Pillar Guide

Email Compliance in 2026: CAN-SPAM, GDPR, CASL & Global Regulations

Navigate email compliance across CAN-SPAM, GDPR, CASL, and emerging regulations. Understand consent requirements, unsubscribe rules, and penalties for non-compliance.

Boxset TeamFeb 20, 202622 min read
complianceCAN-SPAMGDPRCASLunsubscribeconsentdeliverability

Why Compliance Is a Deliverability Strategy, Not Just Legal

Most email teams treat compliance as a checkbox exercise — something legal handles, something you audit once a year. That approach is dangerously outdated in 2026. Email compliance is now a core deliverability strategy, and the reason is simple: mailbox providers have made compliance signals part of their filtering algorithms.

99.5%

of email that fails one-click unsubscribe requirements at Gmail is deprioritized in inbox placement

When Google and Yahoo jointly announced their updated bulk sender requirements in late 2023 (enforced starting February 2024), they did not merely suggest best practices. They mandated specific compliance behaviors — including one-click unsubscribe headers, sub-0.3% complaint rates, and proper authentication — as technical requirements. Senders who fail these requirements see their email throttled, spam-filtered, or rejected outright. Microsoft followed with its own enforcement requirements for Outlook.com in 2025, further tightening the link between compliance and deliverability.

The implication is profound: compliance failures no longer just risk legal penalties. They directly cause inbox placement failure. A missing List-Unsubscribe-Post header does not trigger a lawsuit — it triggers Gmail's spam filter. A deceptive subject line does not prompt a regulatory inquiry — it triggers a spam complaint that damages your domain reputation. The penalties that matter most are not fines from the FTC; they are the silent revenue losses from emails that never reach the inbox.

This convergence of legal compliance and technical deliverability means that every compliance decision is simultaneously a deliverability decision. Implementing double opt-in is not just about GDPR — it improves list quality and reduces complaints. Providing a prominent unsubscribe link is not just about CAN-SPAM — it reduces spam reports that damage your sender reputation. Maintaining a clean consent record is not just about regulatory audits — it ensures you are sending to people who actually want your emails, which is exactly what mailbox providers reward.

The businesses that understand this dual nature of compliance outperform those that treat it as a legal afterthought. They see higher inbox placement rates, lower complaint rates, better engagement, and — not coincidentally — zero regulatory risk. Compliance and deliverability are not competing priorities. They are the same priority viewed from different angles.

Deep dive into CAN-SPAM requirements -->

CAN-SPAM Act: The U.S. Baseline

The Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003 (CAN-SPAM) establishes the foundational rules for commercial email in the United States. Despite being over two decades old, CAN-SPAM remains the primary federal law governing email marketing to U.S. recipients, and the FTC actively enforces it.

CAN-SPAM is notably permissive compared to international regulations. It operates on an opt-out model — you can send commercial email to anyone until they ask you to stop. There is no requirement for prior consent. This makes CAN-SPAM the least restrictive major email law in the world, but it still has specific requirements that carry severe penalties when violated.

The seven core requirements of CAN-SPAM:

  1. No false or misleading header information. The "From," "To," "Reply-To," and routing information must accurately identify the person or business that sent the message. Using a misleading sender name or spoofed domain violates CAN-SPAM.

  2. No deceptive subject lines. The subject line must not mislead the recipient about the contents or subject matter of the message. Subject lines like "Re: Your account" when there was no prior conversation, or "Invoice attached" for a promotional email, violate this requirement.

  3. Identify the message as an advertisement. The law gives senders flexibility in how they disclose this, but the message must be clearly and conspicuously identified as an advertisement or solicitation. Many senders satisfy this with a small-print disclosure in the email footer.

  4. Include a valid physical postal address. Every commercial email must contain the sender's current, valid physical postal address. This can be a street address, a registered P.O. Box, or a private mailbox registered with a commercial mail receiving agency (CMRA). A virtual office address typically qualifies; an entirely fictitious address does not.

  5. Provide a clear opt-out mechanism. The email must include a clear, conspicuous explanation of how the recipient can opt out of future commercial email from you. The opt-out mechanism must be functional for at least 30 days after the email is sent.

  6. Honor opt-out requests within 10 business days. Once a recipient opts out, you must stop sending them commercial email within 10 business days. You cannot charge a fee, require the recipient to provide any information beyond their email address, or make them take any steps beyond sending a reply email or visiting a single web page to opt out.

  7. Monitor what others do on your behalf. If you hire another company to handle your email marketing, you cannot contract away your legal responsibility. Both the company whose product is promoted and the company that originates the message can be held liable.

The penalty for CAN-SPAM violations is up to $51,744 per individual email sent in violation. For a single campaign of 100,000 emails, the theoretical maximum penalty exceeds $5 billion. While regulators rarely pursue maximums, the FTC has imposed multi-million-dollar fines in high-profile cases. In addition to fTC enforcement, state attorneys general can bring CAN-SPAM actions, and some violations carry criminal penalties including imprisonment.

Common CAN-SPAM Mistakes That Trigger Violations

The three most frequently violated CAN-SPAM requirements are: (1) missing or invalid physical address — especially common among startups and remote-first companies that forget to include one; (2) slow unsubscribe processing — many senders technically have an unsubscribe link but continue sending emails for weeks because their suppression system is not properly synced across platforms; and (3) misleading "From" names — using a person's name that recipients do not recognize or associate with the brand, which the FTC considers deceptive header information.

It is critical to understand that CAN-SPAM applies to all commercial email — not just bulk marketing campaigns. One-to-one sales prospecting emails, automated drip sequences, and even transactional emails that contain marketing content are subject to CAN-SPAM requirements. The only emails fully exempt are purely transactional or relationship messages that do not contain any commercial content.

Complete CAN-SPAM compliance checklist -->

GDPR: The European Standard

The General Data Protection Regulation (GDPR), which took effect in May 2018, fundamentally changed how organizations collect, process, and store personal data for individuals in the European Economic Area (EEA). For email marketers, GDPR's impact is seismic: it replaced the permissive opt-out model with a strict opt-in consent requirement and introduced penalties severe enough to bankrupt non-compliant companies.

GDPR applies to any organization that processes the personal data of EU/EEA residents, regardless of where that organization is based. A U.S. company sending marketing emails to a subscriber in Germany is subject to GDPR. A Brazilian company collecting email addresses from French visitors to its website is subject to GDPR. Jurisdiction is determined by the location of the data subject, not the data controller.

The two lawful bases for email marketing under GDPR:

Explicit consent (Article 6(1)(a)) is the primary lawful basis for email marketing. Consent must be freely given, specific, informed, and unambiguous. This means pre-checked boxes are prohibited. Buried consent in terms-of-service is prohibited. Bundled consent (where opting into email is a condition of accessing a service) is prohibited. The subscriber must take a clear affirmative action — typically checking an unchecked box or clicking a dedicated opt-in button — with full knowledge of what they are consenting to. You must also be able to demonstrate that consent was given, meaning you need to store proof of when, how, and what the subscriber consented to.

Legitimate interest (Article 6(1)(f)) can sometimes be used for email to existing customers, but the bar is high. You must conduct a Legitimate Interest Assessment (LIA) documenting that: (1) you have a genuine, current interest in contacting the person, (2) the email is necessary to pursue that interest, and (3) the individual's rights and expectations do not override your interest. Legitimate interest is most defensible for sending to existing customers about similar products or services, and even then, you must provide an easy opt-out at the point of data collection and in every subsequent email.

Data subject rights that affect email operations:

  • Right to erasure (Article 17): Subscribers can request that you delete all their personal data. You must comply within 30 days and confirm deletion.
  • Right to data portability (Article 20): Subscribers can request their data in a machine-readable format to transfer to another controller.
  • Right to access (Article 15): Subscribers can request a copy of all personal data you hold about them, including consent records and email engagement data.
  • Right to rectification (Article 16): Subscribers can request correction of inaccurate personal data.

Organizations processing personal data at scale must appoint a Data Protection Officer (DPO) and maintain a Record of Processing Activities (ROPA). For email marketers, the ROPA should document every email list, the lawful basis for each, consent collection mechanisms, data retention periods, and third-party processors (ESPs) with whom data is shared.

GDPR penalties are the most severe in the world: up to 4% of global annual turnover or EUR 20 million, whichever is higher. These are not theoretical — regulators have imposed nine-figure fines on companies including Meta, Amazon, and Google. Smaller companies have received fines ranging from EUR 5,000 to EUR 500,000 for email-specific violations, including sending marketing emails without valid consent and failing to honor unsubscribe requests promptly.

The practical difference between CAN-SPAM and GDPR cannot be overstated. Under CAN-SPAM, you can buy a list of email addresses and send to them legally, provided you include an unsubscribe link and your physical address. Under GDPR, sending a single marketing email to an EU resident without their explicit prior consent is a violation that can trigger enforcement action. If your subscribers include anyone in Europe, GDPR is your governing standard.

Complete GDPR email compliance guide -->

CASL: Canada's Anti-Spam Legislation

Canada's Anti-Spam Legislation (CASL), enacted in 2014, is widely considered the strictest anti-spam law among major economies. Where CAN-SPAM allows opt-out and GDPR requires opt-in, CASL goes further with prescriptive rules about consent types, expiration windows, and even the installation of software — making it a uniquely comprehensive framework.

CASL applies to any Commercial Electronic Message (CEM) sent to or from a Canadian computer system. This means that sending a marketing email from a U.S. server to a Canadian recipient triggers CASL jurisdiction. The geographic reach is broad and the enforcement is real: the Canadian Radio-television and Telecommunications Commission (CRTC) has imposed penalties up to CAD 1.1 million on individual violations and can levy fines up to CAD 10 million per violation for businesses.

CASL recognizes two types of consent:

Express consent is the gold standard. The recipient has explicitly agreed to receive commercial electronic messages from you. Express consent requires: (1) a clear and simple description of the purpose for which consent is being sought, (2) identification of the person or organization seeking consent, (3) a statement that the recipient may withdraw consent at any time, and (4) contact information including a mailing address and either a phone number, email address, or web address. Express consent does not expire — it remains valid until the recipient withdraws it.

Implied consent exists in specific circumstances but is time-limited:

  • Existing business relationship: If someone has purchased a product, entered a contract, or made a written inquiry within the last 24 months, you have implied consent. After 24 months of no transaction or interaction, implied consent expires and you must obtain express consent to continue sending.
  • Existing non-business relationship: If someone has donated to your charity, volunteered, or been a member of your organization within the last 24 months, implied consent applies.
  • Inquiry or application: If someone has made an inquiry or submitted an application within the last 6 months, you have implied consent. Note the shorter window — inquiries give you only 6 months, not 24.
  • Conspicuous publication: If a person has conspicuously published their email address (e.g., on a business card or public website) without a "no unsolicited email" statement, and the message is relevant to their role or business, implied consent may apply.

CASL's Unique Installation Consent Requirement

CASL goes beyond email to regulate the installation of computer programs. If your email contains links that initiate software downloads, browser extensions, or application installations, you need separate, explicit consent for that installation under CASL. This is unique among global email regulations and catches many SaaS companies off guard. Even auto-updating software requires initial installation consent under CASL.

CASL's unsubscribe requirements are more demanding than CAN-SPAM's. The unsubscribe mechanism must be functional for at least 60 days after the message is sent, and you must process the unsubscribe request within 10 business days. The unsubscribe mechanism must be simple and accessible — requiring a login, providing personal information, or navigating multiple pages to complete the unsubscribe violates CASL.

The critical practical difference with CASL is the consent expiration. Unlike CAN-SPAM (where consent is irrelevant) or GDPR (where explicit consent does not expire), CASL's implied consent windows are hard deadlines. If a customer made their last purchase 25 months ago and you have not obtained express consent, sending them a marketing email violates CASL — even if they have never complained or unsubscribed. This makes consent lifecycle management essential for any organization with Canadian subscribers.

Enforcement under CASL includes both administrative penalties from the CRTC and a private right of action that allows individuals and organizations to sue for statutory damages of up to CAD 200 per violation (CAD 1 million per day). While the private right of action was temporarily suspended and has faced delays, it remains part of the legislation and could be activated, creating additional litigation risk for non-compliant senders.

Global Regulations at a Glance

Email compliance is increasingly a global concern. As countries strengthen their data protection frameworks, senders with international audiences must navigate a patchwork of regulations that vary significantly in consent models, enforcement mechanisms, and penalty structures. The four regulations below represent the most significant frameworks outside of CAN-SPAM, GDPR, and CASL.

POPIA — South Africa's Protection of Personal Information Act. Effective since July 2021, POPIA closely mirrors GDPR in its consent requirements. It requires a lawful basis for processing personal information, including opt-in consent or a legitimate interest justification. POPIA grants data subjects the right to access, correct, and delete their personal information. The Information Regulator enforces compliance, with penalties including fines up to ZAR 10 million (approximately USD 550,000) and imprisonment up to 10 years for serious offenses. For email marketers, POPIA's direct marketing provisions require prior consent unless the recipient is an existing customer and the communication relates to similar products.

LGPD — Brazil's Lei Geral de Protecao de Dados. Brazil's comprehensive data protection law, effective since September 2020, establishes 10 lawful bases for data processing, including consent, legitimate interest, and contract execution. LGPD consent must be free, informed, and unambiguous — similar to GDPR — and can be revoked at any time. The ANPD (National Data Protection Authority) enforces compliance with penalties up to 2% of the company's revenue in Brazil, capped at BRL 50 million (approximately USD 10 million) per infraction. LGPD applies to any processing of data of individuals located in Brazil, regardless of where the processing organization is based.

Australian Spam Act 2003. Australia's Spam Act requires express or inferred consent before sending commercial electronic messages. Inferred consent arises from existing business relationships or conspicuous publication of contact details. The law is enforced by the Australian Communications and Media Authority (ACMA), which can impose penalties up to AUD 2.22 million per day for bodies corporate. Notably, the Australian Spam Act also requires messages to include accurate sender identification and a functional unsubscribe facility that works within 5 business days.

Japan APPI — Act on the Protection of Personal Information. Japan's APPI, significantly amended in 2022, requires prior consent (opt-in) for sending commercial emails. The law requires senders to clearly identify themselves, provide an opt-out mechanism, and maintain records of consent. The Personal Information Protection Commission (PPC) enforces compliance with administrative penalties. While Japan's fines are generally lower than GDPR or LGPD, violations can result in criminal prosecution with imprisonment up to one year and fines up to JPY 1 million for individuals, with higher penalties for corporate violations.

The trend across all these frameworks is clear: the world is moving toward opt-in consent as the default standard for commercial email. The United States, with CAN-SPAM's opt-out model, is increasingly the outlier. Senders who build their programs around the strictest applicable standard — typically GDPR or CASL — will find themselves compliant everywhere. Senders who build to the CAN-SPAM minimum will face escalating legal risk as their subscriber base becomes more international.

For practical purposes, if you send email to recipients in multiple countries, adopt the highest common denominator approach: obtain explicit opt-in consent, provide instant one-click unsubscribe, maintain proof of consent, and honor data deletion requests. This satisfies every major regulation simultaneously and eliminates the need to segment compliance practices by geography.

One-Click Unsubscribe: The 2024 Mandate

The one-click unsubscribe requirement, mandated by Google and Yahoo for bulk senders starting February 2024, represents the most significant shift in email compliance enforcement in a decade. For the first time, mailbox providers are enforcing a compliance standard as a technical filtering criterion — making unsubscribe implementation a direct deliverability concern, not just a legal one.

The technical standard behind one-click unsubscribe is RFC 8058, which defines the List-Unsubscribe-Post header. This is distinct from the older List-Unsubscribe header (RFC 2369), which supported mailto: and HTTP URL-based unsubscribe but required the recipient to take additional steps. RFC 8058 adds a specific requirement: the unsubscribe action must complete with a single POST request, requiring no additional user interaction — no confirmation pages, no login screens, no "are you sure?" dialogs.

What bulk senders must implement:

  1. List-Unsubscribe header: Include a List-Unsubscribe header with an HTTPS URL and optionally a mailto: address. This header tells the email client that an unsubscribe mechanism is available.

  2. List-Unsubscribe-Post header: Include a List-Unsubscribe-Post: List-Unsubscribe=One-Click header. This header signals that the URL in the List-Unsubscribe header supports one-click unsubscription via HTTP POST.

  3. Server-side POST handler: Your unsubscribe URL must accept an HTTP POST request containing the parameter List-Unsubscribe=One-Click and process the unsubscribe immediately. The handler should return an HTTP 200 response and suppress the recipient from future emails without requiring any further action.

  4. No authentication barriers: The unsubscribe POST endpoint must not require the recipient to be logged in, solve a CAPTCHA, or take any additional action. The POST request alone must complete the unsubscription.

Google defines "bulk senders" as anyone sending 5,000 or more messages per day to Gmail accounts. Yahoo has adopted a similar threshold. Both providers have made clear that non-compliance results in increased spam filtering, throttling, and potentially outright rejection of messages.

The enforcement has teeth. Google's spam filter specifically checks for the presence and functionality of List-Unsubscribe-Post headers from bulk senders. Messages that lack this header are more likely to be classified as spam, even if all other signals — authentication, reputation, content — are healthy. This makes one-click unsubscribe one of the highest-leverage compliance actions you can take for deliverability.

Pro Tip from Boxset Team

If you use a major ESP like SendGrid, Mailgun, Postmark, or Amazon SES, check whether they automatically add RFC 8058-compliant List-Unsubscribe-Post headers to your emails. Most major ESPs updated their systems to comply with the Google/Yahoo requirements by early 2024. However, if you send from a custom mail server, a CRM with built-in email capabilities, or a marketing automation platform that handles its own SMTP, you may need to configure these headers manually. Test your headers using Google's Email Header Analyzer or by inspecting the raw source of a received email in Gmail — look for both the List-Unsubscribe and List-Unsubscribe-Post headers.

Beyond the technical implementation, one-click unsubscribe reflects a broader philosophical shift: making it easy to unsubscribe actually improves your deliverability. When recipients can unsubscribe with a single click, they are far less likely to click "Report Spam" — and spam complaints are vastly more damaging to your sender reputation than unsubscribes. A high unsubscribe rate is manageable; a high complaint rate is catastrophic. Making unsubscribe frictionless is one of the most counterintuitive but effective deliverability strategies available.

Complete one-click unsubscribe implementation guide -->

Consent Management Best Practices

Effective consent management is the operational backbone of email compliance. It is not enough to know what the law requires — you need systems, processes, and documentation that prove you are compliant, protect you during audits, and ensure that consent data flows correctly across every platform in your email stack.

The challenge most organizations face is not understanding consent requirements but implementing them consistently across fragmented systems. Your CRM captures consent at one point. Your website forms capture it at another. Your ESP manages unsubscribes. Your customer support team handles deletion requests. Without a unified consent management framework, gaps emerge — and those gaps become compliance violations.

Double opt-in is the gold standard for consent collection and should be your default for new subscribers. In a double opt-in flow, the subscriber enters their email address on your signup form and then receives a confirmation email containing a unique verification link. Only after they click the link are they added to your active sending list. Double opt-in eliminates typo-generated addresses, blocks bot signups, prevents third-party abuse (where someone enters another person's email), and creates an unambiguous record of consent. The slight reduction in signup conversion (typically 15-25% of subscribers do not complete confirmation) is far outweighed by the improvement in list quality, engagement rates, and compliance posture.

Proof of consent is required under GDPR and CASL and is best practice everywhere. For each subscriber, you should store: the exact timestamp of consent, the IP address from which consent was given, the specific form or page where consent was collected, the exact language the subscriber saw (including the checkbox text or consent prompt), and the version of your privacy policy that was active at the time. This data must be retrievable on demand — if a regulator or a subscriber requests proof that consent was given, you need to produce it immediately.

Preference centers go beyond the binary subscribe/unsubscribe choice and give subscribers granular control over what they receive. A well-designed preference center allows subscribers to choose email frequency (daily, weekly, monthly), select content categories (product updates, educational content, promotional offers), and specify communication channels. Preference centers reduce unsubscribes by giving dissatisfied subscribers an alternative to leaving entirely — they can dial down instead of opting out.

Consent logs are an audit trail that documents every consent-related event: initial opt-in, confirmation click, preference changes, unsubscribe requests, re-subscription, and data deletion requests. These logs must be immutable (append-only) and time-stamped. In the event of a regulatory audit, your consent log is your primary evidence of compliance. Treat it like a financial ledger — it must be complete, accurate, and tamper-proof.

Consent management is not a one-time project — it is an ongoing operational discipline. Laws evolve, your tech stack changes, new collection points appear, and subscriber preferences shift. The organizations that maintain the strongest compliance posture treat consent management as a living system with regular audits, automated enforcement, and continuous improvement.

Full consent management framework -->

How Boxset Helps You Stay Compliant

Compliance failures rarely happen because senders do not understand the rules. They happen because compliance requires cross-platform coordination that is difficult to maintain manually. Your ESP processes unsubscribes. Your CRM manages subscriber preferences. Your customer support team handles data deletion requests. Your marketing platform controls send lists. When these systems fall out of sync — and they inevitably do — compliance gaps emerge.

Boxset's Seltra Score addresses this by providing a unified compliance monitoring layer across your entire email infrastructure. Rather than checking compliance in each tool individually, Seltra Score aggregates signals from all connected ESPs, CRMs, and sending platforms to give you a single, real-time compliance health score.

Cross-ESP unsubscribe synchronization is one of the most critical compliance capabilities Boxset provides. When a subscriber unsubscribes from an email sent through SendGrid, that suppression must also apply to emails sent through your Mailgun transactional stream and your HubSpot marketing automation — immediately. Without cross-platform sync, a subscriber who unsubscribes from your marketing emails may continue receiving messages from other platforms in your stack, creating both a compliance violation and a spam complaint risk. Boxset detects unsubscribe events across all connected platforms and flags discrepancies in real time.

Compliance monitoring extends beyond unsubscribes to cover the full spectrum of regulatory requirements. Seltra Score continuously evaluates: whether your List-Unsubscribe-Post headers are present and functional, whether your complaint rates are trending toward thresholds, whether your consent records are complete and current, and whether your sending practices align with the requirements of the jurisdictions where your subscribers are located. When a compliance signal degrades, Boxset alerts your team with specific, actionable guidance on what to fix and why it matters for deliverability.

Monitor Compliance Across Every ESP in One Dashboard

Boxset's Seltra Score tracks unsubscribe sync, complaint rates, header compliance, and consent health across all your sending platforms — catching gaps before they become violations.

Try Seltra Score Free

The connection between compliance and deliverability is not abstract — it is measurable. Senders who maintain high Seltra Scores consistently see higher inbox placement rates, lower complaint rates, and fewer deliverability incidents. By treating compliance as a continuous monitoring discipline rather than a periodic audit, Boxset helps you stay ahead of both regulatory requirements and mailbox provider expectations.

Frequently Asked Questions

Discover Your Seltra Score

Get a single number that reflects the health of your entire email operation. Boxset's Seltra AI analyzes data from all your ESPs to calculate your real deliverability score.

Check Your Score Free

More in Compliance & Regulations