You're getting results from cold email. Clients are responding. Meetings are happening. Revenue is coming in.

Then you hear about spam laws. CAN-SPAM. GDPR. CASL. Your stomach drops a little. You start wondering: am I going to get fined? Is my domain going to get blacklisted? Am I about to lose everything because I didn't know some obscure regulation?

This fear is real - and honestly, it's keeping a lot of good people from using cold email to grow their business. But here's the thing: most of that fear is overblown. The laws aren't as complicated as people make them out to be. And if you follow some basic rules, you're going to be fine.

Let me walk you through what actually matters in 2026.

The Three Laws You Need to Understand

There are really only three regulatory frameworks that matter for cold email if you're in North America or working with European clients.

CAN-SPAM (United States)

CAN-SPAM is the big one for most people. Here's what it actually requires:

That's basically it. CAN-SPAM doesn't require you to get permission before sending the first email. You can cold email. You just have to follow those rules above.

The FTC enforces this. And honestly? They go after the obvious spammers - the people sending millions of emails with fake headers, misleading subjects, and no unsubscribe button. If you're a service business sending personalized emails to real leads, you're not their target.

GDPR (European Union)

GDPR is stricter. If you're emailing people in the EU, you generally need permission before sending that first email. Some countries have exceptions for B2B emails to business email addresses (not personal Gmail addresses), but the safe play is getting permission first.

The good news: GDPR violations happen when you're sloppy or deliberately deceptive. If you're building legitimate lead lists and sending real emails to real business decision-makers, you're fine. It's the people buying random email lists and blasting thousands of identical emails who get in trouble.

CASL (Canada)

CASL is Canada's version of CAN-SPAM, but stricter. You basically need explicit permission before sending. Similar rules apply: clear unsubscribe option, honest subject line, physical address.

If you're only targeting the US, CASL doesn't apply to you. If you're working with Canadian clients, treat it like GDPR - get permission first.

What Actually Matters in Practice

Here's what separates people who never have issues from people who get into trouble:

Use a Legitimate Email Infrastructure

This is non-negotiable. You need:

This infrastructure isn't just for compliance - it's what gets your emails to the inbox instead of spam. If you're using a sketchy sending platform or not setting up DNS records, your emails won't land anyway. You're wasting your time.

Build Real Lead Lists

Don't buy random email lists. Don't use data scraped from LinkedIn without permission. Find real prospects - companies you want to work with, people in roles that make sense for your services.

This matters because:

Personalize Your Emails

Send real emails to real people. Reference something about their company or role. Show you've actually looked at them as a prospect, not just grabbed their email from a list.

This does two things for compliance: it reduces spam complaints (because your emails are actually relevant), and it shows intent. You're not a spammer, you're a business reaching out to potential clients.

Always Include an Unsubscribe Option

Put an unsubscribe link at the bottom of every email. In your email sending platform, make sure unsubscribes are actually processed - don't keep emailing people after they ask to stop.

Seriously. This is easy and it's one of the main things regulators look for.

Keep Records

Save copies of your emails, your lead lists, and your sending logs. If someone ever questions what you did, you want to be able to show: