This is a plain-English summary of US law and mailbox-provider rules, with links to the sources. It is not legal advice. If you send to people outside the US, their country's law applies too, and some are stricter: Canada's anti-spam law, for example, generally requires consent before you send.

The CAN-SPAM Act does not ban unsolicited commercial email. It sets rules for it, and it covers business email too: "The law makes no exception for business-to-business email" (FTC compliance guide). The rules are simple, and every one of them is something a recipient can check in your message.

The seven requirements

From the FTC's CAN-SPAM Act compliance guide for business:

  1. "Don't use false or misleading header information." The From name and address, Reply-To and routing must identify you or your business accurately.
  2. "Don't use deceptive subject lines." The subject must reflect what the message is about. No fake "Re:" or "Your invoice" on a sales email.
  3. "Identify the message as an ad." The FTC gives "a lot of leeway in how to do this, but you must disclose clearly and conspicuously that your message is an advertisement."
  4. Tell recipients where you are. "Your message must include your valid physical postal address. This can be your current street address, a post office box you've registered with the U.S. Postal Service, or a private mailbox you've registered with a commercial mail receiving agency established under Postal Service regulations." A registered private mailbox keeps your home address out of every email.
  5. Tell recipients how to opt out. Explain it clearly, and offer "the option to stop all marketing messages from you."
  6. Honor opt-outs promptly. "Any opt-out mechanism you offer must be able to process opt-out requests for at least 30 days after you send your message. You must honor a recipient's opt-out request within 10 business days." You may not charge a fee, ask for more than an email address, or sell or transfer the address once someone opts out.
  7. "Monitor what others are doing on your behalf." If an agency or a contractor sends for you, you are still responsible: "you can't contract away your legal responsibility."

What a violation costs

"Each separate email in violation of the CAN-SPAM Act is subject to penalties of up to $53,088," says the FTC. That is the current inflation-adjusted maximum in the Code of Federal Regulations (16 CFR 1.98), set in January 2025. The FTC announced that its civil penalty amounts "will remain unchanged during 2026" (Federal Register, 15 September 2026). Per email, not per campaign.

Aggravated violations: harvested and guessed addresses

Some ways of getting addresses make an already unlawful message worse. Under 15 U.S.C. 7704(b)(1), it is an aggravated violation when the sender knew, or should have known, that the address "was obtained using an automated means from an Internet website or proprietary online service operated by another person", where that site says it does not give out or sell addresses, or was generated "by combining names, letters, or numbers into numerous permutations" (a dictionary attack). In plain English: do not scrape addresses from websites, and do not guess them in bulk.

What the mailbox providers add

The law is the floor. Gmail, Yahoo and Microsoft decide whether your mail is delivered, and their rules are stricter (details):

A checklist for every cold email

Check What to do Source
From and Reply-To Your real name and business, on a domain you own FTC guide, rule 1
Subject Says what the email is about FTC guide, rule 2
Ad disclosure A clear line that this is a commercial message FTC guide, rule 3
Postal address Street address, registered PO box, or registered private mailbox FTC guide, rule 4; 16 CFR 316.2(p)
Opt-out One click or one reply, works for 30+ days, processed within 2 days FTC guide, rules 5 and 6; Yahoo
Suppression Opted-out addresses never emailed again, from any domain or tool FTC guide, rule 6
Address source Each address found for one business, one relevant reason; verified before sending 15 U.S.C. 7704(b)(1)
Volume 25 to 30 cold emails per inbox per day after warmup; spam rate under 0.1% lemlist's sending limits; Gmail
Authentication SPF, DKIM, DMARC on the sending domain Gmail, Yahoo, Microsoft

What this site will not help with

MailSetupCheck explains how to send email that is legal, wanted and authenticated. It does not cover, recommend or link to bought or rented lists, scraped addresses, tools for hiding who is sending, misleading subject lines, or ways around a mailbox provider's limits. Relevance is the only thing that keeps cold email under a 0.1% complaint rate.

Also available as Markdown.