Cold email is legal in most places, provided you follow the rules, and the rules differ by jurisdiction. This is a neutral reference to how cold email is regulated in the United States, the EU and UK, Canada, and Australia, with a comparison table and a compliance checklist. It is general information, not legal advice.
Cold email is a message sent to a business contact you have no prior relationship with, for a legitimate business purpose. Spam, by contrast, is bulk, unsolicited, and frequently deceptive email sent indiscriminately. The distinction matters legally, because every major framework below is aimed at the behaviors that define spam rather than at outreach as such. Three behaviors separate the two in practice:
None of the laws described here bans cold email outright. They set conditions: tell the truth about who you are, make the message identifiable as commercial, respect the recipient's ability to refuse, and, in consent-based jurisdictions, have a lawful reason to email that person in the first place.
The Controlling the Assault of Non-Solicited Pornography And Marketing Act, known as CAN-SPAM, was signed into law in 2003 and took effect on January 1, 2004. It was the first national US standard for commercial email and it preempted a patchwork of state anti-spam laws. The Federal Trade Commission (FTC) is the primary enforcer, with additional authority for other federal agencies over the sectors they regulate and a limited right of action for internet service providers. It applies to commercial email generally: business-to-business messages are covered just as consumer messages are.
The FTC's compliance guide for business distills the statute into seven obligations for any commercial message:
Liability under CAN-SPAM is deliberately broad. Both the company whose product or service is promoted and the company that actually transmits the message can be legally responsible, so a business cannot outsource its exposure to a lead generation agency or a sending vendor. More than one party can be on the hook for the same email.
CAN-SPAM is often misread as an opt-in law. It is not. It does not require prior consent before the first email, does not require permission to be documented, and does not restrict who may be emailed. It also does not require that the opt-out be a link: a monitored reply address can satisfy the statute. What it polices is deception and the refusal to let recipients say no. This is the key structural difference between the US regime and the consent-based regimes described below.
Penalties are assessed per email, not per campaign. The statutory civil penalty is adjusted for inflation and currently exceeds $50,000 per violating message. The arithmetic is what makes the statute bite: a single send of 1,000 emails that all omit a postal address is, on paper, 1,000 separate violations, so the theoretical ceiling for that one campaign runs to eight figures. Actual FTC settlements are far below theoretical ceilings, but the per-email structure explains why bulk senders treat even small template mistakes as serious. Deceptive practices can also trigger aggravated penalties, and certain conduct (such as harvesting addresses or falsifying headers at scale) can carry criminal consequences under related provisions.
In Europe two layers of law apply at once. The General Data Protection Regulation (GDPR), in force since May 2018, governs any processing of personal data. The ePrivacy Directive of 2002 governs electronic marketing specifically, and each EU member state implements it in national law; the UK implementation is the Privacy and Electronic Communications Regulations (PECR), which continue to apply alongside the UK GDPR after Brexit. A cold email campaign into the EU or UK must satisfy both layers, and the marketing layer differs slightly from country to country.
GDPR defines personal data as any information relating to an identified or identifiable natural person. A generic inbox such as info@company.com is generally not personal data, but jane.doe@company.com identifies a person and therefore is. That means finding, storing, and emailing a named prospect's work address is processing personal data, and the sender needs a lawful basis for it, a privacy notice that covers it, and processes to honor rights such as access, erasure, and objection.
GDPR offers six lawful bases; for cold outreach the realistic candidates are consent and legitimate interest. Recital 47 of the GDPR notes that direct marketing may be a legitimate interest, but relying on it is not automatic. Regulators expect a documented three-part assessment: identify the interest (for example, marketing a relevant product to businesses), show that emailing this person is necessary for it, and balance it against the recipient's rights and reasonable expectations. A sales director being contacted about sales software sits very differently in that balance than a consumer being contacted from a scraped list. Recipients always retain an absolute right to object to direct marketing, and an objection must stop the emails.
The ePrivacy layer adds two practically important carve-outs. The first is the soft opt-in: an organization may email marketing to its own existing customers about similar products without fresh consent, provided the address was collected during a sale or sale negotiation and every message offers an opt-out. The second, in the UK, is the corporate subscriber exception: PECR's consent rule for unsolicited marketing email protects individual subscribers, so email sent to a corporate subscriber (a company's own domain) is outside that specific consent requirement. This is the main reason B2B cold email is workable in the UK. The exception has limits: sole traders and some partnerships count as individuals, the UK GDPR still governs the personal data of a named employee, and several EU member states apply consent rules to business recipients too, so the position varies across Europe.
GDPR fines can reach 20 million euros or 4 percent of worldwide annual turnover, whichever is higher, with a lower tier for less serious infringements. In the UK, the Information Commissioner's Office (ICO) enforces both regimes and can currently fine up to 500,000 pounds under PECR in addition to UK GDPR penalties. In practice, ICO enforcement against email marketers has concentrated on senders who bought lists, ignored objections, or could not evidence consent; documented, targeted, low-volume B2B outreach with a clean opt-out has drawn far less action. That is an observation about enforcement patterns, not a safe harbor.
Canada's Anti-Spam Legislation (CASL) came into force on July 1, 2014 and is generally regarded as the strictest general-purpose email law in the world. It covers commercial electronic messages of any kind sent to or from Canada, and its starting position is a prohibition: no commercial message may be sent without consent plus prescribed identification and unsubscribe content. Enforcement is led by the Canadian Radio-television and Telecommunications Commission (CRTC), with roles for the Competition Bureau and the Privacy Commissioner.
Express consent means the recipient actively agreed to receive commercial messages, with a clear request that named the sender and the purpose; it does not expire. Implied consent exists only in defined situations, chiefly an existing business relationship (for example a purchase within the previous two years, or an inquiry within the previous six months). A third route matters for B2B senders: the conspicuous publication exception. If a person has conspicuously published their business email address, or given it to the sender, without a statement that they do not want unsolicited messages, and the message is relevant to their business role, consent can be implied. The burden of proving consent always sits with the sender, which is why CASL compliance in practice means keeping records of where every address came from and when.
Every message must identify the sender (and anyone on whose behalf it is sent) by name, include a current mailing address plus a phone number, email address, or web address, and contain an unsubscribe mechanism that can be used in no more than two clicks. The unsubscribe must remain functional for at least 60 days after the message is sent, and requests must be honored within 10 business days.
Administrative monetary penalties under CASL can reach 1 million Canadian dollars per violation for individuals and 10 million Canadian dollars per violation for organizations. The CRTC has issued multimillion-dollar penalties and negotiated substantial settlements since 2014. Directors and officers can be personally liable in some circumstances, which is unusual among email laws and adds to CASL's reputation for strictness.
Australia's Spam Act 2003 predates CAN-SPAM by a few weeks and takes the opposite approach: it is consent-based. A commercial electronic message may be sent only with the recipient's consent, which may be express or inferred. Consent can be inferred from an existing business relationship, or from a business email address that was conspicuously published, provided the message is relevant to the recipient's role and the publication did not say unsolicited messages were unwanted. Every message must accurately identify the sender and include a functional unsubscribe facility that works for at least 30 days and is honored within 5 business days. The Australian Communications and Media Authority (ACMA) enforces the Act and has imposed penalties on major brands; for repeated contraventions, penalties can run to millions of Australian dollars.
Most developed economies now have an analogous regime, usually closer to the consent-based model than to CAN-SPAM. Examples include Singapore's Spam Control Act and Personal Data Protection Act, Japan's Act on Regulation of Transmission of Specified Electronic Mail, Brazil's LGPD data protection law, and South Africa's POPIA. The recurring pattern across nearly all of them is the same triad: identify yourself truthfully, have some justification for the contact, and provide a working opt-out. A sender who builds for that triad, and then layers the stricter consent rules on top for the jurisdictions that demand them, is aligned with most of the world's rules by default.
| Jurisdiction | Main law | Regime type | Key requirements | Enforcement body |
|---|---|---|---|---|
| United States | CAN-SPAM Act (2003) | Opt-out | Truthful headers and subject lines, ad identification, physical postal address, opt-out honored within 10 business days | Federal Trade Commission (FTC) |
| European Union | GDPR + ePrivacy Directive | Consent-based, with legitimate interest available for some B2B | Lawful basis for personal data, consent for individuals, sender identification, right to object | National data protection authorities |
| United Kingdom | UK GDPR + PECR | Consent-based, with a corporate subscriber exception | Consent for individual subscribers, soft opt-in for existing customers, identification, opt-out in every message | Information Commissioner's Office (ICO) |
| Canada | CASL (2014) | Consent-required | Express or implied consent, full sender identification, unsubscribe honored within 10 business days | CRTC (with the Competition Bureau and Privacy Commissioner) |
| Australia | Spam Act 2003 | Consent-required | Express or inferred consent, sender identification, functional unsubscribe honored within 5 business days | Australian Communications and Media Authority (ACMA) |
Three technical standards sit alongside the legal rules. SPF (Sender Policy Framework) lets a domain publish which servers may send email on its behalf. DKIM (DomainKeys Identified Mail) adds a cryptographic signature that proves a message was not altered and really comes from the signing domain. DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the two together, telling receiving servers what to do with mail that fails and reporting abuse back to the domain owner.
Authentication connects to the law in two ways. First, laws such as CAN-SPAM prohibit false or misleading header information, and properly configured SPF, DKIM, and DMARC are how a sender demonstrates at the protocol level that its headers are genuine. Second, authentication has become a de facto sending requirement regardless of law: in 2024 Google and Yahoo began requiring bulk senders to authenticate with SPF, DKIM, and DMARC, to support one-click unsubscribe, and to keep spam complaint rates low. A legally compliant cold email that is not authenticated will increasingly never reach an inbox, so in practice the legal checklist and the deliverability checklist have converged.
In most countries cold email is legal for legitimate business purposes if you follow the applicable rules: identify yourself, tell the truth, and give a working way to opt out. The United States uses an opt-out model (CAN-SPAM), while Canada (CASL), Australia (Spam Act 2003), and, for most individual recipients, the EU and UK (GDPR and ePrivacy rules) require some form of consent or another lawful basis before sending.
No. The US CAN-SPAM Act is an opt-out regime: it does not require prior consent, but it does require accurate header and sender information, a non-deceptive subject line, a valid physical postal address, and a working opt-out that is honored within 10 business days.
Spam is bulk, unsolicited, and often deceptive email sent indiscriminately. Compliant cold email is targeted, identifies the sender truthfully, is relevant to the recipient's role or business, and offers a clear way to opt out. The legal frameworks in most countries are designed to police deception and disregard for consent, not to ban one-to-one business outreach.
It can be. GDPR does not name email channels; it requires a lawful basis for processing personal data, and a work email that identifies a person counts as personal data. Many B2B senders rely on the legitimate interest basis, which requires a documented balancing of the sender's interest against the recipient's rights, plus the ePrivacy or PECR marketing rules of the recipient's country. Marketing to individual consumers generally requires consent.
No. CAN-SPAM applies to commercial email regardless of whether the recipient is a business or a consumer. CASL and Australia's Spam Act apply to commercial electronic messages generally. In the UK, PECR's consent rule targets individual subscribers rather than corporate subscribers, which gives B2B senders more room, but GDPR still governs any personal data involved, including a named person's work email address.
Ceilings vary widely. Under CAN-SPAM, each non-compliant email can carry a civil penalty that currently exceeds $50,000. Under GDPR, fines can reach 20 million euros or 4 percent of worldwide annual turnover, whichever is higher. Under CASL, administrative penalties can reach 10 million Canadian dollars per violation for organizations. Actual enforcement outcomes are usually far below these ceilings, but the ceilings shape risk.
Indirectly. SPF, DKIM, and DMARC are technical standards that let receiving servers verify a message really comes from the domain it claims. They support the accurate-header requirements found in laws like CAN-SPAM, and since 2024 Google and Yahoo have required bulk senders to authenticate with them, so unauthenticated cold email increasingly fails on deliverability before any legal question arises.
Canada's CASL is widely considered the strictest general regime: it requires express or narrowly defined implied consent before sending, places the burden of proving consent on the sender, and carries administrative penalties of up to 10 million Canadian dollars per violation for organizations. The EU and UK rules are also strict for individual recipients, with more flexibility for business-to-business messages.
This reference page is maintained by Emailchaser, a cold email platform. It is general information and not legal advice; consult qualified counsel for your situation.
Address: 151 Calle de San Francisco San Juan, Puerto Rico
Email: support@emailchaser.com
Product
Cold Email SoftwareEmail FinderCampaignsSales CRMLead FinderEmail AccountsEmail VerifierCold Email APIMCP ServerAPI documentationWho it's for
FreelancersFoundersSales teamsMarketing agenciesRecruitment agenciesLead generation agenciesComparisons
Best cold email softwareInstantly alternativesSmartlead alternativesInstantly vs EmailchaserSmartlead vs EmailchaserHunter vs EmailchaserFree tools
All free toolsBulk Email VerifierDeliverability TestEmail Header AnalyzerSMTP Settings FinderCold Email TemplatesBoolean Search BuilderName SplitterCompany Email FormatSpam Word CheckerInternational
Cold email (ES)Cold email (FR)Cold email (DE)Cold email (IT)Cold email (PT)Verifica email (IT)© Copyright 2026 Emailchaser