In Europe, writing to someone who asked for nothing is prohibited except by exception. In the United States, it is permitted until they tell you to stop.
That difference in principle is well known. What is less known is the price of the smallest oversight in the more permissive of the two regimes: 53,088 dollars per message.
An opt-out regime, and formal obligations
The CAN-SPAM Act, codified from Title 15 of the United States Code, requires no prior consent. The FTC confirms this in its own business-facing publications.
In exchange, it imposes a series of formal obligations, listed at 15 U.S.C. 7704, each of which is a separate offence.
Header information must not be materially false or misleading. The subject line must not mislead on a material fact. The message must be identifiable as an advertisement or solicitation. It must carry a valid physical postal address for the sender. It must offer a working, clearly displayed unsubscribe mechanism.
Two deadlines complete the scheme: an unsubscribe request must be processed within ten business days at most, and the mechanism must remain able to receive requests for at least thirty days after the message was sent.
Ten business days: that is five times more generous than the 48 hours Gmail requires. The technical constraint is stricter than the legal one here, which should always guide your configuration.
The amount, and how it works
A CAN-SPAM violation is pursued as an unfair or deceptive practice under the FTC Act. The applicable civil penalty is therefore the one in section 5(m)(1)(A) of that statute, adjusted annually for inflation.
The amount in force was set by a notice published in the Federal Register on 17 January 2025: 53,088 dollars. The FTC restates it as such in its compliance guide: “Each separate email in violation of the law is subject to penalties of up to $53,088.”
That amount was not revised for 2026. The annual adjustment did not happen for want of Bureau of Labor Statistics data, and an Office of Management and Budget memorandum dated 17 April 2026 directs all federal agencies, the FTC included, to keep 2025 levels for the whole year.
Note the phrase that does all the work: each separate email. The amount applies per message, not per campaign.
A campaign of ten thousand non-compliant messages therefore exposes you, in pure theory, to more than five hundred million dollars. That theoretical ceiling is never reached: the FTC settles, and real amounts run to hundreds of thousands or millions. But the calculation method explains why American companies treat unsubscribes with a seriousness that often surprises Europeans.
Two cases, for the real order of magnitude
On 30 August 2024, the FTC obtained from Verkada, a security camera manufacturer, a civil penalty of 2.95 million dollars for CAN-SPAM violations: more than thirty million commercial messages sent over three years, with no working unsubscribe mechanism, no honouring of requests received, and no postal address. The FTC states that this is the largest penalty it has ever obtained on that basis.
On 22 August 2023, the Department of Justice, acting for the FTC, obtained against Experian Consumer Services a permanent injunction and 650,000 dollars in civil penalty, for commercial messages with no unsubscribe notice at all.
In both cases, no consent breach was alleged, and for good reason: US law does not require it. Both are unsubscribe cases.
If you send from Europe
The statute covers interstate and foreign commerce, which includes commercial messages received by recipients located in the United States, regardless of the sender’s nationality.
We stop there, without commenting on the practical conditions for enforcing an American decision against a European company: that is a private international law question on which we have no source to cite, and an improvised opinion would be worth nothing.
The practical reasoning is simpler, and it depends on no legal assessment. If you write to American recipients, you must in any case satisfy the requirements of Gmail, Yahoo and Outlook, whose headquarters and servers are there. And those requirements almost entirely cover CAN-SPAM’s formal obligations, and are stricter on the deadline.
And if you already apply the European regime, you are above the American standard on the heaviest point: consent.
The three other major English-speaking markets do not follow the American model: Canada, the United Kingdom and Australia require consent, in different forms.
What to do tomorrow morning
Open one of your promotional messages aimed at an American audience and check three material things.
Does it carry a valid physical postal address? Not a hypothetical PO box, not a vendor’s address: an address where you actually receive mail.
Is the message identifiable as an advertisement? A purely editorial message that is in fact selling a product raises a problem nobody ever looks at.
Does your unsubscribe mechanism still work thirty days after sending? Token-based unsubscribe links expiring after a week, common in modern tools, fail that requirement without anyone noticing.
Sources
- 15 U.S. Code § 7704, Protection against transmission of unsolicited commercial electronic mail
- Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business
- Federal Register (17 January 2025). Adjustments to Civil Penalty Amounts
- Office of Management and Budget (17 April 2026). Memorandum M-26-11, Cancellation of Penalty Inflation Adjustments for 2026
- Federal Trade Commission (30 August 2024). FTC Takes Action Against Security Camera Firm Verkada
- Department of Justice (22 August 2023). Permanent Injunction and $650,000 Civil Penalty Imposed on Experian Consumer Services
LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.
