The CAN-SPAM Act’s header and subject line requirements are the two rules most senders trip over first. Headers — the “From” name, the “Reply-To” address, and the underlying domain and IP data — must accurately identify whoever initiated the message. Subject lines must not mislead a reasonable recipient about what the email contains. Each violating email can cost up to $53,088 in civil penalties.1Federal Trade Commission. FTC Publishes Inflation-Adjusted Civil Penalty Amounts for 20252The White House. M-26-11 Cancellation of Penalty Inflation Adjustments for 2026
What Accurate Header Information Means
Under 15 U.S.C. § 7704(a)(1), header information in a commercial email cannot be materially false or materially misleading. That includes the “From” name, the “Reply-To” address, and the originating domain name and IP address. Each has to accurately identify the person or business that initiated the message.3Office of the Law Revision Counsel. 15 USC 7704 – Other Protections for Users of Commercial Electronic Mail
The clearest violation is “spoofing” — forging a sender address to impersonate another business or slip past spam filters. But the rule reaches further. Header data that looks technically accurate can still break the law if it was obtained through false pretenses. A domain registered under a fake name is materially misleading. So is routing a message through unauthorized servers to obscure where it actually came from. The metadata has to provide a clear trail back to the real sender.
One point catches senders off guard: the header rule applies to every email, not just marketing. Transactional messages — shipping confirmations, password resets, receipts — are exempt from most CAN-SPAM requirements, but they still cannot carry false routing information.4Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business Header accuracy is the one CAN-SPAM rule with truly universal reach.
Who Gets Named as the Sender
When one email promotes several marketers’ products, the parties can designate a single “sender” responsible for compliance. That designated sender must be identified in the “From” line and must handle the opt-out mechanism, physical address, and all other requirements. If the designated sender fails to comply, every marketer mentioned in the email can be held liable.4Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business
Hiring a marketing firm to send emails on your behalf doesn’t move the liability off your books either. The FTC has been explicit that businesses cannot contract away their CAN-SPAM obligations. Both the company being promoted and the company doing the sending can be pursued for the same violation.4Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business
What Makes a Subject Line Deceptive
A subject line violates CAN-SPAM if the sender knows, or should know based on the circumstances, that a reasonable recipient would be misled about what the email actually contains. The statute pegs this to the same deception standard the FTC uses across its consumer protection work.3Office of the Law Revision Counsel. 15 USC 7704 – Other Protections for Users of Commercial Electronic Mail
The most common violation is faking urgency or familiarity to force a click. A subject line reading “Your account has been debited” on an email that turns out to be a generic promotion fails the test, because a reasonable person would open it expecting account information. Pretending to reply to a prior conversation the recipient never started — “Re: Our meeting Thursday” — is another pattern regulators cite in enforcement actions.
Creative marketing hooks are still allowed. Puffery that no one would take literally can pass. The line gets crossed when the subject line creates a false impression about a material fact: what the email contains, who sent it, or what the recipient needs to do. If the body sells a specific product, the subject line has to connect to that product in some way, or at least signal that the message is commercial.
The Experian case shows how these two rules stack. In 2023, the FTC reached a $650,000 settlement with Experian Consumer Services over marketing emails that told recipients the messages contained “important information about your account” when the content was actually product promotion. The complaint bundled the deceptive subject lines together with a broken unsubscribe mechanism.5Federal Trade Commission. FTC Charges Experian with Spamming Consumers
The Reasonable-Recipient Test in Practice
Because the standard turns on what a reasonable recipient would conclude, subject lines get analyzed in context. A phrase that would mislead a general consumer audience might be fine for a specialist list that would read it differently. Regulators look at the audience, the sender’s history with the recipient, and whether the body of the email delivers on whatever the subject line promised. When it doesn’t, the deception case gets easier to prove.
Penalties Are Assessed Per Email
The civil penalty for each violating email is up to $53,088. That figure reflects the FTC’s 2025 inflation adjustment and remains in effect for 2026 after the Office of Management and Budget canceled the scheduled 2026 cost-of-living update.1Federal Trade Commission. FTC Publishes Inflation-Adjusted Civil Penalty Amounts for 20252The White House. M-26-11 Cancellation of Penalty Inflation Adjustments for 2026
Because the penalty applies to each message, exposure scales with volume. A campaign that hits a million inboxes with a deceptive subject line creates a million separate violations on paper. Actual settlement amounts tend to run far below the theoretical maximum, but the ceiling explains why the FTC treats deceptive-header and deceptive-subject cases as high-priority matters.
Who Enforces These Rules
The FTC is the primary enforcement agency and treats CAN-SPAM violations as unfair or deceptive acts under the FTC Act. Other federal regulators handle entities in their jurisdictions: the OCC for national banks, the SEC for brokers and investment advisers, the FCC for telecom carriers. State attorneys general can also bring CAN-SPAM actions on behalf of their residents.6Office of the Law Revision Counsel. 15 USC 7706 – Enforcement Generally
Individual consumers cannot sue under CAN-SPAM. The statute gives a private right of action only to internet access service providers adversely affected by violations, and courts have read that standing requirement narrowly. Enforcement in practice comes from federal agencies and state attorneys general, not from private plaintiffs.6Office of the Law Revision Counsel. 15 USC 7706 – Enforcement Generally
State laws targeting fraud or deception in commercial email survive federal preemption, along with general state laws that aren’t specific to email — trespass, contract, and tort. A deceptive email blast can therefore trigger a CAN-SPAM enforcement action and a state consumer fraud lawsuit at the same time.7Office of the Law Revision Counsel. 15 USC 7707 – Effect on Other Laws
What Header and Subject Line Compliance Doesn’t Cover
Getting the header and the subject line right does not, by itself, make a commercial email compliant. CAN-SPAM also requires a clear notice that the message is an advertisement (unless the recipient gave prior affirmative consent to the labeling exemption), a valid physical postal address for the sender, and a working opt-out mechanism that stays live for at least 30 days.4Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business A truthful header paired with an accurate subject line still fails the statute if the email carries no unsubscribe option or no physical address.
The header and subject line rules are the two requirements that turn on the content of the message itself rather than on process. That’s why they attract the most enforcement attention, and why they’re the first place to audit a marketing program.