The CAN-SPAM Act in Plain English: What Every Commercial Email Must Do

By MercPrivacy · Published 2026-08-17 · Updated 2026-09-07

CAN-SPAM requires accurate headers, truthful subject lines, identification as an ad, a postal address and a working opt-out honored within the prescribed period. It is enforced by agencies and providers, not by recipients.

The CAN-SPAM Act requires every commercial email to carry accurate header and routing information, a subject line that does not mislead, a clear identification that the message is an advertisement, a valid physical postal address for the sender, and a working opt-out mechanism that is honored within the period the rule prescribes. It is enforced by the Federal Trade Commission, other federal agencies, state attorneys general and internet access providers. It gives an individual recipient no private right of action, so the person receiving the email cannot sue under it.

This article explains what each requirement means in practice, which messages the statute covers and which it leaves alone, the aggravated conduct that turns a compliance failure into something worse, who actually enforces the law and why, and what a recipient can do given that the statute was written to regulate senders rather than to arm recipients.

“People read the acronym and assume it bans spam. It regulates spam. The difference is the whole article.”


What CAN-SPAM Covers and What It Leaves Alone

The statute applies to commercial electronic mail messages, meaning email whose primary purpose is to advertise or promote a product or service. It does not distinguish between consumer and business recipients; a marketing email to your work address is covered exactly as one to your personal account. It applies to the company that sends the message and to the company whose product is advertised in it, and both can be held responsible for a violation.

Transactional and relationship messages sit mostly outside it: an order confirmation, a shipping notice, a warranty notice, an account statement, a message about an employment relationship or a subscription you already have. Those messages need not carry an opt-out or an ad label, but they may not contain false or misleading header information. A message that mixes a receipt with a promotion is judged by its primary purpose, and senders who bury an advertisement inside a transactional subject line are relying on a reading the FTC does not share.

The statute is an opt-out regime. It does not require a sender to obtain your permission before the first email; it requires the sender to identify itself honestly and to stop when you ask. That single design choice explains most of what recipients find frustrating about it.

The Five Things Every Commercial Email Must Do

Accurate header information

The From, To and Reply-To fields and the routing information, including the originating domain and email address, must be accurate and must identify the person or business that initiated the message. A display name that impersonates a bank, a sending domain that was registered under a false identity, or a Reply-To that routes to someone other than the sender all violate this requirement, and it is the one requirement that applies even to transactional mail.

Truthful subject lines

The subject line must reflect the content of the message. “Your invoice is attached” on a sales pitch, “Re:” on a message that is not a reply, and “Account suspended” on an advertisement are deceptive subject lines, and they are the tells that separate a careless marketer from a fraudulent one.

Identification as an advertisement

The message must disclose clearly and conspicuously that it is an advertisement or solicitation. The statute leaves the wording flexible, which is why compliant senders use short phrases in the footer, but the disclosure must be there and must be readable.

A physical postal address

The message must include a valid physical postal address for the sender: a street address, a post office box, or a private mailbox registered with a commercial mail-receiving agency under postal rules. An email with no address, or with an address that resolves to nothing, fails this requirement outright.

A working opt-out, honored promptly

Every commercial email must give the recipient a clear and conspicuous way to opt out of future messages from that sender, and the mechanism must work for the period the rule requires after the message is sent. Opting out may not require a fee, a login, or any information beyond an email address and a preference. The sender must honor the request within the period the rule prescribes, and once you have opted out it may not sell or transfer your address except to a company it hires to help it comply. Whether it is safe to use an opt-out link at all, given how scammers abuse them, is the subject of when unsubscribe is safe.

Aggravated Conduct: Harvesting, Dictionary Attacks and Relays

The statute reserves its heaviest treatment for the methods behind bulk spam. Address harvesting means collecting addresses from websites or services that posted a notice that they do not permit their addresses to be gathered for email. A dictionary attack generates addresses by combining names, words and numbers at a domain and mailing all of them, which is why a newly created address receives spam before it has ever been used. Automated creation of multiple email accounts to send from, and relaying messages through computers the sender is not authorized to use, complete the list.

These practices increase the penalties available to enforcers, and the statute's criminal provisions reach the worst of them, including falsified headers at scale and unauthorized relaying. For a recipient they are useful diagnostically: an email to an address you never published, sent from a domain registered last week through a proxy, with headers that fail authentication, was almost certainly generated or harvested, and no unsubscribe link in it should be trusted.

A compliant marketer and a harvesting operation both send email you did not ask for. The difference shows in the footer and the headers: a real address, a real domain, an opt-out that works. When those are missing, treat the message as a scam signal rather than a marketing problem.

Who Enforces CAN-SPAM, and Why Recipients Cannot

The FTC is the primary enforcer and can seek civil penalties for each non-compliant message, with larger exposure for aggravated conduct. Other federal agencies enforce the statute against the businesses they regulate, so a bank's email is policed by its banking regulator and a carrier's by the FCC. State attorneys general may sue on behalf of their residents. Internet access providers, the companies whose networks carry the mail, may sue senders for the harm spam causes their systems, and some of the largest judgments under the statute have come from those cases.

The person who received the email is not on that list. Congress deliberately omitted a private right of action for individual recipients, which is why a recipient's remedy is a report to an enforcer rather than a claim. The reasoning, and the ways recipients sometimes misunderstand it, are laid out in why you cannot sue over spam email. The statute also preempts most state laws that regulate commercial email, leaving in place only state rules aimed at falsity or deception, which is where the remaining recipient remedies live.

What a Recipient Can Actually Do

Report it, because the reports drive enforcement. Forward spam to the FTC's spam reporting address and to your email provider through its report-spam control, which feeds the filtering that protects everyone on the service. A campaign that generates enough reports draws an enforcement action; individual complaints are the raw material.

Use the opt-out when the sender is a real business with a real address, because a compliant sender will honor it and the statute obliges it to. Do not use it when the message fails the tests above; a click on a harvester's link confirms a live address. For the senders that do not stop, the question becomes which state law applies: a few states preserve private actions for deceptive or unsolicited commercial email under statutes that survived preemption, with figures that vary and change, and state spam laws that still pay covers which ones remain useful.

Then go to the source. Most sustained spam traces to a data broker or a breached list that keeps re-selling your address, and removal at that level does more than any filter. How they got your email explains the supply side. If your inbox has become a full-time job and you cannot tell the compliant marketers from the harvesters, the free 30-minute assessment is a sensible place to sort it.

Where MercPrivacy Fits

MercPrivacy is a data-privacy and unsolicited-contact defense firm in Houston, Texas. On a spam-email problem we build the evidence file with full headers, classify each campaign as a compliant marketer, a non-compliant sender or a scam operation, identify the U.S. company behind the messages where one exists, and file the reports that enforcers act on. Because CAN-SPAM gives a recipient no claim of its own, we pursue the statutory remedies that do exist, under state law where it applies, and we work the supply side: locating the brokers and lists that feed your address to senders and submitting removal and suppression requests, then re-checking, because listings return.

We are not a law firm and do not give legal advice. When a matter warrants a demand or a lawsuit, a licensed attorney is engaged, and any settlement paperwork goes through that attorney. Our own investigative, documentation and administrative work is billed as a straightforward recurring service fee set out in writing before any work starts. More on the spam email page.

Frequently Asked Questions

What are the CAN-SPAM Act requirements for a commercial email?

Accurate header and routing information that identifies the sender; a subject line that does not mislead; a clear disclosure that the message is an advertisement; a valid physical postal address; and a clear, working opt-out mechanism that is honored within the period the rule prescribes. Once a recipient opts out, the sender may not sell or transfer the address except to a company helping it comply.

Can I sue a company for spam email under CAN-SPAM?

No. The statute gives individual recipients no private right of action. Enforcement belongs to the FTC, other federal agencies for the businesses they regulate, state attorneys general, and internet access providers. A recipient's remedies are reporting to those enforcers and, in some states, statutes addressing deceptive or unsolicited commercial email that survived federal preemption.

Does CAN-SPAM require opt-in consent before sending marketing email?

No. It is an opt-out law: a sender may email you without prior permission if the message is honest about who sent it and what it is, includes a postal address, and provides a working opt-out that the sender honors promptly. Requirements for prior consent exist in some other countries and in some state rules aimed at deception, not in the federal statute.

How long does a sender have to honor an unsubscribe request?

The statute sets a short period measured in business days, and the opt-out mechanism must keep working for a set period after the message was sent; verify the current numbers in the rule. Opting out may not require a fee, a login, or any information beyond your email address, and a sender that keeps mailing after the window has closed is in violation regardless of its intent.

Does CAN-SPAM apply to business-to-business email?

Yes. The statute covers commercial email regardless of whether the recipient is a consumer or a business, so a cold sales email to your work address must meet the same requirements: accurate headers, a truthful subject line, identification as an ad, a postal address and a working opt-out. Sellers who claim business email is exempt are wrong about the federal law.

CAN-SPAM tells senders what to do; it does not tell you what to do when they ignore it. MercPrivacy sorts the compliant marketers from the harvesters, builds the header-level evidence file, files the reports enforcers act on, pursues the state remedies that do exist, and works the brokers and lists that keep feeding your address to senders. The free assessment maps the exposure and says what is worth pursuing. Stephanie answers instantly and free, or book your free 30-minute privacy assessment with a specialist at (830) 587-5011.

Start Your Free Privacy Assessment Ask Stephanie

This article is for educational purposes only and is not legal advice. MercPrivacy is not a law firm; when a matter requires legal representation, a licensed attorney is engaged. Statutory figures are the amounts the statutes provide, not predictions of any outcome, and laws change — verify the current text before relying on it.