ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

Is it illegal to send marketing emails without permission?

Back to InsightsIs it illegal to send marketing emails without permission?

Is it illegal to send marketing emails without permission?

Key Facts

  • Sending marketing emails without permission is illegal in most of the world, including the EU, UK, Canada, and Australia, under opt-in laws like GDPR and CASL per this compliance guide.
  • The US is the major exception: CAN-SPAM requires no advance permission, but every email needs a working unsubscribe link and valid postal address per this legal analysis.
  • CAN-SPAM penalties reach $53,088 per non-compliant email — assessed per message, not per campaign — so 100,000 emails could mean billions in exposure per FTC enforcement analysis.
  • Verkada paid the FTC $2.95 million in August 2024 over 30 million emails missing unsubscribe links and a valid postal address per FTC enforcement case analysis.
  • Experian paid $650,000 for promotional emails falsely labeled as account updates — under the primary purpose test, content controls, not the label per enforcement records.
  • There is no B2B exception to CAN-SPAM: the law applies equally whether you're emailing homeowners or procurement managers per FTC enforcement cases.
  • Unwanted texts carry TCPA statutory damages of $500 each — up to $1,500 if willful — making a 200-number purchased list worth $300,000 in exposure under 47 U.S.C. § 227(b)(3).

The Short Answer Depends on Where Your Customers Are

Where your customers live determines whether that marketing email is legal or illegal — and the answer flips depending on which side of the border they're on.

In most of the world, sending marketing emails without permission is simply illegal. Regulations like the GDPR in the EU, PECR in the UK, CASL in Canada, and the Spam Act in Australia all require explicit opt-in consent before you hit send, according to a compliance guide from Usercentrics. That means no pre-checked boxes, no bundling consent into checkout, and no hidden opt-ins — the recipient must take a clear, unambiguous action to agree.

The United States is the major exception. The CAN-SPAM Act operates as an opt-out framework: you don't need advance permission to send a commercial email, but you must make it easy for recipients to stop receiving them, as one legal analysis explains. Permission isn't required — but honest headers, a working unsubscribe link, and a valid physical postal address are.

Don't confuse "no permission required" with "no risk," though. The FTC assesses CAN-SPAM penalties per individual email, not per campaign — up to $53,088 for every non-compliant message, per FTC enforcement case analysis. A campaign of 100,000 emails sent without the required elements could theoretically expose a sender to billions in penalties.

Recent enforcement proves this isn't theoretical:

  • Verkada paid $2.95 million in August 2024 for over 30 million emails missing unsubscribe links, ignoring opt-outs, and lacking a valid postal address.
  • Experian Consumer Services paid $650,000 for promotional emails deceptively labeled as account updates with no opt-out mechanism.
  • Publishers Clearing House faced an $18.5 million judgment that included CAN-SPAM violations for misleading subject headings.

Most violations are boring, not exotic — a missing unsubscribe link, an ignored opt-out request, no postal address. And there's no B2B exception: CAN-SPAM applies equally whether you're emailing homeowners or procurement managers. You're also responsible for mail sent on your behalf, so a vendor's mistake becomes your liability.

This is exactly why CallMyCustomers runs reactivation campaigns only from lists of real customers, with every message approved by the owner and opt-outs honored immediately. Even in the opt-out-friendly US, the safest standard is permission — and it happens to produce better results too, since people who actually want to hear from you are the ones who book.

What CAN-SPAM Actually Requires (Even With Permission)

Even when you have permission to email customers, US law still sets clear rules for commercial messages under the CAN-SPAM Act. Many businesses assume that having consent eliminates compliance concerns, but the law requires specific elements regardless of permission status. These requirements apply equally to promotional emails sent to existing customers or new prospects, making them essential for any marketing campaign. Ignoring these basics can trigger penalties even when your audience expects your messages.

The CAN-SPAM Act mandates five core components for every commercial email: accurate header information (including "From," "To," and routing details), non-deceptive subject lines that reflect the email's content, clear identification that the message is an advertisement or solicitation, a valid physical postal address for the sender, and a functional opt-out mechanism. Crucially, any opt-out request must be honored within 10 business days and the mechanism must remain operable for at least 30 days after sending. These rules aren't theoretical—the FTC enforces them rigorously, often finding that seemingly minor oversights lead to significant liability.

Real-world enforcement shows how "boring" violations generate major penalties. In August 2024, Verkada settled with the FTC for $2.95 million after sending over 30 million commercial emails that lacked unsubscribe links, ignored opt-out requests, and omitted a valid postal address over three years. Similarly, Experian Consumer Services paid $650,000 in 2023 for sending promotional emails falsely labeled as account updates while omitting functional opt-out mechanisms. These cases highlight that regulators focus on pattern and practice, not isolated mistakes, and that missing basic elements like an unsubscribe link or physical address can quickly accumulate into multi-million-dollar exposure.

For service businesses using reactivation campaigns, compliance isn't just about avoiding fines—it's about maintaining trust. CallMyCustomers builds these requirements into every campaign by using only verified customer lists, honoring opt-outs immediately, and ensuring all messages include clear sender identification and a working unsubscribe option. This approach protects your business while keeping communication welcome and effective, turning past customers into booked work without crossing legal lines. The simplest path forward is treating every email as if it could be audited: accurate, transparent, and respectful of the recipient's choice to opt out.

The Traps That Catch Honest Businesses

Most CAN-SPAM violations don't come from spammers. They come from honest businesses that assumed a technicality would protect them — and the FTC's enforcement record shows those assumptions get expensive fast.

The primary purpose test catches "relabeled" promotions. Labeling a promotional email as an "account update" or "transactional message" doesn't exempt it. The FTC tests the email's primary purpose under 16 C.F.R. § 316.3, and as one enforcement analysis puts it, "the label does not control — the content does." Experian Consumer Services learned this the hard way, paying a $650,000 settlement in August 2023 for promotional emails falsely labeled as account updates that lacked opt-out mechanisms.

A promotional subject line alone can make an otherwise mixed email fully commercial. If the email is built to sell, it needs the complete opt-out treatment — accurate headers, a valid postal address, and an unsubscribe mechanism honored within 10 business days and kept functional for at least 30 days after sending.

There is no B2B exception. Service businesses marketing to other businesses often assume commercial email rules apply only to consumers. They don't. FTC enforcement cases confirm CAN-SPAM applies equally to B2B and B2C email, and penalties stack per email — up to $53,088 per non-compliant message, not per campaign. A list of 100,000 emails carries theoretical exposure in the billions.

You're liable for what your vendors send. Hiring an agency or email service provider doesn't transfer legal responsibility. As compliance analyses note, "you are still responsible for mail sent on your behalf." This is why the approval model matters — services like CallMyCustomers have the business owner sign off on every script and offer before anything goes out, keeping the client's name on messages they've actually reviewed.

The stakes rise sharply once texts and calls enter the mix:

  • The TCPA imposes statutory damages of $500 per unwanted text or call, rising to $1,500 if the violation is willful or knowing (47 U.S.C. § 227(b)(3)).
  • Unlike CAN-SPAM's opt-out model, the TCPA is an opt-in law — texts require advance permission, full stop.
  • A purchased list of just 200 numbers could mean up to $300,000 in exposure before any willfulness multiplier.
  • Lead-marketplace buyers inherit consent gaps — if the lead's original consent language didn't cover your messages, you carry that risk.

Finally, federal law isn't the whole picture. Regulatory tracking shows more than 20 US state privacy laws now impose their own opt-out signals and consent rules, layering state-level requirements on top of CAN-SPAM and the TCPA. Most violations are boring — a missing unsubscribe link, an ignored opt-out, no postal address — which is exactly why the Verkada settlement reached $2.95 million over 30 million emails. The lesson: treat permission as the operating standard, not the legal minimum.

How to Reactivate Past Customers the Compliant Way

Reactivate past customers without risking compliance by building your win-back strategy on real relationships and verifiable permission. Start by working only from lists of actual customers—people who have previously booked a service, made a purchase, or engaged with your business in a verifiable way. This ensures you’re not cold-emailing strangers but reconnecting with individuals who already know your brand, which research shows is ~5x cheaper than acquiring a new customer and far more likely to yield a positive response. Most customers forget a business within ~12 months, making timely, permission-based outreach essential to staying top of mind.

Keep proof of consent for every contact on your list, whether it’s a past service record, a signed agreement, or an opt-in from a previous interaction. Under regulations like GDPR and CASL, consent must be freely given, specific, informed, and unambiguous—typically requiring an active choice like checking an unchecked box. Even under the U.S. CAN-SPAM Act, where prior consent isn’t required for marketing emails, you must still honor opt-out requests within 10 business days and maintain a functional unsubscribe mechanism in every message. Failing to do so can result in penalties of up to $53,088 per violating email, assessed per message rather than per campaign, creating significant exposure for non-compliant senders.

Apply the primary purpose test to every message you send: if the email’s main goal is to promote a service, offer, or booking, it’s classified as commercial and must comply with CAN-SPAM requirements, including accurate header information, non-deceptive subject lines, clear identification as advertising, a valid physical postal address, and a working opt-out link. Labeling an email as “transactional” or “account information” doesn’t override its actual commercial nature—content and subject line determine classification, not disclaimers. This test applies equally to B2B and B2C communications, with no exceptions under CAN-SPAM.

Finally, honor opt-outs immediately and without exception. Once a recipient unsubscribes, stop all marketing emails to that address and keep the opt-out mechanism functional for at least 30 days after your last send. Compliant reactivation isn’t just safer legally—it performs better because it’s rooted in trust, relevance, and respect for the customer’s inbox.

Ready to turn your past customers into booked work—approved by you, run by us? Get a free list review to see exactly what your customer list can produce before spending a dollar. We’ll segment your list by recency, old quotes, and happy referrers, then build a permission-based win-back campaign that feels useful, not pushy—so your next booked customer already knows your business.

When Someone Else Sends for You: Vetting a Done-for-You Partner

You remain legally responsible for every message sent on your behalf, even when a third party handles the outreach. The FTC has made this clear: vendor liability does not transfer, and the penalty is assessed per email — up to $53,088 per non-compliant message under CAN-SPAM — not per campaign. A single campaign to a modest list can create millions in exposure if opt-out mechanisms are missing or ignored.

Choosing a done-for-you partner means vetting their compliance infrastructure as rigorously as their copywriting. Look for a provider that requires your pre-approval on every script and message before anything goes out, honors opt-out requests immediately across all channels, and documents consent practices transparently. A free list review before any fees are quoted is also a strong signal — it shows the partner understands your audience and the regulatory boundaries before you commit.

  • Pre-approval of every script, offer, and message — nothing sends without your sign-off
  • Immediate opt-out handling across calls, texts, and emails
  • Transparent consent practices with audit-ready records
  • Free list review and segmentation before any setup fee
  • Replies routed directly into your booking workflow, not a separate dashboard

CallMyCustomers operates on this model: the owner approves every message first, outreach runs from your existing CRM or spreadsheet with no new software to learn, and responses flow straight to your booking process. Real humans handle the judgment calls; automation handles the scale. The result is reactivation that feels useful, not pushy — and stays on the right side of the law.

Frequently Asked Questions

Is it illegal to send marketing emails without permission in the United States?
No, under the CAN-SPAM Act, prior consent is not required to send marketing emails in the U.S., but you must include accurate headers, a valid physical address, a clear opt-out mechanism, and honor unsubscribe requests within 10 business days. Consent is not required in the USA under CAN-SPAM, but compliance with other elements is mandatory.
Can I get fined for sending marketing emails without an unsubscribe link in the U.S.?
Yes, sending marketing emails without a functional unsubscribe link violates the CAN-SPAM Act and can result in penalties of up to $53,088 per violating email, as assessed by the FTC on a per-message basis. Verkada paid $2.95 million for over 30 million emails missing unsubscribe links and ignoring opt-outs.
Does labeling a promotional email as an 'account update' make it compliant with CAN-SPAM?
No, the FTC applies the 'primary purpose test' — if the email's main goal is to promote a product or service, it's considered commercial regardless of labels like 'account update' or 'transactional.' Experian Consumer Services paid $650,000 for promotional emails falsely labeled as account updates that lacked opt-out mechanisms.
Do CAN-SPAM rules apply to business-to-business (B2B) marketing emails?
Yes, CAN-SPAM applies equally to both B2B and B2C emails — there is no exception for business-to-business communication under U.S. law. FTC enforcement cases confirm CAN-SPAM applies equally to B2B and B2C email, with penalties assessed per violating message.
Am I liable if a vendor or email service provider sends non-compliant emails on my behalf?
Yes, you remain legally responsible for all commercial emails sent on your behalf, even if a third party manages your outreach — the FTC does not transfer liability to vendors. You are still responsible for mail sent on your behalf, which is why CallMyCustomers requires client approval of every message before sending.
Should I still get permission to email customers in the U.S. even if CAN-SPAM doesn’t require it?
Yes, while not legally required under CAN-SPAM, obtaining permission is the safest standard and leads to better engagement — people who want to hear from you are more likely to respond and book services. The safest standard is permission, and it happens to produce better results too, since people who actually want to hear from you are the ones who book.

Permission Isn't Just Legal—It's Your Revenue Engine

Whether you're mailing customers in Toronto or Texas, the rules are clear: global markets demand explicit consent, while the U.S. CAN-SPAM Act requires transparency, honest headers, and a working opt-out—even if permission isn't legally required upfront. Ignoring these basics isn't just risky; it's expensive, with fines stacking per email and enforcement targeting honest businesses over technicalities like missing unsubscribe links or deceptive labeling. The smartest path forward treats permission as the standard, not the loophole—because audiences who expect your message engage more, complain less, and convert better. CallMyCustomers helps service businesses turn past customers into booked work by building every reactivation campaign on verified lists, owner-approved messages, and immediate opt-out honoring—so your outreach feels useful, not pushy, and stays compliant across channels. Ready to see what your customer list can produce? Get a free list review and discover how reactivation can become your second revenue engine.

Stay in the Loop