Is B2B cold email legal? CAN-SPAM rules in the US
Updated By the SalesOne research team7 min read
The short answer
Yes. B2B cold email to US recipients is legal without prior consent under CAN-SPAM, which the FTC says makes no exception for business-to-business email. Each commercial message still needs accurate headers, an honest subject line, a valid postal address and a working opt-out that is honored within 10 business days.
Does CAN-SPAM apply to B2B email?
Yes. The CAN-SPAM Act (15 U.S.C. 7701–7713) and the FTC’s rule (16 CFR Part 316) cover every commercial electronic mail message. The FTC’s compliance guide states plainly that the law “makes no exception for business-to-business email”. A message to a work address at a company is covered the same way as a message to a consumer.
What CAN-SPAM does not do is require consent. It is an opt-out law: you may send a commercial email to someone you have never dealt with, as long as the message follows the rules and you stop when they ask. That is why B2B cold email is legal in the US, and why the details of each message matter.
What counts as a commercial email?
An email is commercial when its primary purpose is to advertise or promote a product or service (16 CFR 316.3). Cold outreach and every follow-up in a cold sequence are commercial.
A transactional or relationship message, such as an invoice, a receipt or an update on an existing account, is not commercial, though it still must not contain false or misleading routing information. Mixed messages are judged by the primary purpose test: if the subject line suggests an ad, or the transactional part does not come first, treat the message as commercial.
| Message | Usually treated as | Main obligations |
|---|---|---|
| Cold outreach offering a product or service | Commercial | All requirements below |
| Follow-up in a cold sequence | Commercial | All requirements below |
| Newsletter with promotional content | Commercial | All requirements below |
| Invoice, receipt, account or warranty notice | Transactional or relationship | No false or misleading header information |
| Mixed message | Commercial if the subject line suggests an ad, or the transactional part does not come first | Depends on the primary purpose test |
What are the CAN-SPAM requirements?
The FTC’s guide lists eight main requirements. Every commercial message must meet all of them, including each follow-up:
- Don’t use false or misleading header information. The From, To, Reply-To and routing information must be accurate and identify the sender.
- Don’t use deceptive subject lines. The subject must reflect the content of the message.
- Identify the message as an ad. Disclosure must be clear and conspicuous; the law leaves room in how you do it.
- Tell recipients where you’re located. Include a valid physical postal address: a street address, a USPS-registered post office box, or a private mailbox registered with a commercial mail receiving agency.
- Tell recipients how to opt out. The notice must be clear and easy to act on.
- Remember that subscribers and members can opt out. Membership or a subscription does not remove the right to opt out of commercial messages.
- Honor opt-out requests promptly: within 10 business days. The opt-out mechanism must work for at least 30 days after you send. You cannot charge a fee or ask for more than an email address and preferences, and you cannot sell or transfer the address after an opt-out.
- Monitor what others are doing on your behalf. Both the company whose product is promoted and the company that sends the message can be held responsible.
What are the penalties for violating CAN-SPAM?
Each separate email that violates the law can bring a civil penalty of up to $53,088, according to the FTC guide and the inflation-adjusted amount in 16 CFR 1.98. That figure was set in January 2025; the FTC announced in September 2026 that the 2025 amounts remain in effect.
- Enforcement: the FTC, other federal agencies for the businesses they oversee, and state attorneys general can bring cases.
- Private lawsuits: only internet access service providers have a right of action under the Act (15 U.S.C. 7706(g)). Individual recipients do not.
- Aggravated violations: harvesting addresses, generating addresses by dictionary attacks, and automatically creating accounts to send can increase penalties (15 U.S.C. 7704(b)).
- Criminal penalties apply to fraud-related conduct, such as falsified headers or sending through computers without authorization (18 U.S.C. 1037).
Do state email laws still apply?
Mostly not. CAN-SPAM preempts state laws that specifically regulate commercial email, except to the extent they prohibit falsity or deception (15 U.S.C. 7707(b)).
General state laws on fraud and computer crime still apply, so a deceptive email can be challenged under them even where a state’s own email statute is preempted. In practice, honest, accurate B2B email that meets the federal rules also meets the surviving state rules. The risk sits in the details CAN-SPAM already covers: misleading From names, fake reply threads and subject lines that misdescribe the message.
Is cold email legal in the US?
Yes, for B2B email sent to US recipients under CAN-SPAM. You do not need prior consent, but you do need to follow every requirement above in every commercial message, including each follow-up.
The common practices below show where teams most often go wrong. Most problems are not about whether to send, but about how: a misleading subject line, a missing address or an opt-out that is not honored across every mailbox.
| Practice | Allowed? | Note |
|---|---|---|
| Emailing a work address without prior consent | Yes | CAN-SPAM is an opt-out regime |
| Subject line “Re:” on a first email | No | Misleading if there was no earlier thread |
| Sending from a domain other than your main one | Yes, if accurate | Headers must identify the sender truthfully |
| Omitting a postal address because it is B2B | No | Every commercial message needs one |
| “Reply ‘stop’ to opt out” as the only method | Generally yes | It must work, be clear, and be honored within 10 business days |
| Buying or harvesting email addresses | Risky | Harvesting is an aggravated violation; bought lists often contain opted-out addresses |
Is B2B cold email legal in Canada and the UK?
The rules are stricter than CAN-SPAM. Canada requires consent, and the UK exempts emails to companies from its consent rule but still applies data protection law.
Canada’s anti-spam law (CASL) prohibits sending a commercial electronic message without the recipient’s express or implied consent (section 6(1)). Implied consent can come from conspicuous publication: the person published the address, did not say they refuse unsolicited messages, and the message is relevant to their business role (section 10(9)(b)). Unsubscribe requests must take effect within 10 business days (section 11(3)).
In the UK, the ICO says the PECR rule on marketing by electronic mail does not apply to corporate subscribers, such as companies and limited liability partnerships. Sole traders and some partnerships are treated as individuals. You must still identify yourself and give a valid opt-out address, and UK GDPR applies to business contacts’ personal data. This guide does not cover EU law; check it with counsel.
What should a CAN-SPAM checklist for B2B cold email include?
A checklist should cover the sender, the subject, the address, the opt-out and the people sending for you. Check every message and every sequence step against it.
- The From name and address identify your company or the person sending on its behalf.
- The subject line describes the email honestly. No fake “Re:” or “Fwd:”.
- The message is identifiable as a commercial message.
- A valid physical postal address appears in every message.
- Every message explains how to opt out, and the method works for at least 30 days.
- Opt-outs are honored within 10 business days, across every mailbox and sequence.
- Opted-out addresses are kept on a suppression list and never sold or shared.
- Agencies and tools sending for you follow the same rules, and you check that they do.
How does SalesOne handle CAN-SPAM?
SalesOne checks email steps against CAN-SPAM before they can be sent and blocks the ones that fail. Opt-outs are global: once someone opts out, the address is suppressed across every mailbox and sequence. A person on your team approves every message before it goes out, so no email is sent only because a step was scheduled. These checks support your compliance program; they do not replace counsel’s review of it.
Sources
- FTC: CAN-SPAM Act: A Compliance Guide for Business (edited January 2024) (opens in a new tab)ftc.gov
- eCFR: 16 CFR Part 316 (CAN-SPAM Rule) (opens in a new tab)ecfr.gov
- eCFR: 16 CFR 1.98 (adjusted civil penalty amounts) (opens in a new tab)ecfr.gov
- 15 U.S.C. 7704 (requirements for commercial email) (opens in a new tab)govinfo.gov
- 15 U.S.C. 7706 (enforcement) (opens in a new tab)govinfo.gov
- 15 U.S.C. 7707 (effect on other laws) (opens in a new tab)govinfo.gov
- 18 U.S.C. 1037 (fraud in connection with email) (opens in a new tab)govinfo.gov
- Federal Register: FTC civil penalty amounts (FR Doc. 2026-18853) (opens in a new tab)public-inspection.federalregister.gov
- Canada’s Anti-Spam Legislation, S.C. 2010, c. 23 (sections 6, 10 and 11) (opens in a new tab)laws-lois.justice.gc.ca
- ICO: Business-to-business marketing (UK PECR and UK GDPR) (opens in a new tab)ico.org.uk