Treat every cold email as a commercial message until you have checked its primary purpose. Build the send around a sender the recipient can identify, a subject that matches the message, and a working way to stop future mail. The CAN-SPAM Act makes no exception for business-to-business email.1 It has no volume floor below which its rules switch off.2 A single cold email to one prospect is covered by the same law as a million-address campaign.3 The Act does not require prior permission to send.4
Scope
Decide which rule set applies by checking the email's primary purpose, not the list size or the relationship label.
The primary purpose test determines whether a message is commercial or transactional.5 A commercial message is one whose primary purpose is advertising or promoting a commercial product or service, including email that promotes content on commercial websites.6
Ask whether the message would mainly promote a product or service if the recipient read it without any surrounding context. If so, use the commercial message checklist for outbound selling.
Sender identity and routing
Check what the recipient sees before reviewing the copy. The sender fields should identify who initiated the email and provide an accurate reply route.
The From, To, Reply-To, and routing information, including the originating domain name and email address, must be accurate and identify the person or business that initiated the message.7
Review the final rendered headers, including the domain and reply path. Continue only when those fields give a consistent account of who sent the message.
Subject line
Read the subject by itself. Change it if it creates an expectation the body cannot meet.
Subject lines should accurately represent the contents of the email message.8
Use wording that matches the email's purpose and body. Check the subject again after personalization or a sequence change, since a body edit can leave the subject describing something that is no longer there.
Commercial disclosure
State the message's purpose inside the email. The recipient should not have to infer that it is selling something from the signature, link, or company name.
A commercial email must identify itself as advertising.9
Read the opening and call to action together. If the email promotes a commercial offer, make that purpose clear before releasing it.
Postal address
Treat the address as part of the message. Inspect the final email that will reach the recipient, including the version produced by the sending system.
CAN-SPAM requires a valid physical postal address in every message.10
Check that templates, signatures, and formatting have not removed the address. It must appear in the actual commercial email, not only in an internal campaign record.
Opt-out and suppression
Give the recipient a clean exit and test whether the sending system honors it after the message leaves your control.
Every recipient has the right to make you stop sending further messages.11 An opt-out method must work for at least 30 days after an email is sent, and opt-out requests must be honored within 10 business days.12
The opt-out path may not charge a fee or demand information beyond an email address.13 Test it as a recipient, confirm that the request is recorded, and check that the resulting suppression applies to future sends. A suppression list that covers only one campaign creates a mechanical failure.14
Vendor responsibility
Keep a review point between the vendor's send and your approval. You still need to know which identity, subject, address, and opt-out path the vendor will put in front of recipients.
Hiring an agency does not transfer liability under CAN-SPAM.15
Before a vendor sends, inspect a real rendered message and confirm how opt-outs reach the suppression process. Continue only when you can trace the message from its visible sender fields through its opt-out handling without relying on the vendor's description alone.
What not to do
The common failures are mechanical. Put these checks into the release gate instead of relying on a general compliance setting.
- Do not use false or misleading header information.16
- Do not use a deceptive subject line.17
- Do not make the recipient pay a fee or provide information beyond an email address to opt out.13
- Do not let the suppression list cover only the campaign that generated the opt-out.14
- Do not treat a CAN-SPAM pass as a GDPR pass, because compliance with CAN-SPAM does not establish compliance with GDPR.18
- Do not treat a violating message as harmless because the send is small. Each separate email in violation can face penalties of up to $53,088.19
Use the completed message, rendered exactly as it will send, as the release gate. Hold it when a sender field, subject, disclosure, address, or opt-out test fails, then rerun the check after the fix. This gives you a clear send decision without relying on B2B status, list size, or vendor assurances.