Guide

CAN-SPAM Act, Explained: What Email Senders Legally Owe You

The CAN-SPAM Act is the U.S. federal law that sets the rules for commercial email — and it grants you, the recipient, concrete guarantees: truthful header information, an honest subject line, a visible opt-out, a real physical address, and an unsubscribe honored within 10 business days. The FTC currently lists a civil penalty of up to $53,088 for each separate violating email. Almost everything written about this law is aimed at marketers. This guide reads it from the other side: what the law gives recipients, and the requirement you can verify yourself.

Here is the one-sentence version: the CAN-SPAM Act of 2003 is the U.S. federal law that gives every email recipient the legal right to a truthful commercial message and a working way out of it.

What is the CAN-SPAM Act?

The Controlling the Assault of Non-Solicited Pornography And Marketing Act — Congress worked hard for that acronym — was signed into law on December 16, 2003 and took effect on January 1, 2004 (Public Law 108-187). It was the first national standard for commercial email in the United States, codified at 15 U.S.C. § 7701 and enforced by the Federal Trade Commission under the accompanying CAN-SPAM Rule (16 CFR Part 316).

Two things about the law surprise most people.

First, it does not ban spam. Despite the name, CAN-SPAM is an opt-out law, not an opt-in law. A company you have never heard of can legally send you a commercial email — as long as the message is truthful, identifies itself, and gives you a working way to make it stop.

Second, it covers essentially all commercial email, with no exception for business-to-business messages. The cold outreach in your work inbox is governed by the same rules as the retail promotions in your personal one.

What does a sender legally owe you?

The FTC's current compliance guide distills the law into eight main requirements. Marketers read them as a checklist. Read as a recipient, they are a bill of rights:

The requirement What it guarantees you
No false or misleading header information The "From," "Reply-To," and routing data must accurately identify who actually sent the message
No deceptive subject lines The subject must reflect what is inside — no "Re:" on a message you never sent, no fake invoice
Identify the message as an ad The sender must disclose, clearly and conspicuously, that the message is an advertisement
A valid physical postal address Every commercial email must tell you where the sender physically exists
A clear opt-out mechanism Every message must explain, in a way an ordinary person can spot, how to stop future email
Members keep their opt-out rights Paying for or joining a service does not waive your right to stop its marketing email
Honor opt-outs promptly Your request must be processed within 10 business days, and the opt-out link must keep working for at least 30 days after the message was sent
Responsibility follows the brand A company cannot outsource its way out of the law — both the business being promoted and the agency pressing send can be liable

The opt-out rules go further than most people realize. A sender cannot charge you a fee, cannot require any personal information beyond your email address, and cannot make you do anything more than send a reply or visit a single web page to opt out. The login-walled "email preference center" that demands your password before letting you leave is not just annoying — if it is the only path out, it is on the wrong side of the rule.

And once you opt out, the law follows your address: the sender cannot sell or transfer your email address after your opt-out, except to a company hired to help it comply with the law.

What are the CAN-SPAM Act penalties?

Each separate non-compliant email is subject to a civil penalty of up to $53,088 — per message, not per campaign. That is the amount displayed by the FTC's current compliance guide as reviewed on July 30, 2026; penalty maximums can change, so compliance decisions should use the FTC's live page rather than a copied number.

Multiply that by a mailing list and the theoretical exposure gets absurd quickly, which is the point. In practice, settlements land far below the theoretical maximum. A recent example: in August 2023, the FTC charged Experian Consumer Services with spamming account holders who had no way to opt out — some messages even carried a footer claiming they contained "important account information" when they were marketing. Experian paid a $650,000 penalty and accepted a court order requiring a real opt-out.

Two honest caveats. Enforcement actions are rare relative to the volume of email that skirts the rules. And ordinary recipients do not receive a general private right of action under CAN-SPAM: 15 U.S.C. § 7706 assigns enforcement to federal and state authorities and gives a limited civil action to qualifying internet access services. Your role is reporting, which we cover below.

What does the CAN-SPAM Act not guarantee you?

Reading the law from the recipient side also means being honest about its gaps.

  • No consent required. Unlike the EU's opt-in regime, CAN-SPAM lets any sender email you first. Your rights begin after the message arrives, not before.
  • Ten business days is two weeks. A sender can legally keep emailing you for 10 business days after you unsubscribe. Everything that lands in that window is compliant, however much it feels otherwise.
  • Transactional email is out of scope. Receipts, shipping notices, and account updates are "transactional or relationship" messages — largely exempt, though they still cannot carry false routing information. This is why some marketing dresses up as an "account notice": the Experian case above is exactly that pattern.
  • No one is auditing the unsubscribe button for you. The law requires the opt-out to work. No agency systematically tests whether it does.

How do Gmail and Yahoo go further than the law?

Since February 2024, the two biggest mailbox providers enforce their own sender rules — and on the unsubscribe question, they are strictly tougher than the statute. Google's sender guidelines require anyone sending 5,000 or more messages a day to Gmail addresses to support one-click unsubscribe in the message headers, honor requests within two days, and keep user-reported spam rates below 0.3%.

CAN-SPAM Act Gmail / Yahoo bulk sender rules
Who imposes it U.S. federal law Mailbox providers, as a condition of delivery
One-click unsubscribe required No — a reply or a single web page suffices Yes, via RFC 8058 headers, for bulk promotional mail
Deadline to honor opt-out 10 business days 2 days
Consequence of failure Civil penalties, if the FTC acts Mail lands in spam or gets rejected — automatically

The one-click mechanism is RFC 8058, a standard published in 2017 that puts the unsubscribe action in the email's headers (List-Unsubscribe and List-Unsubscribe-Post) so your mail client can send the request directly — no web page, no "are you sure," no login. It is the machinery behind Gmail's native unsubscribe button, and we wrote a full explainer at /one-click-unsubscribe-explained. We build List-Unsubscribe parsing for a living: Flick (flicked.email) reads those same headers to power its one-swipe unsubscribe.

Notice what happened here. The strongest unsubscribe protections you have in 2026 were not written by Congress — they were written by mailbox providers, enforced not with fines but with the spam folder. Delivery is a privilege the providers can revoke instantly; a federal penalty requires a lawsuit.

Can you actually verify a sender is complying?

Here is the uncomfortable truth about the eight requirements: as a recipient, you can meaningfully verify exactly one of them. You cannot audit a sender's header routing, confirm their postal address is current, or observe whether they scrubbed your address inside the deadline. But you can test whether the unsubscribe worked — unsubscribe, wait out the 10 business days, and watch your inbox.

Compliance on paper is not honor in practice. A sender can present a beautiful, fully compliant opt-out page and still keep mailing you — and unless the FTC comes knocking, the gap between the promise and the behavior stays invisible. We wrote about what actually happens after you click at /does-unsubscribing-work.

That verification gap is why we maintain the Exit Gap Index at flicked.email/graded — a crawler-seeded index that grades real senders from A to F on one question only: when someone unsubscribes, does the mail actually stop? Not whether the link exists. Whether the exit is honored. It is the recipient's-eye audit the law never funded.

What should you do when a sender breaks the rules?

A short, calm escalation path:

  1. Unsubscribe properly first. Use the sender's own mechanism — the one-click header if your client surfaces it, the footer link otherwise. Our full walkthrough is at /how-to-unsubscribe-from-emails.
  2. Note the date. The clock on the sender's 10 business days starts now.
  3. If the mail keeps coming, report it. The FTC takes reports at ReportFraud.ftc.gov, and its consumer guidance on unwanted email covers forwarding messages with full headers. Reports feed the database that enforcement actions are built from.
  4. Mark it as spam. This is the quiet one. Every spam report counts against the sender's 0.3% complaint threshold with Gmail — and crossing it damages their delivery to everyone. The spam button is the most effective enforcement mechanism the law never wrote.

Stop reading your inbox. Start flicking it.

Flick turns every inbox into a finite swipe deck — archive, "no reply needed," or AI-draft → approve, one card at a time. Inbox flicked.

Try the live demo — no signup →

Or get Flick for iPhone on the App Store →

FAQ

What is the CAN-SPAM Act in simple terms?

The CAN-SPAM Act is the U.S. law that requires every commercial email to be truthful and to include a working way to opt out. It was signed in December 2003 and took effect January 1, 2004, and it is enforced by the FTC. It does not ban unsolicited email — it regulates honesty and guarantees the exit.

How much are CAN-SPAM Act penalties per email?

Each separate violating email is subject to a civil penalty of up to $53,088, according to the FTC page reviewed July 30, 2026. Real settlements are fact-specific — Experian paid $650,000 in 2023.

No — CAN-SPAM is an opt-out law, and any sender may email you once without permission. Your enforceable rights begin when the message arrives: it must be truthful, identify itself as an ad, and carry a working opt-out. This is the biggest difference from opt-in regimes like the EU's, where consent must come first.

What are the CAN-SPAM unsubscribe rules?

A sender must give you a clear opt-out in every message, honor your request within 10 business days, and keep the mechanism working for at least 30 days after sending. They cannot charge a fee, demand extra personal information, or require more than a reply or a visit to a single page. After you opt out, they cannot sell or transfer your address except to a compliance vendor.

Can I sue a company for violating the CAN-SPAM Act?

Generally, no. 15 U.S.C. § 7706 provides government enforcement and a limited civil action for qualifying internet access services, not a general individual claim. You can report violations at ReportFraud.ftc.gov and mark offending mail as spam, which counts against the sender's standing with mailbox providers.

This guide is educational information, not legal advice. Rules and penalty amounts can change; use the linked primary sources or qualified counsel for a compliance decision.

Keep reading