Skip to main content
Regulations/CAN-SPAM

CAN-SPAM Compliance

Requirements, penalties, and how to check your website against CAN-SPAM Act.

US

Test your website for CAN-SPAM compliance for free

Enter your domain to start a free scan and open an account - no integration required.

Overview

The CAN-SPAM Act establishes rules for commercial email messages, setting requirements for senders and giving recipients the right to have emails stopped from being sent to them. It applies to any business or individual that sends commercial emails to consumers in the United States.

Penalties

$51,744 per individual email in violation

What Complyy checks

6 automated tests 4 passive, 2 active

Passive (instant scan)

high

Email subject line is not deceptive or misleading

§7704(a)(2) prohibits subject lines that misrepresent the email's content. "RE:" or "FW:" on a first-touch marketing email is treated as deceptive by the FTC.

high

Unsubscribe mechanism present in marketing emails

15 U.S.C. §7704 requires every commercial email to include a clear unsubscribe mechanism. FTC fines are per-email and have reached $16,000 per message.

medium

Physical postal address present in marketing emails

§7704(a)(5) requires every commercial email to contain a valid physical postal address of the sender. This is the most common technical violation found in FTC sweeps.

medium

Physical address matches company business records

The address must belong to the actual sender. Using an unrelated third-party address (or a marketing vendor's address without identifying the sender) defeats the disclosure purpose.

Active (synthetic identity tests)

critical

Unsubscribe request honored within 10 business days(waits up to 14d for response)

§7704(a)(4) requires unsubscribe requests to be honoured within 10 business days. Continued sends after that window are per-message violations.

high

Physical postal address is a real deliverable address

The address must be a real, deliverable location (street address, PO Box, or private mailbox registered with USPS). Fake or non-deliverable addresses make the entire message a violation.

Learn More About CAN-SPAM Act

What is CAN-SPAM compliance?

The CAN-SPAM Act, or the Controlling the Assault of Non-Solicited Pornography And Marketing Act, is a U.S. law that establishes standards for the sending of commercial email by businesses. The law is designed to curb the proliferation of spam emails and provides rules to protect consumers from misleading or deceptive content. To achieve compliance, businesses must adhere to specific practices in both the content and management of email communications. Compliance is not just about policy - it requires tangible adjustments in how businesses disseminate email marketing messages.

The purpose of CAN-SPAM is to give recipients the right to stop unwanted emails and creates penalties for businesses that don't follow the rules. Compliance requires that emails are accurately labelled, provide clear opt-out instructions, and are sent only with the prior consent of the recipient where applicable. Understanding and applying these requirements ensures not only legal compliance but also fosters trust with a business’s audience.

Who must comply with CAN-SPAM?

All commercial email sent to U.S. recipients must comply with the CAN-SPAM Act, regardless of the sender's location or business size. The law applies broadly to any 'commercial electronic mail message' that the primary purpose promotes a product or service, which means almost any email sent by a business.

No revenue or size thresholds exempt a business from compliance with the CAN-SPAM Act - even small businesses and non-profit organizations must adhere to the guidelines. The determining factor for regulation applicability is the email’s content, not the business type or revenue size. Therefore, any entity that sends promotional emails should ensure they're following the required standards to avoid penalties.

Key requirements and obligations

  • Honest Subject Lines: Email subject lines must accurately reflect the content of the message, preventing misleading or deceptive titles.
  • Valid Physical Address: All emails must include a valid physical postal address of the business to indicate that the sender is real and accountable.
  • Clear Opt-Out Instructions: Every email must include a clear and conspicuous opt-out mechanism that allows recipients to easily unsubscribe from future emails.
  • Prompt Unsubscribe Compliance: Businesses must honor opt-out requests within 10 days, and they cannot charge a fee for processing these requests.
  • Identify the Message as an Advertisement: All marketing emails must be labeled as an advertisement.

These requirements ensure that recipients have control over their inboxes and protect them from misleading content, benefiting both the consumer and legitimately operating businesses.

Penalties and fines for non-compliance

Non-compliance with the CAN-SPAM Act can result in significant penalties. Civil penalties can reach up to $46,517 per each individual email that violates the law. Moreover, there is no ceiling on the total fine amount that can be imposed based on violations, meaning businesses can face substantial financial repercussions for mass violations.

In addition, there is a private right of action, allowing internet service providers to sue spammers for damages. This further increases the potential liability for those not adhering to CAN-SPAM guidelines. It is vital for businesses to audit their email practices regularly to ensure they are not at risk of such financial losses and legal challenges.

Any major amendment or closely related law

While the CAN-SPAM Act primarily governs commercial emails, businesses should also be aware of state-level privacy laws that may impose additional requirements. The state of California, for example, has the California Consumer Privacy Act (CCPA), which regulates data collection and transparency practices and can apply to email lists gathered from California residents. Though primarily focused on data privacy, complementary awareness of the CCPA will support CAN-SPAM compliance by managing how data is collected for marketing purposes.

How to check if your website is compliant

Businesses should perform regular checks on their email practices to verify compliance with CAN-SPAM. Key steps include reviewing the content of emails for accurate subject lines, ensuring opt-out instructions are clear, and monitoring the timely processing of unsubscribe requests. Periodically audit the presence of a valid physical address in each email and confirm all your staff members are trained in compliance requirements. Implementing periodic checks can help maintain compliance and demonstrate a commitment to ethical email marketing practices.

Complyy tests these continuously from the outside and captures timestamped evidence.

Frequently asked questions

Who does the CAN-SPAM Act apply to?

The CAN-SPAM Act applies to all businesses that send commercial electronic mail messages to U.S. recipients, regardless of the sender's location or the size of the business.

Does the CAN-SPAM Act apply to non-profits?

Yes, non-profits must comply with the CAN-SPAM Act if they send commercial emails that promote a product or service.

What are the penalties for violating the CAN-SPAM Act?

Violating the CAN-SPAM Act can result in penalties of up to $46,517 for each infringing email, with no cap on the total financial liability.

What is required for a commercial email to be CAN-SPAM compliant?

Commercial emails must include accurate subject lines, a valid physical address, clear opt-out instructions, and a prompt method for processing unsubscribe requests.

Are there any exemptions to the CAN-SPAM Act?

Transactional or relationship emails that do not primarily promote a commercial product or service are not covered by the CAN-SPAM Act.

How quickly must unsubscribe requests be honored under the CAN-SPAM Act?

Businesses must process unsubscribe requests within 10 days of receiving the request under the CAN-SPAM Act.

Does CAN-SPAM apply internationally?

Yes, CAN-SPAM applies to any email sent to U.S. recipients, regardless of where the sender is located.

What information must be included in a CAN-SPAM compliant email?

A compliant email must have a clear advertisement disclosure, an operational opt-out link, a valid physical address, and content that matches the subject line.

Recently Scanned Websites

Live compliance reports from Complyy's public directory.

Browse the full directory →

The Platform

How Complyy enforces CAN-SPAM compliance

Complyy continuously tests your site against CAN-SPAM Act using synthetic identities that behave exactly like regulators — and your customers.

01

Discover

We visit your website as a real user — finding your privacy policy, cookie banner, opt-out links, and contact details.

02

Scan & Test

Passive checks run instantly. Active agents sign up, submit deletion requests, and wait for responses — just like regulators do.

03

Score & Evidence

Every finding is timestamped, SHA-256 hashed, and RFC 3161 certified. Your compliance report is audit-ready from day one.

Why Complyy

The only platform that tests compliance the way regulators do

Real synthetic identities

We register actual accounts — adult and minor — on your platform. No theoretical checks. Real interactions, real evidence.

Active + passive tests

Most tools only check your privacy policy text. Complyy also submits DSAR requests, verifies deletion, and waits for real responses.

Court-admissible artifacts

Every screenshot, response, and timestamp is cryptographically sealed. Built for regulators, DPAs, and legal teams — not just developers.

4

Regulations monitored

19

Compliance tests

Agentic identities

3 min

Avg. first evidence artifact

Is your company CAN-SPAM-compliant?

Get a free compliance scan in minutes. No credit card. No setup. Complyy visits your site, runs every test, and delivers a full evidence report.