Why This Applies to Your Own Outreach, Not Just Client Work
It's easy to think of CAN-SPAM as a rule you enforce on client email campaigns, something in the compliance checklist for a marketing automation platform. It also applies directly to the cold emails an agency sends prospecting for its own new business. Cold email is a real, active channel in this category: 27.7% open rates and 5.1% reply rates were the 2024 benchmark for agency outreach, down from roughly 7% reply rates the year before, per Martal Group's 2025 data. Every one of those emails is a commercial message CAN-SPAM covers.
The Four Requirements That Actually Matter
Per sender.net, four requirements do most of the work in a CAN-SPAM-compliant cold email program. Opt-out requests have to be honored within 10 business days of receipt, and the unsubscribe mechanism itself has to stay functional for at least 30 days after the send. Every commercial email needs a real physical mailing address, a street address, a registered P.O. Box, or a commercial mail-receiving agency box, not a placeholder. Subject lines have to accurately reflect what the email actually contains, no bait-and-switch framing to boost open rates. And critically, liability for all of this cannot be outsourced. If an agency hires an ESP, a cold-email tool, or even another agency to run its outreach, the sending business is still on the hook.
The Penalty Figure, and the Caveat Attached to It
Per sender.net, the maximum civil penalty is $53,088 per non-compliant email, a figure the FTC adjusts for inflation. This research pass could not directly re-verify that number against the FTC's own guide page, which returned a bot-protection block on fetch. It's corroborated through sender.net as a secondary source and the FTC page's own title and URL, confirmed via search, but not through a fresh read of the FTC's current text. Treat that dollar figure as directionally accurate and worth checking against the FTC's live guide before using it in outward-facing marketing copy or a specific legal argument.
What doesn't need a caveat is the scale problem it implies: that per-email ceiling, multiplied across even a modest cold-email list, turns a sloppy compliance posture into real exposure fast.
The Liability-Can't-Be-Outsourced Point, Specifically
This is worth sitting with, because it cuts against a common assumption. An agency that pays a cold-email tool or a lead-gen vendor to run its outbound doesn't transfer CAN-SPAM liability to that vendor. Per sender.net, the sending business remains responsible regardless of who operated the send button. That has a direct implication for how an agency should evaluate any outsourced outreach partner: their compliance posture is your exposure too, not a separate concern you can hand off entirely.
A Practical Checklist for Agency Cold Email
- Does every commercial email include a real, current physical mailing address, not a placeholder or a defunct one?
- Is your opt-out mechanism actually functional, and honored within 10 business days, not just present in the footer?
- Do your subject lines accurately describe the email's content, with no misleading framing to boost opens?
- If you use a third-party ESP or outreach vendor, have you confirmed their process meets these requirements, since liability doesn't transfer to them?
- Have you checked the current CAN-SPAM penalty figure against the FTC's own guide recently, rather than relying on a number from an older source?
| Requirement | What It Means | Source |
|---|---|---|
| Opt-out window | Honor unsubscribe requests within 10 business days; keep the mechanism working for 30+ days after send. | sender.net |
| Physical address | Every commercial email needs a real street address, registered P.O. Box, or commercial mailbox. | sender.net |
| Accurate subject lines | No deceptive or misleading subject-line framing relative to the actual content. | sender.net |
| Liability | Cannot be outsourced to an ESP, cold-email tool, or agency partner. The sending business is responsible. | sender.net |
| Maximum penalty | $53,088 per non-compliant email (2026, inflation-adjusted). Verify against the FTC's current guide before quoting publicly. | sender.net, corroborating FTC guide title/URL |
The penalty figure specifically carries a verify-before-relying caveat: the FTC's own guide page blocked direct fetch in this research pass and the number is corroborated through a secondary source only.
What this means for you
- CAN-SPAM covers an agency's own cold-email prospecting, not just the campaigns it runs for clients.
- Four requirements do most of the work: a 10-business-day opt-out window, a real physical mailing address, accurate subject lines, and liability that can't be outsourced to an ESP or vendor.
- The maximum civil penalty is $53,088 per non-compliant email per sender.net, a figure worth verifying against the FTC's current guide before using in outward-facing copy.
- Hiring a cold-email tool or outreach vendor does not transfer CAN-SPAM liability away from the sending business.
Sources
The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.
