Penalty exposure starts with classification and routing. List size comes later. Before a cold email goes out, classify it, identify the recipient's country, and test whether the sending setup can stop future messages. A single cold email to a single prospect is covered by CAN-SPAM.1 Canada uses an opt-in model.2 Use these checks to decide whether to send, what to preserve, and when to stop.
Start with the message
Classify the message before reviewing the copy. That tells you which rule set applies and what to verify before sending.
CAN-SPAM covers all commercial messages, including email that promotes content on commercial websites, and defines a commercial message by its primary purpose of advertising or promoting a commercial product or service.3 Under CASL, a commercial electronic message is any electronic message that encourages participation in a commercial activity, whether or not profit is expected.4 Promoting a product or service and inviting a prospective customer to an event are examples.5
Ask whether the message encourages participation in a commercial activity or promotes a commercial product or service. Decide whether it is legitimate outbound or spam before checking the compliance mechanics.6
Route the recipient
Country determines the consent path. Keep that route with the recipient record so the sending decision does not depend on a rep's memory.
CAN-SPAM makes no exception for business-to-business email.7 It does not require prior permission to send an email.8 For a Canadian recipient, use the opt-in route and require the permission basis before sending. Ask where that basis came from, what message it covers, and whether the record is still usable. Move on only when you can explain why the message may be sent under the route you selected.
Check the stop path
Test the live message and the suppression behavior. A written policy does not help if the recipient's decision cannot reach the sending system.
CAN-SPAM regulates how messages are sent and gives every recipient the right to make the sender stop sending further messages.9 Check what happens when someone unsubscribes, replies with a stop request, or appears on a suppression list. Review every future send that could reach that person, since a stop request changes the sending decision after the original message.
Map the enforcement risk
Map each rule to who can act, what can trigger exposure, and who may carry the liability. That gives the team a clear place to escalate when a route is uncertain.
The FTC enforces the CAN-SPAM Act and the accompanying CAN-SPAM Rule.10 Each separate violating email can carry a penalty of up to $53,088.11 Federal, state, and private parties can bring claims for violations.12 Fraudulent activities can also carry criminal penalties.13 The company whose product or service is advertised and the person or entity sending the message may both be liable.14
The CRTC enforces CASL alongside the Competition Bureau and the Office of the Privacy Commissioner. CASL's private right of action, which would let individuals sue for statutory damages, remains not in force, so regulators are still the only route to enforcement.15 CASL penalties can reach $10 million for an organization and $1 million for an individual.16
Use those figures as a reason to resolve uncertainty before sending. Penalties and enforcement approaches can change, so verify the current framework before assuming an outreach practice is low risk.17
What not to do
Keep these failure modes beside the send review and test each control before approval.
- Do not use false or misleading header information.18
- Do not let the From, To, Reply-To, or routing information obscure who initiated the message. Those fields, including the originating domain name and email address, must be accurate and identify the initiating person or business.19
- Do not send a commercial electronic message without first obtaining the recipient's consent.20
- Do not send a message with a missing postal address, a failed opt-out link, or a suppression list that covers only one campaign. These are mechanical failure points.21
Run this review before approving a new route. Preserve the permission or suppression decision with the recipient record. Escalate any unclear route for legal review before treating it as low risk.17