If you send marketing emails as a real estate agent or broker, the CAN-SPAM Act requirements for real estate apply to nearly every one of them, and each noncompliant message can carry a civil penalty of up to $53,088. The rules themselves are short. Six elements have to appear in every commercial email, opt-outs must be honored within 10 business days, and the same obligations follow you when someone else sends email on your behalf.
Which Real Estate Emails the Law Covers
CAN-SPAM applies to any email whose primary purpose is commercial advertising or promotion. In a real estate practice, that sweeps in new listing announcements, open house invitations, market updates designed to generate leads, brokerage promotions, and “just sold” emails aimed at attracting new clients.
The law carves out “transactional or relationship messages.” These are emails that facilitate or confirm a transaction the recipient already agreed to, deliver warranty or safety information, or update account status in an ongoing commercial relationship. Confirming a showing appointment, sending closing documents, or updating a current client on their pending transaction sits on the transactional side. Those messages are largely exempt from CAN-SPAM’s requirements, though they still cannot contain false routing information.
One boundary worth flagging, because agents assume it works in their favor: if you tack a few new listings onto the bottom of a genuine closing update, the email may flip to commercial. The FTC looks at whether a reasonable person reading the subject line would conclude the email is an ad, and whether the transactional content appears mainly at the beginning. Bury the update below three featured listings and the whole message becomes commercial, with every requirement below in play.
Six Things Every Commercial Email Must Include
Every marketing email has to satisfy six requirements. Missing one on a single email is enough to create a violation.
- Accurate header information. The “From,” “To,” “Reply-To,” and routing fields must correctly identify you or your brokerage. No misleading sender names, no spoofed addresses.
- Honest subject lines. The subject has to reflect what the email actually contains. “Your offer has been accepted” as a subject on a mass marketing blast is deceptive. “New Listings in [Neighborhood]” on an email about new listings is fine.
- A clear advertisement disclosure. Each email must identify itself as an advertisement. The FTC gives wide latitude on how. A line reading “This is a promotional message” or “Advertisement” in the header or footer works.
- A valid physical postal address. This can be your office street address, a P.O. box registered with the U.S. Postal Service, or a private mailbox registered with a commercial mail receiving agency. Agents who work from home often use a registered P.O. box or commercial mailbox rather than publishing a home address.
- A working opt-out mechanism. The email needs a clear, easy-to-find way for recipients to unsubscribe. It has to remain functional for at least 30 days after you send.
- Prompt opt-out processing. Unsubscribe requests must be honored within 10 business days. You cannot require the recipient to give any information beyond an email address, or make them take any step other than sending a reply or visiting a single web page.
Most email marketing platforms handle several of these automatically, inserting your physical address and an unsubscribe link into every send. The platform does not write your subject lines or verify your header setup. Those stay on you.
Honoring Opt-Outs
A common misconception is that you need someone’s permission before sending them a marketing email. CAN-SPAM is an opt-out law, not an opt-in law. You can email a person who never consented, as long as the message meets every requirement above. The FTC’s compliance guide states plainly that “you don’t need to get members’ consent to send them marketing emails.”
What you cannot do is ignore an unsubscribe. Once someone opts out, you have 10 business days to stop emailing them. You cannot charge a fee, demand personal information beyond an email address, or route the recipient through multiple steps. One click to a single page, or a reply email, has to complete the process.
Opt-outs are permanent and they travel. You cannot sell or transfer the addresses of people who have unsubscribed, except to a company you have specifically hired to help with CAN-SPAM compliance. Your suppression list needs to carry over when you switch email platforms or service providers. Losing that list in a migration and starting fresh is how agents create violations without realizing it.
Purchased Lists and Co-Marketing Emails
CAN-SPAM does not prohibit sending to purchased or rented email lists. If every email on the send meets the Act’s requirements, the send is legal under federal law. That surprises agents who have been told they need prior consent from every recipient.
Purchased lists are still where most compliance problems begin. You have no way to know whether addresses on the list belong to people who already opted out of emails from a previous sender. Because the Act prohibits transferring opt-out addresses, emailing those recipients creates liability for everyone in the chain. You also cannot confirm that header information will match when the list contains stale or incorrect data.
The practical risk runs beyond the statute. High bounce rates and spam complaints from a purchased list damage your sender reputation, which pushes your emails to legitimate contacts into spam folders. Most reputable email marketing platforms prohibit imported purchased lists in their terms of service, and violating those terms can get your account shut down.
When You’re Liable for What Someone Else Sends
Hiring a marketing company, virtual assistant, or email service to send on your behalf does not shift the legal risk off you. The Act makes clear that both the company whose product or service is promoted and the company that physically sends the message can be held liable for violations.
When a single email promotes multiple marketers, one can be designated as the “sender” responsible for compliance. That only helps if the designated sender actually meets every requirement. If they fall short, every marketer mentioned in the email can be exposed.
For agents working with third-party lead generation services or co-marketing with lenders and title companies, the takeaway is direct: confirm that every email mentioning your name or services complies. Written agreements requiring compliance are useful, but they do not eliminate your legal exposure when the third party fails to follow through.
Penalties for Violations
Each individual email sent in violation of the Act can result in a civil penalty of up to $53,088. The FTC adjusts that figure periodically for inflation. A single blast to 5,000 contacts where every email is missing a physical address could theoretically generate over $265 million in exposure. The FTC and courts exercise discretion in practice, but the per-message math means even a small campaign becomes serious when it is systematically noncompliant.
State attorneys general can also bring civil actions on behalf of their residents. State-level damages are calculated at up to $250 per violation, with each individual email counted separately, capped at $2 million for most violation types. Courts can triple that to $6 million when violations are willful or involve aggravated conduct such as harvesting email addresses from websites or using automated tools to generate accounts for sending spam.
Some conduct carries criminal prosecution and up to five years in prison. The criminal provisions target commercial email with materially false header information, use of someone else’s computer without authorization to send bulk emails, and registering for email accounts under false identities to send commercial messages.
One detail catches many agents off guard: individual consumers cannot sue you directly under CAN-SPAM. Only the FTC, state attorneys general, and internet service providers have standing. That narrows who can bring an action, but the agencies with standing have the resources to impose penalties well beyond what a private plaintiff could seek. Enforcement tends to focus on senders with patterns of noncompliance rather than isolated mistakes, though a single large campaign with a systematic problem, such as a broken unsubscribe link across every message, can still generate outsized liability from one event.