Coldoutreach

· 8 min read · Coldoutreach editorial

Is Cold Email Legal? CAN-SPAM Rules for B2B Cold Outreach

Try the sequence composer

Sequence composer booked

I do outreach as

Prospect industry

Tone

Open Reply meetings/mo

warmup active · unsubscribe included · suppression respected

Yes, cold email is legal in the United States. CAN-SPAM (15 U.S.C. 7704) does not require prior consent before you send a commercial email, so B2B cold outreach to a work address is lawful as long as you follow the rules: honest headers and subject lines, a valid physical postal address, and a working opt-out that you honor promptly. Consent is a European idea, not an American one.

That answer surprises people, mostly because GDPR coverage has trained everyone to assume opt-in is universal. It is not. The US federal standard is opt-out, and it has been since 2003. Below: what the law requires, what it costs to get wrong, and how the rules change the moment you email someone in Berlin or Toronto. This is general information, not legal advice.

Is cold emailing illegal?

No. Cold emailing is not illegal in the United States, and no US law bans unsolicited commercial email outright. CAN-SPAM regulates how you send it rather than whether you may send it at all. An unsolicited email to a prospect who never heard of you is perfectly lawful if the message is truthful, identifiable and easy to escape.

The confusion comes from the name. CAN-SPAM stands for Controlling the Assault of Non-Solicited Pornography And Marketing, which sounds like a ban. In practice Congress chose a disclosure-and-exit regime: you may email strangers, but you may not lie about who you are, hide where you are, or trap them in your list. Break those conditions and a lawful cold email becomes an unlawful one. It is a behavioral test, not a permission test.

Do I need consent to send a cold email?

Not in the United States. CAN-SPAM contains no opt-in requirement, no double opt-in requirement, and no pre-existing business relationship requirement. You can lawfully email a VP of Engineering you found on a company website this morning, provided the message identifies you honestly and gives them a working way out.

Consent shows up elsewhere, which is why this myth is stubborn. Canada requires it. Several EU member states require it. US telemarketing and SMS law under the TCPA requires it. Email to US inboxes does not. What matters instead is source quality: scraped and purchased lists produce complaints, and complaints produce filtering, so permission-based list building is a deliverability decision long before it becomes a legal one. Lawful and effective are different tests. You have to pass both.

What are the CAN-SPAM rules for cold email?

CAN-SPAM sets seven core rules, and all seven apply to a one-to-one prospecting email exactly as they apply to a newsletter blast. Truthful routing information, an honest subject line, a disclosure that the message is an ad, your real postal address, a clear opt-out, prompt honoring of that opt-out, and responsibility for anyone you hire.

Rule (15 U.S.C. 7704)What it means in practiceWhat a compliant cold email does
No false or misleading headersFrom, To, Reply-To and routing data must identify the real sender and originating domain.Sends as a named human at the company domain, with a reply-to that reaches that human.
No deceptive subject linesThe subject must reflect the content. A fake "Re:" on a first touch is a violation.Uses a plain subject matching the body: "Question about your SDR onboarding".
Identify the message as an adDisclosure must be clear and conspicuous, though the law lets you choose how.Says plainly why you are writing and that you are pitching.
Include a valid postal addressYour current street address or registered PO box, in every commercial message.Puts the address in the signature, on every email in the sequence.
Tell recipients how to opt outA clear, conspicuous explanation of how to stop hearing from you.One line: "Reply STOP and I will not contact you again."
Honor opt-outs promptly10 business days is the statutory window, and the mechanism must work for at least 30 days after sending.Suppresses the address immediately and globally, across every campaign and inbox.
Monitor what others do for youHiring an agency or freelance SDR does not transfer liability. Both parties can be held responsible.Audits the agency's domains, opt-out handling and suppression list before launch.

Two of these are the ones cold email teams break by accident. The opt-out clock is 10 business days, but an address that gets another sequence step two days after unsubscribing is already a violation if suppression was never applied, so the only safe implementation is immediate and global. And the ad-disclosure rule does not mean stamping "ADVERTISEMENT" on a prospecting email. It means not disguising a pitch as something else. The compliant cold email approach here is to write like an honest salesperson.

What is the penalty for violating CAN-SPAM?

Penalties are assessed per email, not per campaign, which is what makes CAN-SPAM dangerous at outbound volume. The FTC adjusts the maximum civil penalty for inflation every year; as of the 2026 adjustment it runs up to $53,088 per violating email. Check the FTC's current figure before you rely on any number, including this one.

Do the arithmetic on a bad week. A sequence of 2,000 emails with a broken unsubscribe link is not one violation, it is up to 2,000 of them. Regulators rarely assess maximums on first offenses, and enforcement mostly targets deceptive senders rather than sloppy ones. But the structure of the statute is the point: risk scales with volume, so the cost of a compliance bug scales with how well your outbound is working.

One piece of good news. There is no private right of action under CAN-SPAM, so an annoyed prospect cannot sue you personally for a cold email. Enforcement sits with the FTC, with state attorneys general, and with ISPs, which have standing to act against senders who abuse their networks. Practically, the ISPs are the ones you will meet first: they punish complaints long before a regulator ever notices you exist.

Does CAN-SPAM apply to B2B email?

Yes. CAN-SPAM has no B2B exemption. It applies to commercial email whether the recipient is a consumer at a personal address or a Director of Ops at a corporate one, and a one-to-one prospecting email from an SDR is commercial email under the statute. "It went to a work address" is not a defense anyone has ever won with.

What does change the analysis is the message's primary purpose. CAN-SPAM's full rules attach to commercial content, meaning content that advertises or promotes a product or service. Purely transactional or relationship messages sit in a different bucket: they may not carry false header information, but the postal address, ad disclosure and opt-out requirements do not apply. So a reminder chasing an unpaid invoice is not governed the way a prospecting email is, because it is not selling anything. The line gets blurry fast: bolt a promotional offer onto a receipt and you may have converted a transactional message into a commercial one, with all seven rules now in force.

Is cold email legal in the EU under GDPR?

Sometimes, and it depends on the country. In the EU and UK, GDPR governs the personal data in your list and PECR governs the sending. B2B cold email to a corporate address can rely on legitimate interest as a lawful basis in some member states, but several require consent outright, and legitimate interest is never a free pass.

Where legitimate interest is available, it carries conditions most US outbound programs ignore. You owe transparency about where you got the person's data, a privacy notice they can actually reach, a real balancing of your commercial interest against their privacy rights, and an opt-out that works on the first email rather than the fifth. The prospect can also demand access to or deletion of their data, and you have to be able to comply. Emailing a personal address rather than a corporate one moves you sharply toward needing consent.

RegionLawConsent needed?Headline penalty
United StatesCAN-SPAM (15 U.S.C. 7704), FTC-enforcedNo. Opt-out regime.Up to $53,088 per email (2026, inflation-adjusted annually)
EU and UKGDPR plus PECRSometimes. Legitimate interest can cover B2B corporate addresses; several member states require consent.GDPR fines scale to global turnover
CanadaCASLYes. Express or implied consent. Strictest of the three.Up to CAD 10 million for businesses

The operational consequence for a US team selling internationally: segment by region at the list level, not at the send level. Run EU and Canadian segments through separate email sequences with region-appropriate copy, disclosures and suppression rules. Letting one global campaign spray all three regimes at once is the mistake that turns a routine outbound motion into a regulatory problem.

Legal is the floor. Deliverability is the ceiling.

You can satisfy every clause of CAN-SPAM and still land in spam on the first send. Two systems judge your email, and the stricter one is not the government. Gmail filters on complaint rate: at or above 0.3% (three complaints per thousand sends) you get filtered, regardless of how lawful the mail was.

Purchased and scraped lists are where the two systems converge. A bought list has never heard of you, so it complains, complaints trigger filtering, and filtering ends the campaign long before the FTC would have. Legality gives you the right to send. Reputation decides whether anyone reads it. Our cold email deliverability guide covers the authentication, warmup and volume mechanics that keep the second system happy.

What a compliant cold email actually looks like

Strip the theory away and compliance is six elements in a message a prospect will read in nine seconds:

  • Honest from-name: your real name at your real company domain, with a reply-to that reaches your actual inbox. No aliases, no lookalike domains impersonating someone else.
  • Honest subject line: describes what is inside. No fake "Re:", no fake "Following up on our call" when there was no call.
  • Relevance line: why this person, specifically. Not a legal requirement, but the largest driver of whether they reply or hit the spam button, and the spam button is the one that hurts.
  • A clear offer: what you sell and what you want. Vagueness reads as deception, and deception is what the statute punishes.
  • Opt-out line: one sentence, plainly visible. "If this is not relevant, reply 'no thanks' and I will not email you again."
  • Physical postal address: in the signature, on every message in the sequence, including follow-ups. Follow-ups are where teams forget it.

None of that is hard to write once. The hard part is enforcing it across thousands of sends, several sending domains and follow-ups that run for weeks after the first touch. That is a systems problem, and it is where software earns its keep: Coldoutreach adds one-click unsubscribe to every message, applies a global suppression list the instant someone opts out (across every campaign, inbox and domain on the account, not just the one they replied to), and appends your postal address to every step of every sequence. An unsubscribed prospect cannot receive another email from you by accident, which is the exact failure mode that turns a compliant program into a non-compliant one.

If you want the whole thing running on rails, automated cold email outreach with compliance built into the send path costs less than an hour of the lawyer you would call after a violation. Plans start at $39 a month. The law lets you send cold email. It just insists you do it like an adult.

Coldoutreach researches every prospect, writes the sequence and keeps your domain safe. Try the cold email software yourself: pick a persona on the homepage and watch it draft your sequence, no account needed.

Keep reading

Your next 50 prospects, researched and drafted by tonight

Connect your inbox, import your list, and let Coldoutreach research every prospect and write sequences that book meetings.

No credit card to start · Cancel anytime · Unsubscribe honored on every send