Guide

Cold email that stays legal: CAN-SPAM basics for small businesses

Cold email to businesses is legal in the U.S., but it is regulated. Most problems come from four fixable mistakes. This is the short version — not legal advice, but enough to know what to ask about.

Last updated 2026-07-22

What the law requires

Under CAN-SPAM, commercial email must not use deceptive headers or subject lines, must identify itself as a commercial message, must include a valid physical postal address, and must give a working way to opt out — honoured promptly.

Notably, U.S. law does not require prior consent for business email the way some other jurisdictions do. If you contact people in the EU or UK, different and stricter rules apply.

The four mistakes that cause trouble

Misleading subject lines, because a small lift in opens is not worth the exposure. Hiding who you are. Making opt-out hard or ignoring it. And sending to addresses that were scraped without any relevance filter — high complaint rates hurt deliverability long before they attract a regulator.

Habits that keep you deliverable

Send to people for whom the message is plausibly relevant, keep volume proportionate to your domain reputation, remove hard bounces immediately, and process every unsubscribe on the first request.

Deliverability and compliance point the same direction: relevance. The list you would be comfortable defending is also the list that performs.

How this works in practice

Your outreach tooling should attach the required elements automatically, maintain a suppression list, and stop sending to anyone who opts out — without you remembering to do it. If a tool cannot show you the suppression list, that is a red flag.

Caliradi attaches the required elements and honours opt-outs automatically, and you approve every campaign before it sends.

Get Started

← All guides · Home · Pricing