Yes โ under the federal CAN-SPAM Act, you can legally email someone who never opted in, as long as you follow the disclosure and opt-out rules that make it legal. The law does not ask for permission before you hit send. It asks for honesty about who you are and a working link to stop.
The catch is enforcement, not consent: the FTC can fine a business up to $53,088 per email, as of 2026, for hiding the sender, burying the ad label, or ignoring an opt-out request. Scraped or purchased lists carry their own separate risks, from spam filters to state and international law.
๐ง CAN-SPAM does not require opt-in before you send one commercial email.
โ๏ธ Each violating email can draw a fine up to $53,088 under federal law.
๐ Emailing contacts outside the US pulls in GDPR, Canada's CASL, or Australia's Spam Act.
๐ You must honor an opt-out request within 10 business days, with no exceptions.
๐งพ Scraped or purchased lists raise delivery and legal risk the law doesn't erase.
What "Permission" Means Under CAN-SPAM
Most people assume email marketing works like a subscription, where someone has to say yes before a business can email them at all. The CAN-SPAM Act does not work like that. It regulates how you send a commercial email, not whether the person agreed first. That single gap surprises more business owners than any other part of the law.
The Act defines a commercial message as any email whose main purpose is advertising a product or service. It covers a single cold email and a bulk campaign under the same rules, and it makes no exception for business-to-business mail. A message announcing a new product line to a former customer follows the same rules as a message to a total stranger. Size and audience don't change which rules apply.
What the law does demand is narrow and specific. Your header information has to be accurate, your subject line has to be honest, and the message has to disclose that it is an ad. It also has to list your real mailing address, so a recipient can identify who is contacting them. Skip any one of these, and the message becomes a violation regardless of consent.
The opt-out mechanism carries most of the actual legal weight in practice. You must give recipients a clear method to stop future emails, and that method has to keep working for at least 30 days after you send. Once someone opts out, you cannot sell their address, and you cannot charge a fee to honor the request. A vendor you hire strictly to help you comply is the only party you can still share that address with.
Businesses often confuse this narrow rulebook with a broad ban on unsolicited email. It isn't one. The rules exist to keep commercial email honest and reversible, not to require permission before the first message ever arrives.
Which Situation Applies to You?
Not every sender faces the same risk, even under one federal law. The right answer depends on your list source, your recipient's relationship to your business, and where that recipient lives. Match your situation below before you plan your next send.
You're sending a cold email to a purchased or scraped list
If you bought a list or scraped addresses from a website, CAN-SPAM itself does not forbid the email. Your legal exposure comes from elsewhere: most platforms ban scraping in their terms of service, and pulling data against those terms can trigger a breach claim. In some readings, it can even brush up against the Computer Fraud and Abuse Act. The email itself must still meet every other CAN-SPAM rule, from the header to the opt-out link.
A single scraped-list send that spikes spam complaints can also get your sending domain blocklisted within days. That harm often outlasts any short-term reply the email brings. Before you send to a purchased list, confirm both the source's terms and your own opt-out process are ready. Watch your unsubscribe rate on the first send closely, since a spike signals the list needs cleaning before you send again.
You're emailing an existing customer or newsletter subscriber
Subscribers and members still keep the right to opt out, even though you never needed their consent to add them. Before you skip the unsubscribe link on a message to this group, confirm the email is truly transactional. That means it confirms an order, reports account activity, or delivers something the customer already bought. Confirm the category before you decide the unsubscribe link is optional.
If any part of the message promotes a new offer, it needs the full commercial disclosures. A renewal notice that also pitches an upgrade, for example, crosses back into commercial territory. Treat mixed-purpose messages as commercial email whenever the promotional content leads the subject line. When the split isn't obvious, default to including the unsubscribe link, since it costs nothing and removes the ambiguity entirely.
You're prospecting B2B decision-makers
Cold B2B outreach is legal under federal law. The idea that CAN-SPAM only covers consumer spam is one of the most common mistakes founders make when they plan a first sales campaign. The same header, subject-line, and opt-out rules apply to a message sent to a company's general counsel as to a consumer inbox. A title or a job function changes nothing about which disclosures the law requires.
Treat a purchased B2B contact list with the same compliance care you would give a consumer list. A sales team that skips the physical-address rule because the target is "only a business contact" is making the exact assumption the law does not allow. Build one compliance checklist, and apply it to every list you touch, consumer or business.
Some of your recipients live outside the US
CAN-SPAM only controls what happens once an email touches US jurisdiction. A recipient in the European Union is protected by the ePrivacy Directive and GDPR, and both generally require opt-in consent before you can send marketing email at all. Canada's Anti-Spam Law and Australia's Spam Act 2003 add their own consent rules on top. A single mailing list rarely respects these borders on its own, so the sender has to draw the line manually.
A list built for a US audience can quietly become a liability the moment it crosses a border. Segment your recipients by country before every send, so a single campaign doesn't apply the wrong region's rule. When in doubt about a specific country's consent standard, treat opt-in as the safer default. A CRM field for country of residence is a small setup cost against a real compliance gap.
A Worked Example: What One Bad Send Can Cost
Say a small software company buys a list of 20,000 scraped business email addresses and sends one promotional email with no physical address and no working unsubscribe link. Under CAN-SPAM, that single send is not one violation. The FTC calculates penalties per email, not per campaign, so a flawed send to 20,000 addresses is potentially 20,000 separate violations.
At the current maximum of $53,088 per violation, the worst-case exposure on that single send tops a billion dollars. Real enforcement never reaches that ceiling. The FTC and state attorneys general typically pursue penalties in the low hundreds of thousands to low millions for a repeated, proven pattern. A first-time mistake that gets fixed fast rarely draws any fine at all.
| Scenario | Rough exposure |
|---|---|
| 20,000 emails, no violations | $0 |
| 20,000 emails, missing address and opt-out | Up to $53,088 ร 20,000 (theoretical maximum) |
| Typical FTC settlement, documented pattern | Low hundreds of thousands to low millions |
| First offense, corrected quickly | Often no fine, but a consent decree is possible |
The number still matters, even though real fines rarely reach that ceiling. It sets the outer bound a court could impose. That is also why insurers and lawyers treat a "small" list mistake as a real liability. The lesson isn't that one email will bankrupt a company; it's that per-email math turns a sloppy list into a number worth taking seriously.
Run your own version of this math before a large send. Multiply your list size by the current $53,088 ceiling, then compare that figure to what a compliant footer and opt-out link would have cost to build. The gap between those two numbers is a free, five-minute self-check any business can run before the send button gets pressed. Most companies find the compliant version costs an afternoon of setup, not a legal bill.
Three Lessons From Businesses That Got This Wrong
These are composite scenarios built from common compliance mistakes seen across small business email programs. Lesson 3 is grounded directly in a real case; the other two illustrate common, repeatable failures rather than naming an actual company. Each one teaches a distinct lesson, so read all three before you assume your own list is safe.
Lesson 1: The founder who skipped the physical address
A two-person startup sent its first cold campaign from a free email tool that didn't support a footer address field. The founder assumed a small business selling to other small businesses could skip the rule, since nobody reads the fine print anyway. That assumption was wrong on both counts, and it cost the campaign its second send.
A recipient complained to their email provider, which flagged the sending domain within a day. The campaign's delivery rate collapsed before the founder even noticed the missing address. Fixing the footer took ten minutes; rebuilding sender reputation took months.
| What went wrong | Why it mattered |
|---|---|
| No physical mailing address in the email | A core CAN-SPAM requirement, no matter the list size |
| Assumed B2B email is exempt | The law makes no B2B exception |
| Used a tool without a compliant footer | Both the sender and the platform share responsibility |
Lesson 2: The agency that ignored opt-outs for 12 days
A regional marketing agency ran a client's newsletter and treated unsubscribe requests as a weekly batch job instead of a running queue. Several recipients who opted out on a Monday still received the following week's promotion. That was twelve days after their request, well past the 10-business-day limit the law allows. Nobody on the team had assigned ownership of the opt-out list, so the delay went unnoticed for weeks.
One recipient filed a complaint with the FTC after the second unwanted email arrived. The agency spent more on the resulting legal review than the entire campaign had earned in revenue. The client also lost faith in the agency, which cost more than any single fine would have. The fix was simple once found: move opt-out processing to a daily job instead of a weekly one.
Lesson 3: The Florida business that scraped and bought its list
A Florida business planned to scrape emails from public sources, buy extra address lists, and send one unsolicited email to each name with only an opt-out link attached. This scenario is grounded in a real compliance question posed to a consumer-law attorney on Justia. The attorney's answer was direct: the plan would not necessarily violate CAN-SPAM on its own.
Scraping data against a platform's terms of service can still trigger a separate legal claim, apart from email law itself. Even one email can generate enough spam complaints to get a sending domain blocklisted. The deeper risk wasn't the statute on paper; it was trust, delivery, and the real chance that foreign recipients fell under GDPR or CASL instead. The attorney's core advice still stands: build trust in how you source addresses, since paper compliance won't fix a damaged sender name.
Federal Law First โ Then Check Your State and Audience
CAN-SPAM overrides most state anti-spam statutes. That makes federal rules the floor for every US business, no matter where it operates. A handful of states, including California, still enforce narrow rules against certain deceptive email practices. None of them currently add an opt-in rule on top of the federal standard.
Does a state privacy law change the answer?
Wider state privacy laws, like the California Consumer Privacy Act and Virginia's Consumer Data Protection Act, cover how you collect and store personal data. Neither one adds a separate opt-in rule for marketing email. They matter for your privacy policy and your data-retention practices, not for whether you can legally send the message in the first place. Several other states have passed similar privacy laws, and this same pattern holds across nearly all of them.
Treat these laws as a parallel compliance track, not a substitute for CAN-SPAM. A business can satisfy its state privacy obligations and still violate federal email law, or the reverse. Check both, because passing one doesn't clear the other. A short internal checklist covering both tracks takes less time to build than a single regulator inquiry does to answer.
What if you're emailing people outside the US?
The moment your list includes a contact in the European Union, the United Kingdom, Canada, or Australia, the calculus changes. The EU's ePrivacy Directive and GDPR usually require clear opt-in consent before any marketing email goes out. Canada's CASL requires express or narrowly defined implied consent, and Australia's Spam Act 2003 defaults to consent as well.
Segment your list by recipient location before every send. Treat the strictest rule that could apply as your standard for that segment. When a campaign reaches international contacts, or after any regulator inquiry, loop in a licensed attorney rather than guessing at the overlap. That single step is the cheapest insurance available against a multi-country send, and it takes far less time than answering a regulator's letter later.
7 Mistakes That Turn a Legal Email Into a Liability
A compliant CAN-SPAM strategy is easy to describe and easy to get wrong in the details. These are the mistakes that come up most often, each one enough to turn a legal email into a real liability.
- Skipping the physical mailing address. A P.O. box or registered private mailbox works, but leaving the field blank is a straightforward violation regardless of list size.
- Writing a subject line that oversells the offer. A subject line implying a prize, discount, or personal relationship the email doesn't deliver counts as deceptive under the law.
- Burying the ad disclosure. The message must clearly show it is an advertisement; hiding that fact in dense footer text does not satisfy the requirement.
- Processing opt-outs on a delay. Recipients get 10 business days by law, not whenever it's convenient for your email platform's schedule.
- Selling an address after someone opts out. Once a recipient unsubscribes, transferring their address to another company, except a vendor helping you comply with CAN-SPAM, breaks the law.
- Assuming B2B or subscriber status removes the opt-out requirement. Business recipients and existing subscribers both keep the right to unsubscribe from marketing content.
- Scraping addresses without checking a platform's terms. Even a technically compliant email can trigger a breach-of-contract or anti-hacking claim that has nothing to do with CAN-SPAM.
- Ignoring the recipient's country. A list with EU or Canadian contacts needs opt-in consent under GDPR or CASL, no matter how compliant the email is under US law.
Do's and Don'ts for Building a List You Can Use
Do
- Include a real, current physical mailing address in every commercial email.
- Give recipients an opt-out link that keeps working for at least 30 days.
- Process every opt-out request within 10 business days, without exception.
- Label promotional content as an advertisement clearly and plainly.
- Segment international contacts and apply the stricter local consent rule.
Don't
- Don't assume a B2B recipient loses the right to unsubscribe.
- Don't reuse a scraped list without checking the source platform's terms.
- Don't sell or transfer an email address after someone opts out.
- Don't bury the unsubscribe link where an ordinary reader would miss it.
- Don't treat a subscriber's existing relationship as blanket consent for every message.
Pros and Cons of Sending Without Explicit Opt-In
Pros
- Reach new prospects immediately, without waiting for a slow opt-in funnel to build.
- Test a new offer or market before investing in a full permission-based list.
- Combine cold outreach with an existing customer list for broader campaign reach.
- Legal under federal law when every CAN-SPAM disclosure and opt-out rule is followed.
- Faster than building an audience through content or paid opt-in advertising alone.
Cons
- Higher spam-complaint rates, which can damage sender reputation across every list.
- No protection if any recipient falls under GDPR, CASL, or a similar consent law.
- Scraped or purchased data often includes outdated or reassigned addresses.
- Blocklisting risk from a single complaint-heavy send, even with technical compliance.
- Reputational cost that outlasts any short-term reply or conversion the email produces.
What to Do Next
Before your next campaign touches an unverified list, work through these steps in order.
- Confirm your email template includes a real mailing address and a working unsubscribe link.
- Check whether any recipients live outside the US, and separate that segment out.
- Apply opt-in consent to every EU, UK, Canadian, or Australian contact before sending.
- Review how the list was built, and confirm scraping didn't violate a platform's terms.
- Set a process to honor opt-outs within 10 business days, not on a weekly batch.
- Keep records of consent, sends, and opt-outs in case a complaint is ever filed.
- Consult a licensed attorney before a large international send or after any regulator inquiry.

Frequently Asked Questions
Do you need permission to send a marketing email in the US?
No. Federal law under the CAN-SPAM Act does not require prior consent before sending a commercial email. It only requires that the message meets the Act's disclosure, labeling, and opt-out rules.
Is cold emailing legal for B2B sales?
Yes. CAN-SPAM applies to business-to-business email under the same rules it applies to consumer email. The law makes no exception for a recipient's job title or employer.
What happens if I don't include an unsubscribe link?
Your business becomes liable for a CAN-SPAM violation. Every commercial email needs a clear, working opt-out link. Skipping it is one of the most commonly enforced parts of the law.
How long do I have to honor an opt-out request?
Ten business days. The law requires you to stop emailing a recipient within that window after they ask. The opt-out method itself must keep working for at least 30 days.
Can I buy or scrape an email list legally?
It depends on the source. CAN-SPAM doesn't ban a purchased or scraped list outright. Scraping against a platform's terms of service can still create a separate legal claim unrelated to email law.
Does GDPR apply if I email someone in Europe?
Yes, if the recipient is in the EU or UK. GDPR and the ePrivacy Directive usually require signed-up opt-in consent before you send marketing email. That standard is stricter than the US federal rule.
Are subscribers exempt from needing an opt-out option?
No. Anyone on a subscription or membership list keeps the right to opt out of marketing messages. You never needed their consent to add them in the first place, but they can still leave at any time.
What's the maximum fine for a CAN-SPAM violation?
Up to $53,088 per violating email, as of 2026. The FTC adjusts this ceiling from time to time for inflation. Each nonconforming email can count as a separate violation.
Does California's privacy law require opt-in for email marketing?
Not specifically. The California Consumer Privacy Act covers data collection and consumer rights. Unlike GDPR, it doesn't add a separate opt-in rule for marketing email.
Is a "transactional" email exempt from CAN-SPAM's marketing rules?
Mostly, yes. A message that only confirms a transaction, reports account activity, or delivers a purchased product is exempt from most commercial-email rules. It still can't use false routing information, though.
Can I email a business contact without ever getting their consent?
Yes, under US federal law. CAN-SPAM permits cold B2B outreach without prior consent. The message still needs accurate headers, an ad disclosure, a physical address, and a working opt-out.