If you're running cold email campaigns in Canada, you're operating in one of the strictest email jurisdictions in the world. CASL (Canada's Anti-Spam Legislation) is brutal - $1 million per violation for individuals, $15 million for corporations. Most people running cold email in Canada either ignore the law or follow outdated advice that doesn't actually protect them.
The good news: you can run cold email legally in Canada. It's just not the same as running it in the US. This guide covers what actually matters, what doesn't, and how to structure your campaigns to stay compliant without killing your results.
What CASL Actually Requires (Not the Myth Version)
CASL has three core requirements for commercial electronic messages. Most people get them wrong.
First: you need express or implied consent before sending. This trips up most people because they think consent means an opt-in form. Wrong. You can send if you have a "prior business relationship." A prior business relationship exists if someone has inquired about your services, made a purchase, or engaged with your business in the last two years. You don't need their explicit permission. You just can't email a cold list of random email addresses.
Second: your message must include accurate sender identification. This means your actual company name and physical mailing address in the email. Not a PO box - an actual address where someone could theoretically show up. This is non-negotiable and checked by Canadian regulators.
Third: you must have a clear unsubscribe mechanism. Not buried in the footer. Not requiring a login. A working unsubscribe link that removes someone within 10 business days. This one is usually handled correctly because it's obvious.
The part that kills most cold email campaigns: you need evidence that the person opted in or had a prior business relationship with you. If CASL enforcement comes knocking - and they do, especially for high-volume senders - you need to prove it. "I found their email on LinkedIn" is not evidence. You need documentation.
The Legal Gray Area Nobody Talks About: "Implied Consent"
Here's where most Canadian cold email actually happens. CASL allows for "implied consent," which is poorly defined on purpose. The interpretation that Canadian courts and regulators have landed on: if you're emailing someone at a business email address about business services, and they had no prior relationship with you, you're in a gray area that's technically not compliant but rarely enforced at small scale.
CASL enforcement has been minimal against small businesses running cold email to business contacts. The enforcement action you see is against spammers sending millions of emails to consumer addresses, not against a service business sending 50 cold emails a day to plumbers or accountants at their work email addresses.
This doesn't mean it's legal. It means the enforcement risk at small volume is low if you're targeting business addresses. If you scale to high volume - thousands of emails daily - your risk profile changes. Regulators notice patterns.
The smart move: operate as if you need consent or a prior business relationship. Build your list from LinkedIn where you can verify professional context. Use web research to understand why you're emailing someone specific. Document it.
Building a Compliant Cold Email List for Canada
Start with the assumption that you need a legitimate reason to email someone. This shapes how you source your list.
LinkedIn is your safest source. When you email someone from LinkedIn, you have documented that they have a professional profile and work at a specific company. That's not consent, but it's evidence of professional context that defends you if someone complains. Search for your target role, company size, and industry. Pull their business email from their profile or website, not from data brokers.
Data brokers selling "verified email lists" are a legal minefield in Canada. They often don't have documented consent from the people on their lists. You inherit their liability when you use them. Avoid them unless the broker can provide explicit documentation of consent for each email address - which almost none do.
Public web research is defensible. If you find someone's email on a company website, in a public directory, or in a published article, that's documented context. Keep notes on where you found each email. It takes more time upfront, but it's how you defend yourself later.
Partner lists are risky without documentation. If someone gives you a list of leads, you need written confirmation that those people consented to receive marketing emails or had a prior business relationship with you. A verbal "they're all warm" doesn't cut it.
Email Copy Requirements and What They Actually Mean
Your actual email message has specific legal requirements under CASL that aren't about marketing - they're about identification and exit routes.
Your company name must appear in the body or subject line. It needs to be your real legal business name, not a "doing business as" version. If your legal entity is "Growth Analytics Inc." you can't send under "Growth Analytics" without clarification. This is checked.
Your physical mailing address must be included. Full street address, city, province, postal code. A lot of cold email templates skip this, but it's legally required. Put it in the footer. It doesn't kill conversion rates - most people scrolling your email won't see it anyway.
Here's an example footer that covers the legal requirements without reading like a legal notice:
Growth Analytics Inc. 1234 King Street West Toronto, ON M5H 2A1 Canada You're receiving this because we found your company in our outreach research. Unsubscribe here if you'd prefer not to hear from us again.
The unsubscribe link needs to work, and it needs to remove someone within 10 business days. Use a proper email service provider that tracks this automatically. Manual spreadsheets fail during audits.
Volume Matters More Than You Think
CASL enforcement scales with volume. A service business sending 100 cold emails per day to business contacts in Canada faces almost no regulatory risk. A company sending 10,000 daily is on regulators' radar.
If you're scaling beyond a few hundred emails per day in Canada, you should have a compliance lawyer review your process. The cost is usually $1,500-3,000 for a consultation and audit. It's cheaper than a fine.
For sending limits, aim for 100-200 emails per day per sender if you're in Canada. This keeps you under enforcement radar while still building a solid pipeline. You can scale across multiple senders if needed, but coordinate across accounts so you're not hammering the same company from multiple email addresses in one week.
Practical Setup: What Your Campaigns Actually Need
Use a legitimate email service provider (Mailchimp, Brevo, ActiveCampaign, or specialized cold email tools) that supports Canadian businesses. These tools log unsubscribes properly and help you maintain compliance records.
Set up a tracking system where you document: the date you sent, the recipient's email, where you sourced their contact info, and the outcome. If you get contacted by regulators or someone complains, you need to show why you emailed them. A spreadsheet with source info is defensible.
Set your unsubscribe link to remove people from all future campaigns, not just one sequence. CASL requires you to honor unsubscribe requests across your entire organization.
Keep your sender identity consistent. Don't rotate through multiple company names, fake email addresses, or misleading subject lines to bypass filters. CASL specifically prohibits this.
Here's a compliant cold email template structure for Canadian campaigns:
Subject: Quick question about [specific thing you researched about their business] Hi [Name], I work with [similar companies] on [specific problem you solve]. When I looked at [specific detail about their business], I noticed [insight that shows you did research]. Would a quick call make sense to explore if we could help? Thanks, [Your name] Growth Analytics Inc. 1234 King Street West, Toronto, ON M5H 2A1 Unsubscribe
This template hits every requirement: identifies your company, shows specific research justifying the email, includes your address, and has an unsubscribe option. It also doesn't come across as spam - the research detail makes it contextual to their business.
The Gap Between Knowing This and Running It at Scale
Understanding CASL is one thing. Actually running campaigns that stay compliant while maintaining decent reply rates is different. You need list sourcing that documents context, email copy that converts without cutting corners on legal requirements, proper infrastructure logging, and someone monitoring compliance as you scale. Most cold email done at scale in Canada either ignores the law or tanks conversion by over-personalizing and under-scaling. That's the gap - knowing what works legally and actually executing it consistently without the thing falling apart when you try to hit 200 emails per day.
Related Guides
- Cold Email Deliverability Complete Guide: Why Your Emails Aren't Landing in Inboxes
- B2B Cold Email Lead Generation: The Actual Strategy That Works
- Cold Email Infrastructure Setup Guide: The Unsexy Foundation That Actually Gets Replies
- B2B Cold Email Complete Guide 2026: What Actually Works
- Cold Email List Cleaning Guide: Stop Wasting Time on Dead Leads