CAN-SPAM Act, Explained: What Email Senders Legally Owe You
The CAN-SPAM Act is the U.S. federal law that sets the rules for commercial email — and it grants you, the recipient, concrete guarantees: truthful header information, an honest subject line, a visible opt-out, a real physical address, and an unsubscribe honored within 10 business days. The FTC currently lists a civil penalty of up to $53,088 for each separate violating email. Almost everything written about this law is aimed at marketers. This guide reads it from the other side: what the law gives recipients, and the requirement you can verify yourself.
Verification note: This is a documentary source review checked against current sources on August 3, 2026. We did not hands-on test the named product or workflow during this review, so claims are limited to the cited documentation. Interfaces can vary by account, region, rollout, and app version.
Here is the one-sentence version: the CAN-SPAM Act of 2003 is the U.S. federal law that requires covered commercial messages to use truthful routing and subject information and provide a working marketing opt-out.
What is the CAN-SPAM Act?
The Controlling the Assault of Non-Solicited Pornography And Marketing Act — Congress worked hard for that acronym — was signed into law on December 16, 2003 and took effect on January 1, 2004 (Public Law 108-187). It was the first national standard for commercial email in the United States, codified at 15 U.S.C. § 7701 and enforced by the Federal Trade Commission under the accompanying CAN-SPAM Rule (16 CFR Part 316).
Two things about the law surprise most people.
First, it does not generally require prior consent under CAN-SPAM itself. The Act is primarily an opt-out regime: a first commercial message is not automatically unlawful solely because the recipient did not opt in, but it must meet the Act's content and exit requirements. Other federal, state, sector, contract, and non-U.S. rules may still apply, so this is not a universal license to send.
Second, it covers essentially all commercial email, with no exception for business-to-business messages. The cold outreach in your work inbox is governed by the same rules as the retail promotions in your personal one.
What does a sender legally owe you?
The FTC's current compliance guide distills the law into eight main requirements. Marketers read them as a checklist. Read as a recipient, they are a bill of rights:
| The requirement | What it guarantees you |
|---|---|
| No false or misleading header information | The "From," "Reply-To," and routing data must accurately identify who actually sent the message |
| No deceptive subject lines | The subject must reflect what is inside — no "Re:" on a message you never sent, no fake invoice |
| Identify the message as an ad | The FTC guide requires clear and conspicuous ad identification; the statute contains a prior-affirmative-consent exception for this identification rule (15 U.S.C. § 7704(a)(5)(A)(i)) |
| A valid physical postal address | Every commercial email must tell you where the sender physically exists |
| A clear opt-out mechanism | Every message must explain, in a way an ordinary person can spot, how to stop future email |
| Members keep their opt-out rights | Paying for or joining a service does not waive your right to stop its marketing email |
| Honor opt-outs promptly | Your request must be processed within 10 business days, and the opt-out link must keep working for at least 30 days after the message was sent |
| Responsibility follows the brand | A company cannot outsource its way out of the law — both the business being promoted and the agency pressing send can be liable |
The opt-out rules go further than most people realize. A sender cannot charge you a fee, cannot require any personal information beyond your email address, and cannot make you do anything more than send a reply or visit a single web page to opt out. The login-walled "email preference center" that demands your password before letting you leave is not just annoying — if it is the only path out, it is on the wrong side of the rule.
And once you opt out, the law follows your address: the sender cannot sell or transfer your email address after your opt-out, except to a company hired to help it comply with the law.
What are the CAN-SPAM Act penalties?
Each separate violating email is subject to a civil penalty of up to $53,088 — a statutory maximum, not an automatic bill for every defect. That is the amount displayed by the FTC's guide as reviewed on August 3, 2026; actual liability and remedies are fact-specific, and maximums can change.
Multiply that by a mailing list and the theoretical exposure gets absurd quickly, which is the point. In practice, settlements land far below the theoretical maximum. A recent example: in August 2023, the FTC charged Experian Consumer Services with spamming account holders who had no way to opt out — some messages even carried a footer claiming they contained "important account information" when they were marketing. Experian paid a $650,000 penalty and accepted a court order requiring a real opt-out.
One important enforcement caveat: ordinary recipients do not receive a general private right of action under CAN-SPAM. 15 U.S.C. § 7706 assigns enforcement to federal and state authorities and gives a limited civil action to qualifying internet access services. The sources reviewed here do not supply a denominator for violations or enforcement actions, so this page makes no enforcement-frequency claim. Your practical route is reporting, which we cover below.
What does the CAN-SPAM Act not guarantee you?
Reading the law from the recipient side also means being honest about its gaps.
- CAN-SPAM itself generally uses opt-out, not prior opt-in. That does not settle consent duties under other laws. In the EU, GDPR supplies several possible lawful bases while national ePrivacy rules govern much direct marketing; the answer depends on jurisdiction, relationship, and message type (GDPR Article 6; ePrivacy Directive).
- Ten business days is a deadline, not advance permission. The sender must honor a valid opt-out within 10 business days. A message inside that period is not automatically lawful: message classification, scope of the request, deception, routing, and other requirements still matter.
- A genuinely transactional or relationship message is exempt from many—but not all—CAN-SPAM requirements. Receipts, shipping notices, and account updates can qualify under the Act's primary-purpose test, while false or misleading routing information remains prohibited (FTC). Adding promotional content can change the classification depending on placement and emphasis. The Experian action above shows why an “account notice” label does not decide the message's primary purpose.
- The law does not give each recipient a live sender-status test. It requires the opt-out to work and identifies enforcement authorities, but the cited sources do not provide a public, continuously tested sender-by-sender honor registry. Preserve the request and later covered messages if you need to report a failure.
How do Gmail and Yahoo go further than the law?
Since 2024, Gmail and Yahoo have enforced provider rules that are faster or more technical than CAN-SPAM on covered bulk marketing mail. Google's sender guidelines require senders of more than 5,000 messages a day to personal Gmail accounts to support RFC 8058 one-click unsubscribe on covered mail, process those requests within two days, and keep reported spam below 0.3%. Yahoo does not publish a numeric bulk threshold; it requires a functioning List-Unsubscribe header, calls RFC 8058 POST highly recommended, accepts mailto:, and requires honoring requests within two days.
| CAN-SPAM Act | Gmail / Yahoo bulk sender rules | |
|---|---|---|
| Who imposes it | U.S. federal law | Mailbox providers, as a condition of delivery |
| Header requirement | No RFC 8058 mandate — a reply address or another easy internet-based path can satisfy the exit rule | Gmail requires RFC 8058 for covered mail; Yahoo requires a functioning List-Unsubscribe header and highly recommends RFC 8058 POST |
| Deadline to honor opt-out | 10 business days | Two days (Google; Yahoo) |
| Possible consequence of failure | Civil remedies or penalties when an authorized enforcer proves a violation | Provider-specific filtering, deferral, or rejection; neither provider promises an automatic outcome for every non-compliant message |
The one-click mechanism is RFC 8058, published in 2017. It combines an HTTPS List-Unsubscribe URI with List-Unsubscribe-Post so a provider can submit a request without a landing page or login; qualifying DKIM coverage is also required. We explain the standard at /one-click-unsubscribe-explained. On supported Flick cards, a separate Unsubscribe control asks for confirmation, then parses the advertised signals and can send the POST. Flick does not independently verify DKIM coverage or sender honor.
The legal and provider layers do different jobs. CAN-SPAM supplies duties and authorized enforcement routes. Google and Yahoo add scoped delivery conditions and can apply provider-specific filtering, deferral, or rejection, but neither promises an instant or universal outcome for every non-compliant message. Treat the two-day provider clocks as additional scoped controls, not a claim that they are categorically stronger than the statute.
Can you actually verify a sender is complying?
As a recipient, you can inspect the visible subject, From/Reply-To details, postal address, ad disclosure, and opt-out path, but you usually cannot prove who initiated a message, whether an address is valid, or what happened in a suppression database. You can preserve a stronger behavioral record: keep the original message and full headers, record the exact opt-out path and time, note which list or sender identity the request covered, wait through the 10-business-day deadline, and retain later in-scope commercial messages.
Compliance on paper is not honor in practice. A sender can present a beautiful, fully compliant opt-out page and still keep mailing you — and unless the FTC comes knocking, the gap between the promise and the behavior stays invisible. We wrote about what actually happens after you click at /does-unsubscribing-work.
Flick is building the Exit Gap Index around that verification gap, but the live page is not yet a sender audit or grade lookup. As of August 3, 2026, it is a 150-sender work-list with four observations of unsubscribe capability and zero published honor grades. Capability means a sender advertised a mechanism; it does not show that later mail stopped. The planned protocol requires at least three post-request probes over at least 48 hours with preserved evidence, and no founder burner-mailbox observations have occurred. Even a future 48-hour result would not by itself establish a CAN-SPAM violation: the statute allows the full 10-business-day window.
What should you do when a sender breaks the rules?
A short, calm escalation path:
- Unsubscribe properly first. Use the sender's own mechanism — the one-click header if your client surfaces it, the footer link otherwise. Our full walkthrough is at /how-to-unsubscribe-from-emails.
- Note the date. The clock on the sender's 10 business days starts now.
- If the mail keeps coming, report it. The FTC takes reports at ReportFraud.ftc.gov, and its consumer guidance on unwanted email covers forwarding messages with full headers. Reports feed the database that enforcement actions are built from.
- Use your provider's spam control when appropriate. A report is a provider signal; its denominator, aggregation, and effect are provider-specific. Google's public sender guidance tells senders to keep their reported spam rate below 0.3%, but one recipient cannot infer a sender-wide rate or a guaranteed delivery consequence from one report (Google).
Turn the next inbox decision into a finite deck.
Open Flick with an account you control, or practice first with fabricated sample mail. Provider results remain limited to the accounts, messages, and actions Flick actually confirms.
Open Flick with your inbox →FAQ
What is the CAN-SPAM Act in simple terms?
The CAN-SPAM Act is the U.S. law that requires every commercial email to be truthful and to include a working way to opt out. It was signed in December 2003 and took effect January 1, 2004, and it is enforced by the FTC. It does not ban unsolicited email — it regulates honesty and guarantees the exit.
How much are CAN-SPAM Act penalties per email?
Each separate violating email is subject to a civil penalty of up to $53,088, according to the FTC page reviewed August 3, 2026. Real settlements are fact-specific — Experian paid $650,000 in 2023.
Does the CAN-SPAM Act require my consent before a company emails me?
CAN-SPAM generally does not itself require prior consent for a first commercial message. That message still must satisfy the Act, including truthful routing and subject information, required identification, a postal address, and a working opt-out. Other laws may impose additional consent duties; EU rules, for example, combine GDPR lawful bases with national ePrivacy implementation rather than one universal rule for every message.
What are the CAN-SPAM unsubscribe rules?
A sender must give you a clear opt-out in every message, honor your request within 10 business days, and keep the mechanism working for at least 30 days after sending. They cannot charge a fee, demand extra personal information, or require more than a reply or a visit to a single page. After you opt out, they cannot sell or transfer your address except to a compliance vendor.
Can I sue a company for violating the CAN-SPAM Act?
Generally, no. 15 U.S.C. § 7706 provides government enforcement and a limited civil action for qualifying internet access services, not a general individual claim. You can report violations at ReportFraud.ftc.gov and mark offending mail as spam, which counts against the sender's standing with mailbox providers.
This guide is educational information, not legal advice. Rules and penalty amounts can change; use the linked primary sources or qualified counsel for a compliance decision.