
What law covers unsolicited emails?
Key Facts
- Each violating email under the CAN-SPAM Act can carry a civil penalty of up to $53,088, according to the FTC.
- The FTC's largest-ever CAN-SPAM penalty was $2.95 million against Verkada, per FKKS legal analysis.
- CAN-SPAM is an opt-out law requiring no prior consent — the most lenient of the three major email laws, Relationship One reports.
- CAN-SPAM opt-out requests must be honored within 10 business days, with the mechanism active for at least 30 days after sending, per FTC guidance.
- GDPR fines reach €20 million or 4% of annual global turnover — whichever is higher — Emailchef explains.
- Canada's CASL imposes fines up to $10 million CAD for businesses and has been fully enforced since 2016, per legal analysis.
- The FTC makes clear that CAN-SPAM liability cannot be delegated — both the promoter and the sender can be held responsible, per its compliance guide.
The Compliance Minefield of Reaching Out to Past Customers
You have a list of past customers, a stack of quotes that never became jobs, and a real fear that reaching out could land you in legal trouble. That tension keeps a lot of service businesses sitting on revenue they already earned the right to pursue.
Here's the good news: the primary U.S. law governing unsolicited commercial email — the CAN-SPAM Act of 2003 — is an opt-out law, not an opt-in law. According to the FTC's compliance guide, no prior consent is required to email a customer. Legal analyses describe it as the most lenient of the major email laws, in contrast to opt-in regimes like GDPR and Canada's CASL. Reconnecting with someone who already did business with you is squarely within the law's design.
But the stakes are real. Each violating email can carry a civil penalty of up to $53,088, and the FTC's largest CAN-SPAM penalty ever — $2.95 million against Verkada — shows the agency actively enforces this law. And a common misconception creates hidden risk: CAN-SPAM covers all commercial messages, not just bulk spam. A single follow-up email to one past customer about an old quote counts.
The core requirements are straightforward:
- Accurate header information and non-deceptive subject lines
- Clear identification that the message is an advertisement
- A valid physical postal address in every email
- A working opt-out mechanism, honored within 10 business days and kept active for at least 30 days
One more wrinkle matters if you outsource outreach: the FTC is explicit that legal responsibility cannot be delegated. Both the business promoting the product and the party actually sending the email can be held liable. That's why CallMyCustomers works only from lists of real customers, honors opt-outs immediately, and has the owner approve every message before anything goes out — compliance is built into the campaign, not bolted on.
Understanding the rules is the first step; the next is knowing exactly what each requirement demands of your outreach.
CAN-SPAM's Five Non-Negotiable Rules (Plus the Opt-Out Clock)
The CAN-SPAM Act doesn't ask for permission before you hit send — it demands accountability after. That distinction makes it the most lenient of the three major email laws, operating on an opt-out model rather than requiring prior consent like GDPR or CASL. For U.S. service businesses running reactivation campaigns, understanding these rules isn't optional. The FTC enforces them with penalties reaching $53,088 per violating email, and both the promoter and the actual sender can be held liable.
Every commercial message must satisfy five non-negotiable requirements. Header information must be accurate and identify the actual sender. Subject lines cannot be deceptive — they must reflect the email's true content. The message must clearly identify itself as an advertisement. A valid physical postal address must appear in every email. And a functional opt-out mechanism must be included, free of fees or demands for extra personal data beyond the email address itself. FTC guidance makes clear that legal responsibility cannot be delegated to a third-party provider.
- Accurate header information identifying the true sender
- Non-deceptive subject lines reflecting actual content
- Clear identification as an advertisement
- Valid physical postal address in every message
- Free, simple opt-out mechanism requiring only an email address
The opt-out clock starts ticking the moment a recipient clicks unsubscribe. Requests must be honored within 10 business days, and the opt-out mechanism itself must remain active for at least 30 days after the message is sent. No fees, no login requirements, no friction. This applies even when emails are sent through a done-for-you service — the business whose name appears in the "from" line retains full legal exposure.
Transactional emails like appointment confirmations and reminders occupy a narrower lane. They're exempt from most CAN-SPAM requirements only if they contain purely non-commercial content — no upsells, no promotional offers, no "while we have you" cross-sells. iContact notes that even transactional messages must still maintain accurate sender information and truthful subject lines. Add a single promotional element, and the full compliance burden snaps into place. For reactivation campaigns that blend service reminders with special offers, the safest path is treating every message as commercial.
Why You Can't Outsource Legal Responsibility — Even to a Service Like Ours
Many businesses assume hiring an email service shields them from legal risk. The FTC makes clear that liability under CAN-SPAM cannot be delegated — both the company promoting the product and the actual mailer can be held responsible for every violating message, with civil penalties reaching up to $53,088 per email. That shared liability is exactly why we built compliance into every layer of our done-for-you campaigns instead of treating it as a checkbox.
We send emails in your business name, not ours. Every script, offer, and subject line is approved by you before a single message goes out. Our lists contain only your real customers — people who have already done business with you — and every opt-out is honored immediately, well within the 10-business-day window the law requires. The physical postal address in each footer is yours, the header information is accurate, and the message is clearly identified as commercial content.
- Owner-approved scripts and offers before any outreach begins
- Real-customer lists only — no purchased or scraped data
- Opt-outs processed instantly and permanently
- Messages sent in your business name with your contact details
This structure keeps you in control while we handle the execution. The FTC's record $2.95 million penalty against Verkada shows enforcement is real and consequences are severe. When you work with CallMyCustomers, compliance isn't outsourced — it's engineered into the process so both of us stay on the right side of the law.
Beyond CAN-SPAM: When CASL and GDPR Enter the Picture
CAN-SPAM may be the baseline for U.S. email compliance, but it's far from the only law that can apply to your outreach. If your customer list includes contacts in Canada or the European Union, two much stricter frameworks take over — and they don't care where your business is headquartered.
The fundamental difference comes down to consent. CAN-SPAM operates on an opt-out model, meaning you can email first and give recipients a way to unsubscribe later. By contrast, both Canada's CASL and the EU's GDPR require opt-in consent before any commercial message is sent. Relationship One describes CAN-SPAM as "the most lenient of the three laws and the only one that is an opt-out law," a distinction that carries serious financial weight.
The penalty gap is striking. CAN-SPAM violations can cost up to $53,088 per email according to FTC guidance, but CASL pushes that ceiling to $10 million CAD for businesses, while GDPR tops out at €20 million or 4% of annual global turnover — whichever is higher. For a U.S. service business reactivating past customers, these aren't abstract risks. If a single Canadian homeowner or EU-based clinic patient is on your list, the stricter standard applies to that contact.
- CASL requires documented express or implied consent and has been in full effect since 2016
- GDPR demands explicit, freely given opt-in with full data transparency, enforceable since May 2018
- Both laws apply based on the recipient's location, not the sender's
- Neither allows the "send first, ask later" approach permitted under CAN-SPAM
Emailchef notes that following the stricter GDPR standard for all email marketing will automatically satisfy most CAN-SPAM requirements — a practical strategy we've adopted at CallMyCustomers. Since we work exclusively from lists of your actual past customers and secure explicit approval on every script and offer before outreach begins, our campaigns are built on permission-first principles that align with the highest standard across all three regimes. That means when you reactivate a dormant HVAC client or follow up on an old dental quote, the compliance groundwork is already handled — no matter where your customer lives.
Your Compliance-First Path to Reactivated Customers
Compliance isn't a hurdle to clear before reactivation — it's the reason reactivation works at all. As one compliance expert puts it, respecting subscribers is about "building long-term trust," not just avoiding penalties. When every message follows the rules, outreach feels like a service, not spam.
A compliant campaign starts before a single email goes out. CallMyCustomers begins with a free list review, segmenting your customer file by recency — 30 days, 6 months, 12+ months — plus old quotes, expiring memberships, and referral-ready customers. You see your rate, setup, and what your list can produce before spending a dollar.
Next comes choosing a legitimate reason to reconnect. A seasonal reminder, a renewal heads-up before a membership lapses, a fresh angle on an old quote — each one answers "why now?" That's what makes a message useful rather than pushy, and it keeps your subject lines honest, which the FTC's CAN-SPAM guide requires anyway.
Then the owner signs off on every message. This matters legally, not just stylistically: the FTC is explicit that liability cannot be delegated — both the business promoting the product and the party sending the email can be held responsible for violations. Owner approval means the business owner knows exactly what's going out in their name, with accurate headers, a real postal address, and a working opt-out honored within 10 business days.
Once outreach runs, replies route directly into your booking process, with confirmations and no-show follow-up built in. Then the follow-up layer keeps customers from going dormant again:
- Post-service thank-yous, review requests, and referral prompts timed to the job
- Seasonal reminders matched to your service cycle
- Renewal outreach that lands before a membership or contract lapses
- Opt-outs honored immediately — a rule the FTC requires within 10 business days, but done faster as a courtesy
The stakes justify the care. CAN-SPAM penalties can run up to $53,088 per violating email, and the FTC's largest CAN-SPAM penalty ever — $2.95 million against Verkada — shows enforcement is active, not theoretical.
Done right, permission-based reactivation is a trust exercise that pays for itself: your next booked customer already knows your business, and the campaign that reaches them is one they're glad to receive.
Frequently Asked Questions
What law covers unsolicited emails in the US?
Do I need permission to email a past customer under CAN-SPAM?
What are the main requirements to comply with CAN-SPAM?
How much can a CAN-SPAM violation actually cost my business?
If I hire a service to send emails for me, does that shift the legal risk to them?
Does CAN-SPAM apply if my list includes Canadian or EU customers?
The Law Is on Your Side — So Is the Revenue Sitting in Your List
Reaching out to past customers isn't the legal minefield many service business owners fear. The CAN-SPAM Act requires no prior consent — just honest headers, truthful subject lines, a clear ad label, a physical address, and a working opt-out honored within 10 business days. The stakes are real: penalties can reach up to $53,088 per violating email, and liability can't be delegated to whoever sends the messages on your behalf. If your list crosses into Canada or the EU, the stricter opt-in standards of CASL and GDPR apply instead. Your next step is simple: audit your outreach against these five requirements, or let someone who has already built compliance into the process handle it. CallMyCustomers works only from your real customer lists, honors opt-outs immediately, and has you approve every message before it goes out — so reconnecting with past customers stays squarely on the right side of the law. Start with a free list review and see what your dormant customers are worth before you spend a dollar.