What CAN-SPAM Actually Requires from B2B Senders
B2B senders face the same CAN-SPAM requirements and penalties as consumer marketers.

CAN-SPAM applies to business email exactly as it applies to consumer email, with the same requirements (honest headers, non-deceptive subject lines, physical address, functional opt-out, and 10-day honor window) and the same penalty exposure. The rest of this piece walks through what each of those requirements actually demands, using real enforcement actions to show what happens when a B2B sender assumes otherwise.
Why B2B senders are not exempt from CAN-SPAM
A lot of marketers still operate as though business email lives in some lighter compliance lane, a gray zone where the rules that bind consumer marketing don't quite reach. That belief is wrong, and the law doesn't leave much room to argue otherwise. FTC guidance names B2B email as covered without qualification: there's no exception tied to the recipient holding a job title instead of a personal inbox, and no exception tied to where the sender happens to be based.
The clearest proof sits in the Verkada case from August 2024, an FTC and DOJ action against a B2B security camera company that received the largest CAN-SPAM penalty ever imposed ($2.95 million) for failing to provide opt-out mechanisms, honor unsubscribes, and include a physical postal address Communications Law Group outboundsystem.com. Verkada received the largest CAN-SPAM penalty on record, $2.95 million, for failing to give recipients a way to opt out, failing to honor the opt-outs it did receive, and failing to include a physical postal address in its emails Communications Law Group outboundsystem.com. The case only happened because they don't Communications Law Group outboundsystem.com.
This section is precise about what it is and isn't arguing. The point here is narrower and, for B2B senders, more urgent: the law covers business email at all. It does, in full.
CAN-SPAM: An Opt-Out Law, Not a Permission Law
CAN-SPAM lets you send commercial email without asking first. What it regulates is how you send it, and it guarantees the recipient a way to make it stop. That's the detail that trips up marketers who've absorbed compliance habits from GDPR or CASL, both of which generally require consent before the first message goes out. Under U.S. law, a cold email to a VP of Sales is legal on its face. CAN-SPAM doesn't block the first touch; it governs the contents of that touch.
That coverage isn't limited to bulk sends, either. A single, personalized prospecting email from an SDR counts as a commercial email under the law, and it has to comply with the same rules as a mass newsletter.
So where's the line between a commercial email and one that's exempt? A message counts as commercial if a recipient, reading the subject line the way an ordinary person would, would conclude it's advertising something, or if the transactional content doesn't appear in substantial part near the top of the message. Order confirmations, account updates, warranty notices, and shipping details are mostly exempt, but they still can't carry false or misleading routing information. Promotional newsletters, cold outreach, drip sequences, and affiliate campaigns fall on the commercial side by default. For B2B senders, this means drip sequences, product announcements, and feature-update emails that quietly double as upsell vehicles are almost certainly commercial under the test, whatever they're labeled internally.
Requirement 1: Honest "From" fields and routing information
The From, To, Reply-To, and every other routing field in a commercial email has to accurately identify whoever actually sent it. That sounds obvious until you look at how often it gets violated in practice.
One is borrowing a recognizable brand name in the From field, listing something like "Google" as the sender to boost open rates, when the real sender is a different company. The other is using a first name that isn't real, built to manufacture a sense of personal familiarity the recipient hasn't earned. Spoofed or misleading domains in the routing headers fall into the same bucket.
This requirement is unusual in that it applies to both commercial and transactional email alike, making it the one rule that crosses the line between the two categories cleanly. And it's the one area of CAN-SPAM with no interpretive give. Every other requirement discussed here has some flexibility in how it's satisfied. This one, however, allows no such flexibility. Common B2B violations include the following. Rather than resting on a specific figure, the argument here is definitional, with the Verkada example, already placed in the opener, anchoring enforcement credibility for the whole walkthrough.
Requirement 2: Subject lines that match what the email contains
Subject lines have to reflect what's actually in the message. Tricking someone into opening an email with a subject line that misrepresents the content is illegal under the law, full stop.
B2B outreach has its own recognizable violation patterns. "Re: Our conversation," sent to someone who has never spoken with the sender. "Your account has been suspended," used as a hook to open into a promotional pitch. False urgency, or a subject that implies one thing while the body delivers something else.
Experian's 2023 settlement with the FTC, which cost the company $650,000, is the case to know here Unsubscribe Central outboundsystem.com. Experian tacked a notice onto the bottom of promotional emails claiming they contained important account information, and some messages went further, stating outright that "this is not a marketing email" Unsubscribe Central outboundsystem.com. The FTC found these were commercial messages dressed up as something else, and the disclaimer didn't change that finding Unsubscribe Central outboundsystem.com. The lesson generalizes cleanly: labeling a message as non-promotional doesn't make it non-promotional in the eyes of the FTC. Classification follows how an ordinary recipient would read the subject line and body, not what the sender claims about its own intent. Given how visible subject lines are, both to regulators reviewing a complaint and to mailbox providers scoring intent algorithmically, they're the single clearest signal of what a message actually is.
Requirement 3: Identifying the message as an advertisement
Commercial email needs a clear, visible disclosure that it's an advertisement or solicitation. The law doesn't dictate exact wording here. A plain line in the footer, something like "this is a promotional message," is generally enough, and nothing requires a sender to stamp "ADVERTISING MESSAGE" across the body in bold type.
What the law won't tolerate is a disclosure that's technically present but practically invisible. B2B senders tend to skip this step on the assumption that a professional recipient obviously recognizes a sales email when they see one, so the disclosure feels redundant. The law doesn't accept that reasoning as a defense. A short, plain-language line in the footer, something like "you received this email because it is a commercial communication from [Company Name]," satisfies the requirement without disrupting the design of the email at all.
Requirement 4: A valid physical postal address in every message
An email address doesn't satisfy this. Neither does a website URL, and neither does a city name floating without a street or box number attached.
This isn't a rule regulators treat as a formality. Verkada's $2.95 million penalty specifically cited the absence of a valid physical postal address as one of the failures, alongside the missing opt-out mechanism Communications Law Group. For companies running outreach through sales engagement platforms, this creates a real operational risk: the address has to appear in every individual email sent, not just in a master template somewhere upstream. SDR tools that strip footers to make outreach look more personal can silently remove this exact element without anyone noticing until an enforcement letter arrives.
Remote-first companies and solo operators aren't exempt just because there's no headquarters to list. A P.O. box or a registered commercial mailbox satisfies the requirement fine. A home address works too, though the law doesn't do anything to resolve the privacy tradeoff that creates for the person whose home it is. The rule holds that every commercial email must include a valid physical postal address (a street address, a USPS-registered P.O. box, or a private mailbox registered with a commercial mail receiving agency.
Requirement 5: what makes an opt-out mechanism functional
Every commercial email needs a clear, visible way for the recipient to stop future messages. An unsubscribe link is the standard route, but a reply-to opt-out works too, and category-level opt-out menus are fine as long as one of the options lets someone stop all marketing outright rather than just narrowing what they receive.
The law also draws hard limits on what a sender can demand in exchange for honoring that request. No fee. No personal information beyond the email address itself. And no more than one step past the initial click, which rules out multi-page confirmation flows or a login wall standing between the recipient and the exit.
The mechanism has to stay working for at least 30 days after the email goes out. A link that's broken the moment the email sends and a link that fails three weeks later are different failures in practice, but both land on the wrong side of the law. SDR sequences run into a particular version of this problem: they're often built to look like a personal one-to-one email. As a result, they frequently skip the unsubscribe link entirely. Looking personal doesn't exempt a message from the opt-out requirement if its primary purpose is commercial, and most SDR sequences clearly are.
Separately, in 2024, Gmail and Yahoo began requiring senders pushing more than 5,000 emails a day to support RFC 8058, a machine-readable one-click unsubscribe header outboundsystem.com. That's a mailbox-provider rule, not a CAN-SPAM rule, but it pushes the practical floor for anyone sending at real volume above what the statute alone demands outboundsystem.com.
Requirement 6: Honoring opt-out requests within 10 business days
Once someone opts out, the sender has 10 business days to stop sending, and the opt-out mechanism itself has to stay active for at least 30 days from when the email was sent cookie-script.com joinbreaker.ai. After that opt-out, the sender can't sell, transfer, or share the address with anyone else, with one narrow exception: handing it off to a company hired specifically to help with CAN-SPAM compliance.
Ten business days is the outer legal limit, not something to aim for. Most modern email platforms support real-time suppression, and that's the actual best practice cookie-script.com joinbreaker.ai.
B2B operations tend to fail at this step in a few specific, recurring ways. Drip sequences are the clearest case: each email in an automated multi-touch sequence counts as its own potential violation, so an unsubscribe on message two has to suppress messages three through ten, not just pause the current send. CRM-to-ESP sync gaps cause a quieter version of the same failure, where a contact marked unsubscribed inside the CRM doesn't propagate to the email platform fast enough to stop the next scheduled send.
Suppression list hygiene is both a legal requirement and an operational discipline (the 10-day window creates the legal exposure, but the real risk in high-volume sending is the gap between the unsubscribe event and the moment every downstream system knows about it) cookie-script.com joinbreaker.ai.
Requirement 7: Accountability when a third party sends on your behalf
If an agency, an affiliate, a lead-gen vendor, or an outsourced SDR team sends commercial email on a company's behalf, that company stays legally responsible for every requirement covered above, regardless of who's technically pressing send. Both the company whose product is being promoted and the company actually sending the message can be held liable on the same campaign, sometimes with separate fines attached to the same send.
A vendor contract that assigns "all compliance responsibility" to the outreach company doesn't shield the promoting company from the FTC. Regulators don't recognize that kind of private agreement as a liability shield. Practically, this makes vendor diligence a legal necessity rather than a nice-to-have, requiring vendors' templates to carry a physical address, a working opt-out, and accurate From fields, and requiring confirmation of how suppression lists sync before a campaign goes live, rather than after. Affiliate networks deserve particular scrutiny here, since violations often start exactly where unsubscribe lists fail to sync across parties. The claim "someone else handles our email" simply isn't a legal defense, no matter how the contract is worded.
The primary purpose test: how mixed-content emails get classified
The primary purpose test, codified at 16 C.F.R. § 316.3, is what regulators use to sort commercial email from transactional email when a message tries to do both. The test looks at how an ordinary recipient would read the message, not at what the sender calls it internally. A message counts as commercial if a typical reader interpreting the subject line would conclude it's advertising something, or if the transactional content doesn't appear in substantial part near the start of the body.
B2B email runs into this constantly with mixed-content messages. An order confirmation that opens with product recommendations before getting to the actual order details. An account update that leads with a feature upsell and buries the account information further down. A renewal notice structured mostly as a pitch to upgrade, with the renewal itself mentioned almost in passing.
Experian's 2023 settlement is the precedent to point to Unsubscribe Central outboundsystem.com. Its emails told recipients the message contained important account information and stated explicitly that it wasn't a marketing email Unsubscribe Central outboundsystem.com. The FTC found otherwise, because the actual function of the message was to pitch new products, and the disclaimer language did nothing to change that classification Unsubscribe Central outboundsystem.com. The safer path for a sender who genuinely wants transactional treatment is straightforward: put the transactional content first, visibly and substantially, keep promotional material out of the subject line, and make sure any upsell content stays clearly secondary in both placement and visual weight.
What non-compliance costs: the penalty structure
The penalty attaches per email sent, not per campaign, which is what makes automated sequences so dangerous from a liability standpoint Email Calculator / FTC FTC outboundsystem.com iscoldemaillegal.com. The FTC confirmed in September 2026 that it would hold the penalty at its 2025 level of $53,088 per non-compliant email, after the 2026 annual inflation adjustment was cancelled under OMB Memo M-26-11, dated April 17, 2026 Email Calculator / FTC outboundsystem.com iscoldemaillegal.com. Running that figure against a drip sequence sent to a list of any real size turns the arithmetic from a rounding error into a number that ends companies.
Sources
- Compliance Guide for the CAN-SPAM Act
- Can You Send Marketing Emails to Companies?
- Email Outreach Compliance Rules: CAN-SPAM, GDPR & More (2026)
- CAN-SPAM Act Explained: What Cold Emailers Need to Know | Is Cold Email Legal?
- CAN-SPAM Act Requirements: What B2B Marketers Must Know | Breaker Blog
- unsubcentral.com

