt" is false almost everywhere. CASL covers B2B. GDPR covers firstname.lastname@company.com because it identifies a person. Only a narrow slice of EU corporate-role addresses gets softer treatment.
  • Penalties are real but rare; blocklisting is common and immediate. A 0.3% spam-complaint rate at Gmail costs you more revenue this quarter than any regulator will.
  • Compliance starts at data sourcing. If you can't explain where an address came from and prove it's deliverable, you can't answer a deletion request or defend a legitimate-interest assessment.

What is email compliance, actually?#

Email compliance is the set of rules governing who you may email, what you must tell them, and how fast you must stop when they ask. Think of it like driving: the speed limit (the law) is one thing, but the traffic cop who can pull you over tomorrow (Gmail, Yahoo, Microsoft) is what actually changes your behavior. Both matter. Only one of them will act within 48 hours.

There are three layers, and teams routinely confuse them:

  1. Statutory law — CAN-SPAM, GDPR, CASL, PECR, Australia's Spam Act. Enforced by regulators, slow, expensive when it lands.
  2. Mailbox provider policy — Gmail's sender guidelines, Yahoo's bulk sender rules, Microsoft's SNDS thresholds. Enforced by algorithms, instant, and far more likely to affect you.
  3. Contractual terms — your ESP's acceptable use policy. Instantly's, Smartlead's, HubSpot's, and Salesforce's terms all forbid purchased lists in ways stricter than the law.

You can be perfectly legal and still get your domain torched. You can also be technically inside your ESP's rules and still be breaking CASL. Compliance means passing all three.

Which laws apply to your cold emails in 2026?#

Jurisdiction follows the recipient, not you. A three-person startup in Austin emailing a marketing director in Berlin is subject to GDPR. Here's the map:

Law Applies to Consent standard Unsubscribe requirement Max penalty
CAN-SPAM (US) Any commercial email to a US recipient None — opt-out model Honor within 10 business days, no fee, no login wall Over $50,000 per email (FTC adjusts for inflation annually)
GDPR + ePrivacy (EU) Emails to identifiable EU individuals Consent, or documented legitimate interest for B2B Opt-out in every message plus honoring erasure requests €20M or 4% of global turnover
CASL (Canada) Any commercial electronic message to a Canadian address Express or implied consent, required before sending Working link, valid 60 days CAD $10M per violation (businesses)
PECR + UK GDPR Emails to UK recipients Soft opt-in for individuals; corporate subscribers get a lighter regime Opt-out in every message £500,000 under PECR, higher under UK GDPR
Spam Act 2003 (AU) Australian recipients Express or inferred consent Functional unsubscribe, honored in 5 business days AUD 2.2M per day for repeat offenders

Two practical takeaways. First, CAN-SPAM is the outlier — it's the only major regime where you can email a stranger with no prior relationship and be fine, provided you identify yourself and offer an exit. Second, CASL is the strictest, and it applies to B2B with no meaningful carve-out. If your list has .ca domains in it and you sent without consent, you're exposed.

Change my mind meme arguing that B2B cold email is not exempt from consent laws
Change my mind meme arguing that B2B cold email is not exempt from consent laws

Diagram: Which laws apply to your cold emails in 2026
Diagram: Which laws apply to your cold emails in 2026

It depends on where the recipient sits, and the answer is more nuanced than either the "cold email is illegal" crowd or the "B2B is exempt" crowd will tell you.

  1. United States — no consent needed. CAN-SPAM permits unsolicited commercial email. You need accurate headers, a non-deceptive subject line, a physical postal address, identification as an ad or solicitation, and a working opt-out. That's the whole test. The FTC's compliance guide is short enough to read in one sitting.
  2. EU — legitimate interest, documented. Article 6(1)(f) GDPR allows processing for legitimate interests, and Recital 47 explicitly names direct marketing. But you must run and record a three-part balancing test: is the interest legitimate, is the processing necessary, and do the recipient's rights override it? Emailing a VP of Sales about a sales tool passes far more easily than emailing a nurse about crypto.
  3. Canada — consent first, no exceptions. Implied consent exists (an existing business relationship, or a business email address published conspicuously without a "no unsolicited email" notice, where your message relates to their role). That published-address route is the legal basis most Canadian B2B outreach relies on. Document it per contact.
  4. UK — corporate subscribers get a break. PECR's consent rules bind "individual subscribers." Emails to a limited company's corporate addresses fall outside that, though UK GDPR still governs the personal data itself.
  5. Everywhere — role accounts are safer than personal ones. sales@acme.com carries less personal data than jane.mitchell@acme.com. That doesn't make it a free pass, but it changes the risk profile.

The honest summary: cold B2B email is legal in most of the Western world if you do the paperwork. Most teams skip the paperwork.

Diagram: Do you need consent to send B2B cold email
Diagram: Do you need consent to send B2B cold email

What must every commercial email actually contain?#

Strip away jurisdiction and there's a common denominator that satisfies nearly all of them at once. Build your template around these and you're compliant in the US, defensible in the EU, and close in Canada.

  • A truthful "From" name and domain. No spoofing, no lookalike domains, no noreply@ with an unrouted mailbox. Header accuracy is the one thing every regime agrees on.
  • A subject line that matches the body. "Re: our conversation" when there was no conversation is deceptive-subject-line territory under CAN-SPAM and the fastest route to a complaint.
  • A valid physical postal address. Street address, PO box registered to you, or a private mailbox from a Commercial Mail Receiving Agency. Missing address is the single most frequent CAN-SPAM defect.
  • A working, one-click opt-out. No login, no "reply with UNSUBSCRIBE only," no fee, no 12-field preference survey. Gmail and Yahoo now require List-Unsubscribe headers with one-click support for bulk senders.
  • Identification of the message as a solicitation when there's no prior relationship. A plain sign-off naming your company usually satisfies this.
  • Suppression within 10 business days — and in practice, immediately. Automate it; manual suppression lists fail at scale.

Add a sentence naming where you found them ("saw your talk at SaaStr," "found you via your company's team page") and you've also handled the GDPR transparency requirement about the source of the data.

Is compliance the same as deliverability?#

No, but they've converged so far that treating them separately is now a mistake.

Since the 2024 Gmail and Yahoo bulk-sender rules, anything above roughly 5,000 messages a day to those providers requires SPF, DKIM, and DMARC alignment, one-click unsubscribe, and a spam-complaint rate under 0.3%. Microsoft followed with its own thresholds for high-volume senders. These aren't laws — they're the terms on which the majority of B2B inboxes will accept your mail, which makes them functionally binding.

The overlap is that the behaviors that keep regulators away also keep filters away. Honest subject lines lower complaints. Fast suppression lowers complaints. Clean lists lower bounces. A sender with a 0.05% complaint rate and 1% bounce rate is almost never the one getting a regulator's letter.

Where they diverge: you can be flawlessly legal and still tank your email deliverability through bad infrastructure — no DMARC record, a cold domain sending 400 emails on day one, or a list where a third of the addresses no longer exist. Run an SPF checker before your first send and fix authentication once rather than debugging it after your reputation is gone.

Diagram: Is compliance the same as deliverability
Diagram: Is compliance the same as deliverability

How does data sourcing affect email compliance?#

This is where most teams actually fail, and it's upstream of everything else. If you can't answer "where did this address come from?" you cannot:

  • Run a legitimate-interest assessment (you don't know the source)
  • Respond to a GDPR erasure or access request within 30 days
  • Prove implied consent under CASL
  • Defend yourself if the address was scraped from a site with a no-unsolicited-email notice

Compare the common sourcing routes on the dimensions that matter legally:

Sourcing method Provenance you can document Bounce risk GDPR/CASL defensibility Typical ESP terms
Scraped from public sites, unverified Weak — no timestamp or source record High (20–40% on stale pages) Poor; no balancing test possible Usually prohibited
Purchased static list None you control; often resold Very high Poor — consent doesn't transfer to you Prohibited by most ESPs
Manual research (LinkedIn + company site) Strong but doesn't scale Medium Good Allowed
Email finder with source attribution + verification Strong — source, date, and validity per record Low (1–3%) Good; supports legitimate-interest documentation Allowed
Inbound opt-in (form, content download) Strongest — explicit consent record Lowest Best Always allowed

The middle rows are where the pragmatic answer lives. A tool that returns where an address was found and when it was last confirmed gives you an audit trail; a CSV bought from a broker gives you nothing. Tomba publishes its data sources and returns source URLs with results, which is the difference between "we found this on the company's public team page in March 2026" and a shrug.

Then verify before sending. An email verifier run cuts bounces to the low single digits, and bounce rate is the metric mailbox providers weight hardest. Catch-all domains need their own treatment — a catch-all verifier tells you whether the domain accepts everything or the mailbox genuinely exists, which stops you from mistaking "accepted" for "valid."

Bernie asking once again meme about verifying email lists before sending
Bernie asking once again meme about verifying email lists before sending

What does a compliant cold email look like?#

Concrete beats abstract. Here's a structure that satisfies CAN-SPAM outright, and gives you the GDPR transparency you need:

Subject: Question about Acme's Q3 outbound hiring

Hi Jane —

I saw Acme posted two SDR roles this month, which usually means list-building is about to become someone's full-time job. We help teams like yours cut that from days to hours.

Worth a 15-minute look, or should I check back next quarter?

— Dan, Tomba I found your details on acme.com/team. Not relevant? [Unsubscribe here] and I won't email again. Tomba, 1234 Market St, Suite 500, San Francisco, CA 94103

Four compliance elements, none of which cost you conversion: real name and company, source disclosure, one-click opt-out, postal address. The source line does double duty — it's a transparency requirement in the EU and it raises reply rates because it proves you did research.

What to remove: fake Re: prefixes, tracking pixels fired without disclosure in the EU, "you opted in to this" claims when they didn't, and unsubscribe links that route to a login page.

How do you build a compliance stack that survives audit?#

Six steps, in order. Skip none of them.

  1. Segment your list by recipient country before anything else. US contacts get the opt-out flow. EU, UK, and Canadian contacts get the consent-or-documented-interest flow. One template for all geographies is the root cause of most violations.
  2. Record provenance at import. Every contact row needs a source URL and a date. If your enrichment tool doesn't provide it, add the column manually. This is the single highest-leverage habit in the whole list.
  3. Write and file a legitimate-interest assessment. One page, covering the three-part test, per campaign type. Regulators ask to see it; having it is most of the defense.
  4. Authenticate and warm. SPF, DKIM, DMARC on the sending domain. Ramp volume over 3–4 weeks. A warmup calculator gives you a realistic schedule instead of a guess.
  5. Verify before every send, not just at import. B2B data decays roughly 2–3% per month as people change jobs. A list verified in January is meaningfully wrong by June.
  6. Automate suppression and honor it globally. One opt-out should suppress that address across every sequence, every domain, and every sending tool you own. Cross-tool leakage — where someone unsubscribes from Sequence A and gets Sequence B two weeks later — is both a violation and a complaint generator.

For deeper reading on how consent frameworks map to lifecycle marketing, HubSpot's GDPR resources are a reasonable vendor-neutral starting point, and the CRTC's CASL guidance is the authoritative source for Canada.

What are the most common email compliance mistakes?#

  • Assuming B2B exempts you. It doesn't in Canada, and only partially in the UK.
  • Using a PO box you don't actually control, or omitting the postal address entirely.
  • Treating "no bounce" as "valid." Catch-all domains accept everything, including addresses that go nowhere.
  • Buying a list and calling it enrichment. Consent obtained by a broker does not transfer to you under GDPR or CASL.
  • Sending from a domain you can't afford to lose. Use a dedicated sending domain, not your primary corporate one.
  • Manual unsubscribe handling. At any real volume, someone will get missed, and that's the one violation with a paper trail pointing straight at you.

Where should you start?#

Start with your data, because everything downstream inherits its problems. If you can't say where each address came from and whether it's currently deliverable, no template fix or DMARC record will save the program.

Tomba's Email Finder returns professional addresses with source attribution and a confidence score, backed by verification so your bounce rate stays where mailbox providers want it. The free tier gives you 25 searches a month to test provenance quality on your own target accounts; paid plans start at $49/mo, with full pricing details if you're scaling past manual research. Find the address, keep the receipt, verify it, then send something a human would actually want to read. That's the whole discipline.

Start your free trial

Ready to find emails that actually work?

Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.

Get the Tomba newsletter

Practical outbound tactics and product updates — once every two weeks.

Share
0 clapsEnjoyed it? Give a clap.
AU

About the author

Tomba Editorial Team

Was this helpful?

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.