You're sitting at your desk, about to hit send on a cold email campaign. Then doubt creeps in. Are you allowed to do this? Will you get sued? Is your entire email list about to get you in trouble with some regulatory body you've never heard of?
This is the question I get asked constantly - and it's usually asked by someone who's already built their email list, already written their copy, and is now panicking about the legal side of things.
Here's what I'm going to tell you: The rules around cold email consent in 2026 are nowhere near as complicated as people make them out to be. But they do matter. Not because you're a bad person if you don't follow them, but because if you don't understand them, you'll waste money sending emails to the wrong people, get your domain blacklisted, or actually do land yourself in legal trouble.
Let's break down what you actually need to know.
First, understand that consent laws vary by location. This isn't me being wishy-washy - it's just the reality. Your email rules in the US are different from Canada, which are different from the EU.
For B2B cold email in the United States, the CAN-SPAM Act is your main concern. Despite its dramatic name, it's actually pretty straightforward: you can send cold emails to business addresses without prior consent. What you can't do is lie about who you are, what you're selling, or how to unsubscribe.
In Canada, CASL (Canada's Anti-Spam Legislation) is stricter. You technically need prior consent before sending any commercial email - which most people interpret as needing some form of implicit consent. This usually means they've engaged with your company in some way, or downloaded something, or talked to you at a conference.
In the EU under GDPR, it gets more complicated. Different member states have different rules, but generally speaking - you need consent before sending marketing emails to individuals. Business emails to business addresses are often treated differently and more leniently than emails to personal addresses.
The practical translation: if you're doing B2B cold email to business email addresses in North America, you're fine to send without prior consent. If you're emailing personal addresses, or if your recipients are in Canada or the EU, you need to be more careful.
Here's where most people get confused. Consent doesn't have to be explicit. You don't need someone to fill out a form saying "yes, I want your cold emails."
Implied consent exists. If someone has engaged with your company - they visited your website, they downloaded a resource, they replied to a previous email, they met you at an event - that's often enough. The key word is "reasonable expectation." Did they have a reasonable expectation that you might email them?
For cold email specifically, this is why list sourcing matters. If you're pulling emails from a company website's contact page, or from LinkedIn, or from a public directory - that's generally fine. The person made that email address somewhat public, and there's an implied understanding that business people might use it for business purposes.
What doesn't count as consent: buying a list of random emails. Scraping emails off the internet without context. Sending to "info@" addresses without any indication the person there wants to hear from you.
If you're running cold email campaigns, here's what actually matters:
Use email finders that scrape from public sources - LinkedIn, company websites, professional directories. Don't buy pre-made lists of "CEOs in your area." Don't use data brokers selling millions of emails for $50. Your deliverability will suffer and your legal risk increases.
This is non-negotiable. Your emails need an unsubscribe link that actually works. When someone clicks it, they should be removed from your list within 10 days. This is required by CAN-SPAM in the US and similar laws everywhere else. Most email providers handle this automatically - just make sure you're using a reputable one.
Don't pretend you know someone personally. Don't hide who you are or what you're selling. Don't make false claims about your product. This should be obvious, but it's surprising how many people try to game the system.
Keep records of where you got each email address. It doesn't have to be fancy - just know whether this person came from LinkedIn, their company website, a conference list, etc. If someone complains, you need to show that you had a reasonable basis to contact them.
Someone replies saying they want off your list? Remove them right away. Someone marks you as spam? Stop emailing them. Don't argue, don't try to convince them, just respect it.
There are some situations where the rules aren't crystal clear:
Using LinkedIn to find emails and then emailing them - technically a gray area, but widely accepted in B2B. LinkedIn's terms say not to scrape data, but they don't own the emails. Most people do this and it's generally fine.
Emailing people at their work email when they've only connected with you personally - here you're on safer ground. They gave you their work email, and you're emailing them at work about business. That's reasonable.
Finding emails through data brokers or list services - riskier. These lists are often old, inaccurate, or sourced poorly. You'll get worse results and higher complaint rates.
Here's the thing nobody talks about: following consent rules actually makes your cold email work better. Not worse - better.
When you source emails carefully, you get higher-quality addresses. Your deliverability improves. Your unsubscribe rate drops because you're reaching actual humans who have a legitimate reason to hear from you, not random addresses pulled from a purchased list.
When you're transparent in your emails, you get higher reply rates because people know what they're getting. When you respect unsubscribe requests immediately, your domain reputation stays clean.
Following the rules isn't a burden. It's just good email hygiene.
For B2B cold email in 2026: source your emails ethically from public sources, be honest about who you are and what you're selling, include a working unsubscribe link, and respect people who ask to be removed. Do that and you're fine legally and your campaigns will perform better.
If you're worried about getting the technical side right - the infrastructure, the list sourcing, making sure you're hitting actual decision makers - or if you just don't want to spend months figuring this out yourself, that's where people turn to agencies that specialize in this. At BEC Growth, we handle all of this - the compliance side, the list sourcing, the infrastructure, everything. We've run thousands of cold email campaigns and we know exactly how to do this right.
Ready to Sign Clients On-Demand?
BEC Growth builds and manages your entire cold email system from infrastructure to reply handling.
Book a Call →