The CAN-SPAM Act is the US law that sets the rules for commercial email, requiring honest headers and subject lines, a clear way to opt out, and prompt removal of anyone who does. It draws the line between lawful marketing email and the deceptive, header-forging mail that scammers and phishers send.
What is CAN-SPAM?
CAN-SPAM is the federal law that governs commercial email in the US. It does not ban marketing email; it sets conditions for sending it honestly. Senders must not forge who the message is from, must not use deceptive subject lines, must say the message is an ad where relevant, must include a real physical address, and must give recipients a working way to unsubscribe that is honored promptly.
The name captures the intent: controlling the assault of non-solicited pornography and marketing. In practice the core requirements come down to truthful identification and easy opt-out. A message that hides its origin, tricks the reader with a false subject, or refuses to let them leave is where the law is aimed.
For fraud and security teams, those same requirements are a useful boundary. The exact things CAN-SPAM forbids, forged headers, spoofed senders, and deceptive subjects, are the standard techniques of phishing and email-borne scams, so the law's prohibitions overlap heavily with abuse signals.
What the law actually requires
Compliant commercial email comes down to a short, concrete checklist.
Requirement | What it means |
Honest headers | The from, to, and routing information must accurately identify the sender. |
Truthful subject | The subject line cannot mislead about what the message contains. |
Ad identification | The message must be identifiable as an advertisement where required. |
Physical address | A valid postal address for the sender must be included. |
Working opt-out | A clear unsubscribe mechanism that is honored promptly. |
What it looks like in practice
A platform notices a spike in complaints that its brand is appearing in spam. On inspection, the messages are not coming from the company at all. They use forged headers to look like they originate from the brand and carry subject lines promising account rewards, linking to a credential-harvesting page.
This is the behavior CAN-SPAM prohibits, and it is also textbook phishing. The security team responds by tightening email authentication so spoofed mail is rejected, reporting the abuse, and warning customers. The legal framework and the anti-fraud response point the same way: honest, authenticated email is both compliant and harder to impersonate.
What it means for operators day to day
If your company sends marketing or transactional-plus-promotional email, CAN-SPAM is a compliance obligation with per-message penalties: keep your headers and subjects honest, include your address, and make unsubscribe fast and reliable. Poor list hygiene and ignored opt-outs generate complaints that hurt deliverability as much as they create legal exposure.
For fraud and brand-protection teams, the law is also a mirror of the threat. Fraudsters ignore all of it, so the presence of forged senders, deceptive subjects, and no real opt-out is a strong signal that a message is malicious rather than merely annoying. Investing in email authentication protects both your compliance posture and your customers from being phished in your name.
What to watch in the data
- Spoofed sender domains. Mail claiming to be from your brand but failing authentication is a phishing indicator, not a compliance edge case.
- Deceptive subjects. Subject lines that promise rewards, warnings, or account actions to force a click are classic scam bait.
- Missing opt-out. Commercial mail with no working unsubscribe is both a violation and a hallmark of illegitimate senders.
- Complaint spikes. A jump in spam complaints referencing your brand can mean impersonation is under way.
- Link and header mismatch. Display names or links that do not match the true sending domain point to forged, malicious mail.
Quick questions
Does CAN-SPAM require opt-in consent?
No. Unlike some other regimes, it does not require prior consent to send commercial email. Instead it requires honesty and a working opt-out, so recipients can stop future messages, which the sender must then honor promptly.
Who does the law apply to?
Any business sending commercial email to US recipients, and responsibility can extend to the company whose product is promoted, not just the sender. Purely transactional messages are treated differently from promotional ones.
How does CAN-SPAM connect to phishing?
Phishing violates the law by design, using forged headers and deceptive subjects to impersonate a trusted sender. The behaviors CAN-SPAM prohibits are the same ones fraud teams treat as email-abuse signals, so compliance and anti-phishing overlap.
What are the penalties?
Violations can carry significant civil penalties assessed per non-compliant email, which adds up quickly at marketing scale. Aggravated deceptive practices can draw additional liability, which is why legitimate senders keep strict list and header hygiene.
Does following CAN-SPAM stop spoofing of my brand?
Not on its own, because criminals ignore the law. Pairing compliance with strong email authentication is what actually reduces spoofing, since authenticated mail lets receivers reject forged messages sent in your name.
Qué saber junto con CAN-SPAM Act

Informe de Fraude y ALD 2026
Olvídate de las predicciones. Este informe desglosa a qué se enfrentan realmente los equipos de fraude y ALD, y cómo responder.
