TL;DR: Most CAN-SPAM guides stop at the seven requirements and leave you to figure out the risk yourself. This one pairs each rule with its actual enforcement exposure, shows where automation closes the compliance gap, and gives IT company owners a checklist they can run against live campaigns today. You'll finish with a decision matrix, not just a reading list.
What counts as a commercial email under CAN-SPAM
The CAN-SPAM Act defines a commercial email as any message whose primary purpose is advertising or promoting a commercial product or service. That definition is broader than most IT teams assume.
The classification that trips up IT companies most often is the transactional-vs-commercial boundary. A password reset or order confirmation is transactional — it facilitates an agreed-upon transaction. A renewal reminder that includes an upsell, a "your account is expiring" notice with a pricing table, or a product update email that pitches a new feature all cross into commercial territory under CAN-SPAM Act requirements for commercial emails. Primary purpose is the test, not the subject line.
When a single email contains both transactional and promotional content, the FTC looks at what a recipient would consider the dominant reason the message was sent. If promotion is the main point, the whole message is commercial and all seven requirements apply.
For a deeper look at how this distinction works in practice, see what transactional emails are and how they work and the transactional email vs marketing email breakdown. Getting this classification right before building any automated sequence saves significant compliance rework later.
The seven core CAN-SPAM requirements, explained
The CAN-SPAM Act requirements for commercial emails come down to seven rules. Get all seven right and you're compliant. Miss one and the FTC can fine you up to $53,088 per email under the current penalty schedule.
Here's what each rule actually requires.
1. Don't use false or misleading header information. Your "From," "To," and routing information must accurately identify who sent the message. If you're sending on behalf of a client, the entity whose product is being promoted owns the legal responsibility. These CAN-SPAM header rules apply to every commercial send, not just bulk campaigns.
2. Don't use deceptive subject lines. The subject line must reflect the actual content of the email. "Your account update" for a promotional offer is deceptive. "New pricing for your plan" is not.
3. Identify the message as an ad. The law gives you flexibility on how, but commercial intent must be clear somewhere in the message. Most senders satisfy this with a small-print disclosure near the footer.
4. Tell recipients where you're located. Every commercial email must include a valid physical postal address. A P.O. box or registered agent address qualifies. No address at all does not.
5. Tell recipients how to opt out. Every message needs a clear, conspicuous mechanism for opting out of future emails. This is the commercial email unsubscribe requirement most senders get wrong — the opt-out link must be easy to find, not buried in 8pt gray text. If you're still figuring out how transactional and commercial emails differ, note that transactional messages are exempt from this rule.
6. Honor opt-out requests within 10 business days. Once someone uses your opt-out mechanism, you have 10 business days to stop sending. You cannot charge a fee, require login, or ask for more information than an email address to process the request. This window is set by 15 U.S.C. § 7704(a)(4) and has not changed.
7. Monitor what others do on your behalf. If a third-party agency or contractor sends email for you, you're still legally responsible. Hiring out the work doesn't transfer the liability.
A concrete example of where this breaks down: an IT firm sends a "product update" email that includes a promotional upsell. That email is commercial, not transactional — building a permission-based list from the start keeps you on the right side of rules five and six before enforcement becomes a question.
CAN-SPAM Compliance Checklist Matrix: requirements, risk, and automation
Use this matrix as your standing CAN-SPAM compliance checklist. Each row maps one statutory requirement to its enforcement risk and the automation step that reduces exposure.
Requirement | Enforcement risk | Automation opportunity |
|---|
Accurate "From" name and address | Medium | Sender profile locked at the account level; no per-campaign editing |
Non-deceptive subject line | Medium | Subject-line flagging in a pre-send spam check catches misleading patterns before send |
Physical postal address in footer | Low | Footer template enforced globally; address populates automatically |
Clear "Advertisement" identification | Low | Conditional tag inserted by template rule when campaign type = commercial |
Functioning opt-out mechanism | High | Unsubscribe link generated and tested automatically on every send |
Honor opt-out within 10 business days | High | Suppression list updated in real time; no manual step required |
No third-party opt-out violations | High | Suppression list shared across all senders under the account |
The two high-risk rows deserve the most attention. The 10-business-day window is a hard statutory deadline under 15 U.S.C. § 7704(a)(4), and the FTC has cited opt-out failures in the majority of its documented enforcement actions. A suppression list that updates automatically closes that gap without relying on someone remembering to export a CSV.
The medium-risk rows are where most teams get lazy. A deceptive subject line is still a violation even when every other requirement is met, and the line between transactional and commercial email affects which messages need the "Advertisement" tag at all.
For teams building out their email marketing compliance setup from scratch, pairing this matrix with a permission-based email list reduces your surface area before the first campaign sends.
The next section covers what happens when these requirements aren't met, including specific FTC penalty figures.
Penalties for CAN-SPAM violations and real enforcement cases
Each violation of CAN-SPAM is treated as a separate offense. The FTC can fine a sender up to $53,088 per email — a figure adjusted periodically under the Federal Civil Penalties Inflation Adjustment Act. Send a non-compliant campaign to 10,000 addresses and the theoretical exposure runs into the hundreds of millions.
That's not hypothetical. In 2019, the FTC settled with Optin Rebel for $4.1 million over deceptive subject lines and failure to honor opt-out requests. In 2020, FloatMe faced FTC action for CAN-SPAM email compliance violations tied to missing opt-out mechanisms and misleading headers.
The 10-business-day window for processing opt-out requests under 15 U.S.C. § 7704 is the most commonly cited trigger in FTC enforcement email actions. Miss it once at scale and you've handed regulators a clean case.
A few patterns make enforcement more likely:
Sending commercial email with no physical address
Ignoring unsubscribe requests past the 10-day deadline
Using deceptive subject lines that misrepresent the message content
Understanding the difference between transactional and commercial email matters here because CAN-SPAM penalties apply specifically to commercial messages. If you're unsure whether your list was built on solid footing, permission-based email marketing is the right place to start before your next send.
Common CAN-SPAM violations and how to avoid them
The five CAN-SPAM violations that draw the most FTC attention are predictable, and each has a direct fix.
No physical postal address. Every commercial email must include a valid mailing address. Add it to your footer template once so it appears automatically.
Deceptive subject lines. Subject lines that misrepresent the email's content violate the Act directly. Write subject lines that match what's inside, full stop.
Broken or missing opt-out mechanism. Your unsubscribe link must work, and you must honor requests within 10 business days. If you're unsure whether yours qualifies, review what a compliant opt-out mechanism email setup looks like before your next send.
Misleading "From" fields. Sending from a domain that obscures who you are is a standalone violation. Use your actual business domain.
Continuing to mail after an opt-out. This is the most common enforcement trigger. Once someone unsubscribes, they come off your list within 10 business days, no exceptions.
One thing worth checking: if you're mixing promotional and service messages in the same send, understand the difference between transactional and commercial email before you classify it. Misclassifying a commercial email as transactional to sidestep CAN-SPAM Act requirements for commercial emails is itself a violation.
How email automation reduces your CAN-SPAM compliance risk
Manual compliance depends on someone remembering to do the right thing before every send. That's where most violations happen — not from bad intent, but from a missed step at 4 PM on a Friday.
Email marketing automation compliance shifts that responsibility from memory to system. A properly configured platform can insert your physical mailing address into every template automatically, block sends to addresses that have already unsubscribed, and enforce the 10-business-day opt-out window without anyone checking a spreadsheet. Automated unsubscribe processing is especially valuable if you're running sequences across multiple campaigns — a manual list sync will eventually fall behind.
The higher-value layer is pre-send validation. A pre-send spam check that flags issues before a campaign fires catches missing required fields, deceptive subject line patterns, and suppression list gaps before the message leaves your server — not after an FTC complaint arrives.
If you're unclear on which emails need these controls in the first place, the difference between transactional and commercial email determines which sends CAN-SPAM Act requirements for commercial emails actually govern.
CAN-SPAM vs GDPR: the differences that matter for your campaigns
CAN-SPAM and GDPR both govern commercial email, but they operate on opposite logic. CAN-SPAM is opt-out: you can email someone until they tell you to stop. GDPR is opt-in: you need documented consent before the first send. If your list includes EU contacts, GDPR's stricter standard applies to those sends regardless of where your company is based.
The practical gaps matter most on four dimensions:
Consent model: CAN-SPAM allows implied permission; GDPR requires explicit, recorded consent
Opt-out window: CAN-SPAM gives you 10 business days; GDPR requires honoring requests without undue delay, typically within 30 days
Territorial scope: CAN-SPAM covers US recipients; GDPR follows the recipient's location
Penalties: GDPR fines can reach 4% of global annual revenue, far exceeding CAN-SPAM's per-email structure
For permission-based list building that satisfies both frameworks, segment your list by geography before you send.
Closing
CAN-SPAM compliance isn't a one-time audit—it's a standing requirement that touches every commercial email your team sends. The seven rules are straightforward, but enforcement happens at the platform level: accurate headers, non-deceptive subject lines, working unsubscribe links, and a suppression list that actually updates when someone opts out. The gap most teams miss is automation. Manual compliance checks before each send don't scale, and the 10-business-day opt-out window leaves no room for forgotten CSV exports or delayed list updates. The question isn't whether you can stay compliant—it's whether you can do it without turning compliance into a bottleneck. What's your current process for handling unsubscribe requests, and how confident are you that it's hitting the 10-day deadline every time?
FAQ
What are the seven core requirements of the CAN-SPAM Act?
Accurate headers, non-deceptive subject lines, clear ad identification, valid physical address, functioning opt-out mechanism, honoring opt-outs within 10 business days, and monitoring third-party senders on your behalf.
What is considered a commercial email under CAN-SPAM?
Any message whose primary purpose is advertising or promoting a commercial product or service. Renewal reminders with upsells, account expiration notices with pricing tables, and product updates that pitch features all count as commercial, even if they contain transactional elements.
How long do you have to honor an unsubscribe request under CAN-SPAM?
10 business days. This is a hard statutory deadline under 15 U.S.C. § 7704(a)(4) and the most commonly cited trigger in FTC enforcement actions.
What are the penalties for violating the CAN-SPAM Act?
Up to $53,088 per email under the current penalty schedule. A single non-compliant campaign to 10,000 addresses can expose a sender to hundreds of millions in theoretical liability.
Does CAN-SPAM apply to B2B emails sent to business addresses?
Yes. CAN-SPAM applies to all commercial emails regardless of recipient type. The law does not exempt business-to-business messages.
How is CAN-SPAM different from GDPR for email marketing?
CAN-SPAM is a US law focused on message content and opt-out mechanisms; GDPR is EU law centered on consent and data rights. GDPR is stricter—it requires opt-in consent before sending, while CAN-SPAM allows sending first and requiring opt-out.
Can an email marketing platform automate CAN-SPAM compliance?
Yes. Platforms like Evox enforce compliance at send time with pre-send spam checks, automatic unsubscribe link generation, real-time suppression list updates, and locked sender profiles—removing manual review steps and closing the opt-out deadline gap.