Back to Tools

CAN-SPAM Compliance Checker

Verify your email campaigns meet CAN-SPAM Act requirements. Check for required elements like physical address, unsubscribe links, and proper sender identification to avoid penalties.

About this tool

The CAN-SPAM Act carries penalties of up to $51,744 per non-compliant email, and enforcement has increased significantly in recent years. Even if you think your emails are compliant, small oversights like a missing physical address or a broken unsubscribe link can put you at risk. This checker reviews your email against all the major CAN-SPAM requirements so you can fix problems before hitting send.

The core CAN-SPAM requirements every sender must meet

CAN-SPAM has seven main requirements, and they are all mandatory. You need accurate "From" and "Reply-To" headers that identify who is actually sending the email. Your subject line cannot be deceptive or misleading about the email's content. You must include a valid physical postal address (a PO Box or registered agent address counts). You need a clear and conspicuous way for recipients to opt out, and you must honor those opt-outs within 10 business days. If the email is primarily an advertisement, you need to disclose that. And you are responsible for compliance even if a third party sends emails on your behalf.

Where most email marketers slip up

The most common violation is a missing or invalid physical address. Many marketers remove it because they think it looks bad in the email footer, but it is not optional. The second most common issue is unsubscribe links that do not work or require the recipient to log in to unsubscribe. Your opt-out mechanism must be functional for at least 30 days after the email is sent, and it cannot require the recipient to do anything beyond sending a reply email or visiting a single web page. Use our List-Unsubscribe header generator to add one-click unsubscribe support, which Gmail and Yahoo now require for bulk senders.

CAN-SPAM vs. GDPR and other email laws

CAN-SPAM is relatively permissive compared to other email regulations. It uses an opt-out model, meaning you can email people without prior consent as long as you provide a way to unsubscribe. GDPR (EU), CASL (Canada), and many other laws require explicit opt-in consent before sending any marketing email. If you email internationally, you need to follow the strictest law that applies to each recipient. A good rule of thumb: if you build your program around GDPR-level consent, you will be compliant with CAN-SPAM automatically. Validate your subscriber list with our email validator to make sure you are sending to real, deliverable addresses.

Building compliance into your email workflow

Rather than checking compliance after writing each email, build it into your templates. Set up a standard footer that always includes your physical address, an unsubscribe link, and a company identifier. Use email authentication (SPF, DKIM, DMARC) to ensure your "From" address is legitimate and not spoofable. Keep your unsubscribe process simple and immediate. And periodically audit your emails with this checker to catch any drift. The cost of compliance is tiny compared to the cost of a single violation.

Frequently Asked Questions

What is the CAN-SPAM Act?

CAN-SPAM (Controlling the Assault of Non-Solicited Pornography And Marketing) is a US federal law enacted in 2003 that sets rules for commercial email messages. It covers any email whose primary purpose is advertising or promoting a commercial product or service. Violations can result in penalties of up to $51,744 per non-compliant email, and the FTC actively enforces it.

What are the main CAN-SPAM requirements?

There are seven core requirements: no false or misleading header information, no deceptive subject lines, identification that the message is an ad (if applicable), a valid physical postal address, a clear opt-out mechanism, honoring opt-out requests within 10 business days, and monitoring what third parties do on your behalf. All seven must be met for every commercial email.

Does CAN-SPAM apply to transactional emails?

Transactional emails like order confirmations, shipping notifications, and password resets are mostly exempt from CAN-SPAM requirements. However, they still cannot contain false or misleading header information. If a transactional email includes significant marketing content, the FTC may classify the entire email as commercial, making all CAN-SPAM rules apply.

Do I need to include a physical address in every email?

Yes, every commercial email must include a valid physical postal address. This can be your business street address, a PO Box registered with the US Postal Service, or a private mailbox registered with a commercial mail receiving agency. Many startups use a virtual office address or registered agent to satisfy this requirement without sharing a home address.

What counts as a valid unsubscribe mechanism?

Your unsubscribe mechanism must be clearly visible, must not require the recipient to log in or provide information beyond their email address, and must remain functional for at least 30 days after the email is sent. A simple unsubscribe link in the footer that immediately processes the request is the standard approach. Since 2024, Gmail and Yahoo also require one-click List-Unsubscribe headers for bulk senders.

How does CAN-SPAM compare to GDPR?

CAN-SPAM uses an opt-out model (you can send until someone unsubscribes), while GDPR requires opt-in consent before sending any marketing email. GDPR also gives recipients the right to have their data deleted, which CAN-SPAM does not address. If you email EU residents, GDPR applies regardless of where your company is based. Building your program around GDPR consent standards will keep you compliant with CAN-SPAM automatically.

Am I responsible if a third party sends spam on my behalf?

Yes. CAN-SPAM holds both the company whose product is promoted and the company that sends the message responsible for compliance. If you hire an email marketing agency or affiliate marketers who send non-compliant emails promoting your product, you can be held liable. Always monitor third-party sending practices and include compliance requirements in your contracts.

Does CAN-SPAM apply to B2B emails?

Yes, CAN-SPAM applies to all commercial email regardless of whether the recipient is a consumer or a business. Cold B2B outreach emails must include all the same elements: accurate sender information, non-deceptive subject lines, a physical address, and a working unsubscribe link. The only emails exempt are purely transactional or relationship-based messages.