Skip to content

Is B2B cold email legal? CAN-SPAM rules in the US

Updated By the SalesOne research team7 min read

The short answer

Yes. B2B cold email to US recipients is legal without prior consent under CAN-SPAM, which the FTC says makes no exception for business-to-business email. Each commercial message still needs accurate headers, an honest subject line, a valid postal address and a working opt-out that is honored within 10 business days.

Does CAN-SPAM apply to B2B email?

Yes. The CAN-SPAM Act (15 U.S.C. 7701–7713) and the FTC’s rule (16 CFR Part 316) cover every commercial electronic mail message. The FTC’s compliance guide states plainly that the law “makes no exception for business-to-business email”. A message to a work address at a company is covered the same way as a message to a consumer.

What CAN-SPAM does not do is require consent. It is an opt-out law: you may send a commercial email to someone you have never dealt with, as long as the message follows the rules and you stop when they ask. That is why B2B cold email is legal in the US, and why the details of each message matter.

What counts as a commercial email?

An email is commercial when its primary purpose is to advertise or promote a product or service (16 CFR 316.3). Cold outreach and every follow-up in a cold sequence are commercial.

A transactional or relationship message, such as an invoice, a receipt or an update on an existing account, is not commercial, though it still must not contain false or misleading routing information. Mixed messages are judged by the primary purpose test: if the subject line suggests an ad, or the transactional part does not come first, treat the message as commercial.

Message types under CAN-SPAM
MessageUsually treated asMain obligations
Cold outreach offering a product or serviceCommercialAll requirements below
Follow-up in a cold sequenceCommercialAll requirements below
Newsletter with promotional contentCommercialAll requirements below
Invoice, receipt, account or warranty noticeTransactional or relationshipNo false or misleading header information
Mixed messageCommercial if the subject line suggests an ad, or the transactional part does not come firstDepends on the primary purpose test

What are the CAN-SPAM requirements?

The FTC’s guide lists eight main requirements. Every commercial message must meet all of them, including each follow-up:

  1. Don’t use false or misleading header information. The From, To, Reply-To and routing information must be accurate and identify the sender.
  2. Don’t use deceptive subject lines. The subject must reflect the content of the message.
  3. Identify the message as an ad. Disclosure must be clear and conspicuous; the law leaves room in how you do it.
  4. Tell recipients where you’re located. Include a valid physical postal address: a street address, a USPS-registered post office box, or a private mailbox registered with a commercial mail receiving agency.
  5. Tell recipients how to opt out. The notice must be clear and easy to act on.
  6. Remember that subscribers and members can opt out. Membership or a subscription does not remove the right to opt out of commercial messages.
  7. Honor opt-out requests promptly: within 10 business days. The opt-out mechanism must work for at least 30 days after you send. You cannot charge a fee or ask for more than an email address and preferences, and you cannot sell or transfer the address after an opt-out.
  8. Monitor what others are doing on your behalf. Both the company whose product is promoted and the company that sends the message can be held responsible.

What are the penalties for violating CAN-SPAM?

Each separate email that violates the law can bring a civil penalty of up to $53,088, according to the FTC guide and the inflation-adjusted amount in 16 CFR 1.98. That figure was set in January 2025; the FTC announced in September 2026 that the 2025 amounts remain in effect.

  • Enforcement: the FTC, other federal agencies for the businesses they oversee, and state attorneys general can bring cases.
  • Private lawsuits: only internet access service providers have a right of action under the Act (15 U.S.C. 7706(g)). Individual recipients do not.
  • Aggravated violations: harvesting addresses, generating addresses by dictionary attacks, and automatically creating accounts to send can increase penalties (15 U.S.C. 7704(b)).
  • Criminal penalties apply to fraud-related conduct, such as falsified headers or sending through computers without authorization (18 U.S.C. 1037).

Do state email laws still apply?

Mostly not. CAN-SPAM preempts state laws that specifically regulate commercial email, except to the extent they prohibit falsity or deception (15 U.S.C. 7707(b)).

General state laws on fraud and computer crime still apply, so a deceptive email can be challenged under them even where a state’s own email statute is preempted. In practice, honest, accurate B2B email that meets the federal rules also meets the surviving state rules. The risk sits in the details CAN-SPAM already covers: misleading From names, fake reply threads and subject lines that misdescribe the message.

Is B2B cold email legal in Canada and the UK?

The rules are stricter than CAN-SPAM. Canada requires consent, and the UK exempts emails to companies from its consent rule but still applies data protection law.

Canada’s anti-spam law (CASL) prohibits sending a commercial electronic message without the recipient’s express or implied consent (section 6(1)). Implied consent can come from conspicuous publication: the person published the address, did not say they refuse unsolicited messages, and the message is relevant to their business role (section 10(9)(b)). Unsubscribe requests must take effect within 10 business days (section 11(3)).

In the UK, the ICO says the PECR rule on marketing by electronic mail does not apply to corporate subscribers, such as companies and limited liability partnerships. Sole traders and some partnerships are treated as individuals. You must still identify yourself and give a valid opt-out address, and UK GDPR applies to business contacts’ personal data. This guide does not cover EU law; check it with counsel.

What should a CAN-SPAM checklist for B2B cold email include?

A checklist should cover the sender, the subject, the address, the opt-out and the people sending for you. Check every message and every sequence step against it.

  • The From name and address identify your company or the person sending on its behalf.
  • The subject line describes the email honestly. No fake “Re:” or “Fwd:”.
  • The message is identifiable as a commercial message.
  • A valid physical postal address appears in every message.
  • Every message explains how to opt out, and the method works for at least 30 days.
  • Opt-outs are honored within 10 business days, across every mailbox and sequence.
  • Opted-out addresses are kept on a suppression list and never sold or shared.
  • Agencies and tools sending for you follow the same rules, and you check that they do.

How does SalesOne handle CAN-SPAM?

SalesOne checks email steps against CAN-SPAM before they can be sent and blocks the ones that fail. Opt-outs are global: once someone opts out, the address is suppressed across every mailbox and sequence. A person on your team approves every message before it goes out, so no email is sent only because a step was scheduled. These checks support your compliance program; they do not replace counsel’s review of it.

Sources

  1. FTC: CAN-SPAM Act: A Compliance Guide for Business (edited January 2024) (opens in a new tab)ftc.gov
  2. eCFR: 16 CFR Part 316 (CAN-SPAM Rule) (opens in a new tab)ecfr.gov
  3. eCFR: 16 CFR 1.98 (adjusted civil penalty amounts) (opens in a new tab)ecfr.gov
  4. 15 U.S.C. 7704 (requirements for commercial email) (opens in a new tab)govinfo.gov
  5. 15 U.S.C. 7706 (enforcement) (opens in a new tab)govinfo.gov
  6. 15 U.S.C. 7707 (effect on other laws) (opens in a new tab)govinfo.gov
  7. 18 U.S.C. 1037 (fraud in connection with email) (opens in a new tab)govinfo.gov
  8. Federal Register: FTC civil penalty amounts (FR Doc. 2026-18853) (opens in a new tab)public-inspection.federalregister.gov
  9. Canada’s Anti-Spam Legislation, S.C. 2010, c. 23 (sections 6, 10 and 11) (opens in a new tab)laws-lois.justice.gc.ca
  10. ICO: Business-to-business marketing (UK PECR and UK GDPR) (opens in a new tab)ico.org.uk

Where this fits in SalesOne

This guide fits the Engage step: outreach your team approves.

  1. Profile

    Who you are, what you sell, your proof

  2. Target

    Your ideal customer, written as rules

  3. Research

    Every account, from dated sources

  4. Score

    Fit, timing, reach and who decides

  5. Sequence

    A plan and a week of steps per account

  6. Engage(where this page fits)

    Outreach your team approves

  7. Close

    Meetings booked, the brief attached

  8. Refine

    Each run builds on the last

Frequently asked questions

Does CAN-SPAM apply to B2B emails?

Yes. The FTC says the law makes no exception for business-to-business email. Commercial messages to work addresses must meet every requirement.

Do I need consent to send B2B cold email in the US?

Not under CAN-SPAM, which is an opt-out law. You must include an opt-out in every commercial message and honor requests within 10 business days.

Is B2B cold email legal under CASL and UK rules?

Canada’s CASL requires express or implied consent; implied consent can cover a conspicuously published business address when the message fits the person’s role. In the UK, PECR’s email consent rule does not apply to companies, but UK GDPR does.

Can I use a PO box as my CAN-SPAM address?

Yes, if it is registered with the US Postal Service. A private mailbox registered with a commercial mail receiving agency also qualifies, as does a street address.

How fast must I honor an unsubscribe request?

Within 10 business days. Your opt-out mechanism must also keep working for at least 30 days after you send the message.

Can a recipient sue me under CAN-SPAM?

Individual recipients cannot. The FTC, other federal agencies, state attorneys general and internet access service providers can bring actions.

Do follow-up emails need an unsubscribe link?

Every commercial message needs a clear opt-out method. A link is common; a clear instruction to reply also works if it is honored.

Compliance checks before anything is sent

SalesOne checks CAN-SPAM requirements and opt-outs on every email step, and a person approves each message before it goes out.