Is cold email legal? CAN-SPAM, GDPR, and CASL
An operator's reading of the three laws that govern emailing strangers: what each one actually requires, and where the fines start.
Cold email is legal in the United States, conditionally legal in most of Europe, and close to impractical in Canada without prior context. The margin for error is priced at up to $53,088 per email.
The law is one of two rulebooks. The other, enforced faster and without appeals, is mailbox-provider policy, which is why our cold email infrastructure guide treats compliance and deliverability as a single system. If you want the definitional groundwork first, what is a cold email draws those lines.
CAN-SPAM: an opt-out law
The CAN-SPAM Act of 2003 governs commercial email in the US, and the most misunderstood thing about it is what it does not require: consent. You may email a stranger. The FTC's compliance guide reduces the law to seven obligations:
- No false or misleading header information. From, reply-to, and routing data must identify the person or business that sent the message.
- No deceptive subject lines. The subject must reflect the content.
- Identify the message as an advertisement. The law leaves room in how, but disguising a pitch as personal correspondence or a fake "Re:" fails the test.
- Include a valid physical postal address. A street address, a PO box registered with the USPS, or a private mailbox registered with a commercial mail receiving agency all qualify.
- Tell recipients how to opt out, in language a person can spot and use.
- Honor opt-outs within 10 business days, with no fee, no login, and no request for anything beyond an email address.
- Monitor what others send on your behalf. Hiring an agency or a sending tool does not transfer the liability.
Each non-compliant email is a separate violation, currently priced at up to $53,088 in civil penalties. That figure comes from the FTC's inflation adjustment published in the Federal Register on January 17, 2025. The FTC restates the maximum for inflation most Januaries, so check the current adjustment before you quote it back to anyone. The agency does not chase theoretical maximums against small senders, and the per-email arithmetic is still the point: a 1,000-message campaign with a missing postal address is 1,000 violations on paper.
GDPR: legitimate interest, with homework
For prospects in the EU, GDPR governs the processing of personal data, and a work email address tied to an identifiable person qualifies. Consent is one lawful basis. The one B2B outreach actually runs on is legitimate interest, Article 6(1)(f), and Recital 47 says the quiet part aloud: processing for direct marketing purposes "may be regarded as carried out for a legitimate interest."
That sentence is not a free pass. Relying on legitimate interest obligates you to run and document a balancing test (a legitimate interest assessment): a genuine interest, a real need to use email specifically, and a balance that does not override the recipient's rights. Emailing someone in their professional capacity about their professional responsibilities strengthens that balance; scraping personal Gmail addresses collapses it. You must also disclose where you got the address, make objection easy, and delete on request. The penalty ceiling under Article 83 is EUR 20 million or 4% of global annual revenue, whichever is higher.
GDPR is also not the whole picture. The ePrivacy Directive (2002) governs the sending itself, and every member state implemented it as national law, so the practical answer changes at each border. Germany's unfair-competition law (UWG) requires prior consent for commercial email even in B2B; a cold pitch to a CEO in Munich needs the same consent as a consumer campaign. The UK's PECR exempts corporate subscribers, so email to a company address is permitted with identification and a working opt-out. France's CNIL accepts legitimate interest for B2B with a strict opt-out. The soft opt-in that appears across these regimes covers only existing customers, which by definition never describes a cold prospect. Check the target country before the list is built, and drop the strict-consent countries unless you have counsel.
CASL: the strict one
Canada's anti-spam law, in force since July 2014, is a consent regime. Commercial email requires consent before sending, and the burden of proving it sits with the sender.
Express consent means an affirmative act, like a checkbox the person ticked themselves; it never expires unless withdrawn. Implied consent is the narrow door cold email must fit through: a recent existing business relationship within time windows the act fixes, or an email address the person conspicuously published in a business capacity, with no note refusing solicitations, and a message relevant to that person's role. "I found it on LinkedIn" does not, by itself, meet the test.
Every message still needs sender identification and an unsubscribe honored within 10 business days. Penalties reach CAD $1 million per violation for individuals and CAD $10 million for organizations, and directors and officers can be personally liable. Our stance: unless a Canadian prospect plainly published their address in a role relevant to your pitch, or you have genuine prior dealings, leave Canadian addresses out of the sequence.
Mailbox providers enforce stricter rules than the law
A campaign can satisfy every statute above and still land entirely in spam. Gmail's bulk-sender rules (February 2024) demand aligned SPF, DKIM, and DMARC, a spam-complaint rate under 0.3% with a target under 0.1%, and RFC 8058 one-click unsubscribe on bulk mail. Since November 2025, Gmail hard-rejects unauthenticated mail with a 550 error; Microsoft has done the same since May 2025. Nothing in CAN-SPAM requires authentication. The inbox does.
The statutes allow 10 business days for an opt-out; honor it in seconds anyway. In our workspace an unsubscribe lands on a suppression list that is checked before every future send and never expires, and the send path pauses itself at 0.3% complaints or 2% bounces. Provider penalties arrive in days, legal ones in years, and only one of those timelines waits for your lawyer.
The compliance checklist
Every regime above compresses into one working list:
- Send from a domain that identifies your company. A lookalike outreach domain is fine when it discloses who owns it.
- Real From name, real company, working reply address. No forged headers, no fake "Re:".
- A subject line the body can back up.
- A physical postal address in every message.
- A one-sentence opt-out in every message, honored immediately and permanently.
- A record of where every address came from and why you may email it. GDPR makes you disclose the source; CASL makes you prove the consent.
- A country check before sending: US, opt-out rules apply. UK, corporate addresses are fair game. Germany, consent first. Canada, consent first.
- Volume discipline and complaint monitoring, per how many cold emails per day. The strictest regulator you answer to is Gmail.
Read the rules for your target countries before the list exists, and when a deal is worth real money, spend the hour with counsel. It costs less than one email at $53,088.