CAN-SPAM Compliance
Requirements, penalties, and how to check your website against CAN-SPAM Act.
Test your website for CAN-SPAM compliance for free
Enter your domain to start a free scan and open an account - no integration required.
Overview
The CAN-SPAM Act establishes rules for commercial email messages, setting requirements for senders and giving recipients the right to have emails stopped from being sent to them. It applies to any business or individual that sends commercial emails to consumers in the United States.
Penalties
$51,744 per individual email in violation
What Complyy checks
6 automated tests — 4 passive, 2 active
Passive (instant scan)
Email subject line is not deceptive or misleading
§7704(a)(2) prohibits subject lines that misrepresent the email's content. "RE:" or "FW:" on a first-touch marketing email is treated as deceptive by the FTC.
Unsubscribe mechanism present in marketing emails
15 U.S.C. §7704 requires every commercial email to include a clear unsubscribe mechanism. FTC fines are per-email and have reached $16,000 per message.
Physical postal address present in marketing emails
§7704(a)(5) requires every commercial email to contain a valid physical postal address of the sender. This is the most common technical violation found in FTC sweeps.
Physical address matches company business records
The address must belong to the actual sender. Using an unrelated third-party address (or a marketing vendor's address without identifying the sender) defeats the disclosure purpose.
Active (synthetic identity tests)
Unsubscribe request honored within 10 business days(waits up to 14d for response)
§7704(a)(4) requires unsubscribe requests to be honoured within 10 business days. Continued sends after that window are per-message violations.
Physical postal address is a real deliverable address
The address must be a real, deliverable location (street address, PO Box, or private mailbox registered with USPS). Fake or non-deliverable addresses make the entire message a violation.
Learn More About CAN-SPAM Act
What is CAN-SPAM compliance?
The CAN-SPAM Act, or the Controlling the Assault of Non-Solicited Pornography And Marketing Act, is a U.S. law that establishes standards for the sending of commercial email by businesses. The law is designed to curb the proliferation of spam emails and provides rules to protect consumers from misleading or deceptive content. To achieve compliance, businesses must adhere to specific practices in both the content and management of email communications. Compliance is not just about policy - it requires tangible adjustments in how businesses disseminate email marketing messages.
The purpose of CAN-SPAM is to give recipients the right to stop unwanted emails and creates penalties for businesses that don't follow the rules. Compliance requires that emails are accurately labelled, provide clear opt-out instructions, and are sent only with the prior consent of the recipient where applicable. Understanding and applying these requirements ensures not only legal compliance but also fosters trust with a business’s audience.
Who must comply with CAN-SPAM?
All commercial email sent to U.S. recipients must comply with the CAN-SPAM Act, regardless of the sender's location or business size. The law applies broadly to any 'commercial electronic mail message' that the primary purpose promotes a product or service, which means almost any email sent by a business.
No revenue or size thresholds exempt a business from compliance with the CAN-SPAM Act - even small businesses and non-profit organizations must adhere to the guidelines. The determining factor for regulation applicability is the email’s content, not the business type or revenue size. Therefore, any entity that sends promotional emails should ensure they're following the required standards to avoid penalties.
Key requirements and obligations
- Honest Subject Lines: Email subject lines must accurately reflect the content of the message, preventing misleading or deceptive titles.
- Valid Physical Address: All emails must include a valid physical postal address of the business to indicate that the sender is real and accountable.
- Clear Opt-Out Instructions: Every email must include a clear and conspicuous opt-out mechanism that allows recipients to easily unsubscribe from future emails.
- Prompt Unsubscribe Compliance: Businesses must honor opt-out requests within 10 days, and they cannot charge a fee for processing these requests.
- Identify the Message as an Advertisement: All marketing emails must be labeled as an advertisement.
These requirements ensure that recipients have control over their inboxes and protect them from misleading content, benefiting both the consumer and legitimately operating businesses.
Penalties and fines for non-compliance
Non-compliance with the CAN-SPAM Act can result in significant penalties. Civil penalties can reach up to $46,517 per each individual email that violates the law. Moreover, there is no ceiling on the total fine amount that can be imposed based on violations, meaning businesses can face substantial financial repercussions for mass violations.
In addition, there is a private right of action, allowing internet service providers to sue spammers for damages. This further increases the potential liability for those not adhering to CAN-SPAM guidelines. It is vital for businesses to audit their email practices regularly to ensure they are not at risk of such financial losses and legal challenges.
Any major amendment or closely related law
While the CAN-SPAM Act primarily governs commercial emails, businesses should also be aware of state-level privacy laws that may impose additional requirements. The state of California, for example, has the California Consumer Privacy Act (CCPA), which regulates data collection and transparency practices and can apply to email lists gathered from California residents. Though primarily focused on data privacy, complementary awareness of the CCPA will support CAN-SPAM compliance by managing how data is collected for marketing purposes.
How to check if your website is compliant
Businesses should perform regular checks on their email practices to verify compliance with CAN-SPAM. Key steps include reviewing the content of emails for accurate subject lines, ensuring opt-out instructions are clear, and monitoring the timely processing of unsubscribe requests. Periodically audit the presence of a valid physical address in each email and confirm all your staff members are trained in compliance requirements. Implementing periodic checks can help maintain compliance and demonstrate a commitment to ethical email marketing practices.
Complyy tests these continuously from the outside and captures timestamped evidence.
Frequently asked questions
Who does the CAN-SPAM Act apply to?
The CAN-SPAM Act applies to all businesses that send commercial electronic mail messages to U.S. recipients, regardless of the sender's location or the size of the business.
Does the CAN-SPAM Act apply to non-profits?
Yes, non-profits must comply with the CAN-SPAM Act if they send commercial emails that promote a product or service.
What are the penalties for violating the CAN-SPAM Act?
Violating the CAN-SPAM Act can result in penalties of up to $46,517 for each infringing email, with no cap on the total financial liability.
What is required for a commercial email to be CAN-SPAM compliant?
Commercial emails must include accurate subject lines, a valid physical address, clear opt-out instructions, and a prompt method for processing unsubscribe requests.
Are there any exemptions to the CAN-SPAM Act?
Transactional or relationship emails that do not primarily promote a commercial product or service are not covered by the CAN-SPAM Act.
How quickly must unsubscribe requests be honored under the CAN-SPAM Act?
Businesses must process unsubscribe requests within 10 days of receiving the request under the CAN-SPAM Act.
Does CAN-SPAM apply internationally?
Yes, CAN-SPAM applies to any email sent to U.S. recipients, regardless of where the sender is located.
What information must be included in a CAN-SPAM compliant email?
A compliant email must have a clear advertisement disclosure, an operational opt-out link, a valid physical address, and content that matches the subject line.
Recently Scanned Websites
Live compliance reports from Complyy's public directory.
The Platform
How Complyy enforces CAN-SPAM compliance
Complyy continuously tests your site against CAN-SPAM Act using synthetic identities that behave exactly like regulators — and your customers.
Discover
We visit your website as a real user — finding your privacy policy, cookie banner, opt-out links, and contact details.
Scan & Test
Passive checks run instantly. Active agents sign up, submit deletion requests, and wait for responses — just like regulators do.
Score & Evidence
Every finding is timestamped, SHA-256 hashed, and RFC 3161 certified. Your compliance report is audit-ready from day one.
Why Complyy
The only platform that tests compliance the way regulators do
Real synthetic identities
We register actual accounts — adult and minor — on your platform. No theoretical checks. Real interactions, real evidence.
Active + passive tests
Most tools only check your privacy policy text. Complyy also submits DSAR requests, verifies deletion, and waits for real responses.
Court-admissible artifacts
Every screenshot, response, and timestamp is cryptographically sealed. Built for regulators, DPAs, and legal teams — not just developers.
4
Regulations monitored
19
Compliance tests
∞
Agentic identities
3 min
Avg. first evidence artifact
Is your company CAN-SPAM-compliant?
Get a free compliance scan in minutes. No credit card. No setup. Complyy visits your site, runs every test, and delivers a full evidence report.