Why you cannot sue over spam email (and what works instead)

By MercPrivacy · Published 2026-07-31 · Updated 2026-08-02

The federal email statute deliberately gives recipients no right to sue. Recovery, where it exists, runs on state law and turns entirely on falsity.

## The part everyone gets wrong

CAN-SPAM is the federal law governing commercial email. It requires accurate headers, honest subject lines, a working unsubscribe honoured promptly, and a real physical postal address.

And it gives you, the recipient, **no right to sue anybody**.

That is not an oversight. Enforcement was deliberately assigned to the Federal Trade Commission, other federal regulators, state attorneys general, and internet access providers. An individual cannot bring a CAN-SPAM claim, no matter how many messages arrive.

People lose months to this misunderstanding. It is the first thing worth knowing.

## Where recovery actually lives

Federal law leaves room for state statutes — but only to the extent they target **falsity or deception**. That carve-out defines the landscape and draws a hard line:

**Usually not a claim:** an unwanted but honest marketing email, from a real company, with an accurate sender line, a truthful subject and an unsubscribe that works.

**Often a claim:** a forged or falsified header; a sender name or domain misrepresenting who sent it; a domain registered to nobody traceable; or a **subject line engineered to mislead** — a fake reply or forward, a fabricated order confirmation, a false notice that you have won or owe something.

**Aggravated conduct:** harvesting addresses, dictionary attacks, automated creation of throwaway accounts, relaying through hijacked machines. These carry heavier consequences and can be criminal.

## The step that decides everything

**Forwarding a spam email destroys the evidence.**

The routing information proving where a message came from lives in the raw headers, and forwarding replaces them with your own. Once gone, a falsity claim usually cannot be proven at all.

What you need is the original source. In most mail clients the option is called *Show original*, *View source* or *View message details*. Save that raw text — the full Received chain, the Message-ID, the Return-Path and the authentication results.

Do that before anything else. Everything downstream depends on it.

## The honest summary

If the messages are irritating but truthful, the realistic answer is filtering, unsubscribing, and getting the underlying address out of the data-broker market so volume falls at the source.

If the sender is lying about who they are, and the volume is meaningful, the picture is different and the numbers can become significant. The raw headers tell you which situation you are in.