Compliance
Cold email compliance checklist: CAN-SPAM, GDPR and CASL in plain English
This is not legal advice; we are two founders who read the rules carefully because we send this way ourselves. It is the checklist we hold our own product to, with the source for each item so you can check our reading. If you sell into the EU or Canada, talk to a lawyer once — it is cheaper than the alternative.
United States: CAN-SPAM
The law that people assume bans cold email in fact permits it. What it requires, per the FTC's compliance guide: no false or misleading header information (the From, Reply-To and routing must identify the actual sender); no deceptive subject lines — which is why a fake "Re:" on a first email is not just a spam signal but a compliance problem; a clear identification that the message is an advertisement, which a plain, honest pitch satisfies; a valid physical postal address; a clear and conspicuous way to opt out; and opt-outs honoured within ten business days, without charging a fee or asking for anything beyond an email address. The FTC lists penalties of up to tens of thousands of dollars per email, and the company whose product is promoted can be liable even when a vendor sends.
Practical reading: "Not the right person, or don't want more of these? Reply 'no' and I'll close the file" plus a one-line address at the bottom satisfies the opt-out and address requirements, reads as human, and doubles as a reply prompt. The part people get wrong is the ten days: the "no" has to actually stop future sends, everywhere, from every mailbox, forever.
EU and UK: GDPR and PECR
Two layers. GDPR governs the personal data (a work email with a name is personal data). Cold B2B email is generally run on legitimate interest (Article 6(1)(f)): you must have a real interest, the email must be necessary for it, and the recipient's interests must not override yours — which in practice means relevant to their role, low volume, easy to object to, and documented (a short "legitimate interest assessment" you can produce if asked). The UK's PECR (and the ePrivacy rules across the EU) add the marketing-email layer: corporate subscribers (role or company addresses) can be emailed without prior consent in the UK; sole traders and some partnerships count as individuals and need consent; you must identify yourself and give a valid address to object to. Objections must be honoured immediately, and "immediately" means the suppression list, not a to-do.
Canada: CASL
The strictest of the three. Commercial electronic messages need consent — express, or implied. Implied consent for B2B exists where the recipient has "conspicuously published" their business address without a no-unsolicited-messages note and your message relates to their role, or where they gave you the address for that purpose. Every message must identify the sender with contact information and include an unsubscribe mechanism that works for at least 60 days and is honoured within 10 business days. Penalties reach into the millions, so if you send into Canada, keep a record of why you believed consent existed for each address.
The checklist
- From name and address are a real person at your real company; replies go to a monitored mailbox
- Subject line describes the email; no "Re:" on a first message, no fake urgency
- Physical postal address in every message (PO box or virtual office is fine)
- A plain opt-out in every message ("reply 'no'"), plus a suppression list that every mailbox and every sequence honours
- Opt-outs and objections processed within 10 business days — in practice, the same minute
- One documented reason (legitimate interest) for why this role, at this company, would reasonably expect this email
- Relevance test passed: you can say in one sentence why this company needs this product
- Volume that a person could plausibly send (≈30 a day per mailbox), from a domain that is not your primary one
- Records: who you emailed, when, from where, why, and every opt-out — exportable
- For Canada and consumer-facing EU addresses: consent basis noted per address, or don't send
What this has to do with deliverability
Everything on that list is also what Gmail and Microsoft reward. Honest headers, low volume, an easy way out, replies that come back to the same mailbox — receivers measure the same behaviours the law asks for. Google's bulk-sender guidelines require a spam-complaint rate under 0.3%; the fastest way to stay there is to make "no" effortless and honour it instantly. Compliance is not the tax on cold email; it is the technique.
Is cold email legal in the US?
Yes, under CAN-SPAM, if headers and subjects are honest, the message carries a postal address and a clear opt-out, and opt-outs are honoured within 10 business days.
Is cold email legal under GDPR?
B2B cold email can rely on legitimate interest when it is relevant, proportionate, easy to object to and documented. Consumer addresses need consent.
What about Canada?
CASL needs consent; implied consent covers conspicuously published business addresses when the message relates to the role. Identification and unsubscribe are mandatory in every message.
Sources: FTC CAN-SPAM compliance guide · ICO direct marketing guidance (PECR/GDPR) · CRTC on CASL · Google Email Sender Guidelines. Not legal advice.
Keep Your Chain puts the address and opt-out line in every email, turns "no" into a suppression entry automatically, blocks a fake "Re:" in the editor, and exports the records. Plans start at $29 a month.
Join the waitlist