Is Cold Email Legal Under CAN-SPAM in 2026?
Yes. Cold email is legal in the United States under the CAN-SPAM Act, which sets an opt-out regime rather than an opt-in one, so you do not need permission before emailing a business prospect. What you need is compliance with seven specific rules, because the penalty for breaking them runs up to $53,088 per individual email in 2026. We send roughly a million cold emails a month under this law. This is the operator's version of what it requires, checked against the FTC's own guidance, plus the two catches: other countries work differently, and legal is not the same as landing in the inbox.
DAte
Category
Guides
Reading Time
9 Min
PROOF
Results we've gotten for our clients
If you are evaluating outbound from scratch, the relevant question is not whose service list is longest. It is whether the team can create qualified conversations in a market like yours.
90
SALES-ACCEPTED LEADS FOR GAINSIGHT · IN 2 MONTHS
6.5%
OF ALL US RESTAURANT LOCATIONS BOOKED FOR UPSIDE · IN 1 QUARTER
117
OPPORTUNITIES GENERATED FOR ROUTE · IN 1 MONTH
15-MINUTE FIT CHECK
See if we can hit your numbers.
Pick a time. We’ll assess your market, deal size, and sales capacity on the call.

A note on who is talking. We are a cold email agency, not a law firm, so nothing here is legal advice. It is how an agency that operates under this law every day reads it, checked against the FTC's published compliance guide, and if we got a detail wrong, email us and we will fix it.
Is cold email legal in the United States?
Cold email is legal in the United States. The CAN-SPAM Act of 2003 (15 U.S.C. sections 7701 to 7713) governs commercial email and deliberately chose an opt-out model: you may email someone without prior consent, and they get the right to make you stop.
The law applies to any message whose primary purpose is commercial promotion, which covers B2B outreach, B2C marketing, and foreign senders emailing US recipients. The FTC's compliance guide is the primary source, and it is short enough to actually read.
What does CAN-SPAM require in every cold email?
Seven duties, and missing any one of them turns the message into a violation.
Your headers have to tell the truth. The From name, reply-to, domain, and routing information must identify the actual sender, and the subject line must reflect what the message is about.
The message has to be identifiable as commercial, which courts and the FTC read loosely. A cold email offering a business service, written like a normal business email, clears this bar without a flashing advertisement label.
Every email needs a valid physical postal address for your business. A registered agent address or a PO box works.
And the opt-out has to be real: clearly visible, working for at least 30 days after sending, honored within 10 business days, and free. You cannot charge a fee, require a login, or ask for anything beyond an email address to process it.
The seventh duty is the one companies forget: you must monitor what anyone sending on your behalf does. More on that below, because it is the one that reaches you even when you never touch the send button.
What are the penalties in 2026?
Up to $53,088 per individual email. That figure comes from the FTC's January 2025 inflation adjustment and remains the operative maximum for 2026, because the annual update was suspended this year. A lot of compliance content still quotes older numbers.
The per-email structure is the whole threat. A 5,000-send campaign with a broken unsubscribe link is 5,000 separate violations, which is why real settlements happen long before the theoretical maximum: the FTC's largest CAN-SPAM penalty to date is Verkada's $2.95 million in 2024, and Experian paid $650,000 over opt-out failures.
Enforcement comes from the FTC, state attorneys general, and internet service providers. Individuals generally cannot sue you under CAN-SPAM, though state laws add exposure: Washington's email statute allows $500 per message for misleading subject lines, and a 2025 state supreme court ruling put it back in active use.
There is also a criminal tier under 18 U.S.C. section 1037 for the ugly stuff: harvesting addresses, dictionary attacks, and relaying through machines you do not control. That tier carries prison time, and it is the reason scraped email dumps are a worse idea than they look.
Does CAN-SPAM apply to B2B cold email?
Yes. There is no B2B exemption, which surprises people in both directions: your sales outreach is covered by the law, and the law explicitly permits it without prior consent.
The exemption that does exist is for transactional and relationship messages, like receipts, account notices, and updates to an existing customer. Those escape most CAN-SPAM duties, but a sales email to a stranger is never one of them, whatever the subject line pretends.
If an agency sends for you, who is liable?
Both of you. The law holds the company whose product is promoted responsible alongside whoever pushed send, and the FTC has said plainly that liability cannot be outsourced to a vendor.
So vet the sender like the fine lands on you, because it can. Any agency you hire should show you the physical address in its footers, prove the unsubscribe works, keep a suppression list that syncs across campaigns, and log opt-outs against the 10-business-day clock. The four contract questions in our ranked guide to cold email agencies exist for the same reason.
Our own version: clients own every sending domain and mailbox in writing, opt-outs suppress immediately rather than on day nine, and the footer address is real. None of that is heroic. It is the floor, and the agency-vs-in-house math only works if the agency is not creating liability while it books meetings.
What about the EU, the UK, and Canada?
Different laws, different logic. The EU's GDPR builds on consent and legitimate-interest grounds rather than opt-out, with fines scaling to 4% of global revenue or 20 million euros, and Canada's CASL is a consent regime with real enforcement.
The operational answer is to know where your list lives before you send, and to treat US rules as US rules only. Our programs target US B2B companies, which keeps the work inside the CAN-SPAM framework this page describes, and if your market is Toronto or Berlin, get advice from someone with a bar card first.
Is legal the same as landing in the inbox?
No, and this is where most cold email actually dies. Google's sender guidelines and Yahoo's parallel rules require authenticated sending (SPF, DKIM, DMARC), one-click unsubscribe, and spam-complaint rates below 0.3%, and none of that is law. It is just the price of reaching a Gmail inbox.
Compliance is the legal floor and deliverability is the commercial one, and they overlap: honest subject lines and working opt-outs serve both. The infrastructure that clears both floors runs $500 to $2,000 a month, which our pricing guide breaks down alongside what agencies charge to manage it.
The checklist we run on every campaign
Before anything sends: the footer shows the client's real postal address, the unsubscribe link is clicked and confirmed working, and the suppression list from every prior campaign is synced.
On content: the subject line describes the email, the From name is a real person at the real company, and nothing in the headers pretends to be a reply or a forward.
On process: opt-outs suppress the same day, the log timestamps every one against the 10-day requirement, and any new sending vendor gets audited before a single email moves. Boring list, cheap insurance, and it has kept 951,450 sends penalty-free.
Common questions
Do you need permission to cold email someone in the US?
No. CAN-SPAM is an opt-out law, so prior consent is not required for commercial email to US recipients. You need truthful headers, a physical address, and a working opt-out you honor within 10 business days.
Does every cold email need an unsubscribe link?
Every commercial email needs a clear, working opt-out mechanism. In practice that is an unsubscribe link, though a reply-to-opt-out instruction can qualify if it is conspicuous and actually processed. The link version also satisfies Gmail's one-click rule, so use the link.
Can someone sue you over a cold email?
Generally not as an individual under CAN-SPAM, which has no private right of action for recipients. The FTC, state attorneys general, and ISPs enforce the federal law, and some state statutes like Washington's add per-email claims for deceptive subject lines.
Is cold email legal in Canada or the EU?
Not the way it is in the US. Canada's CASL requires consent, and the EU's GDPR requires a lawful basis with heavy fines behind it, so US-style opt-out outreach does not transfer. Segment your list by country before you send anything.
How much is a CAN-SPAM fine per email?
Up to $53,088 per violating email in 2026, applied per message rather than per campaign. Actual settlements land far below the ceiling, and the ceiling is exactly why senders settle.
Fifteen minutes
Tell us your market, your deal size, and what your sales team can absorb. We will tell you whether outbound fits, what we would charge, and exactly how the compliance floor above gets built into it. We run IntentSignal, and the checklist is the same one your program would get.
Author
Andrew Elsakr, co-founder of IntentSignal
Andrew Elsakr is the co-founder of IntentSignal, a B2B lead generation agency working with US B2B companies that have $10K+ average contract value and a sales team. He previously founded Lyne.ai, one of the first AI personalization tools for cold email, and sold it in 2023. IntentSignal clients averaged 30 booked meetings per month per client in 2026.






