Email compliance is not optional. The rules that govern how you send email are enforced by law, and the penalties for getting it wrong are real. This guide covers the major regulations, what each one requires, what happens when you get it wrong, and how to stay compliant.
CAN-SPAM is the primary US law governing commercial email. It applies to any business that sends email to US recipients, even if the business is based overseas. The key requirements are straightforward.
You must not use deceptive subject lines or header information. If the email says "your invoice is ready," the email must actually be about an invoice. You must identify the message as an ad if it is one. You must provide a valid physical postal address in every message. You must honor opt-out requests within ten business days and stop sending immediately.
The penalties are per message. The FTC can assess up to $50,120 per violation, and there is no cap on the total. One bad campaign can cost you millions.
GDPR is the EU's data protection regulation. It applies to any organization that processes personal data of EU residents, regardless of where the organization is based. Email addresses are personal data under GDPR, so sending email to EU recipients puts you in scope.
The key requirements are consent and data minimization. You need a valid legal basis for processing the email address, and for most commercial email that means explicit consent. You must be able to tell where the consent came from, when it was given, and what it covered. You must honor erasure requests within thirty days. You must have a data protection officer or at least a documented process for handling data requests.
The penalties are up to 4 percent of global annual revenue or 20 million euros, whichever is higher. The EU has fined companies in the hundreds of millions for email violations.
CASL is Canada's anti-spam law. It applies to any organization that sends commercial electronic messages to Canadian recipients. The key requirement is consent. You need express consent (the recipient actively opted in) or implied consent (the recipient has a relationship with you, such as a recent purchase).
Every message must include the sender's name, postal address, and a working unsubscribe mechanism. The unsubscribe must be honored within ten business days. The penalties are up to 10 million CAD for organizations and 1 million CAD for individuals, per violation.
Compliance and deliverability are deeply connected. Mailbox providers track your complaint rate, and a high complaint rate is one of the fastest ways to get your domain or IP blacklisted. When people complain, it is usually because they did not consent to receive your email, or because your unsubscribe link does not work.
A clean, compliant list is a list where every recipient actually wants to hear from you. That means lower complaint rates, better engagement, and a healthier sender reputation. The moment you start sending to people who did not consent, you are training the mailbox provider to send you to spam.
Keep a record of every consent. When someone signs up, store the timestamp, the IP address, and the exact language of the consent. If a regulator asks, you need to be able to prove it.
Make the unsubscribe link work. One click, no confirmation, no friction. If the user has to log in or confirm, you are in violation. Test it regularly.
Include a physical address in every email. This is a CAN-SPAM requirement and a CASL requirement. Put it in the footer.
Do not buy lists. A purchased list is a list of people who did not consent to hear from you. Sending to it is a violation of every major regulation and a fast track to a blacklisted domain.
Run the free audit on your sending domain and check that your authentication is clean. Compliance is about the list, but authentication is about the domain. You need both.
Want this checked automatically every day? Inboxproof Pro monitors your domain around the clock and alerts you the moment a record breaks or an IP gets listed. See pricing →