Cold Email Compliance in 2026: Laws, Rules & Best Practices
Cold email is still legal in 2026 — if you follow the rules. Here's how CAN-SPAM, GDPR, and CASL actually work, plus a compliance checklist that protects deliverability.

Cold email is one of the most cost-effective channels in B2B — and one of the easiest to get wrong legally. Send the wrong message to the wrong list in the wrong country, and you are not just hurting your open rates. You are exposing your company to fines that start in the thousands and climb into the millions.
The good news: cold email compliance is not complicated once you understand which laws apply to you and what each one actually demands. This guide breaks down the rules that matter in 2026, compares the major frameworks side by side, and gives you a checklist you can run before every send.
TL;DR#
- Cold email is legal in the US, EU, Canada, and most markets in 2026 — provided you follow the relevant law (CAN-SPAM, GDPR, CASL, or PECR).
- The US is permission-optional; the EU and Canada are permission-first. CAN-SPAM lets you email first and opt out later; GDPR and CASL generally require a lawful basis or consent before the first send.
- Every compliant email needs three things: accurate sender identity, a truthful subject line, and a working one-click unsubscribe.
- Penalties are real: up to $53,088 per email under CAN-SPAM, up to €20M or 4% of global turnover under GDPR.
- Compliance and deliverability overlap. Clean lists, verified addresses, and honest copy keep you both legal and in the inbox.
What is cold email compliance?#
Cold email compliance means sending unsolicited commercial email in a way that satisfies the data-protection and anti-spam laws of the recipient's jurisdiction. Think of it like driving across borders: the car is the same, but the speed limit, the side of the road, and the paperwork change the moment you cross into a new country.
A "cold" email is one sent to someone who has not explicitly asked to hear from you — a prospect you found through research rather than a subscriber who filled out a form. That lack of prior relationship is exactly why regulators pay attention. Compliance is the set of guardrails that keeps legitimate outreach separate from spam.
The three pillars regulators care about are consistent across almost every law:
- Identity — the recipient must know who you really are.
- Honesty — the subject line and body cannot deceive.
- Control — the recipient must be able to make you stop.
Everything else is jurisdiction-specific detail layered on top.
Is cold email legal in 2026?#
Yes — cold email is legal in 2026 in the United States, Canada, the United Kingdom, the European Union, Australia, and most other markets. What changes is the condition attached to that legality.
In the US, you can email a B2B prospect you have never spoken to, as long as you identify yourself, tell the truth, and honor opt-outs. In the EU and Canada, you generally need a lawful basis (often "legitimate interest" for B2B) or explicit consent before you hit send. The act of cold emailing is not banned anywhere mainstream — but the EU and Canada treat the recipient's data as something you must justify holding in the first place.
The mistake teams make is assuming one country's rules cover the world. If your list mixes US, German, and Canadian contacts, you are subject to three different regimes simultaneously. Segment by geography before you write a single line of copy.
What does CAN-SPAM require?#
CAN-SPAM is the US federal law governing commercial email. Despite the name, it does not require opt-in consent — it sets rules for how you send, not whether you may send. The FTC's official CAN-SPAM compliance guide is the canonical source, and the requirements are refreshingly concrete:
- Don't use false or misleading header information. Your "From," "To," and routing details must accurately identify who sent the message.
- Don't use deceptive subject lines. The subject must reflect the content of the message.
- Identify the message as an ad where appropriate — though clear B2B outreach has more latitude here.
- Tell recipients where you are located. A valid physical postal address is mandatory.
- Tell recipients how to opt out, and honor opt-out requests within 10 business days.
- Monitor what others do on your behalf. If you hire an agency, you are still legally responsible.
CAN-SPAM applies per email, and the maximum civil penalty has been inflation-adjusted to $53,088 per individual email as of recent FTC updates. Send a 5,000-person blast with a fake "From" address and the math gets terrifying fast.
How is GDPR different from CAN-SPAM?#
GDPR flips the default. Where CAN-SPAM lets you email first and stop on request, the EU's General Data Protection Regulation treats a prospect's email address as personal data you must have a lawful basis to process before you ever contact them.
For B2B cold email, that basis is usually legitimate interest — you can argue that promoting a relevant product to a relevant decision-maker is a reasonable use of business contact data. But legitimate interest is not a free pass. You must document a Legitimate Interest Assessment, offer an easy opt-out, and stop immediately if asked. You also cannot email personal addresses (like a Gmail account) under the same logic you'd use for name@company.com.
Understanding email deliverability is part of this too: GDPR's emphasis on data minimization and accuracy pushes you toward exactly the hygiene habits that protect your sender reputation.
CAN-SPAM vs GDPR vs CASL vs PECR: which rules apply?#
The four frameworks below cover the markets most B2B senders touch. Match each segment of your list to the right column before you send.
| Attribute | CAN-SPAM (US) | GDPR (EU) | CASL (Canada) | PECR (UK) |
|---|---|---|---|---|
| Consent before sending | Not required | Lawful basis required (legitimate interest OK for B2B) | Express or implied consent required | Soft opt-in / B2B legitimate interest |
| Opt-out required | Yes, honor in 10 days | Yes, immediate | Yes, honor in 10 days | Yes, every message |
| Physical address required | Yes | Recommended | Yes | Recommended |
| Sender identity must be accurate | Yes | Yes | Yes | Yes |
| Max penalty | $53,088 per email | €20M or 4% global turnover | C$10M per violation | £500,000 (ICO) |
| Applies to B2B personal data | Limited | Yes | Yes | Yes |
The pattern is clear: the US is the most permissive, Canada the strictest on consent, and the EU the harshest on penalties. When a contact could fall under more than one regime, comply with the strictest applicable rule.
What about CASL and other national laws?#
Canada's Anti-Spam Legislation (CASL) is widely considered the toughest in the world. It requires express or implied consent before sending a commercial electronic message. Implied consent can come from an existing business relationship — for example, the recipient bought from you in the last two years, or made an inquiry in the last six months. Cold-emailing a Canadian prospect with no prior relationship is the riskiest play of any major market, with penalties up to C$10 million per violation for businesses.
Beyond the big four, watch for:
- Australia's Spam Act — opt-in based, similar in spirit to CASL.
- Brazil's LGPD — modeled closely on GDPR.
- California's CCPA/CPRA — adds state-level data-rights obligations on top of CAN-SPAM for California residents.
If you sell globally, the safe operating posture is "GDPR-grade by default" — build your process to the strictest standard and you clear the lower bars automatically.
How do you stay compliant without killing deliverability?#
Compliance and deliverability are two sides of the same coin. The behaviors that keep regulators happy — accurate data, honest copy, easy opt-outs — are the same ones that keep mailbox providers from flagging you as spam. Here is how the pieces fit together.
Verify every address before you send. Emailing dead or fake addresses spikes your bounce rate, which both wastes spend and damages sender reputation. Run your list through an email verifier so you only contact real, deliverable inboxes. A bounce rate under 2% is the practical target.
Source data ethically. Scraped or purchased lists are a double liability: they tank deliverability and they almost never meet GDPR or CASL consent standards. Build lists from legitimate research — find verified business contacts by domain rather than buying a CSV of unknown provenance.
Authenticate your domain. SPF, DKIM, and DMARC are not laws, but missing them gets you filtered before compliance even matters. Set all three before your first campaign.
Write honest copy. Your subject line must match your body. Beyond being a CAN-SPAM requirement, deceptive subjects train recipients to mark you as spam — the single fastest way to destroy a sending domain. If you need a starting point, proven cold email templates keep you on the right side of both honesty and engagement.
Make opt-out effortless. A one-click unsubscribe link in every email is now effectively mandatory — Google and Yahoo both require it for bulk senders. Honor requests immediately, not "within 10 days."
What are the penalties for non-compliance?#
The financial exposure is not theoretical. Here is what each regime can cost you:
- CAN-SPAM: up to $53,088 per email. A single non-compliant campaign to a few thousand recipients can, in principle, generate eight-figure liability.
- GDPR: up to €20 million or 4% of global annual turnover, whichever is higher. Tier-one violations have produced nine-figure fines against major companies.
- CASL: up to C$10 million per violation for organizations.
- PECR (UK): up to £500,000 in ICO penalties, with the regulator increasingly active.
Beyond fines, the indirect costs bite harder for most teams: a burned sending domain, blocklisting by major providers, and the reputational hit of being named in an enforcement action. Recovering a domain's sender reputation after a spam-trap incident can take months.
What is a practical cold email compliance checklist?#
Run this list before every campaign. If you cannot check all eleven boxes, do not send.
- Segment by jurisdiction — US, EU, Canada, UK, and rest-of-world each get the correct legal treatment.
- Confirm your lawful basis — legitimate interest documented for EU/UK; consent or relationship verified for Canada.
- Verify every address — bounce rate under 2%, no role accounts you don't intend to hit.
- Use a real "From" name and address — no spoofing, no aliases that hide who you are.
- Write a truthful subject line that matches the body.
- Include your physical postal address in the footer.
- Add a one-click unsubscribe link to every message.
- Authenticate your domain with SPF, DKIM, and DMARC.
- Suppress prior opt-outs automatically across all campaigns.
- Log consent and opt-out events so you can prove compliance later.
- Audit your vendors — agencies and tools acting on your behalf are still your legal responsibility.
For deeper background on how these rules are framed across the industry, HubSpot's email marketing legal overview and the official GDPR text at gdpr.eu are both worth bookmarking.
How does data quality protect compliance?#
Most compliance failures trace back to one root cause: bad data. A list full of guessed, scraped, or outdated addresses guarantees high bounce rates, spam-trap hits, and contacts who never consented to anything. Fixing the data fixes most of the risk.
That is where sourcing discipline pays off. Instead of buying a list of unknown origin, build your prospect list from verified, traceable business contacts. Tomba's domain search finds publicly available professional emails for a target company, every result backed by sources you can audit — which is exactly the provenance trail GDPR and CASL expect you to keep. Pair that with verification, and your list is both legal and deliverable from the first send.
The teams that treat compliance as a data-quality problem, rather than a legal afterthought, are the ones still landing in the inbox at scale in 2026.
Build a compliant list with verified data#
Cold email compliance starts before you write a word — it starts with where your contacts come from. The Tomba Email Finder helps you find professional email addresses by name, company, or domain, with every result verified for deliverability and traceable to its source. That means lower bounce rates, a cleaner sender reputation, and the audit trail you need to satisfy GDPR, CASL, and CAN-SPAM alike.
Start free with 25 searches a month, then scale on the Starter plan at $49/mo when your outreach grows. See the full breakdown on the Tomba pricing page, and send your next campaign knowing your list is built to be both compliant and inboxed.
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author