The US is the most permissive major market for cold email, and that is why the volume sequencers built their businesses there. CAN-SPAM requires no consent. It requires honesty (headers, subject lines, sender identity) and a working exit (opt-out honoured within 10 business days). The FTC says "the law makes no exception for business-to-business email". It also leaves B2B senders alone if they keep to those rules.
The penalty ceiling is high and frozen. The FTC raised the per-email maximum to $53,088 in February 2025, then said in September 2026 that "no civil penalty adjustments will be made in 2026". Most guides online still quote $50,120 or $51,744 (Prospeo's tracker shows the history). For 2026 the correct figure remains $53,088 per violating email.
What CAN-SPAM requires
| Requirement | What it means for a cold sequence | Common cold-email failure |
|---|---|---|
| Accurate header information | From, Reply-To and routing must identify the real sender | Persona sender names on inboxes of unrelated lookalike domains |
| Non-deceptive subject line | Subject must reflect the content | "Re:" or "Fwd:" on a first touch |
| Identify as an advertisement | Clear and conspicuous notice that the message is an ad | Almost universally ignored in cold B2B |
| Physical postal address | Valid street address, PO box or registered mailbox | Omitted to "look personal" |
| Opt-out mechanism | Clear explanation of how to opt out | "Reply 'no' if not interested" without honouring it everywhere |
| Honour opt-outs in 10 business days | Across every inbox, domain and campaign sending for the same advertiser | Suppression lists siloed per inbox or per client workspace |
| Monitor others acting for you | Advertiser and sender both liable | Agencies and their clients each assume the other is responsible |
Source for the requirements: FTC compliance guide. The guide adds that unsubscribe mechanisms must work for at least 30 days after sending. It also says "both the company whose product is promoted in the message and the company that actually sends the message may be held legally responsible", which puts agencies and their clients on the hook together.
The "identify as an advertisement" rule is the one cold emailers break most openly. The statute's disclosure duty applies to messages sent without affirmative consent, which describes every cold email. We found no enforcement on that point alone, but a platform that tells users "CAN-SPAM compliant out of the box" without addressing it is overclaiming.
The words that decide liability
The definitions in 15 U.S.C. §7702 decide who is liable:
- Initiate means "to originate or transmit such message or to procure the origination or transmission of such message".
- Procure means "intentionally to pay or provide other consideration to, or induce, another person to initiate such a message on one's behalf". The client who pays an agency to send is an initiator.
- Routine conveyance means "transmission, routing, relaying, handling, or storing, through an automatic technical process". This is the carve-out that keeps a sending platform from being the initiator. Platform liability: what the sequencer itself risks covers where the carve-out runs out.
- Sender means an initiator "whose product, service, or Internet web site is advertised or promoted by the message".
Private plaintiffs cannot sue under CAN-SPAM itself. Only the FTC, other federal agencies, state attorneys general and adversely affected internet access providers can. That is why the private litigation runs through state law.
Criminal exposure: the inbox-farm question
18 U.S.C. §1037 criminalises sending multiple commercial emails with materially falsified headers. It also covers anyone who "registers, using information that materially falsifies the identity of the actual registrant, for five or more electronic mail accounts or online user accounts or two or more domain names" and sends from them. Penalties reach three years where 20+ accounts or 10+ domains are involved.
Cold-email infrastructure today means dozens of lookalike domains and hundreds of mailboxes, often under invented personas (Google vs Microsoft vs SMTP, Inbox & domain infrastructure). Registering them in the real company's name keeps that infrastructure outside the statute's text. Fake registrant identities would bring it inside.
We found no prosecution applying §1037(a)(4) to a B2B cold-email inbox farm. The risk analysis above is our reading of the statute, not a reported case.
State laws: where the private lawsuits are
CAN-SPAM pre-empts state email laws except those aimed at falsity or deception. Two states matter.
California (Bus. & Prof. Code §17529.5). This section bans commercial emails sent from or to California that use a third party's domain without permission, falsified headers, or a subject line "a person knows would be likely to mislead a recipient". Recipients, email service providers and the Attorney General may sue for $1,000 per email, up to $1,000,000 per incident. Damages drop to $100 per email if the defendant had effective preventive practices. That reduction is a direct incentive to buy software that lints subject lines and headers.
Washington (Commercial Electronic Mail Act). The Washington Supreme Court's Brown v. Old Navy decision (April 2025) read CEMA's ban on false or misleading subject lines broadly. Nearly 200 class actions followed, mostly against retailers over countdown and "today only" subject lines. The legislature answered with HB 2274, effective 11 June 2026. It requires actual or fairly implied knowledge of the falsity and cuts statutory damages from $500 to $100 per email. Pending cases keep the old rules.
The Washington wave hit B2C retail, but its legal theory reaches any misleading subject line. Fake-reply openers ("Re: our call") and pretext subjects ("Question about your invoice") are standard cold-email growth hacks. They are also the clearest deception exposure a B2B sender has in the US.
We could not confirm whether any other US state enacted a new commercial-email statute in 2025–2026. Our search budget ran out before a full state survey. Washington's HB 2274 is the only 2026 state change verified here.
Enforcement record
Federal CAN-SPAM enforcement is sparse and targets large, careless senders. The biggest CAN-SPAM penalty to date went to a B2B company:
| Case | Date | Facts | Outcome |
|---|---|---|---|
| Verkada (security cameras, sells to organisations) | 30 Aug 2024 | "More than 30 million commercial emails over a three-year period"; ignored unsubscribes; no opt-out notice; no postal address | $2.95M civil penalty, described as the largest ever for CAN-SPAM |
| Washington CEMA class actions | 2025–2026 | Misleading subject lines, retail | ~200 suits; damages cut prospectively |
The Verkada lesson for a sequencer is that the fine came from opt-out plumbing, not from emailing strangers. Three years of sends to people who had unsubscribed is a suppression-list bug, and it was priced at $2.95M (the penalty was combined with data-security charges in the same order).
We did not find any CAN-SPAM action against a cold-email platform (Instantly, Smartlead, lemlist, Apollo and others) or against a pure cold-outbound agency in 2024–2026. That is consistent with the routine-conveyance shield, but we could not run enough searches to rule it out.
What this means for an entrant
- Global suppression is the feature that prevents the Verkada outcome. Opt-outs must propagate across every inbox, domain, campaign and client workspace sending for the same advertiser within hours. Rotating 200 inboxes makes this hard, and the per-inbox suppression lists common in today's tools make it easy to fail. See Inbox rotation and Workspaces, roles and SSO.
- Lint subject lines and headers for the California and Washington standard. Flag "Re:"/"Fwd:" on first touches, false urgency and mismatched From names. California's $100 reduced-damages tier for senders with "effective preventive practices" gives buyers a legal reason to pay for this.
- Add the postal address and ad-disclosure options, on by default. The cost is a few words in the footer, and it moves the default from "technically non-compliant" to "defensible".
- Keep "routine conveyance" true. The more your platform writes the copy, picks the recipients and supplies the inboxes, the less it looks like an automatic relay. See Platform liability: what the sequencer itself risks before shipping AI campaign builder or done-for-you sending.
- Sell US compliance as cheap insurance, not as the product. US law is permissive enough that buyers will not pay a premium for compliance alone. Bundle it with deliverability (Bounce protection, Unified inbox (Unibox)), where unsubscribes and complaints feed the same reputation system.