Email Marketing

CAN-SPAM Act

Also called CAN-SPAM

The United States law setting rules for commercial email, including honest headers, a working unsubscribe link and a valid postal address.

Quick facts: CAN-SPAM Act

Category
Email Marketing
Also called
CAN-SPAM
Level
Intermediate
Affects
Legal exposure, deliverability, list quality
Where to see it
Your email platform's footer template, sender settings and unsubscribe handling
In this article4
  1. How the CAN-SPAM Act works
  2. Why the CAN-SPAM Act matters
  3. Common mistakes with the CAN-SPAM Act
  4. How to act on it

How the CAN-SPAM Act works

CAN-SPAM is a United States federal law, and it follows the recipient rather than the sender. If a promotional message lands in an inbox belonging to someone in the United States, the rules apply, whether it was sent from Kathmandu, Sydney or Texas. It governs commercial email; a purely transactional message such as an order confirmation sits outside most of the requirements, although its sender details still have to be truthful.

The obligations are practical rather than technical. The From name, reply address and routing details must identify the real sender. The subject line must reflect what is actually inside. An advertisement has to be recognisable as one. Every commercial message needs a valid physical postal address for the business, and a visible, working way to opt out that keeps working after the send and is honoured promptly once someone uses it.

Why the CAN-SPAM Act matters

There are two reasons, and the second is the one businesses miss. The first is legal exposure: penalties are assessed against each offending message, so one careless send to a large list is not one mistake. Handing the work to an agency does not move the risk either — the business being promoted stays responsible for what goes out in its name.

The second is that mailbox providers look for the same signals the law does. A missing unsubscribe link, a disguised sender name and a subject line that hides a sales pitch are exactly what filters treat as suspect, so compliance and email deliverability pull in the same direction. Meeting the rules is not paperwork; it is part of reaching the inbox at all.

Common mistakes with the CAN-SPAM Act

The biggest is treating it as the whole picture. CAN-SPAM is an opt-out law: it does not require permission before the first email. Most other markets a Nepali, Australian or British business sells into do require consent before contact, so a list assembled to CAN-SPAM standards alone can still be unlawful elsewhere. Build to the stricter rule and you are covered in both places.

After that come the everyday failures. Unsubscribe links that demand a login or an explanation. A postal address that nobody has occupied for years. A newsletter subject line on a hard sales email. Opt-outs recorded in one tool but not in the one that actually sends, which is why a suppression list belongs above your sending platforms rather than inside any one of them.

How to act on it

Put the postal address and the unsubscribe link into the template footer once, so no rushed send can leave them out. Then test the opt-out yourself from a real inbox on a phone: one tap, no login, clear confirmation on screen. Keep permission records attached to each address — where it came from, when, and what the person agreed to — because that record is what you rely on if anyone asks.

Finally, set your own bar above the legal one. Asking people to confirm through double opt-in, and treating a spam complaint as seriously as an unsubscribe, produces a list that behaves well in every market you send to. Those habits are the foundation of any workable email marketing programme, not an optional extra bolted on later.

Do and do not

Do

  • Keep the postal address and unsubscribe link in every template
  • Honour opt-outs promptly across every tool that sends
  • Record where and when each address was collected

Do not

  • Assume opt-out consent satisfies UK, EU or Canadian law
  • Hide the unsubscribe behind a login or a survey
  • Assume an agency carries the legal risk for you

Questions people ask about this

Does CAN-SPAM apply to a business outside the United States?

Yes. The law is written around the recipient, not the sender, so a business in Nepal, India or Australia emailing prospects in the United States is expected to meet the same requirements as a company based there. Sending from a foreign domain or a foreign platform changes nothing about the obligations.

Do I need permission before emailing someone under CAN-SPAM?

Not under this law, which works on opt-out rather than opt-in. That is a narrow permission though. The United Kingdom, the European Union, Canada and Australia all expect consent before commercial contact, so a list built only to the United States standard can still break the rules in the markets you actually want to sell into.

Do receipts and order confirmations need an unsubscribe link?

Purely transactional messages, such as a receipt, a delivery update or a password reset, sit outside most of the requirements, so they do not need an opt-out. The sender information must still be accurate. Be careful with hybrids: add a promotion to a receipt and the message starts to look commercial, and the full rules come back into play.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.