Compliance · April 13, 2026

Email Marketing and the Law: CAN-SPAM Basics

Email remains the highest-return marketing channel for many California businesses — and one of the easiest places to violate federal law without realizing it. The CAN-SPAM Act (15 U.S.C. § 7701 et seq.) governs essentially every commercial email your company sends, from mass newsletters to a one-off promotion. The rules are not complicated, but they are specific, and penalties are counted per email. Here is what every business sending marketing email needs to know.

What CAN-SPAM covers

The Act applies to any electronic mail message whose primary purpose is the commercial advertisement or promotion of a commercial product or service. That includes messages to consumers and to other businesses — there is no B2B exemption. It also covers emails promoting content on commercial websites. Purely "transactional or relationship" messages (receipts, shipping updates, account notices) are exempt from most requirements, but they still may not contain false or misleading routing information, and a mixed message is judged by its primary purpose.

Contrary to common belief, CAN-SPAM does not require opt-in consent. It is an opt-out regime: you may email people who never asked to hear from you, provided you follow the rules below and stop when they say stop. (CAN-SPAM does not categorically prohibit sending to purchased lists, but doing so carries other risks, discussed later.)

The seven core requirements

  1. No false or misleading header information. The "From," "To," and routing information must accurately identify the person or business who initiated the message.
  2. No deceptive subject lines. The subject line must reflect the content of the message.
  3. Identify the message as an ad. The law gives leeway on how, but the message must disclose clearly and conspicuously that it is an advertisement — unless the recipient gave prior affirmative consent.
  4. Include your physical postal address. A current street address, a registered P.O. box, or a commercial mail receiving agency box.
  5. Provide a clear opt-out mechanism. Every message must include a conspicuous explanation of how to stop receiving future email, and the mechanism must work for at least 30 days after sending.
  6. Honor opt-outs within 10 business days. You may not charge a fee, require personally identifying information beyond an email address, or make the recipient take any step beyond sending a reply or visiting a single web page. Once someone opts out, you may not sell or transfer their address except to a vendor helping you comply.
  7. Monitor what others do on your behalf. If you hire an agency or affiliate to send email promoting your product, both of you can be legally responsible for violations.

What violations cost

The FTC enforces CAN-SPAM with civil penalties that adjust annually for inflation and currently exceed $50,000 per email. State attorneys general and internet service providers can also sue. Aggravated conduct — address harvesting, dictionary attacks, falsified registrations — increases exposure, and certain fraudulent practices carry criminal penalties. There is no private right of action for individual recipients under CAN-SPAM itself, but that is little comfort: deceptive email practices routinely draw claims under state unfair competition laws.

The California overlay

CAN-SPAM preempts most state spam statutes, but it expressly preserves state laws prohibiting falsity or deception in commercial email. California's anti-spam statute (Bus. & Prof. Code § 17529.5) prohibits emails with falsified headers or misleading subject lines and — unlike the federal act — allows recipients of unsolicited commercial email advertisements to sue for liquidated damages of up to $1,000 per email, capped at $1 million per incident. California courts have applied this to misleading "From" names and deceptive subject lines. In practice, the deception rules are where the real litigation risk sits for California senders.

Separately, if your emails link to your website, your regulatory compliance picture should include any applicable privacy disclosures for those pages, since email capture is a data-collection practice that may need to be described in your privacy policy.

Practical compliance habits

  • Use a reputable email service provider and keep suppression lists synchronized across every platform and vendor that sends for you.
  • Audit affiliate and agency emails — you are responsible for messages promoting your products even when someone else pushes send.
  • Avoid purchased lists. Beyond deliverability damage, they raise deception and consent issues under state law and can taint your sender reputation.
  • Keep records of consent and opt-out processing dates in case a dispute arises.
  • Review subject lines with a simple test: would a reasonable recipient feel misled after opening? If yes, rewrite it.

Businesses that also text customers should note that SMS marketing is governed by a different and far stricter statute — the Telephone Consumer Protection Act — which requires prior express written consent for certain marketing texts sent using regulated automated or artificial/prerecorded-voice technology. Do not assume email rules carry over.

Talk to a California business attorney

If you are building an email program, cleaning up an old list, or responding to a spam-related demand, it is worth confirming your practices meet both federal and California requirements before small errors multiply across thousands of sends. Schedule a free consultation or call (949) 418-2113.

This article is attorney advertising and provides general information only. It is not legal advice and does not create an attorney–client relationship. Facts matter; consult a lawyer about your specific situation.

Free Consultation

Ready to move? Start with a free consultation.

Tell us what you're facing — a contract, a dispute, a debt, a decision. We will map the legal path in plain language, and you will leave the first call knowing your options.

Call Now Free Consultation