
Can you send marketing emails without consent?
Key Facts
- Each violating marketing email under CAN-SPAM carries penalties of up to $53,088, according to the FTC.
- Verkada paid $2.95 million in 2024 — the largest CAN-SPAM settlement in FTC history — for 30 million emails without opt-out options.
- GDPR fines can reach €20 million or 4% of global annual turnover, per a global comparison of email laws.
- Canada's CASL carries fines up to CAD 10 million per violation, among the world's strictest consent rules.
- The law follows your recipient, not your company address — a US business emailing someone in Germany triggers GDPR, industry analysis confirms.
- Implied consent under CASL typically expires after two years, silently turning old customer lists into liabilities, compliance experts warn.
- Experian paid $650,000 after a broken unsubscribe flow went undetected during a platform migration, proving operational blind spots cost as much as intent.
The Short Answer: It Depends Where Your Recipient Lives
Whether you can legally hit "send" on a marketing email without asking permission first depends almost entirely on one thing: where the person receiving it lives. The answer splits the world into two camps — and getting it wrong is expensive.
The US runs on an opt-out model. Under the CAN-SPAM Act, you don't need prior consent to email a US recipient. But "no consent required" doesn't mean "no rules." The FTC's compliance guide for business requires accurate headers, clear identification of advertisements, a valid physical postal address, and a working opt-out mechanism honored within 10 business days. Each violation carries penalties of up to $53,088 per email.
Almost everywhere else, the rules flip. The EU's GDPR, Canada's CASL, the UK's PECR, and Australia's Spam Act all require opt-in consent before the first email ever goes out, according to a global comparison of email marketing laws. Canada's CASL alone carries fines of up to CAD 10 million per violation, and GDPR penalties reach €20 million or 4% of global annual turnover, whichever is higher.
Here's the part that catches most businesses off guard: the law follows your recipient, not your company address. As one industry analysis puts it, a US business emailing someone in Germany means GDPR applies to that contact — where your office sits is irrelevant. A US company emailing a customer in Toronto or Vancouver triggers CASL, full stop.
The practical consequences of ignoring this divide are well documented:
- Verkada paid $2.95 million in 2024 — the largest CAN-SPAM settlement in FTC history — for sending 30 million emails without opt-out options over three years.
- Experian settled for $650,000 after a broken unsubscribe flow during a platform migration went undetected.
- GDPR fines exceeded €1.2 billion in a single year across all enforcement actions.
This is why a permission-first approach matters operationally, not just legally. At CallMyCustomers, every reactivation campaign works from lists of real customers, with every message approved by the business owner and opt-outs honored immediately — because "compliance failures often stem from operational blind spots rather than intentional violations," as that same analysis notes.
The simplest rule of thumb: if your list contains anyone outside the US, assume you need consent. If you sell internationally, follow the strictest standard you touch — GDPR is usually the highest bar.
Want to know exactly what your existing customer list could produce — and whether it's compliant to contact? Get a free list review that shows your rate, setup, and revenue potential before you spend a dollar.
What CAN-SPAM Actually Requires (And What It Doesn't)
The United States takes a fundamentally different approach than most major economies: CAN-SPAM operates on an opt-out model, meaning you can email prospects without prior consent — but only if you follow every rule to the letter. The FTC requires accurate header information, clear identification that the message is an advertisement, a valid physical postal address in every email, and a functioning opt-out mechanism honored within 10 business days. Miss any of these and each violating email carries a penalty of up to $53,088.
- No misleading "From," "To," or routing information — headers must reflect the true sender
- Subject lines cannot be deceptive; they must accurately represent the email's content
- A legitimate physical address (street, PO box, or private mailbox) must appear in every commercial message
- Opt-out requests must be processed within 10 business days with no fees or barriers
- The opt-out mechanism must remain functional for at least 30 days after sending
Enforcement is real and expensive. Verkada paid $2.95 million in 2024 — the largest CAN-SPAM settlement in FTC history — for sending 30 million commercial emails over three years without opt-out options, ignoring unsubscribe requests, and omitting physical addresses. Experian settled for $650,000 when a broken unsubscribe flow during a platform migration went undetected, proving that operational blind spots cost as much as intentional violations.
For US service businesses, the stakes are clear: compliance isn't optional legal overhead. CallMyCustomers builds these requirements into every campaign — accurate sender identification, clear ad labeling, physical addresses, and opt-out links that work immediately. Because the law follows the recipient, not the sender, a US business emailing someone in Germany triggers GDPR. That's why the strictest standard you touch becomes your baseline.
The Consent Traps That Catch Business Owners Off Guard
Most consent violations don't come from reckless spammers — they come from business owners who thought they had permission and didn't. The traps below catch even careful operators.
Implied consent expires. If someone bought from you years ago, that relationship may no longer count as permission. Under Canada's CASL, implied consent is typically valid for only two years, and an expired relationship can silently turn a legitimate list into a liability. This matters for reactivation campaigns in particular: a customer list full of dormant contacts needs a recency check before anyone hits send.
Purchased lists fail platform standards. Even if a vendor claims the contacts opted in, most email platforms reject third-party lists outright. HubSpot's policy is explicit: contacts purchased, rented, or borrowed from a third party cannot be used for marketing email, regardless of what the list seller promises. The same policy rules out pre-checked boxes and verbal consent — consent must be expressed through a verifiable action the contact took.
A reply is not permission. If a customer emails you one-to-one, that conversation doesn't grant consent for bulk campaigns. Per platform requirements, you must direct that contact to a sign-up form to gain explicit opt-in consent before adding them to marketing sends.
Common blind spots include:
- Implied consent expiring after roughly two years under CASL
- Pre-checked boxes and verbal consent failing verifiable-permission tests
- Purchased or rented lists being blocked by email platforms
- One-to-one replies being mistaken for bulk consent
- Broken unsubscribe flows during platform migrations — Experian paid $650,000 over exactly this
The stakes now extend beyond regulators. Compliance and deliverability have converged: since 2024, Gmail and Yahoo require bulk senders to offer one-click unsubscribe, and mailbox providers enforce these standards with the same severity as laws do. As one compliance specialist puts it, compliant lists are higher-quality lists — better engagement, fewer complaints, more revenue per subscriber.
This is why working from a list of genuine, recent customers — with opt-outs honored immediately and consent collected explicitly at booking, the approach CallMyCustomers takes with every campaign — isn't just legal hygiene. It's what keeps your messages landing in inboxes instead of spam folders, and it's why a free list review before any campaign is worth more than any software purchase.
How to Stay Compliant While Reactivating Past Customers
Knowing the rules is one thing; running a reactivation campaign that survives an audit is another. The good news is that compliance and good marketing point in the same direction — compliant lists are higher quality lists, with better engagement and more revenue per subscriber, according to email marketing compliance analysis.
Start with who is actually on your list. Work only from records of real customers — people who bought, booked, or requested a quote — never from purchased or rented lists. As HubSpot's consent documentation makes clear, third-party lists can't be used for marketing email even when they claim opt-in status, and verbal consent doesn't count because it isn't verifiable.
Next, keep proof. Consent must be "expressed by an action the customer took through a verifiable method," so maintain audit trails showing how and when each contact agreed to hear from you — with timestamps and the method used. Implied consent from a past relationship also expires: under CASL it's typically valid for only two years, so segment older contacts carefully before you send.
Honor opt-outs immediately. CAN-SPAM gives you ten business days, but the fastest path to trouble is a broken unsubscribe flow — Experian paid $650,000 after a migration quietly disabled theirs, and Verkada's $2.95 million FTC settlement was the largest CAN-SPAM settlement in history. A practical checklist:
- Email only people with a genuine prior relationship — customers, quotes, appointments
- Log consent with timestamps and the method it was obtained
- Process every opt-out immediately, well inside the 10-business-day window
- If you email internationally, follow the strictest standard you touch — GDPR is usually the highest bar
That last point matters more than businesses expect. The law follows your recipient, not your company address, so a US business emailing someone in Germany triggers GDPR regardless of where the office sits.
This is exactly how CallMyCustomers approaches reactivation: campaigns run only from lists of real customers, the owner approves every message before it goes out, opt-outs are honored immediately, and clinic outreach runs under the required privacy agreements (BAA, HIPAA, TCPA) with explicit consent collected at booking. Permission-based outreach isn't a legal footnote — it's what makes a win-back campaign feel like a welcome reminder instead of spam.
Your Next Step: A Free List Review Before You Send Anything
Before launching any reactivation campaign, your email list deserves a thorough audit—not just for performance, but for compliance. Start by segmenting contacts based on recency and relationship: separate recent customers from lapsed ones, old quotes that never converted, and members whose consent may have expired. This clarity reveals what your list can legally produce and helps avoid costly missteps. As research shows, implied consent often has time limitations—for example, CASL implied consent is typically valid for only two years, meaning older contacts may no longer qualify for marketing outreach without re-permission.
Understanding where your recipients are located is just as critical as how long ago they engaged. The law follows your recipient, not your company address: a US business emailing someone in Germany means GDPR applies to that contact, regardless of where your office sits. This extraterritorial application creates real risk for US-based businesses like CallMyCustomers that serve clients across borders or maintain lists with international contacts. Non-compliance carries severe penalties—GDPR violations can reach up to EUR 20 million or 4% of global annual turnover, while each violating email under the CAN-SPAM Act can incur fines of up to USD 53,088.
To protect your business and improve deliverability, treat compliance as a foundation, not an afterthought. Implement verifiable consent mechanisms, honor opt-out requests within required timeframes (10 business days under CAN-SPAM), and maintain clean, segmented lists aligned with both legal standards and campaign goals. CallMyCustomers’ free list review provides exactly this: a clear view of your list’s health, segmentation potential, and compliant outreach capacity—before you spend a dollar. Every script, offer, and message is approved by you first, ensuring your reactivation efforts are not only effective but fully permission-based and legally sound.
Frequently Asked Questions
Can I email past customers without their permission if my business is in the US?
What happens if I email someone in Germany from my US business without consent?
Does a customer buying from me two years ago count as consent to email them now?
Can I use a purchased email list if the vendor says the contacts opted in?
What are the actual penalties for getting this wrong?
If someone replies to my email, does that mean I can add them to my marketing list?
Permission First, Revenue Second — Or Is It the Same Thing?
So, can you send marketing emails without consent? In the US, yes — if you follow every CAN-SPAM rule, from honest headers to opt-outs honored within 10 business days. Everywhere else, the answer is no, and the law follows your recipient, not your office. The real lesson from Verkada's $2.95 million settlement and Experian's $650,000 mistake is that compliance failures usually come from operational blind spots, not bad intent. The good news: compliant lists are better lists — better engagement, fewer complaints, more revenue per subscriber. Your next steps are simple: audit who's on your list and when they last engaged, verify how consent was collected, and follow the strictest standard you touch. If that sounds like work, it doesn't have to be your work. CallMyCustomers runs reactivation campaigns only from lists of real customers, with every message approved by you and opt-outs honored immediately. Start with a free list review — see your rate, setup, and what your list can produce before you spend a dollar.