You're about to hit send on 500 cold emails to potential clients. Then you pause. What if you're breaking the law? What if the FTC shows up at your door? What if you get sued?
That fear - it stops a lot of people from cold emailing at all. And honestly, it's warranted. Cold email is heavily regulated in the US. But here's the thing - most of the regulations are straightforward if you actually understand them. Nobody talks about them clearly, so people either ignore them entirely or get paranoid and never cold email.
We're going to walk through exactly what you need to know. No legal jargon. Just the actual rules and how to follow them.
There are essentially two federal laws that matter for cold email in the US - CAN-SPAM and the TCPA. Everything else either flows from these or is less commonly enforced.
CAN-SPAM applies to any "commercial email message." This means promotional emails, sales pitches, newsletters - basically anything that's advertising or promoting a commercial product or service. It doesn't matter if it's B2B or B2C. It applies to you.
Here's what you must do to comply with CAN-SPAM:
The penalties for CAN-SPAM violations are real. The FTC can fine you up to $43,280 per violation. That means per email. One campaign of 500 emails could theoretically cost you millions. They don't usually go after small players doing a few hundred emails, but they do go after people who are blatantly ignoring the rules.
This one is trickier because it technically applies to SMS and phone calls, but there's been a lot of legal gray area about whether it applies to email. The safest interpretation is that it does apply in some cases, particularly if you're using an automated system to send emails.
The main TCPA requirement that affects email is this - you need prior express written consent before you email someone. This is why buying cold email lists is risky. Those people didn't consent to receive email from you.
Now, there's a practical exception here. If you're emailing business email addresses (like company domain emails) as opposed to personal email addresses, the TCPA is less likely to be enforced against you. The FTC generally interprets TCPA as protecting consumers, not businesses receiving business solicitations.
But if you're emailing someone's personal email address that you found online without their consent, you're technically in a gray area. It's not a legal certainty that you're violating TCPA, but it's also not a legal certainty that you're not.
There are situations where the rules are less clear, and this is where people either panic or wing it.
This depends on interpretation. Technically, CAN-SPAM doesn't require prior consent - it just requires you to follow the rules listed above. But TCPA might, depending on the circumstances. Most people sending legitimate B2B cold emails to business addresses aren't getting sued, which suggests the enforcement threshold is higher than people think. But it's not zero risk.
LinkedIn messages are a bit of a gray area. LinkedIn's terms of service prohibit certain types of automated outreach, but federal law is less clear. The safest approach - don't use bots or automation tools that violate LinkedIn's terms. If you're sending manual messages or using tools that LinkedIn explicitly allows, you're on safer ground.
Technically, you can. But you need to make sure the list was compiled legally. The people on that list should ideally have some relationship to the service being offered, or at least have indicated interest in receiving commercial emails. A list of random email addresses scraped from the internet? That's riskier.
If you're planning to cold email, here's your compliance checklist:
These aren't burdensome requirements. They're just basic professionalism. If you're sending genuine value to relevant prospects, and you're not deceiving anyone, you're probably fine.
The actual legal risk from cold email isn't the FTC showing up. It's civil lawsuits. Someone in your email list gets annoyed and hires a lawyer. Now you're defending yourself even if you're technically compliant. Legal fees add up fast.
This is why infrastructure matters. It's why you want to work with email providers and processes that are designed to keep you compliant. It's also why you want to send emails that actually provide value - fewer unhappy recipients means fewer potential lawsuits.
If cold email compliance feels overwhelming, or if you want to focus on your actual business instead of worrying about legal requirements and technical setup, that's exactly why some people hand this off entirely. There are agencies that handle all of this - the compliance, the infrastructure, the list sourcing, the copy, the whole operation - so you can focus on closing deals instead of managing spreadsheets and legal checklists.
Ready to Sign Clients On-Demand?
BEC Growth builds and manages your entire cold email system from infrastructure to reply handling.
Book a Call →