Updated July 2026
Yes — cold email is legal in the US, UK, EU & Canada if you follow the rules. See CAN-SPAM's $53,088 per-email fine, GDPR's B2B rules + a compliance checklist.
Yes — cold email is legal in the United States and most other countries, as long as you follow each country's anti-spam rules.
In the US, the CAN-SPAM Act lets you email people without their prior permission — you just need truthful headers and subject lines, a physical address, and a working way to opt out. In the UK and EU, B2B cold email is generally lawful under "legitimate interest". Canada is the strictest and requires consent first.
I'm the founder of Emailchaser, a cold email software, so I've spent years sending cold email inside these rules — and helping thousands of customers do the same.
Here's everything you need to know about sending cold emails legally in 2026:
- Is cold email legal? The short answer
- Cold email vs spam: what's the difference?
- Is cold emailing illegal?
- United States: the CAN-SPAM Act
- US state laws: the new lawsuit risk (Washington & California)
- United Kingdom: PECR + UK GDPR
- European Union: GDPR + ePrivacy
- Canada: CASL
- Google, Yahoo & Microsoft rules (not laws, but enforced faster)
- How to send cold emails legally: 7-point checklist
Disclaimer: I'm a founder, not a lawyer. This article is general information, not legal advice, and laws change — check the current rules in your jurisdiction (and your lawyer) before sending.
Cold email is legal in the US, UK, EU, Canada and Australia when you do three things: target relevant business addresses, tell the truth about who you are and why you're writing, and give recipients an easy way to opt out (then honor it). It becomes illegal when it's deceptive, ignores opt-outs, or goes to consumers in countries that require consent first.
Here's how the major jurisdictions compare as of 2026:
| Jurisdiction | Main law | Consent needed first? | Maximum penalty (as of 2026) |
|---|---|---|---|
| United States | CAN-SPAM Act | No — opt-out regime | Up to $53,088 per email (FTC) |
| European Union | GDPR + ePrivacy | Consumers: yes. B2B: often "legitimate interest" instead | Up to €20M or 4% of global turnover |
| United Kingdom | UK GDPR + PECR | Individuals: yes. Corporate subscribers: exempt from the consent rule | ICO enforcement (fines + enforcement notices) |
| Canada | CASL | Yes — express or implied | Up to CAD $10M per violation (organizations) |
| Australia | Spam Act 2003 | Yes — express or inferred | ACMA enforcement |
This article is the overview. If you want the full per-country detail — consent types, sender obligations, enforcement bodies and penalties for each jurisdiction — read my complete reference: Cold Email Laws by Country.
A cold email is an unsolicited email sent to someone you've had no prior contact with. That alone does not make it spam — or illegal.
Spamhaus defines spam as: "An electronic message is "spam" if (A) the recipient's personal identity and context are irrelevant because the message is equally applicable to many other potential recipients; AND (B) the recipient has not verifiably granted deliberate, explicit, and still-revocable permission for it to be sent."
An email needs all three of the following characteristics to be spam:
A well-sent cold email is unsolicited, but it's targeted at one researched person, relevant to their role, and easy to decline. That's why cold emails, when sent correctly, land in the primary inbox — while spam lands in the junk folder.
Spam characteristics: bulk, identical, irrelevant, sent to personal addresses, no opt-out.
Cold email characteristics: targeted, personalized, relevant to the recipient's business, sent to a work address, with a clear way to opt out. (You can read my other article on whether you need an unsubscribe link in cold emails.)
No — cold emailing is not illegal in the US, UK, EU, Canada or Australia. What's illegal is how some people do it.
Cold email crosses into illegal territory when you:
Stay on the right side of those lines and unsolicited B2B email is a legal, standard sales channel. Now let's go country by country.
Cold email is legal in the United States. You do not need the recipient's permission before emailing them.
The CAN-SPAM Act is an opt-out regime: it regulates all commercial email (not just bulk email), and each separate email that violates it can cost up to $53,088 — that's the FTC's current inflation-adjusted maximum per email, as of mid-2026. The FTC adjusts this figure annually, and it applies per message, so one bad campaign to 5,000 people is 5,000 potential violations.

This is the part most 2026 guides still miss: CAN-SPAM preempts most state spam laws, except state laws that target falsity or deception — and those state laws are now where the real litigation is.
The takeaway for cold emailers: a deceptive subject line isn't just an FTC problem anymore — it's a class-action problem. Write subject lines that are plainly true. (Here's how to write ones that still get opens: cold email subject lines.)
Cold email is legal in the United Kingdom — and the UK is actually one of the friendlier jurisdictions for B2B cold email.

The Privacy and Electronic Communications Regulations (PECR) require consent before sending marketing email to individual subscribers (personal addresses, sole traders and some partnerships). But corporate subscribers — employees at limited companies — are exempt from that consent rule, which is what makes B2B cold email workable in the UK.
Two caveats:
Cold email is legal in the European Union for B2B — but you need to do it properly, because the GDPR treats a named person's work email address as personal data.

GDPR doesn't ban cold email; it requires a lawful basis for processing personal data. For B2B outreach, most senders rely on legitimate interest — GDPR's Recital 47 explicitly says direct marketing "may be regarded as carried out for a legitimate interest". Consumers are different: marketing to individuals generally requires consent.
To rely on legitimate interest you should:
The stakes are the highest of any jurisdiction: GDPR fines can reach €20 million or 4% of global annual turnover, whichever is higher. Each EU member state also layers its own ePrivacy rules on top — my Cold Email Laws by Country guide covers the differences.
Canada has the strictest general anti-spam law: CASL requires consent before you send a commercial electronic message — and the burden of proving consent sits on you, the sender.

Cold email to Canada is still possible under implied consent, which covers narrow cases such as an existing business relationship, or a business email address that's conspicuously published (or given to you) without a no-marketing note — provided your message is relevant to the person's role.
Every message must also fully identify you, include accurate contact information, and contain a working unsubscribe that you honor within 10 business days.
Penalties are serious: administrative monetary penalties reach up to CAD $1 million per violation for individuals and CAD $10 million per violation for organizations, and executives can be personally liable. If you email Canadians, keep records of exactly why each recipient falls under implied consent.
Even where the law is on your side, the mailbox providers have their own rules — and they enforce them in real time by blocking your email, which in practice hurts more than a hypothetical fine.
Since February 2024, Google and Yahoo require senders of roughly 5,000+ emails per day to their users to:
Microsoft began enforcing similar requirements for high-volume senders to Outlook in May 2025.
For cold emailers the practical rules are: authenticate every sending domain, keep volume per inbox low, and target narrowly enough that nobody hits "report spam". If you send bulk or marketing mail alongside cold outreach, you can build compliant one-click headers with our free List-Unsubscribe Header Generator, and my deliverability guide covers the rest.
Laws differ by country, but if you follow these seven rules you'll be compliant almost everywhere:
No. Cold emailing is legal in the US, UK, EU, Canada and Australia — what's illegal is deceptive cold email: false sender information, misleading subject lines, no opt-out, or emailing consumers without consent in consent-required countries.
No, not by themselves. In the US, the CAN-SPAM Act explicitly permits unsolicited commercial email as long as you use truthful headers and subject lines, include a physical address and opt-out, and honor opt-outs within 10 business days. Canada and (for individuals) the EU and UK require consent or another lawful basis.
In the US, no — permission is not required, only compliance with CAN-SPAM's rules. In Canada you generally need express or implied consent (CASL), and in the EU/UK you need consent for consumers or a documented legitimate interest for B2B contacts.
Under CAN-SPAM you must provide a clear opt-out mechanism, but it doesn't have to be a link — for cold email, a reply-based opt-out like "just reply 'no thanks'" satisfies the law. Separately, Google and Yahoo require one-click unsubscribe headers for bulk senders (5,000+ emails/day), which is a deliverability requirement rather than a law.
Yes. B2B cold email is legal in the US under CAN-SPAM, workable in the UK thanks to PECR's corporate-subscriber exemption, generally lawful in the EU under GDPR's legitimate-interest basis, and possible in Canada under CASL's implied-consent categories — provided you identify yourself, stay honest, and honor opt-outs.
Yes, for B2B. GDPR's Recital 47 recognizes direct marketing as a possible legitimate interest, so you can email relevant business contacts without prior consent if you document a legitimate interest assessment, target narrowly, identify yourself, and offer an easy opt-out. Marketing to consumers generally requires consent.
Cold email is legal — spam is not. The difference comes down to targeting relevant business addresses, being honest about who you are, and making it easy to say no.
An email only becomes illegal spam when it's deceptive, ignores opt-outs, or is blasted without consent to people (especially consumers) who could never benefit from it.
I built Emailchaser around the compliant workflow: find targeted leads, double-verify every address, personalize at scale, and suppress opt-outs automatically with the block list. You can see how it works on the cold email software page and try it with a 7-day free trial.
Related reading:
Free tool
Check your email for spam words
Scan your cold email for spam trigger words that send messages to spam, then fix them before you send.
Try the spam word checkerFree tool
Verify an email address for free
Check whether an email address is valid and safe to send to before you launch your cold email campaign.
Try the free email verifierArticle by
George Wauchope
Founder of Emailchaser.
I have been working in the sales & marketing industry for nearly a decade.
When I’m not working on my business, I enjoy eating sushi & doing jiu-jitsu.
Address: 151 Calle de San Francisco San Juan, Puerto Rico
Email: support@emailchaser.com
Product
Cold Email SoftwareEmail FinderCampaignsSales CRMLead FinderEmail AccountsEmail VerifierCold Email APIMCP ServerAPI documentationWho it's for
FreelancersFoundersSales teamsMarketing agenciesRecruitment agenciesLead generation agenciesComparisons
Best cold email softwareInstantly alternativesSmartlead alternativesInstantly vs EmailchaserSmartlead vs EmailchaserHunter vs EmailchaserFree tools
All free toolsBulk Email VerifierDeliverability TestEmail Header AnalyzerSMTP Settings FinderCold Email TemplatesBoolean Search BuilderName SplitterCompany Email FormatSpam Word CheckerInternational
Cold email (ES)Cold email (FR)Cold email (DE)Cold email (IT)Cold email (PT)Verifica email (IT)© Copyright 2026 Emailchaser