The relevant US law is the CAN-SPAM Act, enforced by the Federal Trade Commission. Two facts about it surprise most people.
First, it does not require opt-in. Recipients have the right to opt out after receiving a message; there is no requirement to obtain consent before sending one.
Second, it applies to business-to-business email. The FTC's own guidance is explicit that the law makes no exception for B2B, so "it's B2B" is not a defence for ignoring the rules.
The penalty is what makes the details worth reading: each individual email that violates the Act can carry a civil penalty of up to $53,088. That is per email, not per campaign.
What the Act actually requires
The FTC's compliance guide sets out the obligations on commercial email. In practical terms:
- Accurate header information. Your From, To, Reply-To and routing information must identify who actually sent the message.
- Truthful subject lines. The subject must reflect what is in the message.
- Identify the message as an advertisement. This can be done clearly and conspicuously; the Act gives latitude on how.
- A valid physical postal address. Your real street address or a registered PO box has to appear in the message.
- A clear opt-out mechanism. An obvious explanation of how to stop receiving email from you, with a working email or web-based way to do it.
- Honour opt-outs within 10 business days, and keep the opt-out mechanism working for at least 30 days after sending.
- You stay responsible even if someone else sends for you. Hiring an agency does not contract away your legal responsibility.
That last point deserves emphasis if you are outsourcing outbound. The obligations remain yours. It is entirely fair to ask an agency how each one is handled before you sign.
How we handle it operationally
Remove requests are honoured immediately and suppressed across every campaign, not just the one the request came from. Sending domains resolve to the client's real website rather than a parked page, so the sender is identifiable. The physical address appears in the message. Every reply is read by a person the same business day, which is also how an opt-out gets caught when it arrives as a sentence rather than a click.
Outside the United States
If you are emailing people in the EU or UK, GDPR and the local ePrivacy rules apply and the standard is materially different — consent and legitimate interest work differently there, and the safe assumption is that US-style cold outreach does not transfer. Canada's CASL is stricter than CAN-SPAM as well.
If your market is outside the US, that is a conversation to have with a lawyer who works in the destination jurisdiction before the first send, not after.
A note on what this is
This is a plain-English summary of published FTC guidance, not legal advice, and we are not lawyers. If compliance is a live concern for your business — particularly in a regulated industry or outside the US — talk to counsel.