Skip to content
Infinite Bookings
← Blog
Channels

CAN-SPAM for brokers, in six rules

Quick answer

CAN-SPAM applies to commercial email regardless of whether the recipient is a business, and it has no consent requirement at all — you may email someone who never asked. What it does require is a truthful header and subject line, a physical postal address, a clear identification that the message is an advertisement, and an opt-out that works within ten business days. Penalties run per message.

Alex MakowskiFounder, Infinite BookingsUpdated 2026-08-302 min read

CAN-SPAM is the inverse of the TCPA. The TCPA is strict about permission and quiet about content; CAN-SPAM does not require permission at all and is strict about what the message must contain. Brokers who learned compliance through the TCPA tend to get this backwards in both directions.

  • Header information must be accurate. The from, reply-to and routing must identify who actually sent it.
  • The subject line must not misrepresent the contents. "Re:" on a message that is not a reply is the classic violation.
  • The message must be identifiable as an advertisement, though the law is flexible about how.
  • A valid physical postal address must appear. A PO box that you registered counts.
  • A working opt-out mechanism must be present, and it must work for at least 30 days after sending.
  • Opt-outs must be honoured within 10 business days, and the address must not be sold or transferred afterwards.

Where brokers actually get caught

PracticeProblem
"Re:" or "Fwd:" on a cold emailDeceptive subject line
Sending from a lookalike personal addressInaccurate header information
No postal address in the footerStraightforward violation
Unsubscribe that requires a loginNot a functioning opt-out
Selling a list containing opted-out addressesProhibited transfer

None of these is subtle, and all of them are common in cold outbound aimed at merchants. The first is the one to stop doing today: fake reply prefixes are the single most-cited deceptive-subject practice, and they are used precisely because they work on open rates.

The rule that is not in the statute

Deliverability. Mailbox providers enforce sender reputation far more aggressively than the FTC enforces CAN-SPAM, and they enforce it against your domain. Authenticate with SPF, DKIM and DMARC, warm a sending domain before you use it at volume, and keep complaint rates low — or the compliant campaign lands in spam anyway.

Questions brokers ask

Yes. It covers commercial email regardless of whether the recipient is a business, which makes it the federal rule where the B2B framing genuinely gives you nothing.

Under CAN-SPAM, no — it has no prior-consent requirement. What it requires is truthful headers and subject lines, identification as an advertisement, a physical address and a working opt-out. State law and other countries’ rules can be stricter.

Within ten business days, and the opt-out mechanism must keep working for at least thirty days after the message was sent. The address must not then be sold or transferred to anyone else.

It is the textbook deceptive subject line — the message is not a reply and the prefix exists to suggest it is. It is also the practice most likely to be raised if anyone ever looks at your campaigns.

Civil penalties are assessed per message, which is what makes a bulk campaign expensive rather than a single email. Liability also reaches the business being promoted, not just whoever operated the send.

Get started.

We will tell you straight up if we cannot help you. No commission deals, no free trials, no chasing you for three weeks.

15 minute call

Rather not book?

Text my number instead