What Is CAN-SPAM?

CAN-SPAM is the primary US federal law regulating commercial email. Signed into law in 2003 and enforced by the Federal Trade Commission (FTC), it applies to any commercial message sent in bulk, defined broadly as any electronic mail whose primary purpose is a commercial advertisement or promotion of a product or service. The law does not require prior consent from recipients before sending, which distinguishes it from stricter frameworks like GDPR. Instead, it operates on an opt-out model: you may send commercial email to anyone, but you must make it easy for recipients to stop receiving it.

The key requirements under CAN-SPAM are straightforward. The "From," "To," "Reply-To," and routing information must be accurate and identify who is sending the message. Subject lines must not be misleading about the content of the email. The email must be clearly identified as an advertisement unless the recipient previously gave permission to receive it. A valid physical postal address must be included in every commercial message. An unsubscribe mechanism must be present, and opt-out requests must be honoured within ten business days. Penalties for non-compliance can reach up to $51,744 per email in the most severe cases.

CAN-SPAM's opt-out model contrasts sharply with the opt-in consent frameworks required by GDPR and South Africa's Protection of Personal Information Act (POPIA). Many South African email marketers using US-based platforms like Mailchimp or Klaviyo will encounter CAN-SPAM requirements built into those platforms. The practical implication is that your email template and send process must satisfy CAN-SPAM's minimum requirements by default, but if you are sending to EU or South African residents, the more stringent consent requirements of GDPR and POPIA take precedence over CAN-SPAM's baseline rules.

CAN-SPAM In Practice

The scenario below is an illustrative example, not a Juicy Designs client result. The figures indicate the scale of effect that CAN-SPAM compliance work typically produces, so treat them as indicative rather than measured.

Imagine a South African software company expanding into the North American market that decides to run a cold outreach email campaign targeting small business owners in the United States. Under CAN-SPAM, this would be permissible provided the emails clearly identify the sender, include no misleading subject lines, display a valid physical address (the company could list its Pretoria office), and include a working unsubscribe link. Critically, any recipient who clicks unsubscribe must be removed within ten business days and must not receive further commercial emails from that sender after that period.

The most important practical consequence of CAN-SPAM for South African businesses is the requirement for a physical postal address in every outbound commercial email. Email service providers enforce this automatically for accounts using their platforms, but businesses sending via custom SMTP infrastructure must ensure it is included manually. Additionally, while CAN-SPAM permits sending without prior consent, doing so to poorly targeted lists will generate high spam complaint rates, damaging your sender reputation regardless of your legal compliance. Responsible email marketing that aligns with best practice will always outperform the bare legal minimum, both commercially and in terms of deliverability.

What CAN-SPAM is

CAN-SPAM is a United States law, the Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003, that sets rules for commercial email, establishing requirements for how businesses may send marketing emails and giving recipients the right to stop receiving them. It applies to commercial email messages and sets out obligations that senders must follow, chiefly: not using false or misleading header information (the from, to and routing details must be accurate) or deceptive subject lines; identifying the message as an advertisement where relevant; including a valid physical postal address of the sender; providing a clear and conspicuous way to opt out (unsubscribe) from future emails; and honouring opt-out requests promptly (stopping emails to those who unsubscribe within a set time). CAN-SPAM notably operates on an opt-out basis: it does not require prior consent to send commercial email (unlike stricter consent-based regimes), but it requires that recipients can easily opt out and that opt-outs are honoured, along with the honesty and identification requirements. Violations can carry significant penalties. Understanding CAN-SPAM matters for any business whose email marketing reaches recipients in the United States, since the law applies based on the recipients rather than only the sender's location, and because, even beyond its legal scope, its core requirements, honest headers and subjects, a physical address, easy unsubscribe, and honouring opt-outs, represent baseline good practice for legitimate email marketing that maintains deliverability and trust.

Complying with CAN-SPAM and other email laws

Complying with CAN-SPAM means following its core requirements on every commercial email: accurate, non-deceptive from and header information and subject lines; a valid physical postal address of the sender included in the email; a clear, easy way for recipients to unsubscribe; and prompt honouring of opt-out requests, so that people who unsubscribe stop receiving emails within the required timeframe. These are straightforward for a legitimate sender using a reputable email platform, since such platforms build in unsubscribe links, address fields and opt-out handling, so compliance is mostly a matter of using them properly and not engaging in deceptive practices. Importantly, CAN-SPAM is only one of several email laws a business may need to consider, and it is among the less strict, because it is opt-out based rather than requiring prior consent. Businesses reaching recipients in other jurisdictions must consider those regimes too: notably, consent-based laws like the European Union's GDPR and Canada's CASL are stricter, generally requiring prior consent to send marketing email, not merely an opt-out option, and South Africa's own POPIA sets consent and direct-marketing rules for personal information. So a business with an international audience should comply with the strictest applicable regime for each recipient, which in practice often means adopting a consent-based, permission-first approach that satisfies the stricter laws and comfortably exceeds CAN-SPAM. For a South African business, the sound approach is to follow good, permission-based email practice, emailing people who have opted in, always providing easy unsubscribe, honouring opt-outs, being honest, and including proper sender details, which meets CAN-SPAM's requirements for any US recipients and aligns with the stricter consent-based laws (including POPIA locally) that may apply. Beyond legal compliance, these practices also protect deliverability and reputation, since honest, permission-based, easy-to-unsubscribe email is what inbox providers and recipients reward.

FAQ

Does CAN-SPAM apply to South African businesses?

CAN-SPAM applies to any commercial email sent to US recipients, regardless of where the sender is located. A South African company emailing US-based customers or prospects must comply with its requirements, including providing a valid physical address, a functioning opt-out mechanism, and honest sender identification in the from field and subject line.

Is CAN-SPAM stricter than GDPR?

No. GDPR is considerably stricter than CAN-SPAM. CAN-SPAM allows opt-out email marketing, meaning you can send to people who have not explicitly consented as long as you provide an easy unsubscribe mechanism. GDPR requires prior opt-in consent before sending most commercial emails to EU residents. POPIA, South Africa's equivalent law, also leans closer to GDPR's consent-first approach.

Want a team that knows these metrics cold?

Founder-led digital marketing for South African businesses since 2015. 4.9-star rated, 64+ clients, no long-term contracts.