How the CAN-SPAM Act works
CAN-SPAM is a United States federal law, and it follows the recipient rather than the sender. If a promotional message lands in an inbox belonging to someone in the United States, the rules apply, whether it was sent from Kathmandu, Sydney or Texas. It governs commercial email; a purely transactional message such as an order confirmation sits outside most of the requirements, although its sender details still have to be truthful.
The obligations are practical rather than technical. The From name, reply address and routing details must identify the real sender. The subject line must reflect what is actually inside. An advertisement has to be recognisable as one. Every commercial message needs a valid physical postal address for the business, and a visible, working way to opt out that keeps working after the send and is honoured promptly once someone uses it.
Why the CAN-SPAM Act matters
There are two reasons, and the second is the one businesses miss. The first is legal exposure: penalties are assessed against each offending message, so one careless send to a large list is not one mistake. Handing the work to an agency does not move the risk either — the business being promoted stays responsible for what goes out in its name.
The second is that mailbox providers look for the same signals the law does. A missing unsubscribe link, a disguised sender name and a subject line that hides a sales pitch are exactly what filters treat as suspect, so compliance and email deliverability pull in the same direction. Meeting the rules is not paperwork; it is part of reaching the inbox at all.
Common mistakes with the CAN-SPAM Act
The biggest is treating it as the whole picture. CAN-SPAM is an opt-out law: it does not require permission before the first email. Most other markets a Nepali, Australian or British business sells into do require consent before contact, so a list assembled to CAN-SPAM standards alone can still be unlawful elsewhere. Build to the stricter rule and you are covered in both places.
After that come the everyday failures. Unsubscribe links that demand a login or an explanation. A postal address that nobody has occupied for years. A newsletter subject line on a hard sales email. Opt-outs recorded in one tool but not in the one that actually sends, which is why a suppression list belongs above your sending platforms rather than inside any one of them.
How to act on it
Put the postal address and the unsubscribe link into the template footer once, so no rushed send can leave them out. Then test the opt-out yourself from a real inbox on a phone: one tap, no login, clear confirmation on screen. Keep permission records attached to each address — where it came from, when, and what the person agreed to — because that record is what you rely on if anyone asks.
Finally, set your own bar above the legal one. Asking people to confirm through double opt-in, and treating a spam complaint as seriously as an unsubscribe, produces a list that behaves well in every market you send to. Those habits are the foundation of any workable email marketing programme, not an optional extra bolted on later.