CAN-SPAM Act
A United States law that sets rules for commercial email, establishes requirements for commercial messages, and gives recipients the right to opt out.
The CAN-SPAM Act (Controlling the Assault of Non-Solicited Pornography And Marketing Act) is a US federal law enacted in 2003 that establishes the rules for commercial email. It applies to any electronic message whose primary purpose is commercial advertising or promotion of a product or service. Violations can result in penalties of up to $46,517 per non-compliant email, making compliance a serious business consideration.
The law sets several key requirements for commercial email. Messages must not use deceptive subject lines or false header information. They must identify themselves as advertisements, include the sender's valid physical postal address, and provide a clear mechanism for recipients to opt out of future emails. Opt-out requests must be honored within ten business days. Importantly, CAN-SPAM does not require prior consent to send commercial email it regulates how those emails are sent.
However, compliance is non-negotiable. Every outreach email must include accurate sender information, a physical address, and an unsubscribe option. Teams should build these elements into their email templates by default to ensure every message meets legal requirements.
Key Points
- CAN-SPAM is a US law regulating commercial email with penalties up to $46,517 per violation
- It requires accurate sender info, physical address, and a clear opt-out mechanism in every email
- Unlike GDPR, CAN-SPAM does not require prior consent for commercial email
Best Practices
- Include your company's physical address and a working unsubscribe link in every outreach email
- Honor opt-out requests within ten business days as required by law
- Use accurate sender names and subject lines that honestly represent the email's content
Free Tools
Glossary
CCPA
The California Consumer Privacy Act, a state-level data privacy law giving California residents rights over their personal information.
Email Compliance
The adherence to laws, regulations, and best practices governing the sending of commercial email communications.
GDPR
The European Union's General Data Protection Regulation, a comprehensive data privacy law that governs how organizations collect, process, and store personal data.