CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
Data Privacy Standards

Is it illegal to send spam to someone's email?

Back to InsightsIs it illegal to send spam to someone's email?

Is it illegal to send spam to someone's email?

Key Facts

Yes, Spam Is Illegal — But the Rules Depend on Where Your Recipient Lives

Sending unsolicited commercial email is illegal in virtually every major jurisdiction, but the legal standard shifts depending on where the recipient lives — not where the sender operates. That distinction matters because My AI Call Center runs campaigns from Halifax and Austin, meaning both CAN-SPAM and CASL apply to our operations, and GDPR applies the moment an EU resident is on a list.

The United States follows an opt-out model under the CAN-SPAM Act. It does not require prior consent, but it demands honest headers, a physical address, and a working unsubscribe link that must be honored within 10 business days. Violations carry penalties up to $53,088 per email. Canada and the EU take a stricter approach. CASL and GDPR require explicit, verifiable consent before any commercial email is sent, with fines reaching $10 million CAD for businesses under CASL and €20 million or 4% of global turnover under GDPR. Australia sits in the middle, accepting either explicit or implied consent.

Because recipient location determines which law applies, a single campaign can trigger multiple regimes at once. Compliance platforms and email providers have responded by enforcing the strictest standard across the board. HubSpot, for example, requires verifiable permission through a clear action — a pre-checked box or silence does not count. Purchased lists are prohibited even if the vendor claims consent.

  • U.S. (CAN-SPAM): opt-out required, no prior consent needed
  • Canada (CASL): express or implied consent required before sending
  • EU/UK (GDPR/PECR): explicit opt-in consent required, with records to prove it
  • Australia (Spam Act): consent required, but implied consent accepted in some cases

The practical takeaway is straightforward. If you build every list on documented, verifiable opt-in consent, you satisfy the strictest rules automatically — and you avoid the deliverability damage that comes when 72% of U.S. consumers mark unwanted mail as spam. That is the same list discipline we already enforce for every calling campaign: approved, permissioned, or reviewed contacts only, with consent records checked before launch.

The Three Laws That Decide What 'Spam' Means: CAN-SPAM, CASL, and GDPR

Whether an email counts as illegal "spam" depends entirely on which law governs the recipient. Three regimes dominate the answer — and they disagree with each other in ways that matter a lot for any North American sender.

The CAN-SPAM Act of 2003 is the most permissive of the three. It does not require consent before you send commercial email — but it imposes strict rules on how you send it. Honest subject lines, accurate headers, a physical postal address, and a working opt-out mechanism are all mandatory, and opt-outs must be honored within 10 business days.

The teeth are real. According to the FTC's official compliance guide, each violating email can carry a penalty of up to $53,088 — and the law covers all commercial messages, not just bulk sends. The FTC also makes clear that hiring a third party to send your email doesn't transfer liability: both the company promoted and the company sending can be held responsible.

Canada's Anti-Spam Legislation, in force since 2014, flips the model entirely. Under CASL, you need consent before sending a commercial electronic message — express opt-in, or narrowly defined implied consent. The penalties scale accordingly: legally reviewed compliance analysis puts maximum fines at $10 million CAD for businesses and $1 million for individuals.

Critically, CASL applies to messages sent to or from Canada regardless of where the sender sits. A Texas-based campaign emailing a Toronto contact falls squarely under it.

The EU's GDPR, effective since 2018, treats email consent as a data protection issue. It demands explicit, verifiable opt-in before any commercial message, with penalties reaching €20 million or 4% of global turnover, whichever is higher. Its reach is extraterritorial — if a single EU resident is on your list, GDPR applies to how you email them.

A company operating in both Canada and the U.S. faces CAN-SPAM and CASL simultaneously, plus GDPR the moment an EU address enters the database. Compliance experts increasingly recommend a single practical strategy, summarized by Emailchef's cross-regime guide: follow the strictest standard (GDPR-level opt-in) everywhere, and you automatically satisfy the lower bars.

That means a defensible email program rests on the same foundations:

  • Explicit, verifiable opt-in captured with timestamp and source
  • Accurate sender identity, subject lines, and a physical postal address
  • A functional unsubscribe honored immediately — well inside CAN-SPAM's 10-day window
  • Lists segmented by recipient jurisdiction, since location determines the law

This is precisely why My AI Call Center applies the same discipline to its calling campaigns — approved, permissioned, or reviewed lists only, with consent records checked before anything launches. Operating from both Halifax and Austin, that opt-in-first posture is not a preference; it is the only approach that survives contact with all three regimes at once.

The Hidden Traps: Shared Liability, Transactional Creep, and Platform Rules Stricter Than the Law

Most businesses assume hiring a third-party sender shifts compliance risk off their plate. The FTC says otherwise: both the company whose product is promoted and the company that actually sends the message may be held legally responsible, and you cannot contract away that legal responsibility. This shared liability model means a vendor's mistake — missing opt-out links, deceptive subject lines, no physical address — becomes your enforcement exposure.

The trap deepens with transactional emails. Appointment reminders, payment notices, and shipping confirmations enjoy lighter rules only while they stay purely informational. Add a promotional banner, a cross-sell line, or a "while you're here" offer and the primary purpose test reclassifies the entire message as commercial. Full CAN-SPAM, GDPR, and CASL requirements then apply — consent records, honor windows, suppression lists, the works.

Platforms enforce a stricter layer still. HubSpot's Acceptable Use Policy requires verifiable permission through explicit action; lack of an opt-out does not meet HubSpot's requirements, and purchased or rented lists are prohibited even if the vendor claims opt-in consent. Mailchimp applies comparable standards. Technical deliverability now depends on consent quality, not just legal minimums.

Real enforcement proves the stakes:

  • Verkada paid $2.95 million for missing opt-out mechanisms, no physical address, and failing to honor opt-outs
  • Experian paid $650,000 for failing to provide an opt-out mechanism after complaints

Meanwhile, 72% of U.S. consumers mark unwanted or irrelevant emails as spam, destroying sender reputation faster than any fine. My AI Call Center applies the same discipline to calling campaigns — only approved, permissioned, or reviewed lists, with consent records checked before launch — because the cost of non-compliance compounds across every channel.

The Simplest Safe Strategy: Adopt the Strictest Standard Everywhere

The simplest way to stay compliant across borders is to run every campaign at the strictest standard — GDPR and CASL opt-in — which automatically satisfies CAN-SPAM's lower bar. This isn't just theory; the FTC confirms that both the promoter and the sender share liability, so a managed service cannot contract away its responsibility. Platforms like HubSpot and Mailchimp already enforce verifiable permission that exceeds U.S. minimums, making consent quality a deliverability requirement, not just a legal one.

  • Capture verifiable consent at intake with timestamp, source, and form ID
  • Segment lists by jurisdiction — CASL for Canada, GDPR for EU, CAN-SPAM for U.S.
  • Use a master template that includes physical address, clear sender ID, and functional unsubscribe
  • Honor opt-outs immediately across all channels through a unified suppression list

Research shows 72% of U.S. consumers mark unwanted emails as spam, and the FTC has levied fines up to $2.95 million for missing opt-out mechanisms and unaddressed complaints. My AI Call Center already applies this discipline to calling campaigns — approved, permissioned, or reviewed lists only, with opt-outs logged and honored immediately. Extending that same standard to email means every contact record carries proof of consent before a single message sends.

Run campaigns on lists that hold up under scrutiny. We review list source, consent records, and regulated-area flags before any launch — so you know the number before you approve spend.

Plan My Campaign

How to Build a Permission-First Outreach Program (Before You Send Anything)

Before you dial a single number or send a single email, the list itself must pass a compliance audit. My AI Call Center treats every campaign the same way: list source, consent records, and calling windows are reviewed before launch, and bought lists without clear permission records are flagged — in most cases declined. That discipline mirrors the strictest global email standard. Industry guidance confirms that following GDPR-level opt-in automatically satisfies CAN-SPAM's lower bar, so a single "approved, permissioned, reviewed" standard covers every jurisdiction you operate in.

  • Audit list source and consent records before any campaign launches
  • Segment contacts by jurisdiction — CASL applies to Canadian recipients regardless of sender location per Canadian law
  • Log and honor opt-outs immediately across every channel with a unified suppression list
  • Decline purchased or rented lists that cannot produce verifiable permission records

The FTC makes clear that both the promoter and the sender share liability under CAN-SPAM, so a managed-service model cannot outsource compliance risk. Platforms enforce an even stricter layer: HubSpot requires consent expressed through a verifiable action and explicitly prohibits purchased lists even when vendors claim opt-in per its Acceptable Use Policy. With 72% of U.S. consumers ready to mark unwanted email as spam, list hygiene is a deliverability issue as much as a legal one. The campaign review captures goal, list volume, relationship, consent records, and regulated-area flags — "not sure" answers trigger a manual review tag so nothing launches until the record is clean.

Ready to run a campaign on a list that passes review? Plan My Campaign — the first review is free, and the full number is known before you approve launch.

Managed outbound calling for approved, permissioned lists — from 9¢ per connected minute.

Frequently Asked Questions

Is it actually illegal to send spam emails?
Yes — sending unsolicited commercial email is illegal in virtually every major jurisdiction, though the exact rules depend on where your recipient lives, not where you send from. The U.S., Canada, the EU, and Australia all have enforceable anti-spam laws with substantial penalties.
Do I need someone's permission before emailing them in the U.S.?
Surprisingly, no — the CAN-SPAM Act uses an opt-out model, so prior consent isn't required, but you must use honest subject lines, include a physical address, and honor opt-outs within 10 business days. Each violating email can carry a penalty of up to $53,088 according to the FTC.
What are the penalties for sending spam in Canada or the EU?
Both require explicit consent before you send anything. CASL fines reach $10 million CAD for businesses, while GDPR penalties can hit €20 million or 4% of global turnover, whichever is higher.
If I hire a company to send my emails, am I still liable for violations?
Yes. The FTC states that both the company promoted in the message and the company that sends it can be held legally responsible — you cannot contract away that responsibility. A vendor's missing unsubscribe link or deceptive subject line becomes your enforcement exposure.
Can I use a purchased email list if the vendor claims everyone opted in?
It's risky and often prohibited. Major platforms like HubSpot ban purchased or rented lists outright, requiring verifiable permission through a clear action — a pre-checked box or silence doesn't count. My AI Call Center applies the same discipline to calling campaigns, flagging or declining bought lists without clear permission records.
What's the simplest way to stay compliant across different countries?
Follow the strictest standard — GDPR/CASL-level explicit opt-in — for every campaign, which automatically satisfies CAN-SPAM's lower bar, a strategy confirmed by cross-regime compliance guidance. This also protects deliverability, since 72% of U.S. consumers mark unwanted email as spam, damaging sender reputation faster than any fine.

Permission Isn't a Limitation — It's the Only List Worth Sending To

Sending spam is illegal everywhere that matters — the only real question is which law catches you first. CAN-SPAM's opt-out model, CASL's consent-first mandate, and GDPR's explicit opt-in all point to the same answer: build every list on documented, verifiable permission, and you satisfy the strictest standard automatically. The alternative is expensive. Fines reach $53,088 per email in the U.S., $10 million CAD in Canada, and €20 million or 4% of global turnover under GDPR — before you count the deliverability damage when recipients mark you as spam. The path forward is practical: capture consent with timestamp and source, segment by jurisdiction, honor opt-outs immediately, and decline any list that can't prove permission. That's the same discipline My AI Call Center applies to every calling campaign — approved, permissioned, or reviewed contacts only, checked before anything launches. If your next campaign needs a list that holds up under scrutiny, the first campaign review is free — and you'll know the full number before you approve a single send.

Get campaign planning tips