CAN-SPAM is the US law that lets you send cold commercial email without prior consent. The message must be honest, labelled, signed with a postal address and easy to opt out of. This is not legal advice. Read the statute and ask a lawyer about your own program.
Key takeaways
- CAN-SPAM is an opt-out law. You may send the first cold email without consent, but you must stop within 10 business days of an opt-out request.
- It covers business-to-business email. The definition turns on the purpose of the message, not on who receives it.
- Five things sit in every message you control: true headers, an honest subject line, an ad label, a postal address and a working opt-out.
- Your list source does not change your duties. Filters help you target, but the unsubscribe, the address and the suppression list live in your sending tool.
What it is
CAN-SPAM is the 2003 US law that sets rules for any email whose primary purpose is to advertise or promote a commercial product or service, codified at 15 U.S.C. 7701 and following.
The statute defines a commercial message by its primary purpose. It has no business-to-business exception (15 U.S.C. 7702, September 2026). A cold email selling software to a VP is covered.
The Federal Trade Commission enforces it as an unfair or deceptive practice (15 U.S.C. 7706, September 2026). The penalty is set per violating email. The FTC's inflation-adjusted maximum under 15 U.S.C. 45(m)(1)(A) is $53,088 per violation (16 CFR 1.98, October 2026).
How it works
The core duties sit in 15 U.S.C. 7704(a). Each one is checkable before you press send (15 U.S.C. 7704, September 2026).
- Do not falsify header information. The from line, reply-to and routing data must identify the sender. A from line that accurately names the person who sent it is not misleading.
- Do not use a deceptive subject line. It must not mislead a reasonable recipient about what the message contains.
- Say it is an ad. The message needs a clear and conspicuous identification as an advertisement or solicitation. That duty falls away only when the recipient gave prior affirmative consent, which a cold recipient has not.
- Include a valid physical postal address of the sender.
- Give a working opt-out. The reply address or web mechanism must work for at least 30 days after you send, and you must honor a request within 10 business days.
Worked example, with placeholders. Jane Doe at Acme sends a cold email to a prospect and gets a reply on Monday saying "remove me".
- The opt-out is received on day 0. Acme has 10 business days to stop.
- Acme adds the address to its suppression list the same day, so no sequence step goes out after Monday.
- Acme may not sell, lease or pass that address to anyone else, except to comply with the law (15 U.S.C. 7704(a)(4), September 2026).
- Acme may not ask the person to pay, log in or give anything beyond an email address and their preferences. One reply or one web page is the most you can require (16 CFR 316.5, September 2026).
CAN-SPAM vs opt-in laws
People treat "CAN-SPAM compliant" as "legal to send anywhere". It is not. CAN-SPAM is a US rule, and many other countries require consent before the first message. This page covers the US law only, so check each country's rules before you send there.
| CAN-SPAM (US) | Opt-in regimes (many other countries) | |
|---|---|---|
| Consent before the first cold email | Not required | Generally required |
| Opt-out link | Required in every message | Usually required as well |
| Physical postal address | Required | Varies by country |
| Applies to B2B email | Yes | Varies by country |
| Who enforces | Federal Trade Commission | A national regulator, per country |
| What you do with a mixed list | Follow the strictest rule in the list | Split the list by country and apply each rule |
Treating the US rule as the global rule is the common mistake. A list with prospects in several countries needs a country check before it needs a subject line.
When it matters
You send from many mailboxes
Every mailbox that sends for you is the sender of record in the headers. The from line and reply-to must be real and accurate on all of them. Rotating names or domains to hide who you are is what the header rule is aimed at.
You use a campaign tool
Your sequencer sends the message, so the unsubscribe link and the physical address belong in its templates. Check that opt-outs land on a shared suppression list across every campaign. See best cold email campaigns for how tools handle this.
You hire an agency or write with AI
You cannot hand the duty off. The statute reaches people who send on your behalf and, in some cases, the business being promoted (15 U.S.C. 7705, September 2026). AI-written copy still needs the ad label and the address. See how to personalize cold emails with AI.
You build a list yourself
Do not guess addresses. The statute treats sending to addresses produced by combining names, letters or numbers into permutations as an aggravated violation when the message is already unlawful (15 U.S.C. 7704(b), September 2026). Use an address that has a verification status, and a new domain still needs warming up. See best cold email warm-up tools.
How LeadOcean handles it
LeadOcean is data, not a sending tool. It has no sequencer, no unsubscribe page and no suppression list, so those stay in your email platform. The two things it gives you are a country filter and an email status you can read before you send.
The country filter takes country codes from 254 countries. Use it to split one audience into a US batch and a batch for each other country, so each gets the rules that apply to it. Sizing is free: send count=true as a query parameter with limit 1 in the body (LeadOcean OpenAPI, September 2026).
curl -X POST "https://api.leadocean.io/v1/people/search?count=true" \
-H "x-api-key: $LEADOCEAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"jobLevel": ["VP"], "country": ["US"], "limit": 1}'
curl -X POST "https://api.leadocean.io/v1/people/search?count=true" \
-H "x-api-key: $LEADOCEAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"jobLevel": ["VP"], "country": ["DE"], "limit": 1}'Each call returns a meta.total, capped at 100,000, and spends no records. Add emailStatus to keep only the statuses you will send to. The same filters run in the MCP server through count_leads, which counts mailable people (verified, catch_all_valid and catch_all) by default. They also run in the Exports page of the app at app.leadocean.io, which shows the record price before you start.
LeadOcean makes no compliance claim for your campaigns. Whether a message meets CAN-SPAM depends on what you send, not on where the address came from. Pricing is two plans: Free (1,000 records, one-off, no card) and Pro at $499 a month. See pricing.
FAQ
Is cold email legal under CAN-SPAM?
Yes, in the US, if each message follows the rules above. The law does not require opt-in consent for a first commercial email. It requires honest headers, a clear ad label, a postal address and a working opt-out. This is not legal advice.
Does CAN-SPAM apply to B2B cold email?
Yes. The statute defines a commercial message by its primary purpose and makes no exception for business recipients (15 U.S.C. 7702, September 2026). A message to a work address is covered.
How fast must I honor an unsubscribe?
Within 10 business days of the request. The opt-out mechanism must also keep working for at least 30 days after you send the message. Most teams suppress the address the same day because a tool does it automatically.
Do I need a physical address in every cold email?
Yes. Every commercial message must carry a valid physical postal address for the sender. Put it in the signature or footer of every template, including each step of a sequence.
Does LeadOcean make my emails CAN-SPAM compliant?
No. LeadOcean supplies people and company data. Headers, subject lines, the ad label, the address and opt-outs are decisions in your own sending setup, and a lawyer should review them.
Build a country-split cold email list you can size before you send
Free to start. No credit card. 1,000 records to spend whenever you like.
Get your free API key →