CAN-SPAM Compliance Checklist: 8 FTC Requirements for Senders
Before a U.S. commercial campaign leaves your system, classify the message's primary purpose, identify every responsible sender, test all eight requirements in the FTC's current CAN-SPAM guide, and save the rendered message, raw headers, recipient source, consent record if relevant, and suppression-test evidence. The opt-out endpoint must remain able to process requests for at least 30 days, and a valid request must be honored within 10 business days. Passing this checklist reduces avoidable risk; it is not a legal opinion or a guarantee of compliance.
Verification note: This is a documentary guide checked against current sources on August 3, 2026. We did not hands-on test the named product or workflow during this review, so claims are limited to the cited documentation. Interfaces can vary by account, region, rollout, and app version.
Source-checked August 3, 2026. This is a documentary operator checklist based on current primary sources. We did not review a live campaign, consent record, sending account, or suppression database.
This page has a different job from our recipient-focused CAN-SPAM explainer: it gives an email operator a preflight, an evidence pack, and a recovery path. Use qualified counsel for a campaign whose classification, audience, industry, or jurisdiction is uncertain.
Step 1: classify the message before checking the footer
CAN-SPAM applies broadly to messages whose primary purpose is the advertisement or promotion of a commercial product or service, including B2B mail. It treats purely transactional or relationship messages differently, and the FTC's primary-purpose test controls mixed messages.
| Message you plan to send | Working classification | What to review |
|---|---|---|
| Promotion, sales outreach, commercial newsletter | Commercial | Run all eight checks below |
| Receipt, shipping notice, recall, warranty/security notice, account-status update, employee-benefit notice, or delivery of an agreed service | Potentially transactional/relationship | Confirm it fits one of the statute's narrow categories and keeps truthful routing |
| Receipt or account notice plus promotion | Mixed | Review the subject, ordering, prominence, and amount of commercial material under the FTC's primary-purpose test |
| Editorial newsletter from a commercial site | Potentially commercial | The statutory definition includes promotion of content on a commercially operated site; do not assume “editorial” means exempt |
For a mixed message, ask two questions before send: would a reasonable recipient read the subject as advertising, and does the transactional material appear mainly at the beginning? A commercial subject or promotion placed ahead of a brief transactional note can make the message commercial (FTC examples). Record the classification owner and reasoning in the campaign ticket.
CAN-SPAM generally does not itself require prior opt-in, but that does not resolve duties under state, sector, contract, or non-U.S. law. If your list reaches other jurisdictions, make that a separate legal gate rather than treating this U.S. checklist as universal.
Step 2: run the eight-requirement preflight
The FTC organizes its current business guidance into eight requirements. The right-hand column is the evidence your release owner should preserve.
| # | Release check | Evidence to retain |
|---|---|---|
| 1 | Headers are accurate. From, To, Reply-To, originating domain, and routing information identify the person or business that initiated the message. | A seed copy with full raw headers, sending-domain ownership, and the configured reply path |
| 2 | The subject is not deceptive. It accurately reflects the message; fake reply prefixes and account/invoice framing are rejected unless true. | Approved subject and rendered body in the same revision |
| 3 | Ad identification is handled. The FTC guide calls for clear, conspicuous identification; the statute includes a prior-affirmative-consent exception for this element (15 U.S.C. § 7704(a)(5)(A)(i)). | The visible disclosure or the specific consent record and legal basis relied on for the exception |
| 4 | A valid physical postal address is visible. A current street address, registered U.S. Postal Service P.O. box, or properly registered private mailbox can qualify. | Rendered footer plus the current address owner/verification date |
| 5 | The opt-out is clear and usable. An ordinary person can find and understand it, and any preference menu includes an option to stop all marketing from the sender. | Desktop/mobile seed screenshots, destination URL, and successful test request |
| 6 | Members can still stop marketing. A paid subscription or membership does not erase marketing opt-out rights; only a qualifying transactional/relationship message can omit that exit. | Message classification and the universal-marketing-suppression test |
| 7 | Suppression is free, simple, durable, and timely. The mechanism can process requests for at least 30 days; the sender charges no fee, asks for no identifying information beyond the email address, requires no step beyond a reply or single web page, and honors a valid request within 10 business days. | Request timestamp, endpoint response, suppression timestamp, scope/list IDs, and a later negative-send test |
| 8 | Every vendor and promoted brand is covered. Responsibility cannot simply be outsourced; the promoted company and sender may both be liable. | Contract owner, sender designation where applicable, account inventory, and vendor test result |
The FTC currently displays a maximum civil penalty of up to $53,088 per separate violating email. That is a maximum, not an automatic invoice. Amounts and liability are fact-specific and can change; reopen the live FTC source for a real decision.
Step 3: test the exit as a system, not just a link
A green link check is insufficient. The practical system is message → request → event ingestion → identity resolution → global or list suppression → every downstream sender. Test it with controlled seed addresses.
- Send the exact release candidate to seed mailboxes at the providers you support.
- Save the rendered message and full headers. Confirm the visible exit is readable on desktop and mobile and that keyboard focus reaches it.
- Submit the opt-out. Preserve the request time, confirmation, address, list/campaign identifier, and response.
- Verify the suppression record in the system of record and each synchronized email service. A preference update in one tool is not proof that another tool received it.
- Attempt a controlled later marketing send to that seed. The address should be excluded for the scope it left; document the result and avoid delivering a real unwanted message.
- Re-test the endpoint during the 30-day availability window, not only on launch day.
If the preference center offers category choices, it must also offer a way to stop all marketing from the sender. Do not require login if the only available path then exceeds the FTC rule's permitted reply-or-single-page process or demands more identity data than an email address. See the exact opt-out language in the FTC guide and 16 CFR Part 316.
Step 4: add Gmail and Yahoo's provider rules separately
CAN-SPAM is the legal floor; provider requirements are independent delivery conditions. Do not combine them into one “law” column.
| Control | CAN-SPAM | Gmail | Yahoo |
|---|---|---|---|
| Coverage | Covered U.S. commercial messages | Covered subscription/marketing mail from senders of more than 5,000 messages a day to personal Gmail accounts | Bulk marketing/subscribed mail; Yahoo does not publish a numeric bulk threshold |
| Machine-readable exit | Reply address or another easy internet-based method can satisfy the statute | HTTPS RFC 8058 one-click headers required for covered mail | Functioning List-Unsubscribe required; RFC 8058 POST highly recommended, mailto: accepted |
| Processing deadline | 10 business days | Two days | Two days |
| Consequence | Enforcement and fact-specific remedies if a violation is established | Non-compliance may affect filtering, deferral, or delivery | Non-compliant mail may be sent to spam or rejected |
Sources: Google sender guidelines, Yahoo Sender Hub, and RFC 8058. Gmail's numeric threshold is Google's; do not copy it into Yahoo documentation. Yahoo currently describes POST as highly recommended and mailto: as acceptable, so do not state that Yahoo universally mandates Google's exact mechanism.
What belongs in the campaign evidence pack?
Create one immutable folder or ticket attachment per campaign:
- campaign ID, owner, send time, audience sources, and suppression snapshot version;
- primary-purpose classification, reviewer, and rationale;
- final subject, body, From/To/Reply-To configuration, and raw seed headers;
- ad-identification decision and any affirmative-consent record used for the statutory exception;
- current postal-address verification;
- screenshots of the exit on desktop and mobile;
- request/response evidence, suppression event, synchronized systems, and negative-send result;
- vendor/affiliate list, contract owner, and escalation contact;
- Google/Yahoo provider checks where those rules apply.
This ledger does not turn a bad campaign into a compliant one. It makes the decision reproducible, exposes missing controls before send, and preserves facts if a request later fails.
What should you do if suppression fails?
Treat it as an incident, not a copy-edit.
- Pause affected marketing sends while you determine which lists, brands, aliases, and vendors share the faulty path.
- Preserve evidence: original request, endpoint logs, queue events, suppression records, raw later-message headers, deployment versions, and timestamps. Do not rewrite the history.
- Apply the suppression at the authoritative layer and propagate it to every downstream sender. Do not rely on a one-off filter in the visible campaign tool.
- Find the failure boundary: expired endpoint, identity mismatch, delayed job, vendor sync, restored backup, list-specific scope, or unauthorized re-import.
- Check other recipients and campaigns that traversed the same path. One reported address can reveal a systemic issue without proving its size.
- Escalate to counsel and the responsible vendor when the legal deadline, scope, or affected population is uncertain. Do not invent a harmless explanation in recipient communications.
- Add a regression test before resuming. Keep the incident record with the campaign evidence pack.
The 2023 Experian matter is a useful primary-source warning about promotional messages framed as account information and sent without an opt-out. Read the FTC's allegations and order, not a third-party summary, before drawing parallels to another campaign.
Turn the next inbox decision into a finite deck.
Open Flick with an account you control, or practice first with fabricated sample mail. Provider results remain limited to the accounts, messages, and actions Flick actually confirms.
Open Flick with your inbox →FAQ
Does CAN-SPAM apply to B2B cold email?
Yes, when the message's primary purpose is commercial. The FTC guide says the Act makes no B2B exception. That does not decide compliance with other jurisdictions or sector-specific rules.
Can a preference center ask for a password or profile form?
The FTC says a sender cannot condition honoring an opt-out on a fee, identifying information beyond the email address, or any step beyond a reply email or visiting a single web page. If login or a multi-page form is the only marketing exit, stop release and obtain legal review; offer a direct compliant path instead.
Does every commercial email need the words “This is an ad”?
The FTC says identification must be clear and conspicuous but gives flexibility in form. The statute includes an exception to the ad-identification element when the recipient gave prior affirmative consent (15 U.S.C. § 7704). Preserve the disclosure or the consent evidence supporting the decision; do not assume brand familiarity is consent.
Is every message sent during the ten-business-day window compliant?
No. Ten business days is the deadline to honor a valid request, not blanket permission for every intervening send. A message can still fail another requirement, fall outside the requested list/sender scope, or violate another law or provider rule.
Can an email service provider own this compliance check for us?
A provider can operate controls, but the FTC says legal responsibility cannot simply be contracted away. The promoted business and the company initiating the message may both be responsible. Keep a named internal owner and test the actual vendor path.
For recipient actions after a failed exit, use how to unsubscribe safely and does unsubscribing actually work?. For machine-readable headers, use one-click unsubscribe explained.
Educational information, not legal advice. Rules, interpretations, and penalty maximums can change. Reopen the linked primary sources and consult qualified counsel for a live campaign.