Two facts about US commercial email surprise almost everyone, and they point in opposite directions. The first is that there is no consent requirement: the FTC states that the law “doesn’t require initiators of commercial email to get recipients’ consent before sending them commercial email. In other words, there is no opt-in requirement.” The second is that there is no business exemption: “The law makes no exception for business-to-business email.”
Companies arriving from a European framework usually get both backwards. They assume they need consent they do not need, and they assume a business address is outside the rules when it is squarely inside them.
Everything below is the statute, the rule and the FTC’s own compliance guidance. Two regulatory statuses changed recently enough that most published advice is now wrong about them, and those are flagged where they arise.
The consent model is the opposite of the European one
This is the single structural difference, and it is stated in an official rulemaking document rather than inferred.
The FTC’s plain answer. Asked directly about buying a list, the agency wrote that the Act “doesn’t require initiators of commercial email to get recipients’ consent before sending them commercial email. In other words, there is no opt-in requirement. So in general, as long as you follow the ‘initiator’ requirements of the Act, you can send email until the recipient asks to opt out.”
And it has declined to change it. In its 2019 rule review, the FTC recorded that at least 40 commenters criticised “the CAN-SPAM Act’s opt-out approach” and asked for a consent requirement. Its answer: “Modifying the Rule to require prior consent from recipients of commercial email messages, however, would be beyond the text and scope of the Act.” The rule was retained unchanged.
But consent still buys you exactly one thing. If a recipient gave prior affirmative consent, you are exempt from identifying the message as an advertisement, and the FTC is blunt about the limit: “that’s it. All other CAN-SPAM requirements still apply.”
Which reframes what consent is for. In the US it is not a legal precondition. It is a deliverability and reputation strategy, and it removes one labelling obligation. Those are good reasons to seek it. Legal necessity is not one of them.
One caution the same FTC post attaches. On buying lists: “But buying lists like that can be risky.” The risk is practical rather than statutory, and it is real.
And note what this article is not. If you are emailing recipients in the EU or the UK, a different regime applies and the analysis here does not transfer. This is US law, for a US audience.
No business exemption, and the FTC says so directly
This is where companies get caught, because the assumption feels reasonable and is wrong.
The statement, in full. “Despite its name, the CAN-SPAM Act doesn’t apply just to bulk email. It covers all commercial messages … The law makes no exception for business-to-business email. That means all email, for example, a message to former customers announcing a new product line, must comply with the law.”
Which means one email counts. There is no volume threshold. A single message to a single prospect at a work address is a commercial electronic mail message and carries every obligation below.
And the definition of who is on the hook is broad. To “initiate” includes “to procure the origination or transmission of such message”, and to procure means “intentionally to pay or provide other consideration to, or induce, another person to initiate such a message on one’s behalf.”
So the agency arrangement does not move the risk. The FTC states it directly: “even if you hire another company to handle your email marketing, you can’t contract away your legal responsibility to comply with the law. Both the company whose product is promoted in the message and the company that actually sends the message may be held legally responsible.”
The exception is narrow and it is about purpose, not audience. A transactional or relationship message is exempt, but the categories are closed: completing a transaction the recipient already agreed to, warranty or safety information, a change of terms or a periodic account statement in an existing relationship, employment information, or delivery of goods and services already due.
And mixed messages fall to the commercial side easily. The primary purpose test makes a message commercial if a recipient reading the subject line “would likely conclude that the message contains the commercial advertisement or promotion”, or if the transactional content does not appear “in whole or in substantial part, at the beginning of the body of the message.” The FTC adds that “the law views these categories narrowly.”
None of these are onerous. All of them are checkable by anyone receiving your email, which is why they are what enforcement looks at first.
Header information that is not materially false or misleading. The from, to, and routing information must identify the actual sender.
A subject line that does not mislead. It is unlawful to send with knowledge, actual or “fairly implied on the basis of objective circumstances”, that the subject would “be likely to mislead a recipient, acting reasonably under the circumstances, about a material fact regarding the contents or subject matter.”
Clear and conspicuous identification that the message is an advertisement. Waived only where the recipient gave prior affirmative consent.
Clear and conspicuous notice of the opportunity to decline further messages. Not buried, not conditional.
A valid physical postal address. Defined as “the sender’s current street address, a Post Office box the sender has accurately registered with the United States Postal Service, or a private mailbox the sender has accurately registered with a commercial mail receiving agency.”
That last one is the most commonly missing element in cold outreach, and it is the easiest to check from the outside. An email with no postal address is a documented violation on its face.
The arithmetic is what makes this worth an hour of attention rather than a note in a backlog.
The figure. Up to $53,088 per individual email in violation, under the civil penalty adjustment effective 17 January 2025.
One caveat on how to state it. These amounts are adjusted for inflation, but no further adjustment was published during 2026, so this remains the current figure rather than an annually refreshed one. Cite it with its date.
The mechanism. The statute directs that violations be enforced “as if the violation of this chapter were an unfair or deceptive act or practice” under the FTC Act, which is what brings the per-violation civil penalty into play.
And more than one party can be liable for the same message. “More than one person may be held responsible for violations. For example, both the company whose product is promoted in the message and the company that originated the message may be legally responsible.”
Which changes how you should read a vendor’s compliance assurance. A sending platform’s own compliance does not discharge yours. If your product is promoted in the message, you are in scope regardless of who pressed send.
There is also a rule about what you cannot do with an opted-out address. Selling, leasing, exchanging or transferring it is separately unlawful. Suppression lists are not assets to be traded.
Outbound calling and texting is where a genuine business exemption exists, and where the most-cited recent rule turned out not to apply at all.
The exemption is real, and it is in the Telemarketing Sales Rule. Calls “between a telemarketer and any business to induce the purchase of goods or services or a charitable contribution by the business” are exempt from most of the rule, with narrow carve-outs.
The FTC states it plainly. “The prohibition on calls to numbers on the Registry does not apply to business-to-business calls.”
But the exemption has a boundary that removes most of its comfort. “Telemarketing calls that solicit consumers at their work, that is, calls to business lines that solicit individual employees to buy products or services for their own use or make personal charitable contributions, also are not business-to-business solicitations and are not exempt.”
And mobile numbers are treated as residential by default. The FCC decided in 2003 that it “will presume wireless subscribers who ask to be put on the national do-not-call list to be ‘residential subscribers.’” A decision maker’s cell number on the registry does not become fair game because you are selling to their company.
One status correction worth making explicitly. The FCC’s “one-to-one consent” rule, widely written about as a coming constraint on lead generation, never took effect. The Eleventh Circuit vacated it on 24 January 2025, holding that the Commission “exceeded its statutory authority under the TCPA”; the mandate issued on 30 April 2025 and the FCC formally reinstated the prior definition of prior express written consent in its rules on 29 August 2025.
What did take effect is the revocation rule. Since 11 April 2025, a called party may revoke consent “by using any reasonable method”, the words “stop,” “quit,” “end,” “revoke,” “opt out,” “cancel,” or “unsubscribe” in a text reply count “per se”, requests must be honored “within a reasonable time not to exceed ten business days from receipt”, and a sender “may not designate an exclusive means” of revoking.
With one part of it currently waived. The obligation to treat a revocation received on one type of message as covering unrelated future messages from the same sender is waived until 31 January 2027. The ten business days, the keyword list and the no-exclusive-channel rule are all in force. Do not read the waiver as suspending the rule.
Federal law displaces most state email statutes, but not all of them, and the exception is the one that matters.
The preemption clause. The Act “supersedes any statute, regulation, or rule of a State or political subdivision of a State that expressly regulates the use of electronic mail to send commercial messages”, with one carve-out: “except to the extent that any such statute, regulation, or rule prohibits falsity or deception in any portion of a commercial electronic mail message or information attached thereto.”
So labelling mandates are gone. Before 2003 some states required an “ADV” prefix in the subject line. The FTC notes that “Congress pre-empted those laws with CAN-SPAM.”
But deception claims survive. Anything a state law says about falsity or deception in a commercial message is untouched, and so are state laws “that are not specific to electronic mail, including State trespass, contract, or tort law”, and state law on “acts of fraud or computer crime.”
And the FTC’s own authority is unaffected. Preemption does not touch the Commission’s power to act “for materially false or deceptive representations or unfair practices in commercial electronic mail messages.”
One honest limitation. Exactly how far the falsity and deception carve-out reaches is a question of federal case law, not of the statute’s text. This article does not tell you whether a specific state statute survives preemption, because that answer requires a decision rather than a reading.
What to do with this
Audit one message before changing anything else. Take a live sequence and check the five elements: honest headers, honest subject, advertisement identification unless you hold consent, an unmistakable way to decline, and a valid physical postal address in the footer. The last one is missing from most cold sequences and is visible to anyone who receives it.
Then check the two clocks behind the send. Your unsubscribe endpoint has to keep working for at least thirty days after each message goes out, and every request has to be off the list within ten business days. If your suppression sync runs weekly, that is fine. If it runs when someone remembers, it is not.
On the phone side, treat the business exemption as narrower than it sounds: it covers selling to the business, not selling to the person, and it does not clear a mobile number that sits on the registry.
And when a vendor tells you their platform keeps you compliant, read it as a claim about their obligations rather than yours. Both parties can be liable for the same message, and the one whose product is promoted is always one of them. For teams that decide the exposure is not worth the volume, the alternative is to buy the attention instead, and our page on B2B paid acquisition sets out how that budget is judged on cost per lead rather than on how many messages went out.
Does US law require opt-in consent before sending a cold email?
No. The FTC states plainly that the CAN-SPAM Act does not require initiators of commercial email to get recipients' consent before sending, and that there is no opt-in requirement.
Is business-to-business email exempt?
No, and this is the most common misconception. The FTC states that the law makes no exception for business-to-business email, and that all email must comply.
How fast must I process an unsubscribe?
No more than 10 business days after receiving the request, and the opt-out mechanism itself must stay functional for at least 30 days after the message was sent.
Can I hire an agency and transfer the legal risk?
No. The FTC states you can't contract away your legal responsibility to comply, and that both the company whose product is promoted and the company that sends the message may be held legally responsible.