Email compliance is not one rulebook, it is three or more, and they do not agree with each other. What is perfectly legal outreach in the United States can be a fineable offense in Canada, and the EU sits somewhere in between depending on the member state. This guide walks the three laws that matter most, CAN-SPAM, GDPR, and CASL, in plain language, then gives you the operational checklist that satisfies all of them at once. SpamCipher is a cold email platform built for unlimited email sending and automated cold email, and we are the only platform that can promise you 90%+ inbox placement; compliance is baked into how the pipeline sends, because staying legal and staying in the inbox are the same discipline. One note before we start: this is practical guidance from senders, not legal advice; for edge cases, talk to a lawyer.
What email compliance actually means
Commercial email answers to two separate enforcement layers, and confusing them is the most common compliance mistake we see.
The first layer is law: statutes like CAN-SPAM, GDPR, and CASL, enforced by regulators with fines. The law cares about consent, honesty, and the recipient's right to make you stop. The second layer is the mailbox providers: Google, Yahoo, and Microsoft, whose bulk-sender rules (authentication, one-click unsubscribe, complaint rates under 0.3%) are enforced not with fines but with the spam folder, immediately and at scale. We covered the provider layer in depth in cold email compliance in 2026; this article is about the legal layer, and the good news is the two overlap heavily. Build for the law and you are most of the way to pleasing the providers, and vice versa.
Which law applies is decided by where your recipient is, not where you are. A US company emailing prospects in Toronto answers to CASL. Emailing Berlin means GDPR. Any list with international addresses on it is a multi-jurisdiction list, which is why the practical answer is one process that clears the strictest bar you send into.
CAN-SPAM: the US baseline
The CAN-SPAM Act (2003) governs commercial email to US recipients, and it is the most permissive of the three: it is an opt-out regime. You do not need permission before emailing someone, including cold outreach to strangers, but you must follow the rules of honesty and exit:
- No false or misleading headers. Your from-name, from-address, and reply-to must accurately identify who is sending.
- No deceptive subject lines. The subject must reflect the content. "Re:" on a thread that never existed is a violation, not a growth hack.
- Include a valid physical postal address in every message: your street address, a registered PO box, or a commercial mail drop.
- Give a clear way to opt out, and honor it within 10 business days. You cannot charge for it, require a login, or ask for anything beyond an email address.
- You are liable for your vendors. If an agency sends on your behalf, their violations are your violations.
Penalties run to tens of thousands of dollars per email (the FTC adjusts the exact figure for inflation, and it has been north of $50,000 for years), so a non-compliant blast of a few hundred messages carries theoretical exposure in the millions. The rules are easy to satisfy; the fines are for people who choose not to.
GDPR and ePrivacy: the EU standard
The GDPR (2018) is not an email law, it is a data-protection law, and that distinction matters: an email address that identifies a person is personal data, so storing and using it requires a lawful basis before you ever hit send. For marketing to consumers, that basis is almost always consent: freely given, specific, informed, and provable. Pre-ticked boxes do not count, and you must keep records of who consented, when, and to what.
For B2B cold outreach, many senders rely on the second basis, legitimate interest: emailing a person about something squarely relevant to their professional role. It is workable, but it is not a loophole. You must be able to show the balancing test (your interest versus their privacy), disclose where you got their data if asked, and stop immediately when they object. On top of GDPR sits the older ePrivacy Directive, which member states implement differently: some are relatively permissive about B2B outreach, while others, Germany most famously, effectively require prior consent even business-to-business. If you prospect into the EU at scale, segment by country and match the rule to the strictest market you touch.
GDPR also grants rights your process must actually support: the right to access what you hold, the right to erasure, and the right to object to direct marketing, which is absolute. Fines scale to 20 million euros or 4% of global annual revenue, whichever is higher, and EU regulators have shown they will use the scale.
CASL: Canada, the strictest of the three
Canada's Anti-Spam Legislation (2014) inverts the American model: it is an opt-in regime. You need consent before sending a commercial electronic message to a Canadian recipient, and the burden of proving that consent is on you.
- Express consent is the gold standard: they actively agreed, and it never expires until withdrawn.
- Implied consent covers two useful cases: an existing business relationship (a purchase or contract, generally valid for two years), and the conspicuously published address: a business email published without a no-solicitation note, where your message is relevant to the person's role. That last one is the narrow lane that makes careful B2B prospecting into Canada possible.
- Every message needs your identity, contact information, and an unsubscribe that works and is honored within 10 days.
Penalties reach 10 million Canadian dollars per violation for organizations, and CASL is enforced. If Canadian addresses are on your list, tag them at import and hold them to the CASL standard, because "we treated everyone like CAN-SPAM" is not a defense the CRTC accepts.
The email compliance checklist that satisfies all three
Three laws, one operating procedure. Run every campaign through this list and you clear CAN-SPAM, hold the GDPR line, and stay inside CASL's lanes at the same time.
- Identify yourself honestly in every message: real from-name, real domain, physical postal address in the footer.
- Write subject lines that match the body. Honesty is both a legal requirement and a deliverability strategy.
- Make unsubscribe visible and instant. One click, no login, honored immediately; do not use the 10-day grace period as a feature. Suppression must propagate to every campaign and mailbox you run.
- Know your lawful basis per recipient. US: opt-out applies. EU: consent or a defensible legitimate interest, with the country's ePrivacy rule checked. Canada: express or implied consent, documented.
- Keep provenance records. Where did each address come from, and when? You need the answer for GDPR access requests and CASL consent challenges alike.
- Segment by jurisdiction. Tag country at import and let the strictest applicable rule govern each segment.
- Verify the list before sending. A validated list bounces less, complains less, and contains fewer landmines; verification is step one for compliance the same way it is for deliverability.
- Watch your complaint rate like a regulator would. Complaints under 0.3% keep providers happy and are your early warning that a segment did not want your mail.
This is also where an owned pipeline earns its keep. SpamCipher builds the mechanical half of email compliance into the sending path: one-click unsubscribe headers go on outbound mail automatically, suppression is global and immediate, the abuse monitor throttles anything trending toward complaint trouble before it becomes a report, and compliance monitoring keeps your authentication posture visible. The judgment calls (lawful basis, per-country policy) stay with you; the execution errors that actually trigger complaints get engineered out. That combination, legal process plus enforced sending hygiene, is how SpamCipher, the cold email platform for unlimited, automated cold email, stays the only platform that can promise you 90%+ inbox placement: compliant mail is deliverable mail, and we treat them as one system. If you are building the rest of that system, start with how to send cold email.
Send compliant, land in the inbox
One-click unsubscribe, instant global suppression, abuse monitoring, and verified lists, built into the sending pipeline instead of bolted on. Unlimited, automated cold email with 90%+ inbox placement, and the compliance mechanics handled.
Start sending compliantly


