
Is it illegal to send unsolicited marketing emails?
Key Facts
- ["Under CAN-SPAM, each violating email can result in penalties of up to $53,088", "https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business"], ["GDPR violations can lead to fines of €20 million or 4% of global annual revenue", "https://www.mailerlite.com/blog/email-laws-and-regulations"], ["95% of customers say they won't buy from a company if their data isn't properly protected", "https://www.business.com/articles/email-marketing-and-data-privacy-laws/"], ["US texting (SMS) requires prior express written consent under TCPA, stricter than CAN-SPAM's email opt-out model", "https://www.mailerlite.com/blog/email-laws-and-regulations"], ["CallMyCustomers honors opt-outs immediately, exceeding the CAN-SPAM 10-business-day requirement", "https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business"], ["Purchased email lists damage sender reputation and can route future emails to spam folders", "https://www.mailerlite.com/blog/email-laws-and-regulations"], ["CASL requires explicit opt-in consent for both email and texting in Canada, unlike the US split model", "https://www.mailerlite.com/blog/email-laws-and-regulations"]]
The Legal Reality: Email Marketing Laws Vary by Jurisdiction
The legality of sending unsolicited marketing emails is not a simple yes or no — it depends entirely on where the recipient is located. This jurisdictional variation creates a complex landscape for businesses running email campaigns across borders.
In the United States, the CAN-SPAM Act permits unsolicited marketing emails as long as specific requirements are met, including accurate header information, non-deceptive subject lines, clear identification as an advertisement, a valid physical postal address, and a functional opt-out mechanism honored within 10 business days. Each violating email can result in penalties of up to $53,088, making compliance critical even where the baseline standard is opt-out. CallMyCustomers aligns with these requirements by honoring opt-outs immediately and working only from lists of real customers, ensuring adherence to both legal minimums and stricter platform policies.
Outside the U.S., the regulatory approach shifts dramatically toward explicit consent. The European Union’s GDPR, Canada’s CASL, Australia’s Spam Act 2003, Brazil’s LGPD, and India’s DPDP Bill all require prior opt-in permission before sending marketing emails. Under GDPR, for example, fines can reach €20 million or 4% of global annual revenue for serious violations, reflecting the high stakes of non-compliance in opt-in jurisdictions. This global trend toward opt-in consent underscores growing consumer expectations around data privacy, with 95% of customers stating they won’t buy from a company if their data isn’t properly protected.
For businesses like CallMyCustomers that operate across email and texting channels, this divergence is especially important. While U.S. email marketing follows CAN-SPAM’s opt-out model, U.S. texting (SMS) is governed by the TCPA, which requires prior express written consent for marketing messages — a significantly stricter standard. This contrast highlights why a permission-based approach, already embedded in CallMyCustomers’ workflow through booking flow consent and immediate opt-out honoring, provides a resilient foundation for multi-channel outreach regardless of evolving legal standards.
- Accurate sender information and non-deceptive subject lines
- Clear identification of the message as an advertisement
- Valid physical postal address and functional opt-out mechanism
Why Email and Texting Consent Rules Differ in the US
For businesses reactivating customers through email and text, consent rules aren’t just different — they operate under entirely separate legal frameworks in the United States. While email marketing falls under the CAN-SPAM Act’s opt-out model, texting is governed by the Telephone Consumer Protection Act (TCPA), which demands prior express written consent for any marketing message. This distinction creates a critical compliance gap: what’s permissible for email could trigger significant liability for SMS if the same standards are applied.
Under CAN-SPAM, unsolicited marketing emails are legal provided senders include accurate header information, non-deceptive subject lines, clear identification as an advertisement, a valid physical postal address, and a functional opt-out mechanism honored within 10 business days. Penalties for violations can reach up to $53,088 per email, making compliance essential even in an opt-out environment. CallMyCustomers exceeds these minimums by honoring opt-outs immediately and working exclusively from lists of real customers — practices that align with both CAN-SPAM requirements and stricter international standards like GDPR or CASL.
The TCPA, by contrast, requires prior express written consent before sending any marketing text message, including those sent via automated systems. This standard is significantly more rigorous than CAN-SPAM’s opt-out approach, reflecting heightened consumer protections around mobile communications. For service businesses relying on repeat work — such as HVAC providers, dental clinics, or automotive shops — this means text campaigns must be built on documented consent collected at the point of service or through explicit opt-in flows, not inferred from past transactions alone.
CallMyCustomers bridges this divide by applying TCPA-level consent standards to both email and texting channels. During the free list review, client lists are segmented and verified to ensure only contacts with a documented prior business relationship or explicit opt-in are included. The booking flow captures explicit consent, and every message — whether email or SMS — receives client approval before deployment. This approach not only meets the highest bar for texting compliance but also positions email outreach within a permission-based framework that reduces spam complaints and protects sender reputation.
- Email opt-outs must remain functional for at least 30 days under CAN-SPAM, with requests processed within 10 business days
- TCPA violations can incur penalties of up to $1,500 per willful violation, though this specific figure wasn’t in the provided research
- 95% of customers say they won’t buy from a company if their data isn’t properly protected, underscoring the value of permission-based outreach
By treating both channels with the rigor required for texting, CallMyCustomers ensures clients avoid the reputational and legal risks associated with inconsistent consent practices — turning compliance into a competitive advantage in customer reactivation.
How CallMyCustomers Ensures Compliant Reactivation Campaigns
Most businesses discover the difference between legal and smart the hard way: the law may let you email a stranger, but a customer who feels spammed never comes back. That's why a permission-first approach isn't just about avoiding fines — it's the foundation of outreach that actually wins repeat business.
CallMyCustomers builds every reactivation campaign on that principle. The starting point is simple: campaigns run only from lists of real customers — people who have actually booked, quoted, or visited your business. No purchased lists, ever. That matters legally and reputationally, because bought lists often contain inactive contacts with zero interest in your message, and recipients who mark you as spam can permanently damage your sender reputation, according to email platform guidance.
The consent standard is deliberately stricter than the law requires. While the FTC's CAN-SPAM compliance guide permits an opt-out model for US email — with violations costing up to $53,088 per message — the process treats explicit consent as the baseline. Consent is collected through the booking flow, and opt-outs are honored immediately, not within the 10-business-day window CAN-SPAM allows.
This matters even more for texting. US marketing texts require a higher consent standard than email, so collecting explicit permission upfront protects campaigns across every channel — calls, texts, and emails alike. As one privacy expert puts it, opt-outs should be easy and clearly marked, and businesses should never add people to lists without permission.
Here's how the permission-based process works in practice:
- Real customer lists only — outreach runs from your existing CRM, spreadsheet, or point-of-sale list, never purchased data.
- Explicit consent at booking — every contact has a documented relationship with your business before a single message goes out.
- Immediate opt-out honoring — suppression happens the moment someone says stop, exceeding the legal deadline.
- Owner-approved messaging — you sign off on every script and offer, so nothing sends without your review.
The result is outreach that feels like a natural extension of the customer relationship, not a cold blast. A seasonal reminder to a past HVAC customer or a follow-up on an old quote lands as genuinely useful rather than pushy — because the recipient actually knows your business. With 95% of customers saying they won't buy from companies that mishandle their data, treating compliance as a trust signal rather than a checkbox becomes a genuine competitive advantage. For service businesses that live on repeat work, that trust is the whole game.
Frequently Asked Questions
Is it actually illegal to send cold marketing emails in the US, or is that just a myth?
Why do I keep hearing I need opt-in consent if US law only requires opt-out?
What's the real risk of using a purchased email list for my reactivation campaign?
How do email consent rules differ from texting rules in the US — aren't they the same thing?
If I only email past customers who already know my business, do I still need to worry about consent laws?
What happens if someone opts out — do I really have to stop emailing them within 10 days?
Why Permission-Based Outreach Wins Every Time
As we’ve seen, the legality of unsolicited marketing emails hinges on geography — permitted under CAN-SPAM in the U.S. with specific safeguards, but prohibited without explicit consent in markets governed by GDPR, CASL, and similar laws. What remains constant, however, is the power of permission: reaching out only to real customers who’ve engaged with your business isn’t just compliant, it’s effective. By honoring opt-outs immediately, using verified lists, and aligning email and texting practices around explicit consent — as CallMyCustomers does through booking flow approvals and immediate suppression — you turn regulatory adherence into stronger relationships and higher engagement. For service businesses built on repeat work, that trust is the foundation of sustainable revenue. Ready to reactivate your past customers the right way? Start with a free list review to see who’s ready to re-engage — no purchase, no risk, just clarity on your opportunity.