Email marketing
Is cold email legal in the US? Mostly yes, with sharp edges
US law lets you email someone who never asked — but the rules about how you do it are stricter than most people think, and Florida adds a statute with real teeth.
Start here: this is not legal advice
It is a plain-language summary written by a marketing shop, not a law firm. It is here because the question comes up in almost every sales conversation we have and the answers floating around online are usually wrong in one direction or the other.
If you are planning a cold outreach program of any size, the right move is to spend an hour with a lawyer who handles advertising and privacy work. That hour costs less than one complaint. Read this so you know what to ask.
The US rule is opt-out, and that surprises people
The federal statute governing commercial email in the United States is CAN-SPAM. Its central design choice is the thing most people get wrong: it is an opt-out regime. You do not need someone’s prior permission to send them a commercial message. You need to give them a working way to make you stop, and then stop.
That is genuinely different from the rest of the English-speaking world. The GDPR framework in Europe and Canada’s anti-spam legislation, CASL, both run on consent — you generally need permission before the first message, not after it. A campaign that is fine to send from Fort Lauderdale to Tampa can be a problem sent to Toronto or Dublin.
The other common misreading is a business-to-business exemption. There is not one. CAN-SPAM does not care whether the recipient is a consumer at home or a purchasing manager at work. A commercial message is a commercial message.
What CAN-SPAM actually requires
The obligations are short, specific, and mostly about honesty rather than permission.
- Accurate headers. The from, reply-to and routing information must identify who really sent the message.
- A non-deceptive subject line. It has to reflect what is actually in the email.
- Identify the message as an advertisement. The law allows some flexibility in how, but the recipient has to be able to tell.
- A valid physical postal address. Your street address or a registered post office box. In every commercial message.
- A clear, working opt-out. Easy to find, easy to use, and it cannot demand a fee, a login or any information beyond an email address.
- Honor opt-outs within 10 business days, and keep honoring them.
You are responsible for what a vendor does on your behalf. Hiring an agency, a lead generation firm or a freelancer to send for you does not move the liability off your company. If someone offers you a list and promises they handle compliance, that promise is worth exactly nothing.
Which of your emails this even applies to
Not every message you send is a commercial message. The distinction matters because the postal address and opt-out requirements attach to the commercial ones.
A message whose primary purpose is advertising or promoting a product or service is commercial. Your newsletter almost certainly is, even if it is mostly useful content, because the reason it exists is to promote the firm. A campaign inviting people to a seminar is. A cold introduction is.
A transactional or relationship message is treated differently — an appointment confirmation, an invoice, a document you agreed to send, a status update on a matter somebody has already engaged you for. Those are not advertising, and burying an offer inside one does not keep it transactional. If you attach a promotion to an invoice, you have changed what the message is.
The safe operating position for a small firm is to build every template with a real postal address and a working unsubscribe, and then not have to make the call under time pressure at four on a Friday. The cost of including it on a genuinely transactional email is nothing. The cost of leaving it off a commercial one is per message.
The penalties are per email, which is the part that matters
CAN-SPAM violations carry civil penalties that run into tens of thousands of dollars per individual message. The number people fixate on is the headline figure. The word that should worry them is "per".
Marketing thinking is volume thinking. A campaign to 4,000 addresses feels like one action. Under a per-message penalty structure it is 4,000 of them. A defect that is trivial in a single email — a missing postal address, an opt-out link pointing at a dead page — multiplies by the size of the send.
Florida has its own statute, and it survived preemption
CAN-SPAM preempts most state email laws, which is why people assume the federal rules are the whole picture. They are not, because the preemption has a carve-out: state laws targeting falsity and deception still stand.
Florida’s Electronic Mail Communications Act, at Florida Statutes sections 668.60 through 668.610, lives squarely inside that carve-out. It addresses false or misleading commercial email — deceptive headers, forged routing information, and subject lines likely to mislead the recipient about the contents of the message.
It provides for liquidated damages of $500 per email, and the limitations period runs four years. For a Florida business emailing Florida recipients, that combination is a more realistic exposure than a federal enforcement action. Four years is long enough that a campaign you have entirely forgotten is still live as a claim.
The practical rule: your subject line has to be literally true
Almost everything that gets a sender into trouble under the deception provisions is a subject-line trick, and the tricks are the same ones every time.
A subject beginning "Re:" on a message that is not a reply. "Fwd:" on something never forwarded. "Following up on our conversation" to somebody you have never spoken to. "Your invoice is attached" when there is no invoice. "Final notice" when nothing is ending. Each one is designed to get the message opened by making the reader believe something untrue about what it is.
The test we use internally is simple: could a reader open this email and reasonably say the subject line lied to them? If the answer is anything other than a flat no, it does not go out. That test costs nothing and it removes essentially all of the legal risk in a cold program.
If the subject line would embarrass you when read aloud next to the email, rewrite it.
Blue Ocean Strategies
Legal and effective are different questions
Everything above is about staying inside the law. Whether cold email is a good idea for your business is a separate question, and for most of the firms we work with the answer is no.
Cold email works when your prospect list is small, identifiable and genuinely relevant — a few hundred referral sources you can name, say. It works badly when it is a purchased list of ten thousand addresses, because the complaint rate that produces will do lasting damage to the domain reputation you need for the mail people did ask for.
That is the trade-off nobody selling you a list will mention. Burning your sending domain on strangers means your newsletter stops reaching your actual clients. We would rather build the list you own than rent one that costs you the one you have.
What to do before you send anything
Compliance is not the interesting part of email marketing and it never will be. It is also the part where a small oversight scales by the size of your list, which is exactly why it is worth an hour of somebody qualified.
- Confirm where your recipients are. Non-US addresses may need consent before the first message.
- Put a real postal address in the template, not just the footer of one version of it.
- Test the opt-out link end to end, from a real inbox, before the send — not after.
- Read every subject line against the literal-truth test.
- Write down how suppression works, and make sure a person other than you could run it.
- Take the whole plan to a lawyer once. Not once per campaign — once, before the first one.
Quick answers
Related questions
Under CAN-SPAM, no. It is an opt-out regime, so prior consent is not a requirement. You do need accurate headers, a truthful subject line, a physical postal address and a working opt-out honored within 10 business days. Consent rules are different in Europe and Canada.
No. CAN-SPAM has no B2B exemption. A commercial message to a work address carries the same obligations as one sent to a personal address.
CAN-SPAM preempts most state email laws but not those addressing falsity and deception. Florida’s Electronic Mail Communications Act, sections 668.60 to 668.610, sits in that gap. It provides liquidated damages of $500 per email with a four-year limitations period, which makes deceptive subject lines a meaningful risk for Florida senders.
No. You can be liable for what a vendor sends on your behalf. Anyone offering to handle compliance for you as part of a list purchase is describing a risk they cannot actually take off your books.
No. It is a plain-language summary from a marketing company. Rules change, facts matter, and your situation is not a blog post. Speak to a lawyer who handles advertising and privacy before you run a cold program.
Keep reading
More from the blog
Email marketing
How to write a subject line that is honest and still gets opened
The tricks that lift open rates are the same tricks that create legal exposure. The good news is that specific and honest beats clever anyway.
Read itEmail marketing
The welcome sequence: the one automation almost nobody has
Somebody just raised their hand. The next four days decide whether they remember you in six months, and most businesses use them to send nothing at all.
Read itEmail marketing
A campaign and a newsletter are not the same thing
One asks for something. The other just shows up. Treating them as the same channel is the most common reason a list stops responding.
Read itWant this done for you?
We write, design, print and send the whole thing. You spend about twenty minutes a month on it.
No pitch deck, no discovery-call gauntlet. One conversation, one straight answer.