Guide
CAN-SPAM for course senders: the footer checklist
Last reviewed 18 September 2026
CAN-SPAM is a United States law about how you send commercial email rather than about how you got the address. The FTC compliance guide sets out seven requirements: accurate header information, a non-deceptive subject line, identification of the message as an advertisement where that applies, a valid physical postal address, a clear way to opt out, opt-outs honoured within 10 business days, and responsibility for what anyone sending on your behalf does.
CAN-SPAM surprises European readers twice. It requires no consent at all, so it is far weaker than the ePrivacy rules they are used to, and it applies to every commercial message you send to a United States address regardless of where you are sitting, so it is not somebody else’s problem. Almost all of it is satisfied by a correct footer and an unsubscribe that works. This is a description of the FTC’s published guide rather than legal advice.
What the law actually regulates
CAN-SPAM, in force since 2004, governs commercial electronic mail: messages whose primary purpose is to advertise or promote a commercial product or service. It draws a line between those and transactional or relationship messages, the ones that complete a transaction the recipient has already agreed to or deliver information about an existing relationship. Transactional messages are exempt from most of the requirements but not from the first one: the header information may not be false or misleading in any message.
There is no consent requirement and no small-sender exemption. The FTC guide is explicit that the law covers all commercial messages including business-to-business email, and that there is no exception for a first message or for a list you bought. Nor is there a threshold: the same rules apply to a hundred messages a month and to a hundred million.
For an email course the primary-purpose test is usually easy and occasionally not. A course whose emails teach something and end with an invitation to buy is commercial, and treating it as anything else is a bet on how a regulator reads your own copy. Put the footer on all of it.
The seven requirements, in the FTC’s own order
The compliance guide lists seven main requirements. Six of them are things in the message, and the seventh is about anybody you pay to send it. The table below is that list with what each one means for a small sender.
| The requirement | What it means in practice | Where it lives |
|---|---|---|
| Do not use false or misleading header information | The From, Reply-To and routing information must identify who actually sent the message, and the domain must be one you are entitled to use | Your sending setup and your authentication records |
| Do not use deceptive subject lines | The subject must reflect the content of the message; a subject that promises a refund to open a sales email is the textbook violation | Every subject line, including day one of a course |
| Identify the message as an advertisement | Required where the message is an ad, in a way that is clear and conspicuous; the law leaves the wording to you | The top or the footer of promotional sends |
| Tell recipients where you are located | A valid physical postal address: a street address, a USPS-registered post office box, or a private mailbox registered with a commercial mail receiving agency | The footer of every commercial message |
| Tell recipients how to opt out of receiving future email | A clear, conspicuous explanation, in a way an ordinary person can recognise, read and understand | The footer, as visible text rather than an image |
| Honour opt-out requests promptly | Within 10 business days, with no fee, no information required beyond the address and no hoops such as a login; the mechanism must work for at least 30 days after sending | Your suppression list and your unsubscribe endpoint |
| Monitor what others do on your behalf | Hiring a sending agency does not move the liability; both the company whose product is promoted and the company that sends the mail can be held responsible | Your contracts, and whoever holds your list |
What getting it wrong costs
The FTC guide states that each separate email in violation of CAN-SPAM is subject to a civil penalty, and the maximum is adjusted for inflation each year; in recent years the published figure has stood above $50,000 per message. Per message is the part that matters. There is no per-campaign cap, so the arithmetic on a footer that was missing an address for a send to a list of ten thousand is not a number anybody wants to defend.
Additional provisions cover aggravated violations such as address harvesting and dictionary attacks, and some conduct can be criminal. Those are not risks a careful small sender runs into by accident, which is the point worth taking from this section: the whole exposure for an honest course sender is a footer, a working unsubscribe and a suppression list applied before the next send.
How it differs from the GDPR and CASL
CAN-SPAM is an opt-out regime. You may send until the recipient asks you to stop, and the law regulates the manner of sending and the exit. European rules are an opt-in regime: the ePrivacy rules generally require consent before an unsolicited commercial message, and the GDPR defines what that consent has to be and requires you to be able to demonstrate it. Nothing in CAN-SPAM asks you to keep a record of how an address arrived.
Canada’s CASL is stricter than both in its starting position. It requires express or implied consent before a commercial electronic message, requires you to keep records of that consent, requires prescribed sender identification, and requires an unsubscribe mechanism that works for at least 60 days. The CRTC publishes maximum administrative monetary penalties of up to CAD 1 million for an individual and CAD 10 million for an organisation.
The practical consequence of three regimes is not three lists. If you publish in English you have readers in all three jurisdictions, and the only maintainable answer is to run the strictest version everywhere: consent recorded before the first message, sender and postal address in every footer, an unsubscribe honoured immediately rather than within any of the published windows. Compliance then stops being a per-country question and becomes one path through the code.
Common questions
Does CAN-SPAM require opt-in?
No. CAN-SPAM regulates how commercial email is sent rather than how the address was obtained, so it permits sending until the recipient asks you to stop. That is the opposite of the European position, where the ePrivacy rules generally require consent first and the GDPR defines what consent means and requires proof of it.
Do I need a physical address in every email?
Yes, in every commercial message. The FTC guide requires a valid physical postal address, which may be your street address, a post office box registered with the US Postal Service, or a private mailbox registered with a commercial mail receiving agency. Keeping it as visible text rather than an image matters, because an image-blocked client makes it disappear.
How quickly must I honour an unsubscribe?
CAN-SPAM allows 10 business days, and that is the outer limit rather than a target. Google and Yahoo have required unsubscribe requests to be honoured within two days since February 2024, and the operationally sane answer is immediately, because every message sent after someone asked to leave is a candidate for the spam button.
Does CAN-SPAM apply to me if I am not in the United States?
It applies to commercial messages sent to recipients in the United States, so a sender anywhere with American readers is inside its scope. Since compliance is a correct footer and a working unsubscribe, the cheapest approach is to meet it for every message rather than to segment a list by country.
CAN-SPAM is the least demanding of the three regimes a course sender lives under, and it is the one most often failed, because the failure is a missing postal address rather than anything anybody had to decide. Write the footer once, put it on every email in the sequence, suppress an unsubscribe the moment it arrives, and the United States half of this subject is finished.
Sources
Read next
This page is part of Email deliverability for small senders: authentication and reputation, which is the complete guide to the subject.
- Email deliverability for small senders: authentication and reputation
What deliverability is, how SPF, DKIM and DMARC fit together, and what the Google and Yahoo bulk sender rules require of a small sender.
- Confirmed opt-in (double opt-in): what it costs, and what it buys
What double opt-in (confirmed opt-in) is, what it costs you in list size, and why the mailbox providers have settled the argument.
- Confirmation email template for double opt-in
Three confirmation emails written out in full: plain, warm, and re-permission for an imported list, with the reasoning for every line.
- How to set up SPF, DKIM and DMARC for a sending domain
The order to do it in: a dedicated sending subdomain, SPF, DKIM, DMARC at p=none, two weeks of reports, then quarantine and reject.
- GDPR and email courses: consent, records, and erasure
What the GDPR text actually requires for an email list: consent under Art. 4(11), the burden of proof in Art. 7(1), erasure under Art. 17.
- Unsubscribe requirements: one-click, List-Unsubscribe and two days
What one-click unsubscribe requires under RFC 8058, the two-day honouring window in the Google and Yahoo rules, and what the endpoint must return.
These guides are about the format rather than about any particular tool. What this site itself does is on the home page, and the rest of the set is on the guides index .
Elsewhere on this site
The rest of this site comes at the same subject from other directions: guides on the format itself, a tool for one job each, a page for each kind of work, and what to check when choosing software.
Free tool
DMARC, SPF and DKIM checkerChoosing software
Email course software, tool by tool
Thinking of writing one of these?
5dayemail hosts a five-to-ten day email course: you write it once, and everyone who joins your list gets one email a day, in order, starting from the day they confirm.
Accounts are opened a few at a time rather than by signing up. Leave your address and you will be written to when the next ones open.
One message, when there is room. No course emails, no newsletter, and the address is not passed on. Ask and it is deleted; what is kept, and for how long, is in the privacy policy.