In the US you can email a business you've never spoken to, without asking first. That's legal under the CAN-SPAM Act, as long as the email follows a short list of rules. Those rules apply to business-to-business email just as much as to consumers, and they're easy to follow once you know them.
Does CAN-SPAM apply to B2B email?
Yes. The law covers any "commercial electronic mail message": an email whose main purpose is to advertise or promote a product or service. There's no exception for emails sent to businesses, so a cold email to a restaurant owner is covered in the same way as a newsletter to a shopper.
What it doesn't require is permission. Unlike the rules in Canada or the EU, CAN-SPAM lets you send the first email without prior consent; it's an opt-out law, not an opt-in one.
The seven rules
The Federal Trade Commission, which enforces the law, sums it up in seven requirements:
- 1. Honest header information. The From name, From address, Reply-To and routing must be accurate and identify who's sending. No pretending to be someone else, and no domains set up to hide who you are.
- 2. An honest subject line. It must reflect what the email is about. "Re: your invoice" on a first sales email is deceptive.
- 3. Say it's an ad. The message must be identified as an advertisement or offer. There's no required wording, but it has to be clear and conspicuous; a plain sales email that obviously offers a service usually does this naturally.
- 4. Your postal address. Every email must include a valid physical postal address: a street address, a post office box registered with USPS, or a private mailbox registered with a commercial mail receiving agency.
- 5. A clear way to opt out. Tell people how to stop future emails, in a way that's easy to notice and use. A reply-based opt-out ("reply unsubscribe") or a link both work.
- 6. Honor opt-outs quickly. Within 10 business days. You can't charge a fee, ask for anything beyond an email address and preferences, or make people visit more than one page. The opt-out has to keep working for at least 30 days after you send, and you can't sell or hand over the address of someone who opted out.
- 7. Watch what others do for you. If an agency or service sends email that promotes your business, you are both responsible for following the law.
Commercial or transactional?
An email whose main purpose is a transaction or relationship (a receipt, an account notice, a reply to a question someone asked you) is "transactional" and mostly exempt, though it still can't have false header information. A first sales email to someone who hasn't asked is commercial. If an email mixes both, what decides it is the subject line and what comes first in the body.
What can go wrong
Each email that breaks the rules can bring a civil penalty, and the FTC's figure has been over $50,000 per email in recent years. The law also treats some practices as aggravated violations: for example, collecting addresses from websites that publish a notice saying their addresses may not be used for email, or generating addresses by guessing combinations of names and domains.
CAN-SPAM overrides most state email laws, but not state rules against false or deceptive email, so honesty is the line that matters everywhere.
What inboxes require on top of the law
Being legal doesn't mean being delivered. Since 2024, Gmail and Yahoo have asked senders to:
- authenticate their domain with SPF, DKIM and DMARC;
- keep spam complaints very low (Google's guidance is under 0.3%, ideally under 0.1%);
- for large senders, offer one-click unsubscribe and process it within two days.
Small, personal cold email from your own domain is far from "bulk" volumes, but the same habits keep it out of spam. Our cold email checklist covers warm-up, checking addresses and follow-ups.
Outside the US
Other countries are stricter. Canada's CASL generally needs consent before the first commercial email, and the EU and UK have their own rules on electronic marketing and personal data. If your list includes businesses outside the US, check those rules before you send.
How BeatTheDoor handles it
Every email we send for a client goes out from the client's own domain with an honest From line and subject, names the client, includes their postal address and a "reply unsubscribe" line, and stops at the first opt-out. An opted-out address goes on a shared do-not-email list so no BeatTheDoor client emails it again. See our data sources and compliance, or book a 15-minute demo.
This guide explains US rules in general terms as of October 2026. It isn't legal advice; for anything specific to your business, ask a lawyer.