> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# The CAN-SPAM Act Explained: A Practical Guide to U.S. Email Marketing Compliance
- URL: https://www.thedelatorrereview.com/the-can-spam-act-explained-a-practical-guide-to-u-s-email-marketing-compliance/
- Published: 2026-07-25T19:42:24.000Z
- Updated: 2026-07-25T19:42:24.000Z
- Description: The CAN-SPAM Act establishes the federal rules governing commercial email in the United States. This practical guide explains who the law applies to, the seven core compliance requirements, FTC enforcement trends, penalties, and best practices for building a compliant email marketing program.
- Author: Lydia
- Tags: Marketing, FTC, Privacy, Regulatory Enforcement

The **Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 (CAN-SPAM Act)**, codified at **15 U.S.C. §§ 7701 et seq.**, is the primary U.S. federal law governing commercial electronic messages and is enforced principally by the Federal Trade Commission (FTC). It applies broadly to all commercial electronic messages, including business-to-business (B2B) marketing, ecommerce communications, nonprofit organizations promoting products or services, and foreign businesses sending commercial emails to recipients in the United States. **As of 2026, violations may result in civil penalties of up to $53,088 for each non-compliant email,** making compliance a significant legal and financial priority. At its core, the CAN-SPAM Act requires organizations to follow seven fundamental rules: use accurate header information, avoid deceptive subject lines, identify advertisements where required, include a valid physical mailing address, provide a functional opt-out mechanism, honor unsubscribe requests within 10 business days, and appropriately oversee third parties sending emails on the organization's behalf. **Recent enforcement actions—including the FTC's $2.95 million settlement with Verkada, the largest CAN-SPAM civil penalty to date, and the $650,000 settlement with Experian—underscore that regulators continue to actively enforce** these requirements and that organizations of all sizes should maintain robust email marketing compliance programs.

Rather than prohibiting unsolicited marketing emails altogether, the law establishes a framework for lawful commercial communications by requiring transparency, accurate sender information, and a meaningful opportunity for recipients to opt out of future marketing messages. It also imposes additional restrictions on sexually explicit commercial emails and authorizes significant civil and criminal penalties for noncompliance.

Although the CAN-SPAM Act was enacted in 2003, it has undergone very few substantive statutory amendments. 

Although the CAN-SPAM Act is most commonly associated with email marketing, its requirements extend to other forms of electronic messaging that qualify as commercial messages under the statute and implementing regulations. Depending on the communication channel and applicable legal framework, businesses should also consider whether marketing messages delivered through social media platforms, direct messaging services, or other electronic communication tools may trigger CAN-SPAM obligations or related federal and state requirements.

## Congressional Purpose Behind the CAN-SPAM Act

In enacting the CAN-SPAM Act, Congress recognized both the benefits of electronic messaging and the growing problems associated with unsolicited commercial email. The statute's findings acknowledge that the rapid increase in commercial electronic messages can impose significant costs on recipients, who often have little ability to refuse unwanted messages. Congress also recognized that excessive volumes of unsolicited email can overwhelm inboxes, causing legitimate communications to be lost, overlooked, or inadvertently discarded. Additionally, lawmakers expressed concern that some commercial messages contain material that recipients may find offensive, vulgar, or sexually explicit.

To address these concerns, the CAN-SPAM Act establishes two fundamental policy objectives. First, it seeks to ensure that senders of commercial electronic messages do not mislead recipients about the source or content of their communications. Second, it gives recipients the right to stop receiving future commercial messages from a particular sender by requiring businesses to provide a clear and effective opt-out mechanism. Together, these principles promote greater transparency, consumer choice, and accountability in commercial electronic communications.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-25--2026-at-10_49_38-AM.png)

See, [15 U.S.C. Sec. 7701](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com).

The FTC has rule-making authority over CAN-SPAM and has issued the [**CAN-SPAM Rule**](https://www.ftc.gov/enforcement/rules/rulemaking-regulatory-reform-proceedings/can-spam-rule?ref=thedelatorrereview.com)**.** See, [15 U.S.C. Sec. 7701](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com) et sec. 

## Key Definitions Under the CAN-SPAM Act

The CAN-SPAM Act contains a number of statutory definitions that determine when the law applies and to whom its obligations attach. Although many of these definitions are technical, several are particularly important for organizations that send commercial email campaigns or rely on third-party marketing providers.

See, [15 U.S.C. Sec. 7702](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com).

### Commercial Electronic Mail Message

The cornerstone of the Act is the definition of a **"commercial electronic mail message."** A message falls within the scope of CAN-SPAM if its **primary purpose** is to advertise or promote a commercial product or service, including content on a commercial website. Whether a message is subject to the Act depends on its overall primary purpose—not merely because it mentions a business or includes a link to a commercial website. The Federal Trade Commission (FTC) has adopted regulations that further explain how to determine a message's primary purpose.

### Transactional or Relationship Messages

Not every business email is considered a commercial message. The Act excludes **transactional or relationship messages**, which primarily facilitate or maintain an existing relationship with the recipient rather than promote products or services. Examples include emails that:

- Confirm or complete a purchase or other transaction;
- Provide warranty, recall, safety, or security information;
- Notify customers of changes to account terms, memberships, subscriptions, or account status;
- Deliver periodic account statements or balance information;
- Provide information relating to an employment relationship or employee benefits; or
- Deliver products, services, updates, or upgrades that the recipient is entitled to receive.

These communications generally are not subject to the Act's commercial email requirements because their primary purpose is informational rather than promotional.

### Affirmative Consent

The Act also defines affirmative consent, which exists when a recipient expressly agrees to receive commercial electronic messages. Consent may be provided in response to a clear and conspicuous request or at the recipient's own initiative. If the recipient's email address will be shared with another company for marketing purposes, the recipient must receive clear notice of that possibility when providing consent.

### Sender and Initiate

The Act distinguishes between the sender and the party that initiates a commercial email. Generally, the sender is the person or organization whose products, services, or website are promoted in the message, while initiating a message includes originating, transmitting, or procuring its transmission. Importantly, more than one party may be considered to have initiated a commercial email, meaning **both advertisers and third-party marketers may share responsibility for compliance**.

If an entity operates through separate lines of business or divisions and holds itself out to the recipient throughout the message as that particular line of business or division rather than as the entity of which such line of business or division is a part, then the line of business or the division shall be treated as the sender of such message for purposes of this chapter.

#### Recipient

A recipient is the authorized user of the email address to which the message is sent. The statute treats each email address as a separate recipient, even if multiple addresses belong to the same individual. Conversely, a person who later acquires a reassigned email address is not considered the recipient of messages sent before the reassignment.

### Additional Technical Definitions

The Act also defines several technical terms that support its enforcement framework, including electronic mail message, electronic mail address, header information, domain name, Internet access service, protected computer, and routine conveyance. These definitions clarify the entities, technologies, and activities covered by the statute and are particularly relevant in enforcement actions involving deceptive routing information, spoofing, or the use of third-party email infrastructure.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-25--2026-at-11_08_26-AM.png)

### Predatory and Abusive Commercial Email Practices

Beyond establishing rules for legitimate commercial email, the CAN-SPAM Act also targets the abusive practices commonly associated with spam campaigns. Congress recognized that large-scale unsolicited email is frequently used to facilitate broader unlawful conduct, including fraud, identity theft, malware distribution, and the dissemination of illegal or harmful content. To strengthen enforcement, the Act directed the United States Sentencing Commission to review and, where appropriate, enhance criminal penalties for violations involving large-scale unsolicited commercial email.

- In particular, Congress instructed the Sentencing Commission to consider enhanced penalties where offenders obtained email addresses through deceptive or unauthorized means, such as harvesting email addresses from websites or online services without authorization or using software to generate email addresses randomly. Congress also identified the use of false or misleading domain registration information to conceal the sender's identity as an aggravating factor warranting increased penalties.
- The Act further reflects Congress's view that spam is frequently used as a vehicle to facilitate other serious crimes. The statutory findings note that unsolicited bulk email has become a common means of distributing fraudulent schemes, pornography, computer viruses, worms, Trojan horses, and other malicious content. Accordingly, Congress encouraged the Department of Justice to use the full range of available federal criminal statutes—including laws addressing fraud, false statements, obscenity, child sexual exploitation, and racketeering—to investigate and prosecute individuals who use commercial email to further criminal activity.

These provisions underscore an important aspect of the CAN-SPAM Act: it is not merely a consumer protection statute governing marketing practices. It also serves as an enforcement tool designed to combat sophisticated spam operations that exploit commercial email to perpetrate broader criminal misconduct.

See, [15 U.S.C. Sec. 7703](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com).

## Core Requirements for Commercial Email Under the CAN-SPAM Act

Section 7704 contains the heart of the CAN-SPAM Act's compliance requirements. It establishes the rules that businesses must follow when sending commercial email and prohibits a variety of deceptive practices designed to mislead recipients or frustrate their ability to opt out of future marketing communications. Collectively, these provisions promote transparency, consumer choice, and accountability in commercial email marketing.

The statute broadly defines information as **materially false or misleading** when it impairs the ability of recipients, Internet service providers, or law enforcement agencies to identify, locate, contact, or investigate the sender. This broad definition reinforces Congress's objective of preventing anonymous or deceptive commercial email campaigns that evade accountability.

See, [15 U.S.C. Sec. 7704](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com) (a).

#### Accurate Header Information

The Act prohibits senders from transmitting commercial or transactional emails containing materially false or misleading header information. Header information includes the source, destination, routing information, originating domain name, and email address associated with the message. A sender may not disguise the origin of an email by using deceptive routing techniques, unauthorized domains, fraudulent credentials, or intermediary computers to conceal where the message originated. However, the "From" line is not considered misleading simply because it identifies any person who actually initiated the message.

#### Truthful Subject Lines

Commercial emails must also contain truthful, non-deceptive subject lines. It is unlawful to use a subject heading that would likely mislead a reasonable recipient about a material aspect of the message's contents. The focus is on whether the subject line creates a false or misleading impression regarding what the email actually contains.

#### Functional Opt-Out Mechanism

Every commercial email must include a clear and conspicuous mechanism that allows recipients to opt out of future marketing messages. This may consist of a functioning return email address or another Internet-based mechanism, such as a web-based unsubscribe link. The opt-out mechanism must remain operational for at least 30 days after the message is sent.

The Act also permits senders to provide recipients with preference centers allowing them to select which categories of marketing messages they wish to receive, provided recipients are always given the option to opt out of all commercial emails from the sender. For example, a business may allow recipients to opt out of promotional offers while continuing to receive newsletters, event invitations, product announcements, or other specific categories of communications. However, any such preference center **must always include an option to stop receiving all commercial email messages from the sender**. In other words, while recipients may be offered granular choices, they cannot be forced to remain subscribed to any category of commercial communications.

#### Honoring Opt-Out Requests

Once a recipient exercises the right to opt out, the sender must stop sending covered commercial emails within **10 business days**. This obligation extends not only to the sender itself but also to third parties acting on the sender's behalf. Moreover, once a recipient has opted out, the sender generally **may not sell, lease, exchange, or "otherwise transfer or release"** that recipient's email address except as necessary to comply with the CAN-SPAM Act or another legal requirement.

A recipient may subsequently choose to receive marketing emails again by providing **new affirmative consent**, which restores the sender's ability to communicate commercially with that individual.

#### Required Disclosures

Each commercial email must clearly disclose:

- that the message is an advertisement or solicitation;
- how the recipient can opt out of future commercial messages; and
- the sender's valid physical postal address.

These disclosures ensure recipients can readily identify marketing communications and exercise their statutory rights.

> **Practical Takeaways:** For most organizations, compliance with Section 7704 can be distilled into several operational requirements: (1) Use accurate sender names, domains, and routing information. (2) Avoid deceptive or misleading subject lines. (3) Include a functioning unsubscribe mechanism that remains active for at least 30 days. (4) Honor opt-out requests within 10 business days. (5) Do not transfer or use opted-out email addresses for further marketing. (6) Include required disclosures, including a valid physical mailing address and, where required, identification that the message is an advertisement.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-25--2026-at-11_28_00-AM.png)

## Aggravated Violations: Practices That Trigger Heightened Liability

In addition to the general requirements governing commercial email, the CAN-SPAM Act prohibits several particularly abusive practices that Congress viewed as hallmarks of sophisticated spam operations. These aggravated violations target the methods commonly used by bad actors to build large-scale mailing lists, conceal their identities, and distribute unlawful commercial email.

See, [15 U.S.C. Sec. 7704](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com) (b)

- **Address Harvesting:** The Act prohibits knowingly sending unlawful commercial emails to addresses obtained through address harvesting. This occurs when a person uses automated software to collect email addresses from websites or online services that expressly state their addresses may not be collected, sold, or used for commercial email purposes. Importantly, the statute does not create a property right in email addresses. Rather, it prohibits the unauthorized use of automated tools to obtain addresses in violation of the website operator's stated restrictions.
- **Dictionary Attacks:** The Act also prohibits the use of dictionary attacks to generate recipient lists. A dictionary attack involves using automated software to create large numbers of potential email addresses by combining names, letters, numbers, or other characters in numerous permutations in an attempt to identify valid email accounts.
- **Automated Creation of Email Accounts**: Another prohibited practice is the use of scripts or other automated tools to create multiple email or online user accounts for the purpose of transmitting unlawful commercial email. Spammers often employ this technique to evade spam filters, avoid account suspensions, and continue sending messages after individual accounts have been blocked.
- **Unauthorized Relay or Retransmission**: The CAN-SPAM Rules further prohibits knowingly relaying or retransmitting unlawful commercial email through computers or networks accessed without authorization. This provision targets conduct such as hijacking third-party systems or using compromised computers to disguise the true origin of spam campaigns.

> **Practical Takeaway:** These aggravated violations demonstrate that the CAN-SPAM Act extends well beyond regulating the content of commercial emails. It also targets the technical methods commonly used to facilitate large-scale spam operations. Organizations engaged in legitimate email marketing should ensure that they: (1) Obtain email addresses through lawful and transparent means; (2) Avoid purchasing or using lists generated through harvesting or automated collection techniques; (3) Never generate recipient lists through dictionary attacks or similar automated methods; (4) Use legitimate email accounts and infrastructure rather than creating accounts through automated scripts; and (5) Never route commercial email through unauthorized third-party systems or compromised networks.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-25--2026-at-11_35_41-AM.png)

## Commercial Email Containing Sexually Oriented Material

The CAN-SPAM Act imposes additional requirements on commercial emails that contain sexually oriented material. Recognizing that recipients should be able to identify such messages before viewing their contents, Congress established special labeling and display rules designed to provide advance notice and facilitate filtering by email providers and users.

Violations of these requirements carry substantial consequences. A person who knowingly sends commercial emails containing sexually oriented material without complying with the labeling and display requirements may face **criminal penalties, including fines and imprisonment for up to five years**. For purposes of the Act, sexually oriented material generally refers to content depicting sexually explicit conduct, as defined under federal criminal law. The statute excludes materials in which such depictions constitute only a small and insignificant portion of content that is not primarily devoted to sexual matters.

See, [15 U.S.C. Sec. 7704](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com) (d)

- **Required Warning Labels:** Unless the recipient has previously provided affirmative consent to receive such communications, a commercial email containing sexually oriented material must include warning labels or notices prescribed by the Federal Trade Commission (FTC) in the subject line. These standardized notices are intended to alert recipients to the nature of the message before it is opened and to assist email filtering technologies in identifying the content.
- **Limited Initial Display**: The Act also restricts what may appear when the email is first opened. Before the recipient takes any additional action, the initially visible portion of the message may include only: (1) the required FTC warning label or notice; (2) the disclosures otherwise required under the CAN-SPAM Act, including the sender's identification, opt-out information, and physical mailing address; and (3) instructions or a mechanism allowing the recipient to access the sexually oriented material if they choose to do so. The purpose of this requirement is to prevent recipients from being exposed to explicit content simply by opening the email.

#### Prior Consent Exception

These special labeling and display requirements do not apply where the recipient has previously provided affirmative consent to receive commercial emails containing sexually oriented material. In those circumstances, the sender may communicate without using the mandatory warning labels required for unsolicited recipients.

> **Practical Takeaways:** Organizations that distribute adult-oriented commercial content should ensure that they: (1) Determine whether their communications contain "sexually oriented material" as defined by the Rules; (2) obtain and document affirmative consent whenever possible; (3) include the FTC-prescribed warning labels when consent has not been obtained; (4) limit the initially viewable portion of the email to the disclosures permitted by the statute; (5) maintain robust compliance procedures, as violations may result in both civil enforcement and criminal prosecution.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-25--2026-at-11_45_20-AM.png)

## Liability for Businesses That Benefit from Unlawful Email Campaigns

The CAN-SPAM Act does more than regulate the conduct of those who send commercial emails. It also imposes liability on businesses that **knowingly benefit from unlawful email marketing campaigns**. Section 7705 prevents organizations from avoiding responsibility by outsourcing their marketing to affiliates, lead generators, or third-party email marketers that use deceptive transmission practices.

See, [15 U.S.C. Sec. 7705](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com)

Business may be held liable when its products, services, or brand are promoted through commercial emails that contain **materially false or misleading header information** in violation of Section 7704, if the business:

- knew, or reasonably should have known, that its products or services were being promoted through the unlawful emails;
- received or expected to receive an economic benefit from the campaign; and
- failed to take reasonable steps either to prevent the unlawful transmissions or to detect and report them to the Federal Trade Commission (FTC).

In other words, businesses cannot avoid liability simply by claiming that a third-party marketing company was responsible for sending the emails. If a company knowingly benefits from an unlawful campaign and fails to take reasonable action, it may itself violate the CAN-SPAM Act.

#### Limited Liability for Third Parties

The Act generally does not impose liability on every company that provides goods or services to a business engaged in unlawful email marketing. Vendors, suppliers, and service providers are ordinarily protected from liability merely because they have a commercial relationship with the offending business.

However, this protection does not apply where a third party:

- owns or controls more than 50 percent of the offending business or has a majority economic interest in it; or
- has **actual knowledge** that unlawful commercial emails are promoting the business's products or services and receives, or expects to receive, an economic benefit from those promotions.

> **Key Takeaway:** Section 7705 reinforces an important compliance principle: **outsourcing email marketing does not outsource legal responsibility**. Businesses that knowingly benefit from unlawful commercial email campaigns—or ignore obvious signs of misconduct—may face liability alongside the parties that actually send the emails.

### Enforcement of the CAN-SPAM Act

The CAN-SPAM Act establishes a comprehensive enforcement framework designed to ensure compliance across a wide range of industries. 

- As a general rule, violations of the Act are treated as **unfair or deceptive acts or practices** under the Federal Trade Commission (FTC) Act, giving the **Federal Trade Commission (FTC)** primary responsibility for enforcing the statute. The FTC may investigate violations, seek administrative relief, obtain injunctions, and pursue civil penalties using the same authority it exercises under the FTC Act.
- For businesses operating in regulated industries, however, enforcement authority rests with their primary federal or state regulator. For example, banks are overseen by the federal banking agencies, broker-dealers and investment advisers by the **Securities and Exchange Commission (SEC)**, federally insured credit unions by the **National Credit Union Administration (NCUA)**, air carriers by the **Department of Transportation (DOT)**, telecommunications providers by the **Federal Communications Commission (FCC)**, and insurance companies by applicable state insurance regulators. These agencies may enforce the CAN-SPAM Act using their existing statutory enforcement powers.
- In addition, the CAN-SPAM Rules authorize **multiple layers of enforcement** beyond the Federal Trade Commission. State attorneys general may bring civil actions on behalf of their residents to stop violations, recover actual damages or statutory damages, and, in appropriate cases, obtain enhanced damages for willful or aggravated violations. Likewise, Internet Access Service (IAS) providers—such as email service providers and internet service providers—that are adversely affected by unlawful spam campaigns may seek injunctions and recover actual or statutory damages. Both state regulators and IAS providers may benefit from enhanced damages where violations are intentional or involve aggravated conduct, while courts may reduce damages for organizations that demonstrate commercially reasonable compliance programs.

**Each separate email in violation of the CAN-SPAM Act is subject to penalties of up to $53,088, so non-compliance can be costly.** (See FTC - [CAN-SPAM Act: A Compliance Guide for Business](https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business?ref=thedelatorrereview.com))

The Act also strengthens regulators' ability to stop unlawful email practices quickly. In certain enforcement actions involving deceptive transmission information, misleading subject lines, unlawful opt-out practices, and other specified violations, the FTC and FCC may obtain **cease-and-desist orders and injunctive relief without proving that the sender acted knowingly or intentionally**. This streamlined enforcement mechanism enables regulators to halt ongoing violations before they cause further consumer harm.

See, [15 U.S.C. Sec. 7706](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com)

### Interaction with Other Federal and State Laws

The CAN-SPAM Act establishes a nationwide framework for regulating commercial email, but it does not occupy the entire field of email regulation. Instead, Congress carefully preserved the application of numerous federal and state laws that address fraud, criminal conduct, and deceptive business practices.

See, [15 U.S.C. Sec. 7707](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com)

#### Federal Laws Remain Fully Applicable

The CAN-SPAM Act does not limit the government's ability to enforce other federal statutes that prohibit unlawful conduct involving electronic communications. For example, federal laws addressing **obscenity, the sexual exploitation of children, fraud, and other criminal offenses** continue to apply independently of the CAN-SPAM Act.

Likewise, the Act does not restrict the FTC longstanding authority under the FTC Act to pursue businesses that engage in false, deceptive, or unfair practices in commercial email marketing. As a result, a single email campaign may violate both the CAN-SPAM Act and other federal consumer protection or criminal laws.

#### Limited Preemption of State Email Laws

To create a more uniform national standard, the CAN-SPAM Act generally **preempts state laws that specifically regulate commercial email**. This means states generally cannot impose separate or inconsistent rules governing the content or transmission of commercial email messages.

However, Congress preserved an important exception: state laws that prohibit fraud, falsity, or deception in commercial email remain enforceable. As a result, businesses may still face liability under state laws targeting fraudulent or deceptive email practices.

## Do-Not-Email Registry and Ongoing Review of the CAN-SPAM Act

Recognizing that unwanted commercial email posed an evolving challenge, Congress included provisions requiring the FTC to evaluate additional consumer protections and periodically assess the effectiveness of the CAN-SPAM Act.

#### Proposed National Do-Not-Email Registry

Section 7708 directed the FTC to study the feasibility of creating a nationwide **Do-Not-Email Registry**, similar to the successful National Do Not Call Registry. Congress instructed the FTC to develop a plan and timetable for such a registry while evaluating the significant practical issues associated with its implementation, including technical feasibility, cybersecurity risks, privacy concerns, enforceability, and the potential impact on children with email accounts.

Although the Act authorized the FTC to implement a registry following its study, the agency ultimately concluded that a national Do-Not-Email Registry would likely create more risks than benefits. Unlike telephone numbers, an email registry could become a valuable target for spammers seeking verified, active email addresses, potentially increasing rather than reducing unsolicited email.

See, [15 U.S.C. Sec. 7708](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com) and [National Do-Not-Email Report](https://www.ftc.gov/sites/default/files/documents/reports/can-spam-act-2003-national-do-not-email-registy-federal-trade-commission-report-congress/report.pdf?ref=thedelatorrereview.com)

#### Ongoing Review of the Act

Section 7709 requires the FTC, in consultation with the Department of Justice and other federal agencies, to periodically evaluate the effectiveness of the CAN-SPAM Act and report its findings to Congress. A

See, [15 U.S.C. Sec. 7709](https://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-chapter103&edition=prelim&ref=thedelatorrereview.com)

## Additional Resources

- FTC - [CAN-SPAM Act: A Compliance Guide for Business](https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business?ref=thedelatorrereview.com)
- FTC- [Candid answers to CAN-SPAM questions ](https://www.ftc.gov/business-guidance/blog/2015/08/candid-answers-can-spam-questions?ref=thedelatorrereview.com)
- FTC- [Inflation-Adjusted Civil Penalty Maximums](https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-publishes-inflation-adjusted-civil-penalty-amounts-2024?ref=thedelatorrereview.com)
- [Verkada ](https://www.ftc.gov/news-events/news/press-releases/2024/08/ftc-takes-action-against-security-camera-firm-verkada-over-charges-it-failed-secure-videos-other?ref=thedelatorrereview.com)FTC Enforcement (2024)
- [Experian](https://www.justice.gov/archives/opa/pr/permanent-injunction-and-650000-civil-penalty-imposed-experian-consumer-services-allegedly?ref=thedelatorrereview.com) Enforcement (2023)

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/Screenshot-2026-07-04-at-4.45.19---PM-62.png)