← blogSeptember 7, 202610 min read

Is Cold Email Illegal? Laws & Compliance for 2026

TL;DR. Cold email is legal in the United States. CAN-SPAM never requires prior consent, but it does require accurate sender information, an honest subject line, a valid physical address, and an opt-out that works for at least 30 days and is honored within 10 business days. What actually ends most outreach programs is not a federal action but complaint rates and collapsing deliverability, plus stricter state laws like California's and GDPR or PECR abroad.

Cold email is legal in the United States. You have to follow the CAN-SPAM Act, and you have to be honest about who you are and what you want. That is the whole bargain. Nothing in the federal statute says you need permission before you email a stranger, which still surprises people, but the rules about how the message itself behaves are not negotiable.

Most of the confusion comes from the word "spam" doing two jobs at once. In everyday use it means email you did not ask for. In federal law it means something narrower: email that hides its sender, lies in the subject line, or ignores an opt-out request. Unsolicited is not the problem. Dishonest is.

Cold Email vs. Spam: What the Law Actually Says

Volume and consent are not what separates the two. Deception is. Read the FTC's compliance guide and spam turns out to be unsolicited commercial email with false or misleading header information, a deceptive subject line, or no working way to opt out.

Which means a compliant cold email is a fairly plain object. It says who sent it. The subject line describes the contents. There is a physical mailing address at the bottom and an obvious way to make the next one stop coming. You can be pushy inside those constraints. I would rather you were not, but the law permits it.

CAN-SPAM Act Requirements for Business Outreach

Seven core requirements apply to every commercial electronic message. Your "From," "To," and routing information has to accurately identify the sender. Deceptive subject lines are out. You have to make clear that the message is an advertisement.

You also need a valid physical postal address and a plain explanation of how to opt out. That mechanism has to keep working for at least 30 days after you send, and you have to honor requests within 10 business days. No fee. No asking for more than an email address. No burying the unsubscribe behind a login and four screens of confirmation.

The 10-business-day rule is the one that catches people. If someone unsubscribes and your next campaign goes out to them inside that window, you have violated CAN-SPAM. The rest of the message can be immaculate. It does not matter.

Penalties run up to $53,088 per email, and more than one party can be on the hook: the FTC treats both the company whose product is promoted and the company that actually sent the message as responsible. Purchased lists and ignored opt-outs stack that exposure fast. Honestly, though, a federal action is not what usually ends a startup's outreach program. Complaint rates rise, you get blacklisted, and delivery collapses weeks before anyone in Washington has heard your company name. The fine is the risk that sounds scary in a board meeting. The reputation damage is the one that shows up in your reply rate.

The New Frontier: AI-Generated Content and Spam Filters

In 2024, Google's spam policies started naming AI-generated content at scale directly, and mailbox providers run comparable detection. Drafting with a model is not illegal and never has been. Sending two thousand near-identical model-written messages is still going to trip filters, and there is nothing contradictory about a message that satisfies every deception rule in CAN-SPAM and lands in the spam folder anyway.

No state has passed a law aimed specifically at AI-written cold email yet. My guess, and it is a guess, is that transparency is where this eventually gets litigated: if a recipient asks whether they are talking to a person and nothing in your email indicates otherwise, consumer protection claims are the obvious hook. Use the model for research and a first draft. Then have a human read the thing before it leaves.

State-Level Consumer Protection Laws

Plenty of states run their own consumer protection statutes on top of the federal one. California's Anti-Spam Law, Business and Professions Code Section 17529, is the aggressive one. Private individuals can sue for up to $1,000 per unsolicited email, and up to $1 million for deliberate violations. That private right of action is the part that should get your attention, because CAN-SPAM itself can only be enforced by the FTC and state attorneys general.

Washington lets its attorney general seek civil penalties of up to $2,000 per violation. Utah wants a toll-free number or a valid return address in commercial email. One campaign, one list, and you may be answering to three different standards at once depending on where those contacts happen to live.

The Hidden Liability of Third-Party Lead Lists

Bought lists carry an exposure that startups tend to find out about after the fact. You almost never know how the contacts were collected, whether anyone agreed to hear from third parties, or when the data was last touched. Mail enough stale addresses and the complaints damage your domain reputation, which is bad on its own and can also attract regulatory attention. Then there is the part people miss: if the provider gathered those addresses under a privacy policy promising no third-party sharing, your email breaks a promise you never read and never made. FTC guidance on data privacy and security is unambiguous that businesses own how they obtain and use consumer data, and "the vendor told me it was fine" has never been much of a defense. Build the list yourself through inbound and verified opt-ins where you can. Where you cannot, at minimum know the source.

B2C vs. B2B: How the Rules Differ

CAN-SPAM covers both equally. Enforcement and filtering do not. A cold email to a corporate address gets more latitude in practice, since prospecting is an expected cost of having a work inbox. Consumer email gets scrutinized harder and complained about more, so if you are writing to consumers you need a real reason to be in that inbox and an opt-out that works without exception. Worth noting: California's statute does not care about the B2B and B2C distinction at all, so a single business email can produce a private lawsuit. Assume the strictest rule you could be measured against and build to that.

Cold Email Best Practices for Startups

Discipline beats volume here, and it is not close. The campaigns that work tend to look the same: you research the person, you write an opening line that could not have been sent to anyone else, you say something specific about why you are worth five minutes, and you make the ask small. On the infrastructure side, authenticate with DKIM and DMARC, start with low daily numbers, and climb slowly. SEMAOS ships DKIM and DMARC configured out of the box, and paid plans ramp a custom sending domain in stages rather than opening it up at once. The daily cap lifts as the domain both ages and puts real volume behind it, so a domain that has sat mostly idle does not get waved through on the calendar alone.

Consent is not a yes-or-no field. Explicit consent means someone actively opted in through a form or a checkbox. Implied consent is fuzzier: an existing business relationship, a public professional profile that makes your message relevant, a job title that makes the outreach unremarkable. CAN-SPAM does not require either one. The distinction still matters, because deliverability and several state laws are stricter than the federal floor.

For business outreach, implied consent usually holds up. A consumer who bought one product from you has implied consent for follow-up about that product, and not for your new product line or a partner's offer. Write down why you think consent exists for each contact. If you cannot say it out loud in a sentence, that contact is a liability sitting in your database.

The 30-Day Rule and Why It Matters

Your opt-out has to keep working for at least 30 days after the send. During that window you cannot kill the landing page, strip the unsubscribe link, or move infrastructure in a way that quietly breaks the flow. This is the rule I see broken most often, and almost never on purpose. It happens during a provider migration or a website redesign, when the marketing site gets rebuilt and nobody checks whether the old unsubscribe URL still resolves. A recipient clicks, gets a 404, and you are out of compliance.

Suppression lists live inside your current tool. They do not reliably travel when you export contacts into a new system — often onto a new sending domain too, which is exactly the moment you are most exposed. Keep a permanent do-not-contact file of your own, with the address and the opt-out timestamp, and treat it as something you carry across every migration. SEMAOS handles CAN-SPAM unsubscribe processing and runs a suppression check on every send, and an unsubscribe there blocks future sends across all campaigns rather than just the one that triggered it.

Building a Compliant Outreach Operation

Compliance is a property of your systems, not of any single email. Start by being able to answer where contacts come from, who vets them, and what consent documentation exists. Scraping public sites? Log the date and the URL. Buying data? Keep the contract and whatever the provider represented about consent. None of this is fun, and all of it is what you reach for when a recipient escalates or a regulator writes to you.

Send marketing mail from a dedicated subdomain so a bad campaign cannot take your primary domain down with it. Look at your complaint rate every week. Anything above 0.1% deserves a second look, and above 0.3% mailbox providers will generally act on their own. When the number moves, stop the campaign. Then go find out whether the problem is a stale list or a message nobody wanted, because those have different fixes and guessing wrong wastes a month.

How to Manage Opt-Outs in Cold Email Campaigns

This is the part of CAN-SPAM you touch every day. Every campaign needs an unsubscribe that works, and every request has to be honored within 10 business days. Do it with tooling rather than a spreadsheet, because manual suppression fails on exactly the day you are busiest.

That is the reasoning behind how SEMAOS handles it: unsubscribe processing and suppression checks run on every send, so nothing depends on someone remembering. An unsubscribed contact is blocked across all campaigns, not just the one they clicked out of. Keep the audit trail too. You will probably never need it, and if you do need it, reconstructing it after the fact is not possible.

Do not make "reply to this email to unsubscribe" your only opt-out path. CAN-SPAM asks for a clear and conspicuous opt-out that does not require the recipient to write anything. Use a one-click link.

International Rules: GDPR, PECR, and Beyond

The moment your campaign crosses a border you are working under a different regime. The EU General Data Protection Regulation governs how you collect, store, and use the personal data of EU residents, and it does not care where your company is incorporated. You need a lawful basis for processing. For cold email that basis is normally legitimate interest, which comes attached to a balancing test you are expected to have actually carried out and recorded, not just asserted.

The UK and EU also enforce the Privacy and Electronic Communications Regulations, and PECR is meaningfully stricter than CAN-SPAM. Marketing email to an individual generally needs prior consent, though email to a named corporate contact can fall under a softer standard. So your checklist has to cover two separate bodies of law, data protection and electronic communications, per country. It is more work than the US side. There is no way around that.

Your Compliance Checklist Before You Send

Run this before you launch anything.

RequirementWhat to VerifyWhy It Matters
Sender identity"From" line accurately identifies you or your businessDeceptive headers violate CAN-SPAM
Subject lineHonest and not misleading about contentDeceptive subjects carry separate penalties
Physical addressValid postal address in every messageRequired by CAN-SPAM for all commercial email
Opt-out mechanismClear, working unsubscribe link in every sendMust honor requests within 10 business days
Suppression listUnsubscribed contacts blocked from all campaignsPrevents accidental re-sends
Domain authenticationDKIM and DMARC configured correctlyProtects deliverability and sender reputation

The FTC's CAN-SPAM guidance is the document to keep open in a tab while you set this up. Honest about the sender, clear about the commercial purpose, easy to leave: get those three right and cold email is a perfectly legal channel. Everything else is a matter of not being careless with your list.


So, is cold email illegal? No, not if you follow the rules. What trips teams up is operational, not legal, which is a more boring answer than the question usually expects. SEMAOS includes unlimited contacts on every plan, nightly 0-100 engagement scoring, and CAN-SPAM unsubscribe handling on every send, and it is built for teams of 1 to 50. The free plan runs from your own inbox, forever and without a card, if you want to see how it handles your list.

FAQ

Can you get sued for sending a cold email?

Yes, you can face legal action for cold email, but the risk is manageable. Under the CAN-SPAM Act, the FTC can impose penalties of up to $53,088 per violation for non-compliant email. You also face civil liability if your email violates terms of service or if you use purchased lists that contain scraped data. Following the legal requirements for business-to-business email significantly reduces your exposure.

What is the difference between cold email and spam?

The legal difference comes down to compliance, not consent. Spam is unsolicited email that hides the sender's identity, uses deceptive subject lines, lacks a physical mailing address, and offers no working opt-out mechanism. Cold email is legal when it includes accurate sender information, a clear unsubscribe link, and a valid postal address. If your email meets CAN-SPAM Act requirements, it is not spam under federal law.

Do I need consent to email a business prospect?

Under the CAN-SPAM Act, you do not need prior consent for B2B cold email. The law applies the same rules to business and consumer recipients. However, if you email prospects in the EU or UK, GDPR and PECR require a legitimate interest assessment or explicit consent. For B2C email, you must honor opt-out requests promptly and include a clear unsubscribe link in every message.

Is cold email still effective in 2026?

Yes, cold email remains effective when done right. Response rates depend on relevance and deliverability, not volume. Focus on sending fewer, more personalized messages to well-researched prospects. Maintain your domain reputation by keeping complaint rates low and honoring opt-outs immediately. Features like automatic unsubscribe handling and engagement scoring can help manage compliance and scale without increasing legal risk.