CAN-SPAM rules for small business: what you can actually send
Canada's CASL says you need permission before you email a stranger. The UK's PECR says it depends who the stranger is. The United States asks neither question — nothing in the FTC's list of CAN-SPAM requirements asks for consent at all. It asks for honesty and a working exit. That makes the CAN-SPAM rules a small business has to follow shorter than most guidance implies, and stricter in one place nobody expects.
Before anything else: this is a plain-English summary, not legal advice. We're a marketing company, not a law firm. Every claim below links to the FTC's own guidance or the live rule text so you can check it, and anything with real money riding on it deserves a conversation with a lawyer.
what the CAN-SPAM rules actually require
The FTC's compliance guide for business sets out the whole thing in a handful of rules. In practice they come down to this:
- Accurate headers. Your "From," "To," "Reply-To" and routing information must be accurate and identify who actually sent the message.
- An honest subject line that reflects what's in the email.
- Identify the message as an ad — clearly and conspicuously. The FTC gives you latitude on how, but not on whether.
- A valid physical postal address. Your street address, a post office box you've registered with the US Postal Service, or a private mailbox registered with a commercial mail receiving agency.
- A clear way to opt out, written so an ordinary person can find and understand it. The FTC specifically warns you to make sure your own spam filter isn't blocking the replies.
- Opt-outs honored promptly — the clock is below.
- Responsibility you can't hand off. Hiring someone to send your email doesn't transfer the duty.
Notice what isn't on that list. There's no requirement that the recipient agreed to hear from you first, and the guide is explicit that the law makes no exception for business-to-business email. A message to a former customer announcing a new product line is covered the same way a cold pitch is.
The price of getting it wrong is per message, not per campaign. Each separate email in violation is subject to penalties of up to $53,088. If you want to see that figure at source rather than in a blog, it's in 16 CFR § 1.98(d), the FTC's civil penalty adjustment rule — which, as of August 2026, still carries the amounts set on 17 January 2025. If you see a different figure quoted as the current one, check it against that page before you repeat it.
the part that surprises people: permission isn't the test
CAN-SPAM is an opt-out regime. You may email someone who never asked, provided every message is honest and every exit works. That is the opposite of the position in most of the English-speaking world, and it's why US marketing advice travels so badly.
Two caveats keep that from being a license to do anything.
The first is how you got the addresses. The Act carves out criminal penalties — separate from the civil ones — for harvesting email addresses or generating them through a dictionary attack, which is the practice of mailing made-up addresses in the hope of hitting real ones. "No consent required" and "scrape whatever you like" are not the same sentence.
The second is geography. The rules that apply are the recipient's as well as yours. Email a Canadian prospect and you're inside CASL, where consent is a clock that expires; email a UK sole trader and you're inside PECR, where they count as an individual subscriber. A single list with international addresses on it is quietly governed by three regimes at once. We send cold email ourselves, and our send script hard-blocks anything that doesn't clear the gate for the recipient's country — because the alternative is auditing it by memory, at eight in the morning, once a day, forever.
Where p.a. fits: we write and produce the emails; you own the list and the sending platform. That split is deliberate — the compliance record has to live where the business does. We're the vendor here, so weight our opinion accordingly.
See what the packages cost →
which of your emails this even applies to
Not every email you send is commercial. The test is the message's primary purpose, and the FTC treats a short list of message types as transactional or relationship messages — exempt from most of the Act, though still bound by the truthful-routing rule. Those are messages that only:
- facilitate, complete or confirm a transaction the recipient already agreed to;
- give warranty, recall, safety or security information about something they bought;
- notify them of a change to a membership, subscription, account or loan, or provide regular account balance information;
- provide information about an employment relationship or benefits; or
- deliver goods or services they already agreed to buy.
The categories are read narrowly, and the FTC's own worked example is the useful part: an account statement with one promotional line at the end most likely reads as transactional. The same subject line, with the offer at the top and the shipping note at the bottom, most likely reads as commercial. Where the promotional content sits in the message decides which set of rules you're under.
One more that catches subscription businesses: members and subscribers can still opt out of marketing. You don't need their consent to market to them, but a membership isn't a standing permission either.
the opt-out clock, precisely
This is the requirement most likely to be breached by accident, so it's worth the specifics:
- The opt-out mechanism must keep working for at least 30 days after you send the message.
- You must honor a request within 10 business days.
- You can't charge a fee, require any personally identifying information beyond an email address, or make someone do more than send a reply email or visit a single web page.
- Once someone has opted out, you can't sell or transfer their address — not even as part of a list. The only exception is passing it to a company you've hired to help you comply.
That last point quietly kills the "suppression list we sold with the business" idea. An opt-out isn't an asset.
you can't outsource the liability
If you hire an agency or a platform to run your email, you remain responsible. The FTC's position is that you can't contract away compliance, and that both the company whose product is promoted and the company that sent the message may be held legally responsible.
Which is worth saying plainly, given what we sell: a marketing supplier can write your emails and design your templates, and a sending platform can deliver them, but neither one absorbs the risk. Ask any vendor — us included — how their process handles opt-outs, and treat a vague answer as the answer.
the law is not your hardest gate — Gmail is
Here's the thing the compliance posts miss. You can satisfy every CAN-SPAM requirement and still have your email land nowhere, because the mailbox providers set a higher bar than Congress did and enforce it automatically.
Google's email sender guidelines require SPF or DKIM authentication from all senders to personal Gmail accounts, and SPF, DKIM and DMARC from bulk senders. Unauthenticated messages "might be marked as spam or rejected." Send more than 5,000 messages a day and your marketing email must also support one-click unsubscribe.
Then there's the number that actually governs your fate: Google asks senders to keep the spam rate reported in Postmaster Tools below 0.10%, and to avoid ever reaching 0.30%. One complaint in a thousand is the working ceiling. And the same page tells you plainly not to purchase email addresses from other companies, and not to send to people who didn't sign up.
So the practical position for a US small business is this: the law permits cold email, and your recipients' mail providers punish it if the recipients don't want it. Compliance is the floor. Deliverability is the actual constraint, and it's decided by whether people are glad to hear from you — which is the same argument our guide to email that doesn't get deleted makes on purely commercial grounds.
the honest takeaway
The CAN-SPAM rules a small business needs are a short list you can implement this afternoon: a real postal address in the footer, an honest subject line, an obvious unsubscribe link, a process that clears opt-outs inside ten business days, and a note of who is responsible for checking it. None of that requires software you don't already have.
The harder work is the part the law doesn't ask for. A list of people who want your email is what keeps your spam rate under a tenth of a percent, and no amount of legal compliance substitutes for it. The rules set the floor; the inbox sets the bar. Build for the second and you'll clear the first without thinking about it.
we'll write the emails; you keep the list clean
A fixed monthly fee, a full batch of on-brand content produced for you including the newsletters, and
a dated calendar telling you what goes out when.
Three-month minimum, stated up front, and you own
everything we make.