Email compliance requirements for a US business start with the federal CAN-SPAM Act and expand outward from there: authentication rules enforced by Gmail and Yahoo, the GDPR for European recipients, Canada’s CASL, the TCPA for text messages, HIPAA or GLBA if you operate in a regulated industry, and a growing set of state privacy laws that govern the subscriber data behind your campaigns. Each non-compliant commercial email can draw a federal civil penalty of up to $53,088, so a single campaign sent to 10,000 inboxes can put a company’s exposure in the hundreds of millions of dollars.1Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business2Federal Register. Adjustments to Civil Penalty Amounts
What CAN-SPAM Requires of Every Commercial Email
CAN-SPAM applies to any electronic message whose primary purpose is advertising or promoting a product or service.3Office of the Law Revision Counsel. 15 USC 7702 – Definitions Transactional messages — shipping confirmations, password resets, account statements — are exempt from most of the rules, though they still cannot use false or misleading routing information.1Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business When a message mixes promotional and transactional content, its classification turns on what a reasonable recipient would view as the primary purpose based on the subject line and where the promotional material sits in the email.
Every commercial message must meet a baseline set of rules. The “From,” “To,” “Reply-To,” and routing information have to accurately identify who sent the message. Subject lines must reflect the actual content. Each email needs to include a valid physical postal address, which can be a street address, a registered post office box, or a private mailbox with a commercial mail receiving agency.1Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business The message must clearly identify itself as an advertisement and give the recipient a visible way to opt out.
One point that catches many businesses off guard: CAN-SPAM makes no exception for business-to-business email. A promotional message sent to a corporate purchasing manager is subject to the same rules as one sent to a consumer’s personal inbox.
Handling Unsubscribes and Suppression
Once a recipient opts out, you have ten business days to stop sending them commercial messages, and the opt-out mechanism itself must remain functional for at least 30 days after the original message went out.1Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business4Office of the Law Revision Counsel. 15 USC 7704 – Other Protections for Users of Commercial Electronic Mail You cannot charge a fee, ask for personal information beyond an email address, or force the recipient through more than one webpage to unsubscribe.
After processing the request, the address goes on an internal suppression list that must be cross-referenced against every future campaign. Selling or transferring opted-out addresses is illegal unless the transfer is solely to help another organization comply with the law.4Office of the Law Revision Counsel. 15 USC 7704 – Other Protections for Users of Commercial Electronic Mail This is where compliance programs most often break down in practice. Suppression lists have to be synchronized across every sending platform, marketing automation tool, and agency that touches your outbound email. A single unsynchronized database can generate violations at scale.
Authentication Rules From Gmail and Yahoo
Technical authentication has moved from best practice to a functional gate on whether your email reaches inboxes at all. Since early 2024, Gmail and Yahoo have required all bulk senders — defined as anyone sending 5,000 or more messages per day to their users — to implement SPF, DKIM, and DMARC.5Google. Email Sender Guidelines – Google Workspace Admin Help The bulk-sender classification is permanent once triggered, even if your volume later drops below the threshold.
SPF publishes the list of servers authorized to send email on behalf of your domain. DKIM attaches a cryptographic signature to each message so the receiving server can confirm it was not altered in transit. DMARC tells receiving servers what to do when a message fails the SPF or DKIM check: deliver, quarantine, or reject. A DMARC policy set to “none” provides monitoring data but offers no protection against spoofing. The usual path is to begin with monitoring, move to quarantine, and reach a reject policy once every legitimate sending source is aligned.
Bulk senders also have to support one-click unsubscribe by including a machine-readable List-Unsubscribe header in every marketing message, which is separate from the visible unsubscribe link in the email body.5Google. Email Sender Guidelines – Google Workspace Admin Help Spam complaint rates must stay below 0.10 percent and never reach 0.30 percent, and messages must be transmitted over TLS-encrypted connections. Failing these requirements does not trigger a government fine, but it will get your messages blocked or filtered before they ever reach the inbox.
Sending Marketing Email Outside the United States
European Union: GDPR
The General Data Protection Regulation operates on an opt-in model. You need affirmative, unambiguous consent before the first commercial message is sent.6General Data Protection Regulation (GDPR). GDPR Consent Silence, pre-ticked boxes, and inactivity do not count. The recipient must take a deliberate action, typically checking an unchecked box or clicking a confirmation link.
The burden of proof falls on the sender. Under Article 7, the data controller must be able to demonstrate that the individual consented, and that obligation lasts as long as you continue processing their data.7GDPR-Text.com. Article 7 GDPR – Conditions for Consent In practice, you need to log the timestamp, the specific language the user saw, the method of consent, and which processing activities they agreed to. If you cannot produce that record during an audit, the consent is treated as if it never existed.
Canada: CASL
Canada’s Anti-Spam Legislation recognizes two forms of permission. Express consent holds until the recipient withdraws it. Implied consent is narrower, typically arising from an existing business relationship, and it expires: usually two years after the last purchase or contract, or six months after an inquiry. Every message must identify the sender by name, include a current mailing address, and provide at least one additional contact method that remains valid for at least 60 days after sending.8Innovation, Science and Economic Development Canada. Getting Consent to Send Email Unsubscribe requests, however they arrive, must be honored within 10 business days.9Canadian Radio-television and Telecommunications Commission. Canada’s Anti-Spam Legislation (CASL) Guidance on Implied Consent
Text Message Marketing Is Governed Separately
The rules for SMS marketing sit under the Telephone Consumer Protection Act, not CAN-SPAM, and they are stricter. The TCPA requires prior express written consent before you send any automated marketing text. The consent disclosure has to spell out that the recipient is agreeing to receive automated marketing messages from a named company, that message and data rates may apply, and that consent is not a condition of purchasing anything. Consumers must also be told they can revoke consent at any time.
Statutory damages run $500 per unauthorized text, and courts can treble that to $1,500 per message for willful violations. Unlike CAN-SPAM fines, TCPA claims can be brought by private individuals and through class actions. A text blast to 50,000 people without proper consent creates exposure that dwarfs anything on the email side.
Opt-out processing mirrors the email rules: recipients must be able to reply “STOP” to end messages, and the sender has 10 business days to process the request. One final confirmation message acknowledging the opt-out is allowed, but it cannot contain promotional content.
Industry Overlays: Healthcare and Financial Services
If you handle patient information, HIPAA’s Security Rule requires administrative, physical, and technical safeguards on electronic health information, including when it moves by email.10U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule The rule does not mandate a specific technology. Encryption is classified as “addressable,” meaning covered entities must assess whether it is reasonable and appropriate for their environment and document the rationale if they choose an equivalent alternative.11U.S. Department of Health and Human Services. Security Standards Technical Safeguards Most organizations end up encrypting email containing protected health information because the risk analysis supports it, but the legal requirement is the risk assessment itself.
Financial institutions are subject to the Gramm-Leach-Bliley Act, which requires firms to explain their information-sharing practices to customers and to safeguard non-public personal information such as account numbers, income data, and credit history.12Federal Trade Commission. Gramm-Leach-Bliley Act13FINRA. Books and Records Requirements Checklist for Broker-Dealers14FINRA. Books and Records Electronic records must be stored in a non-rewriteable, non-erasable format or an audit-trail system that can recreate the original if it is modified.15U.S. Securities and Exchange Commission. Amendments to Electronic Recordkeeping Requirements for Broker-Dealers
State Privacy Laws
More than 20 states now have comprehensive consumer data privacy laws, including California’s CCPA, Virginia’s Consumer Data Protection Act, and Colorado’s Privacy Act. These statutes do not directly regulate the content of a marketing email the way CAN-SPAM does. They govern the personal data that powers the campaign: subscriber lists, behavioral tracking, purchase history, and browsing data used for segmentation. Most give residents the right to opt out of the sale or sharing of their personal information, to request deletion, and to see what a business has collected about them.
If your email program pulls data from residents of these states, you likely need to honor opt-out-of-sale requests, provide a deletion mechanism, and include disclosures about how you use personal information. Penalties and enforcement mechanisms vary by state, and some allow private lawsuits in addition to attorney general enforcement.
Penalties and Stacked Liability
The FTC enforces CAN-SPAM through civil penalties of up to $53,088 for each non-compliant email under the most recent inflation adjustment.1Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business2Federal Register. Adjustments to Civil Penalty Amounts The government does not have to prove the sender intended to deceive anyone. Both the company whose product is promoted and the firm that sends the message can be held liable, and you cannot contract that responsibility away to an agency or affiliate.
Some conduct crosses into criminal territory. Harvesting email addresses from websites with automated tools, generating addresses through dictionary attacks, and relaying spam through unauthorized access to someone else’s computer are all federal offenses.4Office of the Law Revision Counsel. 15 USC 7704 – Other Protections for Users of Commercial Electronic Mail Sending commercial email containing sexually oriented material without the required warning label carries a penalty of up to five years in prison.
The frameworks stack. A single email could violate CAN-SPAM, breach HIPAA transmission safeguards, and trigger a state privacy law complaint at the same time. A single unauthorized text could expose the sender to TCPA statutory damages, a state attorney general action, and a class-action lawsuit from the same message. The cost of building proper consent flows, suppression-list infrastructure, and authentication records is small compared to the cost of defending even one multi-front enforcement action.