Outbound Wiki

CAN-SPAM sender requirements

The CAN-SPAM rules for truthful headers and subject lines, commercial disclosure, and a valid postal address.

Treat every cold email as a commercial message until you have checked its primary purpose. Build the send around a sender the recipient can identify, a subject that matches the message, and a working way to stop future mail. The CAN-SPAM Act makes no exception for business-to-business email.1 It has no volume floor below which its rules switch off.2 A single cold email to one prospect is covered by the same law as a million-address campaign.3 The Act does not require prior permission to send.4

Scope

Decide which rule set applies by checking the email's primary purpose, not the list size or the relationship label.

The primary purpose test determines whether a message is commercial or transactional.5 A commercial message is one whose primary purpose is advertising or promoting a commercial product or service, including email that promotes content on commercial websites.6

Ask whether the message would mainly promote a product or service if the recipient read it without any surrounding context. If so, use the commercial message checklist for outbound selling.

Sender identity and routing

Check what the recipient sees before reviewing the copy. The sender fields should identify who initiated the email and provide an accurate reply route.

The From, To, Reply-To, and routing information, including the originating domain name and email address, must be accurate and identify the person or business that initiated the message.7

Review the final rendered headers, including the domain and reply path. Continue only when those fields give a consistent account of who sent the message.

Subject line

Read the subject by itself. Change it if it creates an expectation the body cannot meet.

Subject lines should accurately represent the contents of the email message.8

Use wording that matches the email's purpose and body. Check the subject again after personalization or a sequence change, since a body edit can leave the subject describing something that is no longer there.

Commercial disclosure

State the message's purpose inside the email. The recipient should not have to infer that it is selling something from the signature, link, or company name.

A commercial email must identify itself as advertising.9

Read the opening and call to action together. If the email promotes a commercial offer, make that purpose clear before releasing it.

Postal address

Treat the address as part of the message. Inspect the final email that will reach the recipient, including the version produced by the sending system.

CAN-SPAM requires a valid physical postal address in every message.10

Check that templates, signatures, and formatting have not removed the address. It must appear in the actual commercial email, not only in an internal campaign record.

Opt-out and suppression

Give the recipient a clean exit and test whether the sending system honors it after the message leaves your control.

Every recipient has the right to make you stop sending further messages.11 An opt-out method must work for at least 30 days after an email is sent, and opt-out requests must be honored within 10 business days.12

The opt-out path may not charge a fee or demand information beyond an email address.13 Test it as a recipient, confirm that the request is recorded, and check that the resulting suppression applies to future sends. A suppression list that covers only one campaign creates a mechanical failure.14

Vendor responsibility

Keep a review point between the vendor's send and your approval. You still need to know which identity, subject, address, and opt-out path the vendor will put in front of recipients.

Hiring an agency does not transfer liability under CAN-SPAM.15

Before a vendor sends, inspect a real rendered message and confirm how opt-outs reach the suppression process. Continue only when you can trace the message from its visible sender fields through its opt-out handling without relying on the vendor's description alone.

What not to do

The common failures are mechanical. Put these checks into the release gate instead of relying on a general compliance setting.

  • Do not use false or misleading header information.16
  • Do not use a deceptive subject line.17
  • Do not make the recipient pay a fee or provide information beyond an email address to opt out.13
  • Do not let the suppression list cover only the campaign that generated the opt-out.14
  • Do not treat a CAN-SPAM pass as a GDPR pass, because compliance with CAN-SPAM does not establish compliance with GDPR.18
  • Do not treat a violating message as harmless because the send is small. Each separate email in violation can face penalties of up to $53,088.19

Use the completed message, rendered exactly as it will send, as the release gate. Hold it when a sender field, subject, disclosure, address, or opt-out test fails, then rerun the check after the fix. This gives you a clear send decision without relying on B2B status, list size, or vendor assurances.

Sources

  1. 1
    “The CAN-SPAM Act makes no exception for business-to-business email.”
  2. 2
    “There is no B2B carve-out, no exemption for one company writing to another, and no volume floor below which the rules switch off.”
  3. 3
    “A single cold email to a single prospect is covered by the same law as a million-address blast.”
  4. 4
    “What the Act does not do is require permission.”
  5. 5
    “The primary purpose test decides whether a message is commercial or transactional.”
  6. 6
    “It covers all commercial messages, which the law defines as “any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service,” including email that promotes content on commercial websites.”
  7. 7
    “Your “From,” “To,” “Reply-To,” and routing information – including the originating domain name and email address – must be accurate and identify the person or business who initiated the message.”
  8. 8
    “And make sure they give an accurate representation of what’s in the email message.”
  9. 9
    “To comply with the CAN-SPAM Act, a commercial email must use accurate header information and a non-deceptive subject line, identify itself as advertising, provide a valid physical postal address, explain how to opt out, preserve subscribers’ right to opt out of marketing, honor requests within 10 business days, and monitor vendors that send on the company’s behalf.”
  10. 10
    “It requires honesty about who you are and what the message is, a working unsubscribe honoured within ten business days, and a valid physical postal address in every message.”
  11. 11
    “It regulates how you send, and it gives every recipient the right to make you stop.”
  12. 12
    “An opt-out method must work for at least 30 days after send, and requests must be honored within 10 business days.”
  13. 13
    “Opt-out requests must be honoured within 10 business days, and you may not charge a fee or demand information beyond an email address”
  14. 14
    “That combination is why US outbound is legal and why the mistakes that get people caught are mechanical ones: a missing postal address, an opt-out link that fails, a suppression list that only covers one campaign.”
  15. 15
    “It applies to business-to-business email as well as consumer email, and hiring an agency does not transfer liability.”
  16. 16
    “Don’t use false or misleading header information.”
  17. 17
    “Prohibition on deceptive subject lines;”
  18. 18
    “Complying with CAN-SPAM does not make you compliant with GDPR, which is consent-based.”
  19. 19
    “Each separate email in violation of the CAN-SPAM Act is subject to penalties of up to $53,088, so non-compliance can be costly.”