CAN-SPAM compliance is the shortest homework in outbound. The statute is not long, the FTC publishes a plain English guide to it, and almost everything it asks for is mechanical: a real address in the header, a subject line that matches the message, a postal address, a way out, and a promise to honour that way out quickly. Most teams still get two of the seven wrong, and the two they get wrong are the two that are hard to fix after the fact.
This is a checklist for a cold outbound email specifically, which is a narrower thing than the general marketing email the guide is usually read for. It is not legal advice, and it covers United States law only. If you send into the EU, the UK, Germany or Canada, read the last section before you do anything else, because CAN-SPAM is by some distance the most permissive of the rules you are subject to.
The seven requirements
The FTC's compliance guide sets out seven rules. They apply to any commercial electronic mail message whose primary purpose is commercial advertising or promotion, which a cold sales email plainly is. There is no exemption for a small sender, none for a personalised message, and none for a first touch.
1. Headers that tell the truth
The "from", "reply to" and routing information have to identify the person or business that initiated the message, and the domain name and originating address have to be accurate. This is the one people assume they cannot get wrong, and then they buy a tool that sends through a shared pool from a lookalike domain with a display name nobody at the company uses.
Practically: send from a domain you control, with a display name that is a real person or a real business name, and a reply address that reaches somebody. If a reply bounces, you have failed this rule and you have also thrown away the only signal in outbound that is worth anything.
2. Subject lines that are not deceptive
The subject line has to reflect the content of the message. The failure mode here is not the obvious one. Almost nobody writes "You have won" on a B2B cold email. What they do write is a subject that implies a relationship that does not exist: "following up on our conversation" when there was no conversation, "re: your request" when nothing was requested, "quick question about the invoice" when there is no invoice.
Each of those is a subject line designed to be opened for a reason that is not true. That is the exact thing the rule is about, and it is also the fastest way to earn a complaint from a person who feels tricked into opening something.
3. Saying it is an advert
The message has to disclose clearly and conspicuously that it is an advertisement. The rule gives latitude on how, and a cold sales email that says plainly who you are, what you sell and why you are writing generally satisfies it on its face. What does not satisfy it is a message engineered to read as personal correspondence with the commercial purpose buried in a postscript.
The practical test: could a reasonable person tell in the first two lines that a company is trying to sell them something? If not, rewrite the first two lines.
4. A valid physical postal address
Every commercial message needs your valid physical postal address. A registered office, a street address or a post office box registered with the postal service all qualify. A city name does not, a country does not, and an address that belonged to you two offices ago does not.
This is the requirement most often missing from a cold email, because the template it was written from was a reply, not a campaign. It is also trivially checkable, which is why it is the first thing an investigator looks at.
5. A working way to opt out
A clear and conspicuous explanation of how the recipient can stop receiving email from you, and a mechanism that works. One that requires the recipient to log in, to give a reason, to fill in a form with more than an email address, or to opt out of things one at a time, does not meet the rule.
In a cold email this often means the plain sentence rather than the button. "Reply with the word stop and I will not write again" is a legitimate mechanism if somebody is actually watching the mailbox and acting on it. If nobody is watching the mailbox, it is not a mechanism, it is a sentence.
6. Honouring it promptly
Opt out requests must be honoured within ten business days, the mechanism has to keep working for at least thirty days after the message was sent, and you may not charge a fee, require any identifying information beyond an email address, or make the recipient take any step other than sending a reply or visiting a single page. You also may not sell or transfer an address after somebody has opted out, except to a provider helping you comply.
Ten business days is the legal ceiling, not the target. If a suppression takes ten days to propagate across three tools, somebody who asked you to stop is going to hear from you again, and that person reports spam rather than asking twice.
7. Watching who sends on your behalf
You cannot contract out of responsibility. If an agency, a contractor or a tool sends on your behalf, both the company whose product is promoted and the company that sends the message can be held responsible. The practical consequence for anyone buying outbound software is that "the vendor handles compliance" is not a thing that exists.
The other rulebook: the mailbox providers
CAN-SPAM is the law. It is not the thing that will actually stop your email. The mailbox providers have their own requirements, they enforce them automatically, and they are stricter.
Since 1 February 2024, Google and Yahoo have required bulk senders to authenticate with SPF, DKIM and DMARC, to offer one click unsubscribe in the message headers and process it within a couple of days, and to keep spam complaints below a threshold. Google's guidance is explicit about the number: keep the spam rate reported in Postmaster Tools below 0.30% and aim to stay under 0.10%.
Those are not fines. They are worse, in the way that matters operationally: there is no notice, no appeal and no ten business day grace period. Delivery simply degrades, for every message from that domain, including the ones your finance team sends.
The two that outbound teams get wrong
In order of how often it happens.
The missing address block. A first touch email written to look like a personal note has no footer, because footers look like marketing. That instinct is right about tone and wrong about the law. Put the address in, keep it small and keep it plain, and stop trying to disguise a commercial message as correspondence.
The subject line that implies a prior relationship. This is the one people defend, on the grounds that it works. It does work, in the sense that it raises open rate and lowers reply rate, because the person who opens it is annoyed by the time they reach the first line. It is also the clearest case of a deceptive subject line in ordinary B2B outbound, and it is the single fastest way to move a complaint rate.
Where CAN-SPAM stops
CAN-SPAM is an opt out regime. Almost nowhere else is. Three cases worth knowing before you send outside the United States:
- The EU and the UK. Processing personal data needs a lawful basis under the GDPR, and the ePrivacy rules restrict unsolicited electronic marketing. Business to business cold email is possible in several member states on a legitimate interest basis, with a genuine balancing test and a record of it, but it is a considered position rather than a default.
- Germany. Under UWG section 7, unsolicited commercial email without prior consent is treated as an unreasonable nuisance, including in a business context, with narrow exceptions. Assume you need consent.
- Canada. CASL requires express or implied consent, and implied consent has to rest on something documented, such as an existing business relationship or a published address that does not carry a statement refusing such messages.
The operational point is not the legal detail, which changes and which your counsel should own. It is that a single global sequence cannot be compliant everywhere at once, so the lawful basis has to be a field on the contact and not an assumption about the campaign.
The checklist, on one screen
- The from name and reply address are real, on a domain you control, and a reply reaches a person.
- The subject line describes what is actually inside, and implies no relationship that does not exist.
- The commercial purpose is obvious within the first two lines.
- A valid physical postal address appears in every message.
- There is an opt out that needs nothing but an email address, and a one click unsubscribe header.
- Opt outs are suppressed everywhere, within hours rather than within the ten day ceiling.
- Anyone sending on your behalf is checked, because you remain responsible.
- SPF, DKIM and DMARC pass on the sending domain.
- Complaint rate is watched in Postmaster Tools and kept under 0.10%.
- The lawful basis for contacting each person is recorded per contact, not assumed per campaign.
Nine of those ten can be handled by software rather than by a person, and seven of the nine on the draft itself in the moment between writing a message and queueing it, which is what cold email software should be doing with that moment. The other two, authentication and the complaint rate, are checked on the sending domain rather than on the text. The tenth, the lawful basis, is a decision a person has to make and record. No tool can make it for you, and any tool that claims to is selling you the exact false confidence this checklist exists to prevent.
If you want to see the mechanical nine run on a real draft, the spam score checker page explains each check line by line, and the demo on the homepage runs the lot on whatever you paste into it.