Skip to main content
VA Horizon
Book a Call
Compliance

CAN-SPAM for Agency Cold Email: What It Actually Requires

Quick answer

CAN-SPAM applies to every commercial email an agency sends, including its own new-business prospecting, not just client campaigns. Per sender.net, opt-out requests must be honored within 10 business days, every email needs a real physical mailing address, and subject lines can't misrepresent the content. The maximum civil penalty is $53,088 per non-compliant email in 2026 (inflation-adjusted by the FTC), and liability can't be outsourced to an ESP or agency partner. Verify that exact figure against the FTC's own current guide before quoting it publicly. This research corroborated it through a secondary source after the FTC page itself returned a bot block.

Cold email remains one of the more common outbound channels agencies try (59% have used outbound, per SparkToro), which makes CAN-SPAM one of the more relevant compliance questions in this vertical, not a theoretical one.

Why This Applies to Your Own Outreach, Not Just Client Work

It's easy to think of CAN-SPAM as a rule you enforce on client email campaigns, something in the compliance checklist for a marketing automation platform. It also applies directly to the cold emails an agency sends prospecting for its own new business. Cold email is a real, active channel in this category: 27.7% open rates and 5.1% reply rates were the 2024 benchmark for agency outreach, down from roughly 7% reply rates the year before, per Martal Group's 2025 data. Every one of those emails is a commercial message CAN-SPAM covers.

The Four Requirements That Actually Matter

Per sender.net, four requirements do most of the work in a CAN-SPAM-compliant cold email program. Opt-out requests have to be honored within 10 business days of receipt, and the unsubscribe mechanism itself has to stay functional for at least 30 days after the send. Every commercial email needs a real physical mailing address, a street address, a registered P.O. Box, or a commercial mail-receiving agency box, not a placeholder. Subject lines have to accurately reflect what the email actually contains, no bait-and-switch framing to boost open rates. And critically, liability for all of this cannot be outsourced. If an agency hires an ESP, a cold-email tool, or even another agency to run its outreach, the sending business is still on the hook.

Want this handled for you?

Pay per booked meeting for your industry. No retainer.

Book a B2B Call

The Penalty Figure, and the Caveat Attached to It

Per sender.net, the maximum civil penalty is $53,088 per non-compliant email, a figure the FTC adjusts for inflation. This research pass could not directly re-verify that number against the FTC's own guide page, which returned a bot-protection block on fetch. It's corroborated through sender.net as a secondary source and the FTC page's own title and URL, confirmed via search, but not through a fresh read of the FTC's current text. Treat that dollar figure as directionally accurate and worth checking against the FTC's live guide before using it in outward-facing marketing copy or a specific legal argument.

What doesn't need a caveat is the scale problem it implies: that per-email ceiling, multiplied across even a modest cold-email list, turns a sloppy compliance posture into real exposure fast.

The Liability-Can't-Be-Outsourced Point, Specifically

This is worth sitting with, because it cuts against a common assumption. An agency that pays a cold-email tool or a lead-gen vendor to run its outbound doesn't transfer CAN-SPAM liability to that vendor. Per sender.net, the sending business remains responsible regardless of who operated the send button. That has a direct implication for how an agency should evaluate any outsourced outreach partner: their compliance posture is your exposure too, not a separate concern you can hand off entirely.

A Practical Checklist for Agency Cold Email

  1. Does every commercial email include a real, current physical mailing address, not a placeholder or a defunct one?
  2. Is your opt-out mechanism actually functional, and honored within 10 business days, not just present in the footer?
  3. Do your subject lines accurately describe the email's content, with no misleading framing to boost opens?
  4. If you use a third-party ESP or outreach vendor, have you confirmed their process meets these requirements, since liability doesn't transfer to them?
  5. Have you checked the current CAN-SPAM penalty figure against the FTC's own guide recently, rather than relying on a number from an older source?
RequirementWhat It MeansSource
Opt-out windowHonor unsubscribe requests within 10 business days; keep the mechanism working for 30+ days after send.sender.net
Physical addressEvery commercial email needs a real street address, registered P.O. Box, or commercial mailbox.sender.net
Accurate subject linesNo deceptive or misleading subject-line framing relative to the actual content.sender.net
LiabilityCannot be outsourced to an ESP, cold-email tool, or agency partner. The sending business is responsible.sender.net
Maximum penalty$53,088 per non-compliant email (2026, inflation-adjusted). Verify against the FTC's current guide before quoting publicly.sender.net, corroborating FTC guide title/URL

The penalty figure specifically carries a verify-before-relying caveat: the FTC's own guide page blocked direct fetch in this research pass and the number is corroborated through a secondary source only.

What this means for you

  • CAN-SPAM covers an agency's own cold-email prospecting, not just the campaigns it runs for clients.
  • Four requirements do most of the work: a 10-business-day opt-out window, a real physical mailing address, accurate subject lines, and liability that can't be outsourced to an ESP or vendor.
  • The maximum civil penalty is $53,088 per non-compliant email per sender.net, a figure worth verifying against the FTC's current guide before using in outward-facing copy.
  • Hiring a cold-email tool or outreach vendor does not transfer CAN-SPAM liability away from the sending business.

Sources

The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.

FAQ

Does CAN-SPAM apply to an agency's own new-business cold email, or just client campaigns?
It applies to both. Any commercial email an agency sends, including its own prospecting, is covered by CAN-SPAM.
How fast do I have to honor an unsubscribe request under CAN-SPAM?
Within 10 business days, per sender.net, and the unsubscribe mechanism itself has to stay functional for at least 30 days after the send.
What is the maximum penalty for a CAN-SPAM violation?
$53,088 per non-compliant email in 2026, per sender.net's inflation-adjusted figure. This research could not independently re-verify that exact number against the FTC's own guide page, which was bot-blocked on fetch, so confirm it directly before quoting it publicly.
If I use a cold-email tool or hire a vendor to send my agency's outreach, am I still liable under CAN-SPAM?
Yes. Per sender.net, liability cannot be outsourced to an ESP or agency partner. The sending business remains responsible regardless of who operates the tool.
Does a cold email need a real physical address?
Yes. A street address, a registered P.O. Box, or a commercial mail-receiving agency box, per sender.net. A missing or placeholder address is a compliance gap.

No cold-email list to keep compliant. We text, with consent, and document it.

Book a 15-minute call and see how VA Horizon books exclusive, double-confirmed agency new-business meetings, published at $250 to $450 per meeting plus one $300 setup fee.

Book a B2B Call

Pay per booked meeting · No retainer · Free no-show replacement