truthEmail7 min read

Nobody Needs Your Opt-In

Federal email law doesn't require opt-in like most people assume, and the real legal exposure has shifted to one state's court rulings.

Share this page

Short answer

Federal law (CAN-SPAM) doesn't require consent before sending a commercial email and gives individuals no right to sue over violations; only the FTC and state regulators can enforce it. The real financial risk now runs through state deception law, especially Washington's CEMA, where a 2025 court ruling turned misleading subject lines into a wave of over 100 private lawsuits.

Key takeaways

  • CAN-SPAM is an opt-out law, not opt-in. You can send a first commercial email without prior consent under federal law.
  • There's no private right of action under CAN-SPAM. Only the FTC, DOJ, state attorneys general, and ISPs can enforce it.
  • The FTC's maximum penalty is $53,088 per non-compliant email as of 2026, assessed per message, not per campaign.
  • Washington's CEMA now lets individuals sue directly over misleading subject lines. Lawsuits went from about 8 to over 100 within a year of an April 2025 court ruling.
  • State comprehensive privacy laws add opt-out and disclosure obligations around email marketing even though they aren't email-specific statutes.
  • The TCPA does not apply to email. It governs phone calls and text messages; commercial email is governed entirely by CAN-SPAM.

This is not legal or professional advice. I am not a lawyer. The sources I cite may be incomplete, my interpretation of them may be wrong, and the law changes. Do your own research and hire a qualified attorney before you act on any of this.

Federal law does not require permission before you email someone commercially. That single fact runs against almost everyone's assumption, usually because GDPR, CASL, and the last twenty years of "always get opt-in" marketing advice have trained people to expect a consent requirement that the actual U.S. statute never imposed. CAN-SPAM is an opt-out regime. You can email a stranger with no prior relationship and no consent, and be fully compliant, as long as you follow the rules and let them leave when they ask. That's the first confusion. The second is bigger: almost nobody can sue you over it, except in one state, where the exposure just became enormous.

This is CAN-SPAM territory, not TCPA. The Telephone Consumer Protection Act, the law that governs phone calls and text messages with per-call statutory damages, has no reach into email at all. Email runs under a completely separate statute, with a different structure, different penalties, and a different enforcement path. Conflating the two is one of the most common mistakes in this space.

What the federal law actually requires

The CAN-SPAM Act (2003) sets seven rules for any commercial email, meaning any message whose primary purpose is advertising or promoting a product or service. B2B and B2C are both covered; there's no exemption for cold outreach to businesses.

  • No false or misleading header information (From, domain, routing data)
  • No deceptive subject lines
  • Clear identification that the message is an advertisement
  • A valid physical postal address (a PO box is fine)
  • A working, clearly visible opt-out mechanism
  • Opt-outs honored within 10 business days
  • Responsibility for what a third-party marketer does on your behalf, you can't outsource liability to your ESP or agency

That's the entire federal standard, laid out in the FTC's own compliance guide for business. No consent requirement, no double opt-in, no cooling-off period. Businesses that already do double opt-in are doing it as a deliverability and trust practice, not because the law requires it.

"Reply to unsubscribe" isn't a compliance checkbox

The FTC's rule on opt-out mechanisms is narrow by design: you can require a recipient to do one of exactly two things to opt out, reply to the email or visit a single web page. Nothing more. No fee, no login, no extra information beyond the email address itself. A reply-based opt-out is fully legal on its own terms.

Where it breaks down is what happens after the reply gets sent. The law doesn't just require that recipients have a way to unsubscribe. It requires the sender to actually process that request within 10 business days. A lot of cold-email tooling sends from rotating addresses or inboxes nobody actively monitors, purpose-built for deliverability, not for catching replies. Telling someone to reply STOP when nothing on your end is watching that inbox isn't a compliance mechanism. It's an instruction with no system behind it, and the gap between the two only becomes visible when someone complains and you can't produce a record the request was ever honored.

This is exactly the kind of thing that gets skipped in outbound-sales communities, where the advice optimizes for reply rates and deliverability, not for whether the removal request on the other end of that reply actually goes anywhere. A working unsubscribe link tied to an automated suppression list closes that gap. A reply address nobody reads doesn't, no matter what the footer says.

The number that gets people's attention

Each non-compliant email is a separate violation, and the FTC's inflation-adjusted maximum is $53,088 per message as of 2026, up from $16,000 when the law passed in 2003. That's not a typo and not per campaign: a 10,000-email send with a broken unsubscribe link is 10,000 separate violations in theory. In practice the FTC settles based on scale and conduct, not the theoretical ceiling, but the ceiling is what gives them room to negotiate hard. Verkada paid $2.95 million in 2024, the largest CAN-SPAM penalty to date, over deceptive marketing emails.

Here's the part that surprises people who assume every consumer protection statute works the same way: there is no private right of action under CAN-SPAM. An individual who gets a non-compliant email cannot sue under the federal statute, no matter how many rules it broke. Enforcement runs through the FTC, the DOJ, state attorneys general, and ISPs, not through the recipient. A federal law with a $53,088-per-email penalty and nobody but the government allowed to collect it sounds like a contradiction. It isn't. The leverage just sits somewhere else, as the next section shows.

Why there's no 50-state patchwork, until there is

CAN-SPAM contains an express preemption clause. It displaces state laws that specifically regulate commercial email. That's unusual: most areas of consumer protection law let states pile their own rules on top of the federal floor, which is how you end up with fifty different versions of the same requirement. Congress built CAN-SPAM specifically to stop that from happening to email: one national standard, not fifty.

The preemption has one exception, and it's load-bearing: state laws survive if they address falsity or deception, rather than regulating commercial email as such. A state can still punish you for lying in an email. It just can't impose its own separate consent or labeling regime on top of the federal one.

For twenty years that exception was a footnote. In 2025 it became the whole story.

The state where the exception ate the rule

Washington has had an anti-spam law, CEMA, on the books since 1998. Courts read it narrowly for most of that time: a subject line only violated CEMA if it misled someone about whether the email was an ad at all.

On April 17, 2025, the Washington Supreme Court threw that reading out. In Brown v. Old Navy, ruling 5-4 on a certified question, the court held that CEMA prohibits any false or misleading information in a subject line, not just information misleading about the email's commercial nature. Old Navy had sent emails saying a sale was ending on a specific date; the sale continued past that date. That's enough. The statutory penalty: $500 per violation, and unlike CAN-SPAM, CEMA lets an individual bring the claim directly.

The number of CEMA lawsuits went from roughly eight, total, before the ruling, to over a hundred within about a year. Old Navy, Macy's, Nike, and Discount Tire have all been named, mostly over the same pattern: urgency language in a subject line ("Ends tonight," "Last chance") that didn't quite match what happened next. In January 2026, a federal judge ruled on the obvious defense, that CAN-SPAM preempts this: it doesn't, because CEMA fits squarely inside the falsity-and-deception exception. The Washington legislature narrowed the standard in March 2026, adding a requirement that the sender knew or should have known the subject line was misleading, but didn't apply that change retroactively, so the existing wave of lawsuits proceeds under the old, stricter standard.

The lesson generalizes past Washington. CAN-SPAM's federal floor is genuinely permissive, no consent needed, no private lawsuit exposure. The real risk in commercial email right now isn't the federal statute. It's whatever your state's deception-based consumer protection law says about subject lines, and whether that state, like Washington, has an aggressive plaintiffs' bar that just found a lever with real numbers attached to it.

One more layer, still forming

State comprehensive privacy laws, the CCPA/CPRA-style statutes now active in around twenty states, aren't email laws and so aren't touched by CAN-SPAM's preemption clause at all. They don't require opt-in to send commercial email either. But they increasingly require honoring opt-out-of-sale and opt-out-of-targeted-advertising signals, disclosing how an email list was built, and letting people access or delete the data behind it. None of that is CAN-SPAM. All of it can apply to the same email program. This layer is newer and less litigated than the CEMA wave, worth watching rather than treating as settled.

What this means if you're actually sending email

You don't need consent to send a first commercial email under federal law. You do need every one of the seven CAN-SPAM elements, every time, because the per-email penalty math makes even honest mistakes expensive at scale. And you need to treat your subject lines as a legal document if you have any meaningful list of Washington residents, or frankly anywhere else, since Washington's plaintiffs' bar has shown exactly how fast a state deception statute can go from ignored to load-bearing once one court reads it broadly. "Sale ends tonight" needs to be true tonight.

Sources

Federal law

Washington CEMA litigation

This is not legal or professional advice. I am not a lawyer. The sources I cite may be incomplete, my interpretation of them may be wrong, and the law changes. Do your own research and hire a qualified attorney before you act on any of this.

Frequently asked

Do I need permission before sending someone a commercial email?

No. Federal law (CAN-SPAM) is an opt-out regime, not opt-in. You can email someone with no prior relationship as long as you follow the seven core rules and honor opt-outs.

Can I get sued for a bad marketing email?

Not under federal law directly, CAN-SPAM has no private right of action. But in Washington state, an individual can sue directly under CEMA for a misleading subject line, and that theory has spread to over a hundred lawsuits since April 2025.

How much can the FTC fine a company for CAN-SPAM violations?

Up to $53,088 per non-compliant email as of 2026, assessed per message, not per campaign.

Do state privacy laws require opt-in for email marketing?

Not directly. CCPA-style state privacy laws don't set email-specific consent rules, but they do require honoring opt-out-of-sale and targeted-advertising signals, which can touch the same email program.

Does CAN-SPAM apply to B2B cold email?

Yes. CAN-SPAM covers any commercial email, B2B and B2C alike. There's no exemption for business-to-business outreach.

Does the TCPA apply to marketing emails?

No. The TCPA governs phone calls and text messages. Email is governed entirely by a separate law, the CAN-SPAM Act.

Is telling someone to reply "unsubscribe" enough to be compliant?

Only if you actually monitor and process that reply within 10 business days. The instruction itself isn't the compliance, the system behind it is.

Sources

Keep reading