- © 2026 Mailsoftly Inc. The name "Mailsoftly" and the Mailsoftly logo are registered trademarks of Mailsoftly Inc.
Consent, honest headers, a real address, and one-click unsubscribe. Here is what CAN-SPAM, GDPR, CASL, and CCPA actually require, and how to stay clear of penalties.
by Isabella Torres · Last updated: 2026-08-19Email marketing laws require four things from every commercial sender: a lawful basis to contact each person (consent or a legitimate business relationship), truthful sender information and subject lines, a valid physical postal address, and a working way to unsubscribe that you honor promptly. The specifics vary by country, but those pillars are near universal.
The main frameworks you will meet are CAN-SPAM in the United States, GDPR across the European Union, CASL in Canada, and the CCPA and CPRA in California. Each defines consent, disclosure, and enforcement differently, and where your subscribers live decides which rules apply, not where your company sits.
This guide breaks down what each law demands, how they overlap, and the concrete steps that keep your program safe. Compliance is not just legal cover. It is also the fastest route to better deliverability and higher engagement.
New here? Start with our primer on Email Marketing Fundamentals for the fundamentals, then come back to this guide.
Quick context: Mailsoftly offers transparent pricing, free hands-on migration, and human support. 500 contacts and 2,000 emails per month, no credit card.
Start free with Mailsoftly →
Key Takeaways
Email marketing laws are regulations that govern how businesses can send commercial and promotional messages to people’s inboxes. They exist to protect consumers from unwanted mail, deception, and privacy abuse, and to hold senders accountable for how they collect and use contact data.
These rules emerged because email is cheap to send at scale, which made it easy to abuse. Legislators responded by defining what counts as consent, what a sender must disclose, and how quickly a recipient’s wishes must be respected. The result is a patchwork of national and regional laws that share a common spirit even when the letter differs.
For marketers, this matters beyond avoiding fines. Mailbox providers like Gmail and Outlook watch the same signals the laws care about: did the person want this, and can they easily stop it. Compliant senders tend to see better inbox placement, which is why treating the rules as a floor rather than a ceiling pays off. If you are building a program from scratch, our guide to Email Marketing Fundamentals covers how consent and strategy fit together.
Read enough? Try Mailsoftly free with 500 contacts and 2,000 emails per month, no credit card.Start free with Mailsoftly →
CAN-SPAM requires that commercial email use accurate header and sender information, carry a non-deceptive subject line, include a valid physical postal address, disclose the message as an advertisement where relevant, and offer a clear opt-out that you honor within ten business days. It is enforced by the Federal Trade Commission.
Unlike Europe and Canada, the United States uses an opt-out model. You may email a person until they ask you to stop, as long as you follow the disclosure rules. That does not make purchased or scraped lists safe, because low engagement and spam complaints will still wreck your deliverability. The law sets a legal floor, but the mailbox providers set a much higher practical bar.
Each separate email that violates CAN-SPAM can draw a penalty of up to $53,088, and the count is per message, so a single non-compliant campaign to a large list can multiply fast. There is no exception for outsourcing: both the company whose product is promoted and the firm that sends the mail can be held liable.
GDPR requires a lawful basis before you process anyone’s personal data, and for marketing email that basis is almost always freely given, specific, informed, and unambiguous consent. Pre-ticked boxes do not count, silence does not count, and you must keep records proving when and how each person opted in.
The regulation protects anyone in the European Union regardless of where your business is based. That extraterritorial reach is the reason a company in Texas still has to comply the moment it emails a subscriber in Germany. GDPR also grants people strong rights: to access their data, to correct it, to have it erased, and to withdraw consent as easily as they gave it.
Penalties are the harshest of any framework here, reaching up to 20 million euros or four percent of global annual revenue, whichever is greater. Beyond consent, GDPR expects data minimization, meaning you only collect what you genuinely need, and purpose limitation, meaning you use data only for what people agreed to.
GDPR and CASL are opt-in: you need permission before the first email. CAN-SPAM is opt-out: you can send until someone unsubscribes. When your list spans regions, default to opt-in so a single workflow satisfies the strictest law.
CASL is one of the strictest anti-spam laws in the world. It requires express or implied consent before you send a commercial electronic message, clear sender identification, and a functioning unsubscribe mechanism that works for at least sixty days and is processed within ten business days.
Implied consent under CASL covers situations like an existing business relationship or a recent purchase, but it expires, so you cannot rely on it forever. Violations can reach up to ten million Canadian dollars per infraction for a business, and the burden of proving consent sits with the sender, not the recipient.
California’s CCPA, expanded by the CPRA, is a privacy law rather than an email-specific one, but it shapes how you handle subscriber data. It gives California residents the right to know what personal information you collect, to have it deleted, and to opt out of its sale or sharing. If your signup form feeds data into ad platforms, that “sale or sharing” definition can apply, so your privacy notice and preference controls need to reflect it.
| Law | Region | Consent model | Max penalty |
|---|---|---|---|
| CAN-SPAM | United States | Opt-out | $53,088 per email |
| GDPR | European Union | Opt-in | 20M euros or 4% of revenue |
| CASL | Canada | Opt-in (express or implied) | 10M CAD per violation |
| CCPA / CPRA | California | Opt-out of sale or sharing | $7,500 per intentional violation |
The simplest path to global compliance is to default to the strictest rule that touches your list. If you build every workflow around opt-in consent, clear disclosure, and easy unsubscribing, you satisfy CAN-SPAM, GDPR, and CASL at once without maintaining four separate processes.
Start at the point of collection. Use unbundled, unchecked consent boxes with plain language that says what people are signing up for. Store the timestamp, source, and wording of each opt-in so you can prove it later. A double opt-in confirmation adds a layer of proof and quietly improves list quality by filtering out typos and bots.
On the sending side, keep your footer honest: a real address, a genuine sender name, and a one-click unsubscribe that removes people fast. Run periodic list hygiene to purge unengaged and bounced contacts, and route data-subject requests to a defined owner so erasure and access demands are handled on time. Choosing an email platform that bakes these controls in removes most of the manual risk.
Mailsoftly is built with these safeguards in place: consent capture, automatic unsubscribe handling, an address block in every footer, and list hygiene tools that keep your data clean. You can compare plans on our transparent pricing page and start on the free tier while you audit your program.
For the broader picture on this topic, see our complete Email Marketing Fundamentals guide, which covers strategy, fundamentals, and advanced playbooks.


Yes. What matters is where your recipient is located, not where your company is registered. If you email someone in the European Union, GDPR applies even if you operate entirely from the United States. Because most lists span multiple regions, the safest approach is to comply with the strictest law that touches any contact.
Single opt-in can be legally sufficient in many cases, but double opt-in gives you stronger proof of consent and cleaner data. It sends a confirmation email that the subscriber must click, which filters out typos and fake addresses. Under GDPR and CASL, where the sender must prove consent, that extra record is genuinely valuable.
Under CAN-SPAM and CASL you have up to ten business days to process an opt-out, but best practice is to act immediately. Modern platforms remove unsubscribes automatically, so there is rarely a reason to wait. Never require someone to log in, reply, or fill out a form to unsubscribe, since that itself can breach the law.
Purely transactional messages, such as receipts, shipping updates, and password resets, are generally exempt from the marketing-specific rules because they are not promotional. The moment you add a promotional element, though, the message can be treated as commercial and the full requirements apply. Keep transactional and marketing content clearly separated to avoid ambiguity.
Under GDPR and CASL, emailing a purchased list is effectively illegal because you have no valid consent from those individuals. CAN-SPAM does not ban it outright, but purchased lists deliver poorly, generate spam complaints, and damage your sender reputation. In practice, buying lists costs you far more in deliverability than it ever returns.
Ready to switch?Start free with Mailsoftly →
500 contacts, 2,000 emails per month. Free hands-on migration. No credit card.

Ready to boost your email marketing?
Start sending beautiful, targeted emails that convert — free to get started.
Try Mailsoftly FreeNo credit card required