You're about to hit send on a cold email campaign, and you pause. You've heard stories about spam laws, CAN-SPAM violations, GDPR fines, and legal cease-and-desist letters. So you wonder: am I allowed to do this? Will I get sued?
The answer is yes, you're allowed to do cold email - but there are real rules you need to follow, and they're not as complicated as people make them sound. The confusion happens because most advice conflates "best practices" with "legal requirements." They're different things.
This post breaks down what's actually illegal versus what just tanks your deliverability. If you follow the legal stuff, you'll stay out of trouble. If you also follow the best practices, you'll actually get replies.
The Main Laws That Actually Apply to B2B Cold Email
There are three laws you need to know about. If you operate in or send to people in these regions, they apply to you.
CAN-SPAM (United States)
CAN-SPAM is the federal law that governs commercial email in the US. It's been around since 2003 and it's what most people worry about. The actual legal requirements are minimal:
- Your email must have a truthful subject line - you can't mislead people about what the email is about
- You must identify the email as an advertisement
- You must include your physical business address somewhere in the email
- You must include an unsubscribe mechanism and honor opt-out requests within 10 business days
That's it. Those four things are what make an email legal under CAN-SPAM. The law doesn't require you to have prior consent to send the initial email. You don't need permission to cold email someone in the US.
Penalties for CAN-SPAM violations start at $43,280 per email (as of 2024), but that's only if you're knowingly and repeatedly violating the law - like sending millions of spam emails after being warned. A handful of aggressive cold emails isn't going to trigger federal action.
GDPR (European Union and EEA)
This is where B2B cold email gets stricter. GDPR applies if you're sending to anyone in the EU, UK, or EEA countries - even if you're not based there.
Under GDPR, you technically need "legitimate interest" or "prior consent" to send cold email. For B2B, legitimate interest usually covers it - you're reaching out to a business professional at their work email because you have a genuine business purpose. You're not harvesting their personal data or doing anything creepy.
The key: if someone asks you to stop, you must stop immediately. And you need to be able to explain your legitimate interest if asked. "We thought they might want our service" is legitimate interest. "We bought their email from a list and spam everyone" is not.
GDPR fines are serious - up to 4% of annual revenue or 20 million euros, whichever is higher. But again, that's for egregious violations. Sending 50 personalized cold emails to relevant business contacts won't trigger that.
CASL (Canada)
CASL is Canada's strict anti-spam law. It requires prior consent before sending commercial emails to anyone in Canada. Unlike CAN-SPAM or GDPR, there's no legitimate interest exception for B2B.
However - and this matters - if you're sending to a business email address ([email protected]) as opposed to a personal email, you're usually okay. The spirit of CASL is to protect consumers, not B2B professionals. Still, it's worth checking the specific rules if Canada is a major market for you.
What ISPs and Email Providers Actually Care About
Here's the practical reality: ISPs (Gmail, Outlook, etc.) don't care about CAN-SPAM unless you're sending millions of emails. What they care about is whether your email looks like spam and whether people complain.
Gmail's spam folder is populated by machine learning algorithms that look at sender reputation, authentication records, user behavior (do people mark it as spam?), and content patterns. This is why cold email deliverability is more about technical setup than legal compliance.
If you have proper SPF, DKIM, and DMARC records set up, a warm IP address, a low spam complaint rate, and non-spammy email content, you'll land in the inbox. If you don't, you'll land in spam - regardless of whether you're technically following CAN-SPAM.
This is why many B2B agencies send emails that technically violate CAN-SPAM (no unsubscribe link, no physical address) and still land in inboxes. The ISP doesn't check for CAN-SPAM compliance. It checks for user experience signals.
The Practical Rules for B2B Cold Email That Won't Get You in Trouble
Always include an unsubscribe mechanism
This is a legal requirement under CAN-SPAM and GDPR. The unsubscribe link doesn't have to be obvious, but it needs to exist. Most cold email platforms include a footer with a link like "manage preferences" or "unsubscribe." Honor opt-out requests immediately - don't keep sending after someone asks you to stop.
Use a subject line that's actually honest
CAN-SPAM requires a truthful subject line. This doesn't mean you have to write boring subject lines. It means the email should be about what the subject line says.
This is legal:
Quick question about [Company] growth
This is not:
Your account has been suspended - click here
That second one is deceptive. The person doesn't have a suspended account. You lied to get them to open it. That's a CAN-SPAM violation.
Include your actual business information
CAN-SPAM requires you to identify your business and include your physical address. You can put this in the email signature or footer. Example:
John Smith BEC Growth New York, NY (555) 123-4567
That's sufficient. You don't need your full street address, just your business name and location.
Target B2B, not personal accounts
Send to people at their work email address ([email protected]), not their personal email. This keeps you compliant with GDPR legitimate interest and CASL. It also improves deliverability because you're reaching decision-makers at their business accounts where they check professional emails.
Don't use misleading sender information
Your "from" address should actually be you or your company. CAN-SPAM forbids spoofing. If you're sending from [email protected], that address should actually receive replies. If you're sending from a personal Gmail account, it should be your actual email.
What You Don't Actually Need to Do
You don't need prior consent to send B2B cold email in the US or most of Europe (GDPR has the legitimate interest exception). You don't need to add disclaimers or legal jargon. You don't need to have a formal "do not contact" list before you start - just honor opt-outs when they come in.
Cold email is legal. Spamming is not. The difference is personalization, relevance, and respect for opt-outs.
The Real Gap: Knowing vs. Executing at Scale
Understanding B2B cold email legality is one thing. Actually building compliant infrastructure while maintaining sender reputation, finding the right leads, writing emails that convert, and managing responses at scale is another. You need proper authentication records, a warming strategy, list validation, reply infrastructure, and CRM integration - all while staying on the right side of the law. That's where most agencies struggle.