
Is it illegal to send spam to someone's email?
Key Facts
- A single spam email can cost up to $53,088 under CAN-SPAM, per the FTC's compliance guide.
- Canada's anti-spam law fines businesses up to $10 million CAD for emailing without consent, according to legally reviewed analysis.
- GDPR penalties for illegal emailing reach €20 million or 4% of global turnover, per Mailchimp's compliance research.
- 72% of U.S. consumers mark unwanted emails as spam, destroying sender reputation faster than any fine.
- Verkada paid $2.95 million for missing opt-out links and ignored unsubscribe requests, per FTC enforcement records.
- Hiring a third-party sender doesn't shield you — both promoter and sender share liability, the FTC confirms.
- HubSpot bans purchased lists even with claimed consent, requiring verifiable opt-in action, per its Acceptable Use Policy.
Yes, Spam Is Illegal — But the Rules Depend on Where Your Recipient Lives
Sending unsolicited commercial email is illegal in virtually every major jurisdiction, but the legal standard shifts depending on where the recipient lives — not where the sender operates. That distinction matters because My AI Call Center runs campaigns from Halifax and Austin, meaning both CAN-SPAM and CASL apply to our operations, and GDPR applies the moment an EU resident is on a list.
The United States follows an opt-out model under the CAN-SPAM Act. It does not require prior consent, but it demands honest headers, a physical address, and a working unsubscribe link that must be honored within 10 business days. Violations carry penalties up to $53,088 per email. Canada and the EU take a stricter approach. CASL and GDPR require explicit, verifiable consent before any commercial email is sent, with fines reaching $10 million CAD for businesses under CASL and €20 million or 4% of global turnover under GDPR. Australia sits in the middle, accepting either explicit or implied consent.
Because recipient location determines which law applies, a single campaign can trigger multiple regimes at once. Compliance platforms and email providers have responded by enforcing the strictest standard across the board. HubSpot, for example, requires verifiable permission through a clear action — a pre-checked box or silence does not count. Purchased lists are prohibited even if the vendor claims consent.
- U.S. (CAN-SPAM): opt-out required, no prior consent needed
- Canada (CASL): express or implied consent required before sending
- EU/UK (GDPR/PECR): explicit opt-in consent required, with records to prove it
- Australia (Spam Act): consent required, but implied consent accepted in some cases
The practical takeaway is straightforward. If you build every list on documented, verifiable opt-in consent, you satisfy the strictest rules automatically — and you avoid the deliverability damage that comes when 72% of U.S. consumers mark unwanted mail as spam. That is the same list discipline we already enforce for every calling campaign: approved, permissioned, or reviewed contacts only, with consent records checked before launch.
The Three Laws That Decide What 'Spam' Means: CAN-SPAM, CASL, and GDPR
Whether an email counts as illegal "spam" depends entirely on which law governs the recipient. Three regimes dominate the answer — and they disagree with each other in ways that matter a lot for any North American sender.
The CAN-SPAM Act of 2003 is the most permissive of the three. It does not require consent before you send commercial email — but it imposes strict rules on how you send it. Honest subject lines, accurate headers, a physical postal address, and a working opt-out mechanism are all mandatory, and opt-outs must be honored within 10 business days.
The teeth are real. According to the FTC's official compliance guide, each violating email can carry a penalty of up to $53,088 — and the law covers all commercial messages, not just bulk sends. The FTC also makes clear that hiring a third party to send your email doesn't transfer liability: both the company promoted and the company sending can be held responsible.
Canada's Anti-Spam Legislation, in force since 2014, flips the model entirely. Under CASL, you need consent before sending a commercial electronic message — express opt-in, or narrowly defined implied consent. The penalties scale accordingly: legally reviewed compliance analysis puts maximum fines at $10 million CAD for businesses and $1 million for individuals.
Critically, CASL applies to messages sent to or from Canada regardless of where the sender sits. A Texas-based campaign emailing a Toronto contact falls squarely under it.
The EU's GDPR, effective since 2018, treats email consent as a data protection issue. It demands explicit, verifiable opt-in before any commercial message, with penalties reaching €20 million or 4% of global turnover, whichever is higher. Its reach is extraterritorial — if a single EU resident is on your list, GDPR applies to how you email them.
A company operating in both Canada and the U.S. faces CAN-SPAM and CASL simultaneously, plus GDPR the moment an EU address enters the database. Compliance experts increasingly recommend a single practical strategy, summarized by Emailchef's cross-regime guide: follow the strictest standard (GDPR-level opt-in) everywhere, and you automatically satisfy the lower bars.
That means a defensible email program rests on the same foundations:
- Explicit, verifiable opt-in captured with timestamp and source
- Accurate sender identity, subject lines, and a physical postal address
- A functional unsubscribe honored immediately — well inside CAN-SPAM's 10-day window
- Lists segmented by recipient jurisdiction, since location determines the law
This is precisely why My AI Call Center applies the same discipline to its calling campaigns — approved, permissioned, or reviewed lists only, with consent records checked before anything launches. Operating from both Halifax and Austin, that opt-in-first posture is not a preference; it is the only approach that survives contact with all three regimes at once.
The Hidden Traps: Shared Liability, Transactional Creep, and Platform Rules Stricter Than the Law
Most businesses assume hiring a third-party sender shifts compliance risk off their plate. The FTC says otherwise: both the company whose product is promoted and the company that actually sends the message may be held legally responsible, and you cannot contract away that legal responsibility. This shared liability model means a vendor's mistake — missing opt-out links, deceptive subject lines, no physical address — becomes your enforcement exposure.
The trap deepens with transactional emails. Appointment reminders, payment notices, and shipping confirmations enjoy lighter rules only while they stay purely informational. Add a promotional banner, a cross-sell line, or a "while you're here" offer and the primary purpose test reclassifies the entire message as commercial. Full CAN-SPAM, GDPR, and CASL requirements then apply — consent records, honor windows, suppression lists, the works.
Platforms enforce a stricter layer still. HubSpot's Acceptable Use Policy requires verifiable permission through explicit action; lack of an opt-out does not meet HubSpot's requirements, and purchased or rented lists are prohibited even if the vendor claims opt-in consent. Mailchimp applies comparable standards. Technical deliverability now depends on consent quality, not just legal minimums.
Real enforcement proves the stakes:
- Verkada paid $2.95 million for missing opt-out mechanisms, no physical address, and failing to honor opt-outs
- Experian paid $650,000 for failing to provide an opt-out mechanism after complaints
Meanwhile, 72% of U.S. consumers mark unwanted or irrelevant emails as spam, destroying sender reputation faster than any fine. My AI Call Center applies the same discipline to calling campaigns — only approved, permissioned, or reviewed lists, with consent records checked before launch — because the cost of non-compliance compounds across every channel.
The Simplest Safe Strategy: Adopt the Strictest Standard Everywhere
The simplest way to stay compliant across borders is to run every campaign at the strictest standard — GDPR and CASL opt-in — which automatically satisfies CAN-SPAM's lower bar. This isn't just theory; the FTC confirms that both the promoter and the sender share liability, so a managed service cannot contract away its responsibility. Platforms like HubSpot and Mailchimp already enforce verifiable permission that exceeds U.S. minimums, making consent quality a deliverability requirement, not just a legal one.
- Capture verifiable consent at intake with timestamp, source, and form ID
- Segment lists by jurisdiction — CASL for Canada, GDPR for EU, CAN-SPAM for U.S.
- Use a master template that includes physical address, clear sender ID, and functional unsubscribe
- Honor opt-outs immediately across all channels through a unified suppression list
Research shows 72% of U.S. consumers mark unwanted emails as spam, and the FTC has levied fines up to $2.95 million for missing opt-out mechanisms and unaddressed complaints. My AI Call Center already applies this discipline to calling campaigns — approved, permissioned, or reviewed lists only, with opt-outs logged and honored immediately. Extending that same standard to email means every contact record carries proof of consent before a single message sends.
Run campaigns on lists that hold up under scrutiny. We review list source, consent records, and regulated-area flags before any launch — so you know the number before you approve spend.
Plan My CampaignHow to Build a Permission-First Outreach Program (Before You Send Anything)
Before you dial a single number or send a single email, the list itself must pass a compliance audit. My AI Call Center treats every campaign the same way: list source, consent records, and calling windows are reviewed before launch, and bought lists without clear permission records are flagged — in most cases declined. That discipline mirrors the strictest global email standard. Industry guidance confirms that following GDPR-level opt-in automatically satisfies CAN-SPAM's lower bar, so a single "approved, permissioned, reviewed" standard covers every jurisdiction you operate in.
- Audit list source and consent records before any campaign launches
- Segment contacts by jurisdiction — CASL applies to Canadian recipients regardless of sender location per Canadian law
- Log and honor opt-outs immediately across every channel with a unified suppression list
- Decline purchased or rented lists that cannot produce verifiable permission records
The FTC makes clear that both the promoter and the sender share liability under CAN-SPAM, so a managed-service model cannot outsource compliance risk. Platforms enforce an even stricter layer: HubSpot requires consent expressed through a verifiable action and explicitly prohibits purchased lists even when vendors claim opt-in per its Acceptable Use Policy. With 72% of U.S. consumers ready to mark unwanted email as spam, list hygiene is a deliverability issue as much as a legal one. The campaign review captures goal, list volume, relationship, consent records, and regulated-area flags — "not sure" answers trigger a manual review tag so nothing launches until the record is clean.
Ready to run a campaign on a list that passes review? Plan My Campaign — the first review is free, and the full number is known before you approve launch.
Frequently Asked Questions
Is it actually illegal to send spam emails?
Do I need someone's permission before emailing them in the U.S.?
What are the penalties for sending spam in Canada or the EU?
If I hire a company to send my emails, am I still liable for violations?
Can I use a purchased email list if the vendor claims everyone opted in?
What's the simplest way to stay compliant across different countries?
Permission Isn't a Limitation — It's the Only List Worth Sending To
Sending spam is illegal everywhere that matters — the only real question is which law catches you first. CAN-SPAM's opt-out model, CASL's consent-first mandate, and GDPR's explicit opt-in all point to the same answer: build every list on documented, verifiable permission, and you satisfy the strictest standard automatically. The alternative is expensive. Fines reach $53,088 per email in the U.S., $10 million CAD in Canada, and €20 million or 4% of global turnover under GDPR — before you count the deliverability damage when recipients mark you as spam. The path forward is practical: capture consent with timestamp and source, segment by jurisdiction, honor opt-outs immediately, and decline any list that can't prove permission. That's the same discipline My AI Call Center applies to every calling campaign — approved, permissioned, or reviewed contacts only, checked before anything launches. If your next campaign needs a list that holds up under scrutiny, the first campaign review is free — and you'll know the full number before you approve a single send.