Short answer: yes, sending cold email to a business contact in the United States is legal. CAN-SPAM does not require permission before you send. It regulates *how* you send commercial email — honest headers, honest subject lines, a working opt-out, a real postal address — and it gives regulators teeth if you ignore those rules.
That surprises people who've been told cold email is "basically illegal now." It isn't. But the gap between "legal" and "safe" is where most outbound teams get into trouble, because Gmail and Microsoft enforce their own rules far more aggressively than the FTC ever will.
One important caveat before we start: this is not legal advice. I'm describing how the statute is generally understood by people who run outbound programs. If you're sending at scale, in a regulated industry, or into multiple countries, run your process past an actual lawyer.
{"h2":"What CAN-SPAM actually requires"}
The CAN-SPAM Act of 2003 covers any "commercial electronic mail message" — email whose primary purpose is advertising or promoting a commercial product or service. A cold sales email qualifies. A transactional email (receipt, password reset, order update) mostly doesn't.
There are seven obligations, and none of them is "get consent first."
{"table":{"headers":["Requirement","What it means in practice"],"rows":[["No false or misleading header info","Your From name, From address, and reply-to must accurately identify the sender. No spoofed domains, no fake aliases pointing nowhere."],["No deceptive subject lines","The subject can't misrepresent the content. \"Re: our call yesterday\" when there was no call is a problem."],["Identify the message as an ad","Required unless the recipient gave prior affirmative consent. In practice, clear sender identification and a plain commercial pitch is how most B2B senders satisfy this."],["Include a valid physical postal address","A street address, PO box, or registered agent address in the footer of the email."],["Provide a clear opt-out mechanism","An unsubscribe link or reply-to-opt-out instruction that a normal person can find and use."],["Honor opt-outs within 10 business days","And you can't charge a fee, require a login, or ask for anything beyond an email address to process it."],["You're responsible for what others do on your behalf","Hiring an agency doesn't transfer liability. Both the sender and the business being promoted can be held liable."]]}}
Penalties are per email, not per campaign. The statutory maximum adjusts for inflation and is now north of $50,000 per violating message. Nobody gets fined for one sloppy footer, but the math is why you don't want a 40,000-message campaign with no unsubscribe path.
{"h2":"What CAN-SPAM does not require"}
This is the part most "is cold email legal" articles get wrong.
{"ul":["Consent. There is no opt-in requirement for US commercial email. Unsolicited is fine.","Double opt-in. Not a legal concept in the US. It's a deliverability and list-quality practice.","A one-click unsubscribe link specifically. The law says \"clear and conspicuous\" opt-out. Reply-to-unsubscribe can satisfy the statute — though mailbox providers now expect the link, which is a different problem.","Immediate processing. You have 10 business days. Do it same-day anyway.","Separate consent for follow-ups. A three-step sequence to a contact who hasn't replied is not a violation. It may still be annoying."]}
So a compliant cold email can be entirely unsolicited. What it can't be is disguised.
{"h2":"State laws still matter"}
CAN-SPAM preempts most state anti-spam statutes, but not the parts dealing with falsity or deception. California's Business & Professions Code §17529.5 is the one that comes up most: it prohibits commercial email with falsified header information or misleading subject lines, and it has been used in private litigation, not just regulator enforcement.
Practical translation: the "clever" tactics are the legally risky ones. Fake reply threads, made-up sender names, subject lines implying an existing relationship, domains registered to obscure who you are. Straightforward outbound from a real company with a real address is not what these laws were built to catch.
Separately, if you're emailing consumers rather than businesses — or handling personal data of California residents at scale — CCPA/CPRA creates its own obligations around data sourced from third parties. That's a data-privacy question, not an anti-spam one, but it lands on the same desk.
{"h2":"If you email outside the US, the rules flip"}
CAN-SPAM's permissive opt-out model is the exception globally, not the norm. A quick orientation:
{"ul":["Canada (CASL): consent-based. You need express or implied consent before sending, with limited exceptions (existing business relationship, conspicuously published business address relevant to their role). Penalties run into the millions and there's an enforcement history.","EU/EEA (GDPR + ePrivacy): processing a business contact's email is personal data processing. Many B2B senders rely on legitimate interest, which requires a documented balancing assessment, a clear privacy notice, and a real opt-out — plus per-country variation in how business email is treated.","UK (PECR + UK GDPR): unsolicited email to corporate subscribers (limited companies, LLPs) is permitted; sole traders and partnerships are treated more like individuals.","Australia (Spam Act): consent-based, with inferred consent for a published work address that's relevant to the recipient's role."]}
If your list is mixed geography, the safest operating model is to build one process that satisfies the strictest jurisdiction you touch, then segment where you genuinely need different behavior. Trying to run four compliance regimes in parallel inside one sequence tool is how mistakes happen.
{"h2":"Legal and deliverable are different problems"}
Here's the uncomfortable part: Google and Microsoft are not enforcing CAN-SPAM. They're enforcing their own bulk sender guidelines, and those are stricter in the ways that actually cost you money.
Since 2024, bulk senders hitting Gmail and Yahoo thresholds are expected to authenticate with SPF and DKIM, publish DMARC, keep spam complaint rates under 0.3%, and — for promotional mail — support one-click unsubscribe via the List-Unsubscribe header (RFC 8058). None of that is law. All of it determines whether your mail reaches an inbox.
Which means the compliance checklist and the deliverability checklist overlap heavily. Authenticate properly (SPF, DKIM, and DMARC setup guide), keep complaints low, make opting out trivially easy, and don't email addresses that bounce or don't exist (verify every lead first). Doing the legal minimum and the platform maximum turns out to be roughly the same work.
{"h2":"A practical compliance setup for outbound"}
What this looks like day to day for a US-based B2B sender:
{"ul":["Send from a domain that clearly belongs to your company, with WHOIS and DNS that don't hide who you are.","Real person in the From name, real reachable reply-to address. Replies go to a human.","Physical postal address in every message footer — the same one on your website.","An unsubscribe link plus List-Unsubscribe headers, not just \"reply STOP.\"","Opt-outs processed automatically and instantly, and applied workspace-wide so a different campaign can't re-email the same person next month.","A global suppression list covering unsubscribes, hard bounces, complaints, current customers, and anyone your team has marked do-not-contact.","Subject lines that describe the email. If you wouldn't say it out loud on a call, don't put it in a subject.","Records: where each contact came from, when they were added, when they opted out. If a complaint ever lands, this is the file that saves you.","Geographic segmentation if you send to Canada or the EU, with different consent logic and different footers."]}
{"h2":"How Sendvanta handles the mechanics"}
Most of the checklist above is plumbing, and plumbing should be default-on rather than a setting someone forgets to enable. In Sendvanta, suppression and one-click unsubscribe ship on by default: unsubscribe links and List-Unsubscribe headers are added to sequences, opt-outs are applied at the workspace level across every campaign and mailbox, and hard bounces and complaints flow into the same suppression list automatically. Drafts get SpamAssassin-scored before send, which catches a lot of subject-line and footer problems before a regulator or a spam filter has to. You connect your own Gmail, Microsoft 365, or SMTP mailboxes — mail is never proxied through shared IPs, so the sending identity in the headers is genuinely yours.
You can test the whole flow on the free plan: $0 forever, no credit card, 1,000 active leads and 3,000 emails a month. Paid plans start at $29/mo. More detail on what's included.
{"faq":[{"q":"Do I need permission before sending a cold email in the US?","a":"No. CAN-SPAM is an opt-out regime — unsolicited commercial email is legal as long as you identify yourself honestly, include a valid postal address, provide a working opt-out, and honor opt-out requests within 10 business days."},{"q":"Is B2B cold email exempt from CAN-SPAM?","a":"No. CAN-SPAM applies to commercial email regardless of whether the recipient is a business or a consumer. There is no B2B carve-out in the US statute, unlike the UK's PECR rules for corporate subscribers."},{"q":"Can I get fined for one non-compliant email?","a":"In theory the statutory maximum exceeds $50,000 per message and adjusts for inflation. In practice, enforcement targets patterns — high-volume senders with deceptive headers, no opt-out, or ignored unsubscribe requests — not a single missing footer."},{"q":"Does a reply-to-unsubscribe instruction satisfy the law?","a":"Generally yes under CAN-SPAM, which requires a clear opt-out mechanism rather than a specific link. But Gmail and Yahoo expect List-Unsubscribe one-click support from bulk senders, so link-based opt-out is the practical standard."},{"q":"Can I email EU contacts the same way I email US contacts?","a":"No. GDPR and ePrivacy treat business email addresses as personal data and require a lawful basis, a privacy notice, and documented balancing if you rely on legitimate interest. Segment EU contacts and handle them separately."}]}
Ready to send outbound that lands?
Create your free Sendvanta workspace — no credit card required.
Start free