CAN-SPAM
US law (2003) governing commercial email — requires accurate sender info, working unsubscribe, and no deceptive subject lines.
CAN-SPAM is the US federal law governing commercial email, passed in 2003. The act sets minimum standards rather than requiring opt-in: senders can email recipients who haven't previously consented, provided they comply with specific obligations.
The core requirements: no false or misleading header information, no deceptive subject lines, clear identification of the message as advertising (where applicable), a valid physical postal address in every email, and a clear opt-out mechanism that processes within 10 business days. Violations carry per-email penalties of up to $50,120 (adjusted for inflation), and the FTC actively enforces.
CAN-SPAM is significantly weaker than GDPR or Canada's CASL — it's opt-out rather than opt-in. International senders shouldn't assume CAN-SPAM compliance covers them globally. For audiences spanning the US, EU, UK, and Canada, the GDPR-compliant opt-in standard is the safest universal baseline.