Key takeaway
Email marketing laws come down to three things at once: a lawful basis for having the address, a message that says who sent it and where they are, and a way out that you honour on a clock. The message half is a template change you make once, and the penalty behind it runs to $53,088 an email. The permission and suppression half is your data model, and that's the half I've watched fail. The inboxes ask more than the statutes do.
What email marketing laws actually require.
Email marketing laws govern the marketing email itself, not how a law firm markets itself, and satisfying them comes down to three things at once. You had a lawful basis for having the address, the message says who sent it and where they are, and there's a working way out that you honour. Almost nobody fails at the message. Footers are easy, every platform ships one, and the template gets written once. I've built these platforms for over a decade and I've never seen a footer be the problem. What fails is the record behind the send, because "we had permission" is a claim about something that happened months earlier and most senders can't produce it. And doing all of it still doesn't get the mail delivered. The legal floor and the inbox floor are different heights, and the inbox one is higher.
"Legal" is three questions wearing one word, which is why the advice about it reads as contradictory. Permission is a data question: what you hold, about whom, and how it got there. Message contents is a template question. Unsubscribes are an operations question, and it's the only one of the three with a clock attached. They land on different people and they fail in different ways, which is why the sections below take them one at a time rather than as one long list.
The seven things American law asks of a marketing email.
CAN-SPAM is the US federal rule for commercial email, and two things about it catch senders out. It covers all commercial messages rather than bulk sends, so a single one-to-one sales email is inside it. And it's opt-out rather than opt-in, so the consent American senders assume they need isn't something federal law asks for. The FTC's compliance guide sets out seven requirements and puts the penalty at up to $53,088 for each separate email in violation.
- Keep the header information accurate. The from name, the reply-to, and the routing data have to be true.
- Don't write a deceptive subject line. It has to reflect what the message is about.
- Identify the message as an advertisement. The wording is yours, but it has to be clear.
- Give a valid physical postal address. A street address or a registered post office box both qualify.
- Tell people how to opt out, somewhere a reader can find without hunting.
- Honour the opt-out promptly, and keep the mechanism working after the campaign is over.
- Stay responsible for what anyone sends on your behalf. Hiring it out doesn't move the liability.
Six of those seven are template work, done once, and the seventh isn't. What others do on your behalf is the clause that reaches your agency, your contractor, and whoever ran that one campaign from their own account. Both the company being promoted and the company pressing send can be held responsible, so an arrangement where each assumes the other is on it leaves both exposed.
Where a message stops being transactional.
A transactional or relationship message can skip the unsubscribe link. The test is the message's primary purpose, not the system that sent it, not the endpoint it went through, and not which folder the template lives in. A receipt, a shipping notice, a password reset, or an update about an account somebody already has: those are transactional because that's what they're mostly about.
The boundary moves the day marketing gets added to a receipt. A shipping confirmation that gains a "customers also bought" block has changed what it is, and it changed during a sprint rather than during a legal review. The practical test is what a recipient would say the message was about after reading the subject line and the first screenful. If the promotional half is the part they'd name, it's a commercial message, and it owes everything in the section above: the identification, the address, and the way out.
Nothing in a stack does that analysis for you, and it has to be done per message. A platform can tell you which endpoint sent something and which template it used. It can't tell you what the message was mostly about. That judgement belongs to whoever wrote the template, and it has to be made again every time somebody adds a block to it.
Consent means a different thing in every jurisdiction.
Everything above is about the message. This is about the record that had to exist before the send. The short version: the United States asks you to stop when you're told, and most of the rest of the world asks you to prove you were invited.
| Jurisdiction | Consent standard | Governing law / mechanism |
|---|---|---|
| United States | Opt-out. No prior consent required for commercial mail. | Identify yourself and stop on request. State privacy laws add data rights on top, not a consent gate in front. |
| European Union | Opt-in, and provable. Consent must be a clear affirmative act, freely given and specific. | Withdrawing consent has to be as easy as giving it was, under GDPR Article 7. |
| United Kingdom | Opt-in, with a narrow exception. Doesn't reach a bought list. | The ICO's soft opt-in covers your own recent customers for similar products, only if you offered a way out at collection and in every message since. |
| Canada | Express or implied consent. | CASL section 6 requires the message to identify the sender, give a way to reach them, and set out an unsubscribe mechanism. |
| Australia | Consent, accurate sender information, and a functional unsubscribe facility. | That's the order the Spam Act 2003 sets them out in. |
Which regime applies is decided by where the recipient is, not by where you are. A single contacts table holding addresses in five countries is five legal regimes wearing one CSV, and nothing in the file tells you which row is which. That's a data problem long before it's a legal one, which is why the split between a template change and a data model decides how hard this gets.
The unsubscribe clock is not one number.
Three numbers, and two of them are the same. CAN-SPAM gives you ten business days to honour an opt-out and requires the mechanism itself to keep working for at least thirty days after you send the message. CASL gives ten business days as well, and section 11 adds that the mechanism has to cost the recipient nothing. GDPR answers with a design requirement instead of a deadline: withdrawal has to be as easy as consent was.
| Regime | Deadline to honor | Other requirement |
|---|---|---|
| CAN-SPAM | 10 business days | Mechanism must keep working for at least 30 days after the send. |
| CASL | 10 business days | Mechanism must cost the recipient nothing (section 11). |
| GDPR | No fixed deadline; a design requirement instead. | Withdrawal has to be as easy as giving consent was. |
Those numbers are ceilings, and treating them as targets is how a sender ends up in the worst position available, which is a documented delay. A complaint about a message sent nine days after somebody unsubscribed is a complaint with your own timestamps inside it. If suppression in your stack is a list that somebody exports and re-imports rather than a job that runs, the delay isn't an accident. It's the design.
A deadline is per sender, not per system. Campaigns from one platform, receipts from another, and anything leaving through a bring-your-own provider key are one sender in law and three suppression lists in practice. An unsubscribe honoured in one of them is a violation in the other two, and the person who told you is holding the receipt. Three lists is what a stack assembled from three products costs you, and no amount of care inside any one of them closes the gap between them. The fix is structural rather than procedural: one stack that answers to one command, so suppression is something the system does on every path at once rather than a reconciliation somebody remembers to run.
The mailbox providers now enforce a stricter rule than the law.
Separately from any statute, the large mailbox providers publish their own requirements for senders, and those are the ones that decide whether a message arrives at all. Google asks bulk senders to keep the spam rate reported in Google Postmaster Tools below 0.10%, and never to reach 0.30%. It also requires marketing mail to support one-click unsubscribe and to carry a clearly visible unsubscribe link in the body.
The law measures whether you broke a rule. The mailbox measures whether people wanted the message. Those are different questions, and only one of them has a regulator attached to it. A sender can hold a spotless compliance record and still be filtered, because 0.30% is three complaints in a thousand and no statute has ever cared about three complaints in a thousand.
That cuts both ways. None of it is enforceable against you, because nobody fines a business for a spam rate. It also isn't negotiable. There's no appeal, no notice period, and no hearing, just a slow slide in inbox placement that looks like a subject-line problem for about a month before anyone reads it correctly. The practical consequence is a cheerful one. A one-click unsubscribe header and a suppression job that runs the same day clear the legal floor and the inbox floor together, and cost less than working out which of the two you're arguing with.
Compliance you can run instead of read.
Every page on this subject ends by telling you to conduct a regular compliance audit, and none of them says what's in one. Here's what's in one. Which contacts have a consent record and which don't. Which addresses unsubscribed in the last week, and whether every sending path honoured them. Which sends went to a country that wants opt-in. Which sending domains still authenticate, and which one quietly stopped when somebody edited a DNS record.
Read that back and notice what it is. Those are queries, whoever holds the data. Every one is a question whose answer already sits in your own contact records, and the shape of that work is asking, not reading a checklist once a quarter and filing it. A dashboard is a place to look things up one screen at a time, and you can't ask a screen four questions on a Monday morning and get four answers back. That's what an AI-native email platform is for. Every capability exists as an API endpoint and an MCP tool first, and the screen is rendered from it, which is the opposite order to every platform built for somebody clicking through it.
Consent, suppression, and proof live in your contact data rather than in your footer, so whichever platform holds it decides how hard any of this gets. Nitrosend keeps it in one place you can query: unlimited contacts on every plan, suppression that every sending path reads, and the MCP server, API, and CLI switched on from the free tier. Start there, and ask it something.
Go deeper
Sources
- FTC, CAN-SPAM Act: A Compliance Guide for Business: the seven requirements, the $53,088 per-email penalty, the ten business days to honour an opt-out, the thirty days the mechanism has to stay live, and the primary-purpose test for transactional messages.
- Regulation (EU) 2016/679, Article 7: consent as a clear affirmative act, the controller's obligation to demonstrate it, and withdrawal being as easy as giving it.
- ICO, Electronic mail marketing: the UK consent rule, the scope of the soft opt-in, that it doesn't reach bought-in lists, and the position on marketing to companies.
- CASL, S.C. 2010, c. 23, section 6: sender identification, contact information, and the requirement to set out an unsubscribe mechanism.
- CASL, section 11: the unsubscribe mechanism at no cost to the recipient, given effect without delay and no later than ten business days.
- Spam Act 2003 (Cth), sections 16 to 18: unsolicited commercial electronic messages, accurate sender information, and a functional unsubscribe facility.
- Google, Email sender guidelines: the 0.10% and 0.30% spam-rate numbers reported in Postmaster Tools, and the one-click unsubscribe and visible unsubscribe link required on marketing mail.
Common questions
Three groups of them. The message has to identify who sent it, carry a valid physical postal address, use an honest subject line, say it's an advertisement, and give a working way to opt out. You have to have had a lawful basis for holding the address, which in the US means nothing in advance and in most of Europe means provable consent. And you have to honour opt-outs on a clock, which is ten business days under CAN-SPAM and CASL. Separately from the law, the large mailbox providers require one-click unsubscribe on marketing mail before they'll deliver it reliably.
Not under federal law. CAN-SPAM is an opt-out regime, so you can send a commercial message to somebody who never asked for it, as long as the message identifies you, carries a postal address, and gives a way out that you honour within ten business days. State privacy laws add data rights on top of that rather than a consent gate in front of it. Consent still matters commercially, because the mailbox providers judge you on complaint rates and people complain about mail they didn't ask for.
It depends entirely on where the people on it are. In the United States, sending to a bought list isn't unlawful in itself, though every CAN-SPAM requirement still applies to each message and you stay responsible for how the list was collected. In the EU, the UK, Canada, and Australia it's effectively unworkable, because consent has to be provable and specific to you. The UK's soft opt-in covers your own recent customers and doesn't reach a bought-in list. The deliverability answer is simpler than the legal one: bought lists produce spam complaints, and complaints are what mailbox providers filter on.
No, if the message really is transactional. The test is the message's primary purpose, not the system or endpoint that sent it. A receipt, a shipping notice, a password reset, or an update about an existing account can skip the unsubscribe link. The moment a promotional block is added and the message is mostly about that, it's a commercial message and it owes the identification, the postal address, and the opt-out like any campaign. Nothing in your stack makes that call for you: it's a judgement about content, made again each time someone edits the template.
Ten business days under CAN-SPAM in the US, and ten business days under CASL in Canada, which also requires the unsubscribe mechanism to cost the recipient nothing. CAN-SPAM adds that the mechanism has to keep working for at least thirty days after the message goes out. The GDPR sets no deadline and instead requires withdrawal to be as easy as consent was. Treat all of those as ceilings. A same-day suppression job that every sending path reads is easier to run than a delay you'd have to explain.
It can. The regulation follows the people whose data you hold rather than your own address, so a company outside the EU that markets to people in the EU is generally in scope. The practical consequence for email is that a single contacts table with addresses from several countries is several legal regimes at once, and nothing in the file tells you which row is which. Recording where a contact was when they signed up, and what they agreed to, is what makes that answerable later.
Yes, for commercial email under CAN-SPAM. The FTC requires a valid physical postal address, and a street address or a registered post office box both qualify. Canada and Australia ask for accurate sender identification and contact information in a similar spirit. This is the cheapest requirement on the whole list: it's one template change, made once, and it applies to every send afterwards. If a compliance review turns up a missing address, that's an afternoon of work rather than a project.
Usually not, which is the opposite of what most guides imply. The ICO's position is that marketing to corporate subscribers, meaning companies and other corporate bodies, is allowed without the specific consent that individuals require, and it recommends keeping a do-not-email list as good practice. Individual subscribers, including sole traders and most partnerships in the UK, are treated as individuals and do need consent or the soft opt-in. So the question isn't whether the address ends in a company domain, it's what kind of legal person is behind it.