Is Cold Email Legal? Yes — If You Follow These Rules (2026)

Updated July 2026

Yes — cold email is legal in the US, UK, EU & Canada if you follow the rules. See CAN-SPAM's $53,088 per-email fine, GDPR's B2B rules + a compliance checklist.

Yes — cold email is legal in the United States and most other countries, as long as you follow each country's anti-spam rules.

In the US, the CAN-SPAM Act lets you email people without their prior permission — you just need truthful headers and subject lines, a physical address, and a working way to opt out. In the UK and EU, B2B cold email is generally lawful under "legitimate interest". Canada is the strictest and requires consent first.

I'm the founder of Emailchaser, a cold email software, so I've spent years sending cold email inside these rules — and helping thousands of customers do the same.

Here's everything you need to know about sending cold emails legally in 2026:

- Is cold email legal? The short answer
- Cold email vs spam: what's the difference?
- Is cold emailing illegal?
- United States: the CAN-SPAM Act
- US state laws: the new lawsuit risk (Washington & California)
- United Kingdom: PECR + UK GDPR
- European Union: GDPR + ePrivacy
- Canada: CASL
- Google, Yahoo & Microsoft rules (not laws, but enforced faster)
- How to send cold emails legally: 7-point checklist

Disclaimer: I'm a founder, not a lawyer. This article is general information, not legal advice, and laws change — check the current rules in your jurisdiction (and your lawyer) before sending.

Is cold email legal? The short answer

Cold email is legal in the US, UK, EU, Canada and Australia when you do three things: target relevant business addresses, tell the truth about who you are and why you're writing, and give recipients an easy way to opt out (then honor it). It becomes illegal when it's deceptive, ignores opt-outs, or goes to consumers in countries that require consent first.

Here's how the major jurisdictions compare as of 2026:

JurisdictionMain lawConsent needed first?Maximum penalty (as of 2026)
United StatesCAN-SPAM ActNo — opt-out regimeUp to $53,088 per email (FTC)
European UnionGDPR + ePrivacyConsumers: yes. B2B: often "legitimate interest" insteadUp to €20M or 4% of global turnover
United KingdomUK GDPR + PECRIndividuals: yes. Corporate subscribers: exempt from the consent ruleICO enforcement (fines + enforcement notices)
CanadaCASLYes — express or impliedUp to CAD $10M per violation (organizations)
AustraliaSpam Act 2003Yes — express or inferredACMA enforcement

This article is the overview. If you want the full per-country detail — consent types, sender obligations, enforcement bodies and penalties for each jurisdiction — read my complete reference: Cold Email Laws by Country.

Cold email vs spam: what's the difference?

A cold email is an unsolicited email sent to someone you've had no prior contact with. That alone does not make it spam — or illegal.

Spamhaus defines spam as: "An electronic message is "spam" if (A) the recipient's personal identity and context are irrelevant because the message is equally applicable to many other potential recipients; AND (B) the recipient has not verifiably granted deliberate, explicit, and still-revocable permission for it to be sent."

An email needs all three of the following characteristics to be spam:

  1. Sent in bulk — the same email blasted to hundreds or thousands of people.
  2. Not personalized — the message applies equally to any recipient.
  3. Unsolicited — no express or implied consent.

A well-sent cold email is unsolicited, but it's targeted at one researched person, relevant to their role, and easy to decline. That's why cold emails, when sent correctly, land in the primary inbox — while spam lands in the junk folder.

Spam characteristics: bulk, identical, irrelevant, sent to personal addresses, no opt-out.

Cold email characteristics: targeted, personalized, relevant to the recipient's business, sent to a work address, with a clear way to opt out. (You can read my other article on whether you need an unsubscribe link in cold emails.)

Is cold emailing illegal?

No — cold emailing is not illegal in the US, UK, EU, Canada or Australia. What's illegal is how some people do it.

Cold email crosses into illegal territory when you:

  • Use false or spoofed "From" / "Reply-To" information.
  • Use a deceptive subject line that misrepresents the email's content.
  • Provide no way to opt out, or keep emailing people after they've opted out.
  • Email consumers without consent in consent-required jurisdictions (Canada, most of the EU, Australia).
  • Send to personal email addresses (e.g. someone's Gmail) instead of business addresses — in the EU, UK and Canada this will generally be unlawful without consent, and everywhere it invites spam complaints.

Stay on the right side of those lines and unsolicited B2B email is a legal, standard sales channel. Now let's go country by country.

United States: the CAN-SPAM Act

Cold email is legal in the United States. You do not need the recipient's permission before emailing them.

The CAN-SPAM Act is an opt-out regime: it regulates all commercial email (not just bulk email), and each separate email that violates it can cost up to $53,088 — that's the FTC's current inflation-adjusted maximum per email, as of mid-2026. The FTC adjusts this figure annually, and it applies per message, so one bad campaign to 5,000 people is 5,000 potential violations.

image of the US flag

How to comply with CAN-SPAM

  • Accurate header information. Your "From", "To" and "Reply-To" must truthfully identify you.
  • Honest subject lines. The subject must reflect the actual content of the email.
  • Identify the message as an ad. The law gives leeway on how, but you can't disguise a commercial pitch as something else.
  • Include a valid physical postal address. Your street address, registered P.O. box or commercial mailbox — most senders put it in the signature.
  • Give a clear opt-out. It does not have to be an unsubscribe link — a reply-based opt-out ("if this isn't relevant, just reply 'no thanks'") satisfies the requirement. See my article on unsubscribe links in cold email.
  • Honor opt-outs within 10 business days, and keep your opt-out mechanism working for at least 30 days after sending.
  • You're liable even if you outsource. Hiring an agency doesn't transfer legal responsibility.

US state laws: the new lawsuit risk (Washington & California)

This is the part most 2026 guides still miss: CAN-SPAM preempts most state spam laws, except state laws that target falsity or deception — and those state laws are now where the real litigation is.

  • Washington (CEMA). In April 2025, the Washington Supreme Court held in Brown v. Old Navy that any false or misleading information in a commercial email's subject line violates Washington's Commercial Electronic Mail Act — with statutory damages of $500 per email. That triggered a wave of class actions (over sixty in one federal district alone), mostly over "false scarcity" subject lines like "Sale ends tonight" when the sale didn't end. Washington then narrowed the law: from June 11, 2026, damages drop to $100 per violation (or actual damages) and require the sender's knowledge — but the litigation risk is real, and a federal court upheld CEMA against a CAN-SPAM preemption challenge in early 2026.
  • California (B&P Code § 17529.5). California's anti-deception email law has seen a similar flurry of lawsuits against senders over misleading subject lines.

The takeaway for cold emailers: a deceptive subject line isn't just an FTC problem anymore — it's a class-action problem. Write subject lines that are plainly true. (Here's how to write ones that still get opens: cold email subject lines.)

United Kingdom: PECR + UK GDPR

Cold email is legal in the United Kingdom — and the UK is actually one of the friendlier jurisdictions for B2B cold email.

image of the UK flag

The Privacy and Electronic Communications Regulations (PECR) require consent before sending marketing email to individual subscribers (personal addresses, sole traders and some partnerships). But corporate subscribers — employees at limited companies — are exempt from that consent rule, which is what makes B2B cold email workable in the UK.

Two caveats:

  • UK GDPR still applies to the person's data. A named work email (jane@company.co.uk) is personal data, so you need a lawful basis (usually legitimate interest), you must identify yourself, and you must stop when someone objects.
  • PECR still requires you to identify who you are and provide a valid contact address for opt-outs in every message.

How to comply in the UK

  • Only email people at companies (corporate subscribers), never personal addresses.
  • Identify yourself and your business, and include a contact/postal address in your signature.
  • Offer an easy opt-out in every email and honor it immediately.
  • Keep subject lines honest and the pitch relevant to the recipient's role.

European Union: GDPR + ePrivacy

Cold email is legal in the European Union for B2B — but you need to do it properly, because the GDPR treats a named person's work email address as personal data.

image of EU flag

GDPR doesn't ban cold email; it requires a lawful basis for processing personal data. For B2B outreach, most senders rely on legitimate interest — GDPR's Recital 47 explicitly says direct marketing "may be regarded as carried out for a legitimate interest". Consumers are different: marketing to individuals generally requires consent.

To rely on legitimate interest you should:

  • Document a Legitimate Interest Assessment (LIA) — a written purpose / necessity / balancing test showing your interest doesn't override the recipient's rights.
  • Target narrowly. The email must be relevant to the recipient's professional role — something they wouldn't find unexpected or disruptive. Regulators like France's CNIL accept legitimate-interest B2B prospecting on exactly this condition.
  • Be transparent. Say who you are, why you're contacting them, and where you got their data if asked.
  • Offer an easy opt-out in every email, honor objections immediately, and delete their data on request.

The stakes are the highest of any jurisdiction: GDPR fines can reach €20 million or 4% of global annual turnover, whichever is higher. Each EU member state also layers its own ePrivacy rules on top — my Cold Email Laws by Country guide covers the differences.

Canada: CASL

Canada has the strictest general anti-spam law: CASL requires consent before you send a commercial electronic message — and the burden of proving consent sits on you, the sender.

image of the Canadian flag

Cold email to Canada is still possible under implied consent, which covers narrow cases such as an existing business relationship, or a business email address that's conspicuously published (or given to you) without a no-marketing note — provided your message is relevant to the person's role.

Every message must also fully identify you, include accurate contact information, and contain a working unsubscribe that you honor within 10 business days.

Penalties are serious: administrative monetary penalties reach up to CAD $1 million per violation for individuals and CAD $10 million per violation for organizations, and executives can be personally liable. If you email Canadians, keep records of exactly why each recipient falls under implied consent.

Google, Yahoo & Microsoft rules (not laws, but enforced faster)

Even where the law is on your side, the mailbox providers have their own rules — and they enforce them in real time by blocking your email, which in practice hurts more than a hypothetical fine.

Since February 2024, Google and Yahoo require senders of roughly 5,000+ emails per day to their users to:

  • Authenticate email with SPF, DKIM and DMARC.
  • Keep spam complaint rates below 0.3% (ideally under 0.1%).
  • Include one-click unsubscribe (RFC 8058 List-Unsubscribe headers) on marketing/bulk mail and honor opt-outs within two days.

Microsoft began enforcing similar requirements for high-volume senders to Outlook in May 2025.

For cold emailers the practical rules are: authenticate every sending domain, keep volume per inbox low, and target narrowly enough that nobody hits "report spam". If you send bulk or marketing mail alongside cold outreach, you can build compliant one-click headers with our free List-Unsubscribe Header Generator, and my deliverability guide covers the rest.

How to send cold emails legally: 7-point checklist

Laws differ by country, but if you follow these seven rules you'll be compliant almost everywhere:

  1. Only email relevant business addresses — never personal ones. Find work emails with an email finder, or use Emailchaser's Lead Finder to pull targeted leads from LinkedIn Sales Navigator, so every recipient actually matches your offer.
  2. Personalize every email. Remember the spam definition: bulk + identical + unsolicited. Personalization is what legally (and practically) separates cold email from spam.
  3. Tell the truth everywhere. Accurate "From" name, accurate reply address, and a subject line that honestly reflects the email — false-scarcity subject lines are now drawing US class actions.
  4. Identify yourself and include a physical address. Put your company name and postal address in your signature; CAN-SPAM and CASL both require it.
  5. Give an easy opt-out and honor it fast. A reply-based opt-out works for cold email. When someone opts out, add them to your block list — Emailchaser has one built in — so no campaign can ever email them again. (US: within 10 business days. Canada: 10 business days. Google/Yahoo: two days.)
  6. Verify addresses before you send. High bounce rates wreck sender reputation and invite spam filtering. Use a free email verifier — Emailchaser double-verifies every lead with two providers and only emails addresses both mark valid, which keeps bounce rates under 1%.
  7. Know your recipient's jurisdiction. US = opt-out. UK/EU = legitimate interest + easy opt-out. Canada/Australia = consent. When in doubt, meet the strictest standard — details in Cold Email Laws by Country.

Frequently asked questions

Is cold emailing illegal?

No. Cold emailing is legal in the US, UK, EU, Canada and Australia — what's illegal is deceptive cold email: false sender information, misleading subject lines, no opt-out, or emailing consumers without consent in consent-required countries.

Are unsolicited emails illegal?

No, not by themselves. In the US, the CAN-SPAM Act explicitly permits unsolicited commercial email as long as you use truthful headers and subject lines, include a physical address and opt-out, and honor opt-outs within 10 business days. Canada and (for individuals) the EU and UK require consent or another lawful basis.

Is it illegal to email someone without their permission?

In the US, no — permission is not required, only compliance with CAN-SPAM's rules. In Canada you generally need express or implied consent (CASL), and in the EU/UK you need consent for consumers or a documented legitimate interest for B2B contacts.

Is it illegal to send an email without an unsubscribe link?

Under CAN-SPAM you must provide a clear opt-out mechanism, but it doesn't have to be a link — for cold email, a reply-based opt-out like "just reply 'no thanks'" satisfies the law. Separately, Google and Yahoo require one-click unsubscribe headers for bulk senders (5,000+ emails/day), which is a deliverability requirement rather than a law.

Is B2B cold emailing legal?

Yes. B2B cold email is legal in the US under CAN-SPAM, workable in the UK thanks to PECR's corporate-subscriber exemption, generally lawful in the EU under GDPR's legitimate-interest basis, and possible in Canada under CASL's implied-consent categories — provided you identify yourself, stay honest, and honor opt-outs.

Are cold emails legal in Europe under GDPR?

Yes, for B2B. GDPR's Recital 47 recognizes direct marketing as a possible legitimate interest, so you can email relevant business contacts without prior consent if you document a legitimate interest assessment, target narrowly, identify yourself, and offer an easy opt-out. Marketing to consumers generally requires consent.

Final thoughts

Cold email is legal — spam is not. The difference comes down to targeting relevant business addresses, being honest about who you are, and making it easy to say no.

An email only becomes illegal spam when it's deceptive, ignores opt-outs, or is blasted without consent to people (especially consumers) who could never benefit from it.

I built Emailchaser around the compliant workflow: find targeted leads, double-verify every address, personalize at scale, and suppress opt-outs automatically with the block list. You can see how it works on the cold email software page and try it with a 7-day free trial.

Related reading:

Free tool

Check your email for spam words

Scan your cold email for spam trigger words that send messages to spam, then fix them before you send.

Try the spam word checker

Free tool

Verify an email address for free

Check whether an email address is valid and safe to send to before you launch your cold email campaign.

Try the free email verifier
picture of George Wauchope

Article by

George Wauchope

Founder of Emailchaser.

I have been working in the sales & marketing industry for nearly a decade.

When I’m not working on my business, I enjoy eating sushi & doing jiu-jitsu.

About the author