On this page
CAN-SPAM is the inverse of the TCPA. The TCPA is strict about permission and quiet about content; CAN-SPAM does not require permission at all and is strict about what the message must contain. Brokers who learned compliance through the TCPA tend to get this backwards in both directions.
- Header information must be accurate. The from, reply-to and routing must identify who actually sent it.
- The subject line must not misrepresent the contents. "Re:" on a message that is not a reply is the classic violation.
- The message must be identifiable as an advertisement, though the law is flexible about how.
- A valid physical postal address must appear. A PO box that you registered counts.
- A working opt-out mechanism must be present, and it must work for at least 30 days after sending.
- Opt-outs must be honoured within 10 business days, and the address must not be sold or transferred afterwards.
Where brokers actually get caught
| Practice | Problem |
|---|---|
| "Re:" or "Fwd:" on a cold email | Deceptive subject line |
| Sending from a lookalike personal address | Inaccurate header information |
| No postal address in the footer | Straightforward violation |
| Unsubscribe that requires a login | Not a functioning opt-out |
| Selling a list containing opted-out addresses | Prohibited transfer |
None of these is subtle, and all of them are common in cold outbound aimed at merchants. The first is the one to stop doing today: fake reply prefixes are the single most-cited deceptive-subject practice, and they are used precisely because they work on open rates.
The rule that is not in the statute
Deliverability. Mailbox providers enforce sender reputation far more aggressively than the FTC enforces CAN-SPAM, and they enforce it against your domain. Authenticate with SPF, DKIM and DMARC, warm a sending domain before you use it at volume, and keep complaint rates low — or the compliant campaign lands in spam anyway.
Questions brokers ask
Does CAN-SPAM apply to B2B email?
Yes. It covers commercial email regardless of whether the recipient is a business, which makes it the federal rule where the B2B framing genuinely gives you nothing.
Do I need consent to send a cold email to a merchant?
Under CAN-SPAM, no — it has no prior-consent requirement. What it requires is truthful headers and subject lines, identification as an advertisement, a physical address and a working opt-out. State law and other countries’ rules can be stricter.
How quickly must an unsubscribe be honoured?
Within ten business days, and the opt-out mechanism must keep working for at least thirty days after the message was sent. The address must not then be sold or transferred to anyone else.
Is using "Re:" in a cold subject line a violation?
It is the textbook deceptive subject line — the message is not a reply and the prefix exists to suggest it is. It is also the practice most likely to be raised if anyone ever looks at your campaigns.
What are the penalties under CAN-SPAM?
Civil penalties are assessed per message, which is what makes a bulk campaign expensive rather than a single email. Liability also reaches the business being promoted, not just whoever operated the send.
