You're about to send cold emails to potential clients. Then you start thinking - am I breaking any laws here? What if I get sued? What about spam complaints?

It's paralyzing. You've got a good service, people need what you sell, but one wrong move and suddenly you're worried about legal trouble.

Here's the thing - cold email isn't illegal. But there are rules. And most people either ignore them completely or overthink them into paralysis. Neither helps you.

I'm going to walk you through the actual legal landscape for cold email in the USA in 2026. Not the scary version. The real version.

CAN-SPAM is the law that matters

There's one federal law you need to know about - the CAN-SPAM Act of 2003. This is what the FTC enforces, and this is what actually applies to your cold email.

The CAN-SPAM Act applies to commercial messages. That's emails promoting a product, service, or business. If you're sending cold emails to sell your service, you're sending commercial messages. So CAN-SPAM applies to you.

Here's what you need to do to comply:

That's it. That's the federal requirement. If you do these five things, you're legally compliant with CAN-SPAM.

What CAN-SPAM doesn't require (and what people get wrong)

A lot of people think CAN-SPAM requires prior express written consent before sending a cold email. It doesn't.

CAN-SPAM lets you send cold emails to people who've never heard from you before. Zero prior relationship required. You don't need permission to hit send.

The consent requirement? That's for transactional emails - like receipts or password resets. Not for cold outreach.

This is why cold email actually works as a business development channel. You can reach out to people cold, legally, without jumping through permission hoops first.

State laws - the complication

Federal law is the floor. But some states have added their own requirements on top of CAN-SPAM, and this is where it gets annoying.

New York and Tennessee have stricter standards for cold email - they require that you've had some prior business relationship or reasonable expectation that the person wants to hear from you. California's rules are similar in some cases.

In practice? This means you need to be thoughtful about your targeting. Don't just blast random email lists. Send to people who actually fit your ideal client profile - people who have a legitimate reason to care about what you're selling.

If you're selling accounting services to accountants, or marketing services to business owners, you're fine. You have a legitimate business reason to reach out. The state laws aren't trying to stop that.

What they're trying to stop is spam - sending mass emails to people with zero connection to your business.

The email authentication stuff (SPF, DKIM, DMARC)

This isn't a legal requirement, but it matters for deliverability - and bad deliverability will kill your campaign before legality ever matters.

Set up SPF, DKIM, and DMARC records for your sending domain. These tell email providers that you're the legitimate sender. Without them, ISPs assume you're a spammer and dump your emails in spam folders.

This is infrastructure work, not legal work, but it's table stakes. Your email service provider should have guides for setting this up.

Avoid these things

Beyond the basics, there are a few specific things that will get you in actual trouble: