Guide
Cold email, legally: CAN-SPAM in plain English
The US rules for commercial email, translated — what CAN-SPAM actually requires, what it doesn't, and the mistakes that get small businesses in trouble.
This is education, not legal advice. Email law has real penalties and real edge cases, and rules differ by country and by channel (text messages are governed far more strictly — see TCPA in the AI & automation glossary). Before launching any outreach campaign, have a lawyer review your specific plan.
Cold email to businesses is legal in the United States — if you follow CAN-SPAM. The law is more permission-less than Europe’s GDPR — its own, stricter data-privacy law, a different set of rules entirely — but it has hard requirements, and automation makes violations scale just as fast as outreach.
What CAN-SPAM actually requires
1. Tell the truth in the envelope. Your “From” name, reply address, and subject line can’t be deceptive. “Quick question” as a subject for a sales pitch lives in a gray zone; impersonating a colleague or faking a reply thread (“RE: our call”) does not — that’s straightforwardly deceptive.
2. Identify it as an ad — reasonably. The law requires “clear and conspicuous identification that the message is an advertisement,” interpreted with flexibility. An honest message that plainly offers your service satisfies this; a message engineered to look personal-but-not-commercial invites trouble.
3. Include your physical postal address. Every commercial email needs a valid postal address for your business — street address or registered P.O. box. It usually lives in the footer. No address, no campaign.
4. Give a working unsubscribe — and honor it fast. Every message needs an opt-out that works without a login or a fee, and requests must be honored within 10 business days. In practice, honor them immediately and automatically: a suppression list your sending system checks before every send. One “oops, they were still in the queue” is a violation per message.
What it doesn’t require (common myths)
You don’t need prior consent to email a business contact in the US. You don’t need “double opt-in” for cold B2B outreach. You don’t need to stop after one message. What you do need is the discipline above on every single message — and a sense of proportion, because legality is the floor, not the strategy.
The automation angle
If software sends your email, the compliance work moves from “remembering” to system design: the footer with your postal address is in the template, the unsubscribe link is generated per-recipient, the suppression list is checked at send time, and nobody can bypass it by being in a hurry. This is a place where good automation is more compliant than a busy human — and sloppy automation is a violation machine. The plumbing that makes it safe is the same plumbing described in Anatomy of a lead-intake pipeline, pointed outward.
The deliverability reality check
Separate from the law: inbox providers are stricter than regulators. Send too much too fast from a cold domain and your mail lands in spam regardless of legality — warm up sending domains gradually, keep lists clean and verified, and watch bounce rates. Legal and delivered are two different projects; you need both.
Found this useful?
It is one of many — the rest of the library is free to read too. Browse around, or send a note if you want to talk something through.
Browse the libraryor get in touch