Cold emailing a business contact is legal in the US without prior permission — the law that governs it, CAN-SPAM, is not an opt-in law. It requires three things: honest sender and subject information, a real physical postal address in the email, and an easy way to opt out that you honor within 10 business days. The common fear that "you can't cold email without consent" comes from confusing email law with phone law — the TCPA's opt-in rules govern robocalls and texts to cell phones, not the kind of one-to-one cold email a BDR sends to a business contact. The rules get stricter the moment you email someone in the EU or UK, where the GDPR applies. This page is a compliance checklist for legitimate outreach — not legal advice.
The compliance checklist
Here is the asset — run every sending program through it:
- [ ] Be honest about who you are. A real sender name, a real company, a truthful subject line. No spoofing, no "re:" on a thread that never existed, no invented urgency.
- [ ] Include a real physical postal address. CAN-SPAM requires it in commercial email to US recipients. A street address (or a valid registered agent's address) satisfies it; a bare P.O. box can be a gray area.
- [ ] Make opt-out easy and honor it fast. A working unsubscribe link in every commercial email, honored within 10 business days. Keep a suppression list — never email someone who opted out.
- [ ] Mark it truthfully. If an email is primarily advertising, you can label it — CAN-SPAM says you may, not must. What it forbids is disguising an ad as a personal note or hiding that it's from a business.
- [ ] Know when GDPR applies. If you email anyone in the EU/UK, their personal data is covered. A legitimate-interests basis for B2B outreach can work, but you must balance it against their rights, identify yourself, and make opting out trivial. This is the layer most US-only guides skip.
- [ ] Send like a human at human volume. Law isn't the only filter — mailboxes are. A blast that reads as bulk trips deliverability filters and spam complaints long before any regulator notices.
- [ ] When in doubt, ask a lawyer. This checklist is not legal advice. If you're scaling outreach or emailing EU/UK contacts, a compliance question is worth a real attorney's answer.
The required-elements table
What a compliant US commercial email must carry, in plain English:
| Element | Why it's required | What to do |
|---|---|---|
| Truthful subject | CAN-SPAM bans misleading subjects | Match the subject to the actual email; no deception |
| Truthful sender | No fake "from" or forged headers | Your real name and your company's domain |
| Physical postal address | Required in every commercial email | A real street or registered address in the footer |
| Working opt-out | Recipients must be able to stop you | A clear unsubscribe link, honored within 10 business days |
| No opt-in needed (US B2B) | CAN-SPAM is honesty-based, not consent-based | Research + relevance are your permission |
Where the penalties live
CAN-SPAM violations carry statutory penalties per separate email, and the amounts are adjusted for inflation each year — the FTC's civil-penalty levels now run to tens of thousands of dollars per message. The damage is rarely a fine in practice for a single honest outreach email; it's the pattern — deceptive headers, no address, no opt-out, at scale — that draws enforcement and, more often, gets you blocked and reported into the spam folder. Compliance is a business decision, not a legal nicety, and it compounds with the same habits that make cold email work in the first place: honesty, specificity, and respect for the reader.
Send clean, then send often
Email law sets the floor, not the ceiling — the ceiling is whether you land in the inbox at all. Keep your outreach on the right side of deliverability, and remember cold email is one channel in a cold email vs cold call decision, not the whole of outreach. Send cleanly, and the craft of the email itself — not the law — decides the reply.