
What are the legal requirements for email marketing?
Key Facts
- Each CAN-SPAM violation can cost up to $53,088 per email according to FTC enforcement FTC CAN-SPAM Compliance Guide
- Opt-out requests must be honored within 10 business days with no fees or extra steps Usercentrics CAN-SPAM Compliance
- Unsubscribe links must remain functional for at least 30 days after sending an email Usercentrics CAN-SPAM Compliance
- 72% of US consumers mark unwanted emails as spam, even if legally compliant Usercentrics CAN-SPAM Compliance
- 7 in 10 consumers prefer email as their primary channel to hear from brands Usercentrics CAN-SPAM Compliance
- Verkada paid $2.95 million for thousands of noncompliant CAN-SPAM emails Usercentrics CAN-SPAM Compliance
- Experian was fined $650,000 for missing opt-out links in marketing emails Usercentrics CAN-SPAM Compliance
The CAN-SPAM Act: Core Legal Requirements for Commercial Email
The CAN-SPAM Act sets the baseline for every commercial email sent in the United States, and the cost of ignoring it is steep — up to $53,088 per violating email according to the FTC. Unlike GDPR or CASL, this law operates on an opt-out model: you do not need prior consent to email, but you must give recipients a clear way to stop hearing from you. For service businesses running reactivation campaigns, that distinction shapes every list upload and every send.
The Act applies to any message whose primary purpose promotes a product or service, including B2B outreach and emails driving traffic to commercial content. Compliance starts with transparency: header information — From, To, Reply-To, and routing data — must accurately identify the sender. Subject lines cannot be deceptive; they must reflect what the email actually contains. Every commercial message must also include a valid physical postal address and a clear, conspicuous disclosure that the email is an advertisement.
- Accurate sender identification in all header fields
- Non-deceptive subject lines that match the email content
- Clear advertisement disclosure
- Valid physical postal address
- Functional opt-out mechanism honored within 10 business days
The opt-out mechanism is where many campaigns stumble. Recipients must be able to unsubscribe with a single click or reply — no fees, no extra steps, no login required. Once a request arrives, you have 10 business days to honor it, and the unsubscribe link must stay live for at least 30 days after the email is sent. The FTC has enforced this aggressively: Experian paid $650,000 for missing opt-out links, and Verkada faced a $2.95 million penalty for thousands of noncompliant messages.
Liability extends beyond your own sends. If a third-party affiliate markets on your behalf and violates CAN-SPAM, your business can be held responsible — contractual clauses do not shield you. That matters when you work with partners to reach past customers. At CallMyCustomers, every reactivation campaign runs on lists of real customers who have done business with you, opt-outs are honored immediately, and every message is approved before it goes out. Permission-based reactivation isn't just safer — it's the only way to protect the relationships you've built.
Why Consent Matters Even When Not Legally Required Under CAN-SPAM
Even when not legally required under CAN-SPAM, obtaining consent before sending marketing emails delivers significant strategic advantages for businesses focused on long-term customer relationships. CallMyCustomers’ reactivation model thrives on permission-based outreach, recognizing that trust and relevance drive better results than volume alone. While CAN-SPAM allows senders to email commercial messages without prior opt-in, relying solely on an opt-out model increases the risk of spam complaints and reputational harm, especially when recipients didn’t expect the communication. Research shows that 72 percent of US consumers are ready to mark unwanted or irrelevant emails as spam, highlighting how even legally compliant emails can damage engagement if perceived as intrusive. Adopting opt-in standards aligns with stricter global regulations like GDPR and CASL, reducing compliance complexity for businesses that may serve international customers or plan to expand beyond U.S. borders. This proactive approach also future-proofs marketing efforts against evolving privacy laws that increasingly prioritize consumer permission. Beyond legal alignment, permission-based practices foster stronger consumer trust — a critical factor when re-engaging past customers who may have lapsed due to neglect, not dissatisfaction. By ensuring recipients have explicitly agreed to hear from a business, companies improve open rates, reduce unsubscribe requests, and enhance the overall quality of their email list. For service businesses where repeat work hinges on reliability and familiarity, this trust translates directly into higher reactivation success. Ultimately, choosing consent even when not mandated isn’t just about avoiding penalties — it’s about building a sustainable, respectful channel that turns inactive contacts into loyal, booked customers. Consumer behavior data indicates that seven in ten consumers say email is their preferred way to hear from a brand, making permission-based outreach not only compliant but also more effective.
- Honor opt-out requests within 10 business days without fees or extra steps
- Maintain a functional opt-out mechanism for at least 30 days after sending
- Use accurate header information and non-deceptive subject lines
- Clearly identify emails as advertisements and include a valid physical address
- Adopt permission-based practices to align with GDPR and CASL, even when not required by CAN-SPAM
Practical Compliance Steps for Service Businesses Running Reactivation Campaigns
Practical Compliance Steps for Service Businesses Running Reactivation Campaigns
For US service providers, reactivation campaigns offer a powerful way to re-engage past customers without the cost of acquiring new leads. However, even permission-based outreach must comply with the CAN-SPAM Act to avoid significant penalties. Every commercial email must include accurate header information, a non-deceptive subject line, clear identification as an advertisement, and a valid physical postal address. Additionally, opt-out mechanisms must remain functional for at least 30 days after sending and be honored within 10 business days.
CallMyCustomers integrates these requirements into its done-for-you process by starting with a free list review that segments contacts by recency, old quotes, or expiring memberships. This segmentation ensures messages feel relevant and useful, reducing the likelihood of spam complaints. Before any outreach begins, the business owner approves every script, offer, and message — maintaining control while leveraging automation for scale.
To further reduce risk, businesses should implement a message approval workflow that verifies CAN-SPAM compliance before sending. This includes checking for clear opt-out links, accurate sender details, and truthful subject lines. Opt-out requests must be routed directly into the booking or CRM system to ensure immediate suppression from future campaigns. For affiliate or partner-driven campaigns, contractual compliance clauses and active monitoring are essential, as both the business and third parties can be held liable for violations.
By aligning reactivation efforts with these practical steps, service businesses can turn dormant customers into booked appointments — safely, legally, and with the owner’s final say on every message sent.
Frequently Asked Questions
Do I need someone's permission before sending them a marketing email in the US?
How much can I actually be fined for violating CAN-SPAM?
What has to be included in every commercial email to be compliant?
How quickly do I have to honor an unsubscribe request?
Can I get in trouble if a marketing partner or affiliate sends noncompliant emails for me?
Is it risky to email past customers who never explicitly opted in?
Compliance Is the Floor — Trust Is the Strategy
The legal requirements for email marketing are straightforward once you know them: accurate sender information, honest subject lines, clear advertisement disclosure, a valid physical address, and an opt-out mechanism honored within 10 business days and kept live for at least 30 days after sending. The stakes are real — the FTC can impose penalties of up to $53,088 per violating email — and liability extends to affiliates marketing on your behalf. But the smartest service businesses go beyond the legal minimum. Since 72 percent of US consumers will mark unwanted emails as spam, permission-based outreach to people who already know your business isn't just safer legally — it's what actually gets replies and booked appointments. Before your next campaign, audit your list for real customer relationships, review your opt-out process, and confirm every message meets CAN-SPAM basics. If you'd rather focus on the work while a team handles the compliance details — with you approving every message before it goes out — CallMyCustomers offers a free list review that shows exactly what your past customers could produce before you spend a dollar.