CAN-SPAM Act

The CAN-SPAM compliance checklist, in plain English

The CAN-SPAM Act is U.S. law, not a mailbox provider guideline — and it applies to essentially every commercial email a business sends. The good news: compliance comes down to seven concrete rules. Here is the checklist, with what each rule really means.

Updated July 2026 · 9 min read

What CAN-SPAM covers

Passed in 2003 and enforced by the U.S. Federal Trade Commission, the CAN-SPAM Act sets the rules for commercial email — any message whose primary purpose is to advertise or promote a product or service. A few points surprise people: the law is not limited to bulk mail, so a single one-to-one sales email counts; there is no exemption for business-to-business email; and “transactional” messages (receipts, account notices) are treated separately and are mostly exempt. If your message is selling something, assume CAN-SPAM applies.

The CAN-SPAM requirements at a glance

Every requirement in the law reduces to one line. If you can answer yes to all seven, you are compliant:

  • No false or misleading header information.
  • No deceptive subject lines.
  • The message is identified as an ad.
  • A valid physical postal address appears in the message.
  • Recipients are told how to opt out.
  • Opt-outs are honored within 10 business days.
  • You monitor what agencies and platforms send on your behalf — the liability stays yours.

The rest of this page walks each requirement in checklist form, with what it really means in practice.

The seven rules

The FTC distills the law into seven requirements. Every commercial message has to satisfy all of them:

  • Don't use false or misleading header information. Your From, To, Reply-To, and routing details — including the originating domain and email address — must be accurate and identify who sent the message.
  • Don't use deceptive subject lines. The subject has to reflect what is actually in the message.
  • Identify the message as an ad. You get latitude in how, but you must disclose clearly and conspicuously that the message is an advertisement.
  • Tell recipients where you are located. Every message needs a valid physical postal address — a street address, a USPS-registered P.O. box, or a properly registered private mailbox.
  • Tell recipients how to opt out. Include a clear, conspicuous explanation of how to stop receiving email from you.
  • Honor opt-out requests promptly. Process them within 10 business days (more on this below).
  • Monitor what others do on your behalf. If you hire an agency or platform to send your mail, you are still legally responsible for compliance — you cannot outsource the liability.

The opt-out rules, in detail

The opt-out requirements are where senders most often slip. CAN-SPAM says the mechanism you offer must be able to process requests for at least 30 days after you send the message, and you must honor a valid unsubscribe within 10 business days. You cannot charge a fee, require any personal information beyond an email address, or make the recipient take any step other than sending a reply or visiting a single web page. You also may not sell or transfer an address once someone has opted out.

CAN-SPAM best practices that go beyond the law

The statute is a floor from 2003; mailbox providers grade on a much harder curve. These practices aren't legally required — they are what keeps compliant mail out of the spam folder:

  • Use confirmed (double) opt-in. CAN-SPAM doesn't require consent at all, but providers price consent in through complaint rates — mail people never asked for gets marked as spam.
  • Honor unsubscribes immediately, not in 10 business days. The law allows 10; Gmail and Yahoo expect one-click opt-outs processed within two.
  • Add RFC 8058 one-click unsubscribe headers even below bulk-sender volume. They cost nothing, and an easy exit is a complaint that never happens.
  • Keep the unsubscribe one click, no login. Gating opt-out behind a password or a fee isn't just bad practice — it violates the FTC rule outright.
  • Authenticate with SPF, DKIM and DMARC. CAN-SPAM is silent on authentication; spam filters are not. The Gmail DMARC requirements guide has the exact records to publish.
  • Prune non-openers and bounces. A complaint rate above 0.3% sinks legally compliant mail just as fast as illegal mail.
  • Sync suppression lists across every tool that sends for you. The seventh rule makes you liable for an agency's sends — an out-of-date suppression list at a vendor is your violation.

What it costs to get wrong

CAN-SPAM penalties are assessed per email, not per campaign. Each separate message in violation can draw a civil penalty of up to $53,088 (a figure the FTC adjusts for inflation), so a single non-compliant send to a large list carries real exposure. Deceptive practices can also trigger additional penalties under other FTC authority.

How CAN-SPAM fits with Gmail and Yahoo's rules

CAN-SPAM and the mailbox-provider rules overlap but are not the same. CAN-SPAM is the legal floor that applies to all commercial senders. The Gmail & Yahoo sender requirements go further for bulk senders — for example, they mandate RFC 8058 one-click unsubscribe, which CAN-SPAM does not strictly require. Meeting the law keeps you out of legal trouble; meeting the provider rules keeps you out of the spam folder. You want both.

Run your email through the checklist

Rather than eyeball every rule, let the free CAN-SPAM compliance checker do it. Paste your newsletter or upload the raw .eml and it looks for a physical address, a clear opt-out, honest headers, and the unsubscribe mechanics — then gives you a plain-English verdict on what to fix.

Frequently asked questions

What is the CAN-SPAM compliance checklist for businesses?

It is the seven FTC requirements every commercial email must meet: accurate header information, a non-deceptive subject line, clear disclosure that the message is an ad, a valid physical postal address, a conspicuous opt-out notice, opt-outs honored within 10 business days, and responsibility for anything a vendor sends on your behalf.

Does CAN-SPAM apply to B2B email or a single sales email?

Yes. The law covers any message whose primary purpose is commercial — there is no exemption for business-to-business email and no minimum volume, so a single one-to-one sales email counts. Transactional messages like receipts and account notices are mostly exempt.

What are the penalties for violating CAN-SPAM?

Civil penalties are assessed per email, not per campaign — currently up to $53,088 for each separate message in violation, a figure the FTC adjusts for inflation. A single non-compliant send to a large list carries real exposure.

How quickly must an unsubscribe request be honored under CAN-SPAM?

Within 10 business days. The opt-out mechanism must keep working for at least 30 days after you send, must be free, and cannot ask for anything beyond an email address or a visit to a single web page.

Is CAN-SPAM the same as the Gmail and Yahoo sender requirements?

No. CAN-SPAM is U.S. law and the legal floor for all commercial email. The Gmail and Yahoo sender requirements go further for bulk senders — mandating SPF, DKIM, DMARC, and one-click unsubscribe (Gmail requires RFC 8058 headers; Yahoo strongly recommends them). Compliant senders need both.

What are the CAN-SPAM requirements?

CAN-SPAM has seven core requirements: accurate header information, honest subject lines, identifying the message as an ad, including a valid physical postal address, offering a clear way to opt out, honoring opt-outs within 10 business days, and taking responsibility for email sent on your behalf. Each applies per email sent, and there is no exemption for B2B mail.

What are CAN-SPAM best practices?

Beyond the legal minimum: use confirmed opt-in, honor unsubscribes immediately rather than within the 10-day window, add RFC 8058 one-click unsubscribe headers, authenticate with SPF, DKIM and DMARC, and keep your spam-complaint rate under 0.3%. CAN-SPAM compliance keeps you out of court; these practices keep you out of the spam folder — Gmail and Yahoo enforce them regardless of what the statute requires.

Check your email against CAN-SPAM

Paste your message or upload the raw .eml and get a plain-English read on the physical-address, opt-out, and header rules — before you hit send.

Run a free check

Keep reading

Primary sources