CAN-SPAM is the US's commercial email law. The seven core requirements: don't lie about who you are, don't lie about what's in the email, identify the message as an ad, include a real address, give recipients a clear opt-out, honor opt-outs within 10 business days, and monitor anyone you contract to send on your behalf. Pitch2Retail handles all seven automatically β but here's exactly how.
What is CAN-SPAM?
The Controlling the Assault of Non-Solicited Pornography And Marketing Act (15 U.S.C. Β§ 7701) is the US federal law governing commercial email. Unlike CASL, CAN-SPAM uses opt-out consent β you don't need permission before sending the first message, but you must give a clear way to opt out and honor it.
CAN-SPAM applies to any commercial email sent to a US recipient, regardless of where the sender is based. Penalties: up to $50,120 per violation (per email).
The 7 core requirements
| # | Requirement | How Pitch2Retail handles it |
|---|---|---|
| 1 | Don't use false / misleading header information | From, Reply-To, and routing info are pulled from your verified connected account (Gmail / Outlook / Resend) |
| 2 | Don't use deceptive subject lines | Compliance lint flags subjects like "Re:" or "Fwd:" when not actually a reply/forward |
| 3 | Identify the message as an ad | Pitches are conversational outreach (which CAN-SPAM treats more permissively than display ads); we still ensure no deception about the commercial nature |
| 4 | Tell recipients where you're located | Physical address required during onboarding, auto-injected into every email footer |
| 5 | Tell recipients how to opt out | One-click unsubscribe link in every email footer + plain-English explanation |
| 6 | Honor opt-outs promptly (β€10 business days) | Processed instantly via /api/track/unsub/:pitchId β well under the 10-day requirement |
| 7 | Monitor what others do on your behalf | Platform enforces all 6 above, regardless of which client triggered the send |
Truthful headers (s.5(a)(1))
The following identifying information must be truthful in every email Pitch2Retail sends on your behalf:
- From: address must accurately identify you. We pull this from your connected Gmail / Outlook / Resend domain β it cannot be spoofed.
- Reply-To: must work and reach you. Defaults to the same as From.
- Routing data: SMTP envelope, message-ID, and DKIM signature all derive from the actual sending account.
Non-deceptive subject lines (s.5(a)(2))
A subject line is "deceptive" under CAN-SPAM if a reasonable recipient would be misled about the message contents. Common violations:
- "Re:" or "Fwd:" prefixes when it's not actually a reply or forward
- Implying a personal relationship that doesn't exist ("Did you get my last note?")
- Implying winnings or prizes ("Your shipment is waiting")
- Mismatched body content (subject promises one thing, body delivers another)
Pitch2Retail's templates avoid all of these by design. The compliance lint blocks send when high-severity deceptive patterns appear.
Physical postal address (s.5(a)(5))
Every commercial email must include a valid physical postal address. This can be:
- Your current street address
- A registered US Postal Service post office box
- A commercial mail receiving agency address (registered under USPS regulations)
Pitch2Retail collects this address during onboarding (required field on first paid subscription) and auto-injects it into every email's footer. You can update it anytime in Settings.
Opt-out mechanism (s.5(a)(3-4))
The opt-out must:
- Be clear and conspicuous in the message
- Allow opt-out via a simple Internet-based mechanism (one-click is the standard)
- Function for at least 30 days after the message was sent
- Be processed within 10 business days of the request
- Not require the recipient to provide identifying info beyond their email + opt-out preference
- Not require payment, fee, or sending additional information
Pitch2Retail's unsubscribe link satisfies all of these:
- Plain-text "Unsubscribe" hyperlink in the message footer (always shown)
- Single GET request β no login, no captcha, no fee
- Functional indefinitely (we keep the redirect alive forever; the suppression list is permanent)
- Processed instantly (~0 milliseconds, well under 10 business days)
Sender vs. ESP liability
Under CAN-SPAM, both the sender (you) and the entity that initiates transmission (Pitch2Retail acting as your sending tool) can be liable. We share the burden:
| What you're responsible for | What we're responsible for |
|---|---|
| Truthful brand identification (your business name, real address) | Truthful header / routing data on the wire |
| Non-deceptive subject + body content | Compliance lint to detect common deceptive patterns |
| Not bulk-emailing irrelevant recipients | Audience builder + suppression list enforcement |
| Respecting your industry's specific rules (FDA, FTC, etc.) | Category-specific lint (FDA / NHPD for supplements) |
Enforcement and penalties
CAN-SPAM is primarily enforced by the Federal Trade Commission (FTC) and the Department of Justice (DOJ). State attorneys general and ISPs can also bring private actions.
Penalties:
- Up to $50,120 per email (adjusted annually for inflation)
- Aggravating factors (harvesting, dictionary attacks, automated address generation) can multiply penalties
- Criminal penalties available for the most egregious violations
If your product touches US healthcare, pharmaceuticals, supplements, or medical devices β additional FDA regulations apply on top of CAN-SPAM. See our AI Usage page for how the compliance lint blocks banned health claims.
One platform. Three jurisdictions. Zero stress.
CASL, CAN-SPAM, and GDPR all enforced by default. Start your 14-day free trial.
Start free trial β