If you're sending cold emails to Canadian businesses, CASL (Canada's Anti-Spam Legislation) is probably on your radar. If it isn't, it should be. Canada has one of the strictest anti-spam laws globally, and the penalties are real - up to $1 million per violation for individuals, $10 million for companies. But here's the thing: most people running cold email campaigns either overcomplicate CASL or ignore it entirely. Neither approach works.
The gap between January 2026 and now matters because enforcement is increasing, and compliance infrastructure is getting tighter. If you're targeting Canadian buyers - and you probably are, since Canada has solid B2B markets - you need to understand what CASL actually requires, not what people think it requires.
What CASL Actually Requires (The Short Version)
CASL applies to any commercial electronic message sent to a Canadian email address. It doesn't matter where you are when you send it - if it lands in Canada, CASL applies.
The core rule: You need either explicit or implied consent before sending a commercial message. This is stricter than CAN-SPAM in the US. You can't just send to any address you find and include an unsubscribe link. You need consent first.
"Implied consent" is the practical path for cold email. It exists when someone has an existing business relationship with you, they've made a recent inquiry about your services, or they've engaged with your content and it's reasonable to assume they'd want to hear from you.
In cold email terms: If you're emailing someone at their business email address because their company's website indicates they're a decision-maker in your target industry, and you're reaching out with something relevant to their business, that's defensible as implied consent. It's not a guarantee, but it's the foundation cold email in Canada sits on.
The Three Non-Negotiables for CASL Cold Email
1. Your From Name and Email Address Must Be Real and Accurate
You can't use a generic "noreply" address or a fake name. The sender's identity must be true. If you're John Smith, you sign as John Smith. If you're running a campaign on behalf of a company, the email comes from a real person at that company, not from a bot or masked address.
2. The Subject Line Can't Be Deceptive
This is straightforward - don't mislead someone about what's in the email. You can use curiosity or urgency in the subject line (that's fine everywhere), but you can't claim it's a response to something they never sent, or that it's from a company it isn't from. The subject line should give a reasonable sense of what's inside.
3. You Must Include Clear Unsubscribe Information
Every commercial email needs an unsubscribe mechanism. This can be a link, an email address to reply to, or a clear mailing address. You must honor unsubscribe requests within a specific timeframe - generally within 10 business days. Don't ask why they're unsubscribing, don't try to talk them out of it, just remove them.
What Your Email Actually Needs (The Practical Setup)
Here's what a CASL-compliant cold email looks like in practice:
Subject: Quick question about your demand gen approach Hi [Name], I noticed your team's been ramping up content around ABM. We've helped similar B2B platforms increase qualified pipeline by 40% in their first 90 days using a different sequencing model. Worth a quick conversation? John John Smith BEC Growth [email protected] --- If you'd prefer not to receive emails like this, just let me know and I'll remove you from our list. BEC Growth Inc. 123 Main St Toronto, ON M1A 1A1
Notice what's here: A real person's name, a real company, a real email address. The subject line describes what's in the email. The unsubscribe is explicit and easy - "let me know." At the bottom, you could add a full address or keep the unsubscribe simple depending on your setup.
That's it. You don't need to add "This is a commercial message" in neon letters. You don't need a 50-word legal disclaimer. Just be straightforward.
Common CASL Mistakes That Cost You
Mistake #1: Hiding Your Unsubscribe Option
If someone has to hunt through three paragraphs to find the unsubscribe mechanism, that's a problem. Make it visible in the email footer. One sentence, clear link or instruction.
Mistake #2: Targeting Broad Consumer Lists
If you're buying a list of email addresses and none of them have any prior engagement with you or your company, CASL gets trickier. The implied consent argument weakens significantly. For B2B cold email - where you're targeting people by role and company - this is usually fine. For B2C or when you're sending to generic address lists, you're in a gray zone.
Mistake #3: Not Respecting Unsubscribes Immediately
When someone replies "remove me," remove them. The same day. Add them to a suppression list you use across all future sends. Continuing to email someone after they've unsubscribed is where CASL enforcement actually focuses. This is straightforward to avoid.
The Infrastructure Side That Matters
From an email infrastructure perspective, CASL compliance requires:
- Authenticated email domains (SPF, DKIM, DMARC configured correctly)
- A clear unsubscribe mechanism that actually works
- An active suppression list you maintain and update
- Accurate physical mailing address on file
If you're using a reputable email service provider (SendGrid, Mailgun, Klaviyo, etc.), they'll handle most of the authentication. The unsubscribe mechanism needs to be tied to your CRM or database so you can suppress future sends.
Physical address is something many people miss. CASL requires it. If you're a solo operator, it can be a business address or your office address. If you're a company, use your registered business address. This is listed in the email footer.
CASL vs. Other Compliance Rules You're Already Dealing With
If you're sending cold emails internationally, you're likely juggling CASL, CAN-SPAM (US), GDPR (EU), and potentially others. The good news: CASL is stricter on some points and looser on others. If you're already compliant with GDPR requirements for cold email, CASL is actually easier - GDPR requires explicit consent for almost all cold email, while CASL allows implied consent in business contexts.
If you understand CAN-SPAM compliance for cold email, CASL feels like a stricter version of the same basic concept - real sender, clear subject, easy unsubscribe - with higher penalties for violations.
Why This Matters Right Now
Canada's spam enforcement has stepped up enforcement in recent years. The CASL authorities aren't randomly scanning every email sent to Canada, but if someone complains about you or your domain starts getting flagged, they will investigate. The penalties are steep enough that compliance isn't optional if you're serious about Canada as a market.
For B2B cold email specifically, this is manageable. You're targeting business decision-makers with relevant offers. The implied consent argument is solid. You just need to execute the basics correctly: real sender, clear unsubscribe, respect opt-outs immediately.
If you're running a cold email campaign yourself, this setup takes a few hours. The unsubscribe mechanism needs to be connected to your system so it actually suppresses future sends. The harder part isn't understanding the rules - it's maintaining compliance across dozens of campaigns, managing suppression lists correctly, and making sure your sequences respect unsubscribe requests the moment they come in. That's where most teams fall apart at scale.
Related Guides
- Cold Email Compliance in 2026: What You Actually Need to Know About GDPR
- Cold Email Compliance in 2026: What You Actually Need to Know About Spam Laws
- Cold Email Compliance Checklist 2026: What Actually Matters (And What Doesn't)
- Cold Email Compliance by Country: The Actual Rules That Matter
- B2B Cold Email and Spam Compliance: What Actually Matters (And What Doesn't)