CAN-SPAM
US federal rules for commercial email — honest subject lines, real postal address, working unsubscribe (opt-out model).
Say it out loud
“The US rule. We do not need permission first, but we do need honesty, an address and a working unsubscribe.”
CAN-SPAM does not require prior opt-in at the federal level, which is why American and European email programmes are built so differently. What it does require is that headers and subject lines are not deceptive, that a physical postal address appears, and that opt-outs are honoured within ten business days. State law can be tougher, and Washington's is.
- 10 business days
- to honour an opt-out
- FTC, CAN-SPAM compliance guide
This is the one that gets litigated, and Washington state goes further than the federal standard.
Any clear way. A recognisable brand newsletter generally reads as one.
A registered PO box counts. An empty footer does not, and this is the single most common miss.
And you may not charge for it, or require a login, or ask why.
Penalties are assessed per email, and the figure is inflation-adjusted every year, which is why the number on most blog posts is wrong.
Yours
Nobody does this for you.
What goes wrong
Running a US programme on CAN-SPAM logic and then sending to a list with EU, UK or Canadian addresses in it. The permission bar is set by where the recipient is, not by where you are.
Not the same as
- GDPR / ePrivacy
- CAN-SPAM is opt-out. The EU is opt-in. They are opposite defaults, not different flavours of the same rule.
The dated rules behind this
A definition is not a citation. These are the pages with the primary source, the date it was published, and what to do about it.
See also
Where this sits
Stop 1, you get the address. Someone hands you an email address, and the terms of that handover decide everything after it.