Is Cold Email Legal? A Jurisdiction-by-Jurisdiction Guide for 2026
Yes — cold email is legal almost everywhere, but "legal" means something different in each country.
Yes — cold email is legal almost everywhere, but “legal” means something different in each country. The United States runs an opt-out regime: you may send first and must let people leave. The EU, the UK, Canada and Australia run consent-first regimes with narrow exceptions. The rules that vary most are consent, identification and how fast you honour an opt-out.
This article is general information, not legal advice. Rules change and national implementations differ. Read the primary sources linked below and take advice from a qualified lawyer in each market you send to.
Key takeaways
- Nowhere bans cold email outright. Every regime below regulates how you send.
- The US is opt-out. No consent needed up front — but honest headers, a location, and a working opt-out honoured promptly.
- The EU/UK, Canada and Australia are consent-first, with exceptions narrower than most senders assume.
- B2B is a real distinction in Europe, but not a free pass — data-protection law still applies to a named person at a company.
- Three habits cover most of the overlap: identify yourself truthfully, make opting out one easy step, stop when asked.
What does US law actually require?
The CAN-SPAM Act is enforced by the Federal Trade Commission, and its compliance guide for business reduces to a short list: don’t use false or misleading header information, don’t use deceptive subject lines, identify the message as an ad, tell recipients where you’re located, tell them how to opt out, honour opt-out requests promptly, and monitor what anyone sending on your behalf is doing.
Two points get missed. The FTC states plainly that you don’t need consent before sending marketing email — the protection sits on the opt-out side. And the penalty is per message: up to $53,088 for each separate email in violation. A sloppy campaign multiplies.
What does the EU require?
The operative rule is Article 13 of the ePrivacy Directive (2002/58/EC). Article 13(1) allows direct marketing by electronic mail “only … in respect of subscribers who have given their prior consent.” Article 13(2) carves out the soft opt-in: if you obtained the contact details in the context of a sale, you may market “its own similar products or services” provided the customer was given a free, easy chance to object at collection and in every message. Article 13(4) prohibits marketing mail that disguises or conceals the sender’s identity, or that arrives “without a valid address to which the recipient may send a request that such communications cease.”
Article 13(5) is the clause the B2B world leans on: paragraphs 1 and 3 “shall apply to subscribers who are natural persons,” while Member States must ensure the legitimate interests of non-natural-person subscribers are “sufficiently protected.” That is a mandate for national variation, not an exemption — several Member States extended the consent rule to businesses anyway.
The GDPR separately governs the personal data behind the address. Recital 47 says processing “for direct marketing purposes may be regarded as carried out for a legitimate interest” — the usual Article 6(1)(f) basis for B2B prospecting — paired with Article 21’s unconditional right to object at any time, free of charge.
Is the UK different?
In substance, no. The UK carried the ePrivacy rules into its Privacy and Electronic Communications Regulations (PECR) alongside the UK GDPR: same architecture, same soft opt-in, same lighter position for corporate subscribers. Read the ICO’s electronic mail marketing guidance first.
What does Canada require?
Canada’s Anti-Spam Legislation (CASL) is the strictest of the five. Before sending a commercial electronic message you need consent — express (a proactive opt-in) or implied (a defined relationship, which expires). Every message must carry identification information and an unsubscribe mechanism, and the CRTC states businesses must act on unsubscribe requests within 10 days. See the regulator’s CASL pages and its implied-consent guidance. The burden of proof sits with you: you must be able to prove the consent you relied on.
What does Australia require?
The Spam Act 2003, administered by the ACMA, is built on three rules: consent (express or inferred), identify (say who authorised the message, with accurate business details), and unsubscribe (a functional, low-friction opt-out that stays live). See the ACMA’s guidance on avoiding sending spam.
How do the regimes compare side by side?
| Jurisdiction | Consent before first email? | Must identify sender / location | Opt-out requirement | Primary source |
|---|---|---|---|---|
| United States (CAN-SPAM) | No — opt-out regime | Yes: truthful headers, no deceptive subject, physical location, ad disclosure | Clear opt-out, honoured promptly; up to $53,088 per violating email | FTC guide |
| EU/EEA (ePrivacy + GDPR) | Yes for natural-person subscribers; soft opt-in for existing customers; Art. 13(5) leaves business subscribers to national law | Yes — concealing sender identity is prohibited | A valid address to stop must be present; GDPR Art. 21 right to object at any time | ePrivacy Art. 13 · GDPR |
| United Kingdom (PECR + UK GDPR) | Same architecture as the EU, applied under UK rules | Yes | Working opt-out; right to object | ICO PECR guidance |
| Canada (CASL) | Yes — express or implied consent, and implied consent expires | Yes — identification information in every message | Unsubscribe mechanism, acted on within 10 days | CRTC |
| Australia (Spam Act 2003) | Yes — express or inferred consent | Yes — the message must identify who authorised it | Functional unsubscribe that stays available | ACMA |
What about the providers’ own rules?
Legality is only half the gate. Mailbox providers enforce their own sender requirements regardless of which law applies to you, and those decide whether your mail is delivered. All senders, at any volume, must authenticate with SPF or DKIM, publish valid forward and reverse DNS, use TLS, and keep spam complaints below 0.30% — with 0.10% as the recommended target, per Google’s sender guidelines. Above 5,000 messages a day to a provider’s consumer mailboxes the bar rises to SPF and DKIM plus DMARC, and one-click unsubscribe on marketing mail. Yahoo publishes equivalent best practices with no numeric threshold at all; Microsoft’s outbound guidance asks for authentication, list hygiene, honoured unsubscribes and a consistent From address.
Complying with the law and being blocked by a provider are entirely compatible states. Plan for both.
How WarmySender handles this
The compliance mechanics are structural rather than something you remember to do. Every campaign email carries an opt-out — a link or reply-to-unsubscribe — and your workspace’s company address goes in the footer, covering the identification and location requirements the FTC, CRTC and ACMA all ask for. Opt-outs and replies feed a suppression list that campaigns check before every send.
On the deliverability side, email warmup builds sending history gradually instead of doubling volume, and real-time email verification keeps invalid addresses out of a send. The deliverability FAQ covers authentication.
Because WarmySender is agentic-first, all of that holds when an AI agent drives. An agent can build, launch and manage cold email, LinkedIn and Instagram campaigns, verify addresses and tune warmup in plain language — but it never sends a message itself and can never raise a limit. It hands the campaign to the scheduler, which paces every action inside safe caps and the gradual ramp no matter who pressed go.
Frequently asked questions
Is buying an email list legal?
In the US, CAN-SPAM does not prohibit sending to a purchased list, but every other obligation still applies and you inherit the list’s complaint risk. In consent-first jurisdictions a purchased list almost never carries the consent the law requires, because consent has to be something the recipient gave you. Providers also judge you on complaint rate, and bought lists are the fastest route to breaching it.
Does B2B cold email need consent in Europe?
The ePrivacy Directive’s consent rule in Article 13(1) is written for subscribers who are natural persons, and Article 13(5) leaves protection of business subscribers to national law — so the answer genuinely varies by Member State. Even where business addresses are outside the consent rule, a named individual’s work address is still personal data under the GDPR, so you need a lawful basis (usually legitimate interests) and must honour the Article 21 right to object.
How fast do I have to honour an unsubscribe?
It depends where the recipient is: the FTC requires opt-outs honoured promptly, the CRTC gives CASL senders 10 days, and Australia’s Spam Act sets a statutory period. The safe engineering answer is to suppress the address immediately and treat the legal deadline as a backstop you never rely on.
Do I need a physical address in a cold email?
Under CAN-SPAM, yes — the FTC lists “tell recipients where you’re located” as a core requirement. CASL and the Spam Act both require identification information for the business that authorised the message, and the ePrivacy Directive prohibits concealing the sender’s identity. A real postal address in the footer satisfies all four at once.
Does using an AI agent to write or send outreach change the legal position?
No. The obligations attach to the sender — the business the message goes out for — not to the tool that composed it. The FTC’s guidance already covers the principle: monitor what others do on your behalf. Practically, an agent should be able to build and launch campaigns but never bypass your opt-out footer, suppression list or sending limits — the boundary WarmySender enforces.