ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

Can you send marketing emails without consent?

Back to InsightsCan you send marketing emails without consent?

Can you send marketing emails without consent?

Key Facts

The Short Answer: It Depends Where Your Recipient Lives

Whether you can legally hit "send" on a marketing email without asking permission first depends almost entirely on one thing: where the person receiving it lives. The answer splits the world into two camps — and getting it wrong is expensive.

The US runs on an opt-out model. Under the CAN-SPAM Act, you don't need prior consent to email a US recipient. But "no consent required" doesn't mean "no rules." The FTC's compliance guide for business requires accurate headers, clear identification of advertisements, a valid physical postal address, and a working opt-out mechanism honored within 10 business days. Each violation carries penalties of up to $53,088 per email.

Almost everywhere else, the rules flip. The EU's GDPR, Canada's CASL, the UK's PECR, and Australia's Spam Act all require opt-in consent before the first email ever goes out, according to a global comparison of email marketing laws. Canada's CASL alone carries fines of up to CAD 10 million per violation, and GDPR penalties reach €20 million or 4% of global annual turnover, whichever is higher.

Here's the part that catches most businesses off guard: the law follows your recipient, not your company address. As one industry analysis puts it, a US business emailing someone in Germany means GDPR applies to that contact — where your office sits is irrelevant. A US company emailing a customer in Toronto or Vancouver triggers CASL, full stop.

The practical consequences of ignoring this divide are well documented:

  • Verkada paid $2.95 million in 2024 — the largest CAN-SPAM settlement in FTC history — for sending 30 million emails without opt-out options over three years.
  • Experian settled for $650,000 after a broken unsubscribe flow during a platform migration went undetected.
  • GDPR fines exceeded €1.2 billion in a single year across all enforcement actions.

This is why a permission-first approach matters operationally, not just legally. At CallMyCustomers, every reactivation campaign works from lists of real customers, with every message approved by the business owner and opt-outs honored immediately — because "compliance failures often stem from operational blind spots rather than intentional violations," as that same analysis notes.

The simplest rule of thumb: if your list contains anyone outside the US, assume you need consent. If you sell internationally, follow the strictest standard you touch — GDPR is usually the highest bar.

Want to know exactly what your existing customer list could produce — and whether it's compliant to contact? Get a free list review that shows your rate, setup, and revenue potential before you spend a dollar.

What CAN-SPAM Actually Requires (And What It Doesn't)

The United States takes a fundamentally different approach than most major economies: CAN-SPAM operates on an opt-out model, meaning you can email prospects without prior consent — but only if you follow every rule to the letter. The FTC requires accurate header information, clear identification that the message is an advertisement, a valid physical postal address in every email, and a functioning opt-out mechanism honored within 10 business days. Miss any of these and each violating email carries a penalty of up to $53,088.

  • No misleading "From," "To," or routing information — headers must reflect the true sender
  • Subject lines cannot be deceptive; they must accurately represent the email's content
  • A legitimate physical address (street, PO box, or private mailbox) must appear in every commercial message
  • Opt-out requests must be processed within 10 business days with no fees or barriers
  • The opt-out mechanism must remain functional for at least 30 days after sending

Enforcement is real and expensive. Verkada paid $2.95 million in 2024 — the largest CAN-SPAM settlement in FTC history — for sending 30 million commercial emails over three years without opt-out options, ignoring unsubscribe requests, and omitting physical addresses. Experian settled for $650,000 when a broken unsubscribe flow during a platform migration went undetected, proving that operational blind spots cost as much as intentional violations.

For US service businesses, the stakes are clear: compliance isn't optional legal overhead. CallMyCustomers builds these requirements into every campaign — accurate sender identification, clear ad labeling, physical addresses, and opt-out links that work immediately. Because the law follows the recipient, not the sender, a US business emailing someone in Germany triggers GDPR. That's why the strictest standard you touch becomes your baseline.

Most consent violations don't come from reckless spammers — they come from business owners who thought they had permission and didn't. The traps below catch even careful operators.

Implied consent expires. If someone bought from you years ago, that relationship may no longer count as permission. Under Canada's CASL, implied consent is typically valid for only two years, and an expired relationship can silently turn a legitimate list into a liability. This matters for reactivation campaigns in particular: a customer list full of dormant contacts needs a recency check before anyone hits send.

Purchased lists fail platform standards. Even if a vendor claims the contacts opted in, most email platforms reject third-party lists outright. HubSpot's policy is explicit: contacts purchased, rented, or borrowed from a third party cannot be used for marketing email, regardless of what the list seller promises. The same policy rules out pre-checked boxes and verbal consent — consent must be expressed through a verifiable action the contact took.

A reply is not permission. If a customer emails you one-to-one, that conversation doesn't grant consent for bulk campaigns. Per platform requirements, you must direct that contact to a sign-up form to gain explicit opt-in consent before adding them to marketing sends.

Common blind spots include:

  • Implied consent expiring after roughly two years under CASL
  • Pre-checked boxes and verbal consent failing verifiable-permission tests
  • Purchased or rented lists being blocked by email platforms
  • One-to-one replies being mistaken for bulk consent
  • Broken unsubscribe flows during platform migrations — Experian paid $650,000 over exactly this

The stakes now extend beyond regulators. Compliance and deliverability have converged: since 2024, Gmail and Yahoo require bulk senders to offer one-click unsubscribe, and mailbox providers enforce these standards with the same severity as laws do. As one compliance specialist puts it, compliant lists are higher-quality lists — better engagement, fewer complaints, more revenue per subscriber.

This is why working from a list of genuine, recent customers — with opt-outs honored immediately and consent collected explicitly at booking, the approach CallMyCustomers takes with every campaign — isn't just legal hygiene. It's what keeps your messages landing in inboxes instead of spam folders, and it's why a free list review before any campaign is worth more than any software purchase.

How to Stay Compliant While Reactivating Past Customers

Knowing the rules is one thing; running a reactivation campaign that survives an audit is another. The good news is that compliance and good marketing point in the same direction — compliant lists are higher quality lists, with better engagement and more revenue per subscriber, according to email marketing compliance analysis.

Start with who is actually on your list. Work only from records of real customers — people who bought, booked, or requested a quote — never from purchased or rented lists. As HubSpot's consent documentation makes clear, third-party lists can't be used for marketing email even when they claim opt-in status, and verbal consent doesn't count because it isn't verifiable.

Next, keep proof. Consent must be "expressed by an action the customer took through a verifiable method," so maintain audit trails showing how and when each contact agreed to hear from you — with timestamps and the method used. Implied consent from a past relationship also expires: under CASL it's typically valid for only two years, so segment older contacts carefully before you send.

Honor opt-outs immediately. CAN-SPAM gives you ten business days, but the fastest path to trouble is a broken unsubscribe flow — Experian paid $650,000 after a migration quietly disabled theirs, and Verkada's $2.95 million FTC settlement was the largest CAN-SPAM settlement in history. A practical checklist:

  • Email only people with a genuine prior relationship — customers, quotes, appointments
  • Log consent with timestamps and the method it was obtained
  • Process every opt-out immediately, well inside the 10-business-day window
  • If you email internationally, follow the strictest standard you touch — GDPR is usually the highest bar

That last point matters more than businesses expect. The law follows your recipient, not your company address, so a US business emailing someone in Germany triggers GDPR regardless of where the office sits.

This is exactly how CallMyCustomers approaches reactivation: campaigns run only from lists of real customers, the owner approves every message before it goes out, opt-outs are honored immediately, and clinic outreach runs under the required privacy agreements (BAA, HIPAA, TCPA) with explicit consent collected at booking. Permission-based outreach isn't a legal footnote — it's what makes a win-back campaign feel like a welcome reminder instead of spam.

Your Next Step: A Free List Review Before You Send Anything

Before launching any reactivation campaign, your email list deserves a thorough audit—not just for performance, but for compliance. Start by segmenting contacts based on recency and relationship: separate recent customers from lapsed ones, old quotes that never converted, and members whose consent may have expired. This clarity reveals what your list can legally produce and helps avoid costly missteps. As research shows, implied consent often has time limitations—for example, CASL implied consent is typically valid for only two years, meaning older contacts may no longer qualify for marketing outreach without re-permission.

Understanding where your recipients are located is just as critical as how long ago they engaged. The law follows your recipient, not your company address: a US business emailing someone in Germany means GDPR applies to that contact, regardless of where your office sits. This extraterritorial application creates real risk for US-based businesses like CallMyCustomers that serve clients across borders or maintain lists with international contacts. Non-compliance carries severe penalties—GDPR violations can reach up to EUR 20 million or 4% of global annual turnover, while each violating email under the CAN-SPAM Act can incur fines of up to USD 53,088.

To protect your business and improve deliverability, treat compliance as a foundation, not an afterthought. Implement verifiable consent mechanisms, honor opt-out requests within required timeframes (10 business days under CAN-SPAM), and maintain clean, segmented lists aligned with both legal standards and campaign goals. CallMyCustomers’ free list review provides exactly this: a clear view of your list’s health, segmentation potential, and compliant outreach capacity—before you spend a dollar. Every script, offer, and message is approved by you first, ensuring your reactivation efforts are not only effective but fully permission-based and legally sound.

Frequently Asked Questions

Can I email past customers without their permission if my business is in the US?
It depends entirely on where your recipients live — US recipients fall under CAN-SPAM's opt-out model, but if anyone on your list is in the EU, Canada, UK, or Australia, you need their explicit opt-in consent before sending because the law follows the recipient, not your company address .
What happens if I email someone in Germany from my US business without consent?
GDPR applies to that contact and violations can reach €20 million or 4% of global annual turnover, whichever is higher — your US office location doesn't exempt you .
Does a customer buying from me two years ago count as consent to email them now?
Under Canada's CASL, implied consent from a purchase typically expires after two years, so older customer relationships may no longer qualify as valid permission for marketing emails .
Can I use a purchased email list if the vendor says the contacts opted in?
Major platforms like HubSpot explicitly prohibit using purchased, rented, or borrowed lists for marketing emails regardless of what the list seller claims, because third-party consent isn't verifiable .
What are the actual penalties for getting this wrong?
CAN-SPAM violations carry up to $53,088 per email, CASL fines reach CAD 10 million per violation, and GDPR penalties can hit €20 million or 4% of global turnover — Verkada paid $2.95 million in 2024 for CAN-SPAM violations alone .
If someone replies to my email, does that mean I can add them to my marketing list?
No — a one-to-one reply doesn't grant consent for bulk campaigns; you must direct them to a sign-up form to obtain explicit, verifiable opt-in consent before adding them to marketing sends .

Permission First, Revenue Second — Or Is It the Same Thing?

So, can you send marketing emails without consent? In the US, yes — if you follow every CAN-SPAM rule, from honest headers to opt-outs honored within 10 business days. Everywhere else, the answer is no, and the law follows your recipient, not your office. The real lesson from Verkada's $2.95 million settlement and Experian's $650,000 mistake is that compliance failures usually come from operational blind spots, not bad intent. The good news: compliant lists are better lists — better engagement, fewer complaints, more revenue per subscriber. Your next steps are simple: audit who's on your list and when they last engaged, verify how consent was collected, and follow the strictest standard you touch. If that sounds like work, it doesn't have to be your work. CallMyCustomers runs reactivation campaigns only from lists of real customers, with every message approved by you and opt-outs honored immediately. Start with a free list review — see your rate, setup, and what your list can produce before you spend a dollar.

Stay in the Loop