The CAN-SPAM Act is the U.S. federal law governing commercial email. It applies to commercial messages and gives recipients the right to stop further marketing email. It also imposes requirements around sender identification, subject lines, physical address disclosure, opt-out mechanisms, and honoring opt-outs.
CAN-SPAM- What is CAN-SPAM? The U.S. commercial email law and what it actually requires
- Start with the message's primary purpose
- What counts as transactional or relationship email under FTC guidance
- Mixed messages can become commercial
- B2B email is not exempt from CAN-SPAM
- Unsubscribe is a state change, not just a footer link
- One-click unsubscribe is not the CAN-SPAM Act itself
- The opt-out record has to survive your data pipeline
- Legal minimum and mailbox-provider minimum are different layers
- Keep enforcement amounts out of evergreen copy unless you maintain them
- Worked example
- What CAN-SPAM requires
- What passes and what does not
- Common mistakes
- Questions we get asked
- OnVoard's take
What is CAN-SPAM? The U.S. commercial email law and what it actually requires
Despite the name, CAN-SPAM is not limited to bulk spam. The Federal Trade Commission (FTC) says it covers commercial email generally and has no business-to-business exception.
Start with the message's primary purpose
The first question is not “did this email go to a list?” It is “what is the message primarily for?” The FTC describes 3 broad content types:
- commercial content: advertises or promotes a commercial product or service
- transactional or relationship content: facilitates an agreed transaction or provides certain information about an existing transaction or relationship
- other content: neither commercial nor transactional/relationship
A message containing only commercial content has a commercial primary purpose and is subject to CAN-SPAM's commercial-message requirements. A properly transactional/relationship message is treated differently and is exempt from most of those requirements, although routing information must still not be false or misleading.
This classification matters because teams often assume that “customer email,” “automated email,” or “post-purchase email” is automatically transactional. The FTC's categories are narrower than that.
Primary purpose decides the category, not the sender’s intent
- Only commercial contentCommercialCAN-SPAM commercial-message requirements apply
- Only qualifying transactional/relationship contentExempt from most commercial provisionsRouting information must still be truthful
- Mixed, subject or opening reads as promotionalCommercial
- Mixed, transactional content leads and subject is neutralCan remain transactional/relationship
What counts as transactional or relationship email under FTC guidance
The FTC lists 5 categories where the primary purpose can be transactional or relationship:
- facilitating, completing, or confirming a commercial transaction the recipient already agreed to
- providing warranty, recall, safety, or security information about a product or service the recipient used or purchased
- providing certain information about an ongoing commercial relationship, such as terms/features changes, standing changes, or regular account-balance information
- providing information about employment or employee benefits
- delivering goods or services the recipient already agreed to receive
That covers a normal receipt or shipping update more naturally than it covers a win-back coupon, cross-sell, or sale announcement.
Mixed messages can become commercial
A common ecommerce email contains both operational and promotional material. The FTC says that when commercial and transactional/relationship content are mixed, primary purpose controls. 2 signals are especially important in its guidance:
- what a reasonable recipient would infer from the subject line
- whether the transactional/relationship content appears mainly at the beginning of the message
If the subject line looks promotional, the email can be treated as commercial even though a transaction is mentioned. The same applies when promotional content dominates and transactional material is buried later. Example: Likely transactional orientation > Subject: Your order #4821 has shipped > > Tracking number, delivery date, order details first. > > A small recommendation appears at the end. Likely commercial orientation > Subject: 30% off this weekend > > Sale hero, product grid, discount CTA first. > > “By the way, your order shipped” at the bottom. The shipment event does not transform the second email into a transactional message.
B2B email is not exempt from CAN-SPAM
The FTC explicitly says there is no business-to-business exception. A commercial message sent to a business address can still fall within CAN-SPAM.
This matters for teams that maintain separate “consumer” and “business” mailing logic. The recipient's work address does not by itself remove CAN-SPAM obligations.
One-click unsubscribe is not the CAN-SPAM Act itself
Modern mailbox providers may require RFC 8058 one-click unsubscribe for qualifying bulk promotional mail. That mechanism uses message headers and an HTTPS POST so the mailbox interface can offer a native unsubscribe action.
That is an email ecosystem requirement layered on top of legal obligations, not a sentence you should casually attribute to CAN-SPAM itself. A sender can therefore face multiple unsubscribe requirements simultaneously:
- legal opt-out rights
- visible unsubscribe presentation in the email
- provider-specific one-click behavior
- internal preference-center behavior
The safest implementation satisfies the strictest applicable combination rather than trying to find one universal minimum.
The opt-out record has to survive your data pipeline
CAN-SPAM compliance can fail even when every template has a perfect footer. The failure often happens later in the data path. Imagine this sequence:
- a recipient opts out
- the email platform records the suppression
- the commerce database still shows the contact as a customer
- a nightly sync re-creates the marketing profile
- a campaign query selects “all customers”
- the recipient receives marketing again
The unsubscribe UI worked. The system did not. A durable implementation needs the opt-out to have higher precedence than ordinary profile imports and segment membership. Record at least the address/identity, effective marketing scope, timestamp, source of the request, and enough audit context to explain why the contact is blocked. Then make every campaign and automation evaluate that state before sending.
The FTC also says that after an opt-out, a sender cannot sell or transfer that email address except to a company hired to help comply with CAN-SPAM. That restriction is another reason to treat opt-out data as controlled compliance state rather than ordinary lead data.
Legal minimum and mailbox-provider minimum are different layers
A U.S. sender can comply with the federal 10-business-day opt-out deadline yet still operate a poor or non-compliant mailbox-provider experience. Gmail's current subscription guidance, for example, calls for unsubscribe requests to be honored within 48 hours for subscription messages.
Likewise, RFC 8058 defines a one-click POST protocol that mailbox providers can require. CAN-SPAM's FTC guidance focuses on the recipient's legal opt-out right and conditions on that process. The right architecture therefore does not ask “which rule is the real one?” It records the applicable layers:
message classification→ legal requirements→ mailbox-provider requirements→ internal preference promise→ effective sending rule
If multiple rules apply, the operational system should satisfy all of them. Meeting one layer does not cancel the others.
Compliance does not end when the message sends
Before sending
- Truthful From, To, and routing headers
- Accurate, non-deceptive subject line
- Clear disclosure that it is an advertisement
- Valid physical postal address
- Clear, conspicuous opt-out mechanism
After a recipient opts out
- Mechanism stays operable for at least 30 days
- Opt-out honored within 10 business days
- Address not sold or transferred, except to a compliance vendor
- Vendors and agencies still monitored for compliance
Keep enforcement amounts out of evergreen copy unless you maintain them
Civil penalty ceilings can change over time. The FTC's public compliance page can be updated with a new inflation-adjusted amount while copied articles remain stale for years.
The durable educational point is that each non-compliant email can carry significant enforcement exposure and that responsibility cannot simply be outsourced to a vendor. If a page chooses to publish a current dollar amount, treat it as freshness-sensitive data with a publication-window verification step rather than as permanent glossary copy.
Worked example
A U.S. retailer sends:
> Subject: Final hours: 25% off summer styles > > Hero image, product recommendations, discount code, shop-now CTA.- The message is plainly commercial in purpose
A CAN-SPAM-oriented review would ask:
- Are From/routing details accurate?
- Is the subject line truthful?
- Is the ad/commercial nature appropriately disclosed?
- Is a valid postal address included?
- Is the opt-out mechanism clear and workable?
- Will an opt-out be honored within 10 business days?
- Will downstream systems keep the address suppressed from covered marketing?
- If a vendor sends on the retailer's behalf, is the retailer still monitoring compliance?
Then the team must separately apply mailbox-provider rules and any other applicable privacy/direct-marketing laws.
What CAN-SPAM requires
The FTC's current business guidance summarizes the main obligations.
1. Do not use false or misleading header information
The From, To, Reply-To, routing information, and originating domain/email address must accurately identify the person or business initiating the message.
2. Do not use deceptive subject lines
The subject line must accurately reflect the content of the message.
3. Identify the message as an advertisement
Commercial messages must include a clear and conspicuous disclosure that the message is an advertisement. The law gives flexibility in how that disclosure is presented.
4. Include a valid physical postal address
The message must tell recipients where the sender is located. The FTC says this can be a current street address, a registered post office box, or a properly registered private mailbox.
5. Tell recipients how to opt out
The opt-out explanation must be clear and conspicuous, and the recipient must be able to understand how to stop future marketing email.
6. Make the opt-out mechanism workable
The FTC says the mechanism must be able to process requests for at least 30 days after the message is sent.
7. Honor opt-outs within 10 business days
A sender may not charge a fee, require information beyond the recipient's email address, or force more than a reply email or a single web page as a condition of honoring the request.
8. Monitor vendors acting on your behalf
A business cannot contract away CAN-SPAM responsibility merely by hiring an email platform, agency, or other provider. The FTC says both the company whose product is promoted and the company that sends the message may bear legal responsibility.
What passes and what does not
- A common oversimplification is “CAN-SPAM requires prior opt-in before any marketing email.” That is not how the FTC describes the federal CAN-SPAM framework
- CAN-SPAM principally establishes requirements for commercial messages and gives recipients an opt-out right. However, that does not mean a sender is free to email anyone in any context. Other U.S. laws, state laws, contractual/platform rules, sector-specific obligations, and laws in other countries can impose additional requirements, including consent requirements
- So the correct operational rule is not “CAN-SPAM says cold email is always fine.” It is: determine every rule that applies to the recipients, message, data source, and jurisdiction
Common mistakes
- Believing CAN-SPAM applies only to “spam” or very large sends
- Assuming B2B email is exempt
- Calling every customer email transactional
- Hiding promotional content inside an operational template
- Adding an unsubscribe link but failing to persist or propagate the suppression
- Assuming hiring an ESP transfers away legal responsibility
- Treating the federal rule as the only relevant law worldwide
- Saying RFC 8058 one-click unsubscribe is “required by CAN-SPAM” rather than distinguishing provider/technical requirements
- Hardcoding a penalty dollar amount into evergreen content without maintaining it as enforcement amounts change
Questions we get asked
Does CAN-SPAM apply only to bulk email?
No. The FTC says the Act covers commercial messages and is not limited to bulk email.
Does CAN-SPAM apply to B2B email?
Yes. FTC guidance says there is no business-to-business exception.
How fast must I honor an opt-out under CAN-SPAM?
FTC guidance says within 10 business days. Other rules can require faster handling; current Gmail subscription guidance, for example, calls for processing unsubscribe requests within 48 hours.
Is a receipt subject to all commercial-email requirements?
A message whose primary purpose properly falls within the transactional/relationship categories is treated differently under CAN-SPAM and is exempt from most commercial-message provisions. Mixed or promotional content can change the primary-purpose analysis.
Does CAN-SPAM require one-click unsubscribe headers?
Do not conflate the law with mailbox-provider standards. RFC 8058 defines the one-click mechanism, and providers such as Gmail impose it for qualifying bulk subscription/promotional messages. CAN-SPAM itself is the U.S. legal framework for commercial email opt-out and related requirements.
Can I add someone back after they unsubscribe?
Do not silently reactivate a recipient just because their address is re-imported or they purchase again. A new marketing permission or resubscription should be handled explicitly under your applicable rules and documented product policy. CAN-SPAM also restricts selling or transferring addresses after an opt-out except for a company hired to help with compliance.
OnVoard's take
The cleanest CAN-SPAM implementation is not a checklist attached to the email composer. It is an end-to-end state machine.
Classify the message purpose, make the sender and content truthful, expose a clear opt-out, turn that request into durable suppression, and make every workflow respect it. Then layer mailbox-provider and jurisdiction-specific requirements on top. That architecture is harder to break than relying on marketers to remember which footer to paste into which campaign.
Every app on every plan. Connect your store and switch on the flows in an evening.