Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Meet CAN-SPAM, GDPR, and CASL email requirements. Use when sending commercial email, implementing unsubscribe, managing consent, or classifying transactional vs commercial messages.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-14 | ✗→✓ | ▲ Improved | 135% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 623% | 0% |
| case-17 | ✓→✓ | = Same ✓ | 297% | 0% |
| case-23 | ✓→✓ | = Same ✓ | 273% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 367% | 0% |
Navigate CAN-SPAM, GDPR, and CASL requirements so your emails are legally compliant across jurisdictions.
domain-authentication - SPF, DKIM, DMARC setup (required for bulk sender compliance)suppression-lists - managing bounces, complaints, and opt-outstransactional-email - sending receipts, auth emails, and notifications (mostly exempt)cold-outreach - B2B cold email that doesn't violate consent lawsMost email senders need to comply with at least one of these. If you send internationally, you likely need all three.
| | CAN-SPAM (US) | GDPR (EU/EEA) | CASL (Canada) | |---|---|---|---| | Consent model | Opt-out (can send until they unsubscribe) | Opt-in (need consent before sending) | Opt-in (express or implied consent required) | | Applies to | Commercial email messages | Any processing of personal data (email address = personal data) | Commercial electronic messages (CEMs) | | Consent type | Not required to send; must honor opt-out | Explicit consent or legitimate interest | Express consent (never expires) or implied consent (time-limited) | | Unsubscribe deadline | 10 business days | Without undue delay (typically 30 days max) | 10 business days | | Physical address | Required in every commercial email | Not required in email itself (but must be available) | Required - sender identification with contact info | | Sender identification | Accurate From, Reply-To, routing info | Data controller identity must be available | Name and contact info of sender required | | Record keeping | No specific requirement | Must prove consent was given (timestamp, method, purpose) | Must retain consent records for 3 years after relationship ends | | Transactional exemption | Yes - mostly exempt from CAN-SPAM rules | Contractual basis covers transactional email | Yes - non-commercial messages exempt | | Penalties (max) | $51,744 per email (no cap on total) | 4% of global annual revenue or 20M EUR | $10M CAD per violation (business) | | Enforcement | FTC | National data protection authorities | CRTC | | Extraterritorial | Applies to email sent to US recipients | Applies if you process EU resident data, regardless of sender location | Applies to messages sent to or accessed in Canada |
Practical rule of thumb: If you comply with GDPR and CASL (the strictest), you automatically satisfy CAN-SPAM. Build for the strictest standard you face, not the loosest.
CAN-SPAM is an opt-out law. You can send commercial email to anyone until they tell you to stop. This sounds permissive, but the requirements for what your emails must contain are strict.
If you hire another company to send email on your behalf, you're both legally responsible. "Our vendor handles that" is not a defense. Monitor what they send under your name.
GDPR is fundamentally different from CAN-SPAM. It's an opt-in framework - you need a lawful basis to process someone's personal data (an email address counts) before you send anything.
You need one of these for every email you send:
| Basis | When it applies | What it requires | |---|---|---| | Explicit consent | Marketing, newsletters, promotional email | Freely given, specific, informed, unambiguous. Clear affirmative action (not pre-checked boxes). Must be as easy to withdraw as to give. | | Legitimate interest | B2B outreach, existing customer marketing ("soft opt-in") | Must pass a three-part test: (1) you have a legitimate interest, (2) processing is necessary for that interest, (3) it doesn't override the individual's rights. Document your assessment. | | Contractual necessity | Transactional email, order confirmations, account notifications | Email must be necessary to fulfill a contract or pre-contractual steps the recipient requested. | | Legal obligation | Regulatory notifications, compliance communications | You're legally required to send the communication. |
Under the ePrivacy Directive (which works alongside GDPR), you can email existing customers about similar products or services without explicit consent if:
This is the "soft opt-in" and it's widely used in B2B. But it only applies to your own similar products - you can't use it to email about unrelated offerings or share the address with partners.
Valid GDPR consent must be:
| Right | What it means for email senders | |---|---| | Right to object | Any recipient can object to direct marketing at any time. You must stop immediately. Their objection overrides any legitimate interest claim. | | Right to erasure | Recipients can request deletion of their personal data. You must comply within 30 days unless you have a legal obligation to retain it. | | Right of access | Recipients can request a copy of all data you hold about them, including consent records, send history, and engagement data. | | Right to rectification | Recipients can request correction of inaccurate data. |
You can retain data when it's necessary for legal compliance, defending legal claims, or archiving in the public interest. Document your reasoning.
CASL is the strictest of the three. It requires consent before sending any commercial electronic message (CEM), and it distinguishes between express and implied consent with different expiry rules.
Express consent means the recipient took a clear, proactive action to agree to receive your messages. Examples: checking an unchecked opt-in box, filling out a subscription form, sending a written request.
Express consent does not expire as long as the recipient doesn't withdraw it. But you must be able to prove you obtained it.
When requesting consent, you must disclose:
Implied consent is time-limited and arises from an existing relationship:
| Relationship type | Consent duration | |---|---| | Purchased a product or service | 2 years from the transaction | | Active contract or membership | Duration + 2 years after expiry | | Inquiry or application | 6 months from the inquiry | | Conspicuously published email (e.g., on a website) | Only for messages relevant to their role/function | | Referral from another person | Single message allowed |
Once implied consent expires, you must stop sending or obtain express consent.
CASL is explicit about what you must retain:
This is not optional. If you can't produce these records during an audit, the CRTC will treat the messages as unconsented.
Getting this classification right matters because transactional emails are exempt from most compliance requirements (unsubscribe links, physical address, ad identification). Getting it wrong exposes you to penalties.
Under CAN-SPAM, transactional or relationship messages include:
Under GDPR, these are covered by the contractual necessity basis - no separate consent needed if the email is necessary to fulfill a contract.
Under CASL, transactional messages are generally exempt from consent requirements if they're directly related to an existing commercial activity.
This is where most mistakes happen. An order confirmation that includes a promotional banner at the bottom is a mixed-content email.
CAN-SPAM rule for mixed content: If the subject line would lead a recipient to think it's a commercial message, or if the transactional content doesn't appear primarily at the beginning, it's classified as commercial. Put transactional content first and keep promotional elements minimal and clearly secondary.
Best practice: Keep transactional and commercial emails completely separate. Don't add promotional content to order confirmations, password resets, or account alerts. It risks reclassifying the entire message as commercial.
Since June 2024, Google and Yahoo require RFC 8058 one-click unsubscribe for all bulk senders (5,000+ messages/day). Microsoft announced similar requirements for Outlook.com effective May 2025. This is now table stakes for any marketing email.
Add two headers to every marketing/promotional email:
List-Unsubscribe: <https://example.com/unsubscribe?id=abc123>
List-Unsubscribe-Post: List-Unsubscribe=One-ClickList-Unsubscribe=One-ClickList-Unsubscribe and List-Unsubscribe-Post headers must be covered by your DKIM signatureThe older mailto: form still works but is not sufficient on its own for the bulk sender requirements:
List-Unsubscribe: <mailto:unsubscribe@example.com?subject=unsubscribe-abc123>Include both the HTTPS and mailto forms for maximum compatibility:
List-Unsubscribe: <https://example.com/unsubscribe?id=abc123>, <mailto:unsubscribe@example.com?subject=unsubscribe-abc123>
List-Unsubscribe-Post: List-Unsubscribe=One-ClickAt minimum, store these fields for every consent:
| Field | Purpose | Required by | |---|---|---| | recipientEmail | Who consented | All | | basis | Consent type: explicit_opt_in, legitimate_interest, contractual, legal_obligation | GDPR, CASL | | source | Where consent was collected: signup form URL, import file, verbal | GDPR, CASL | | jurisdiction | Which law applies: us, eu, ca | All (determines rules) | | grantedAt | Timestamp when consent was given | GDPR, CASL | | revokedAt | Timestamp when consent was withdrawn (null if active) | All | | consentText | The exact wording shown when consent was collected | CASL (required), GDPR (recommended) | | ipAddress | IP at time of consent collection | Recommended for audit |
Platforms like molted.email store consent records with basis, source, jurisdiction, and timestamps as a first-class data model, making audit responses straightforward.
Double opt-in (confirmation email) is not legally required by any of the three laws, but it's strongly recommended for GDPR and CASL compliance because:
For CASL implied consent, you need to track expiry:
if consent.basis == 'implied' and consent.jurisdiction == 'ca':
if consent.source == 'inquiry':
expires = consent.grantedAt + 6 months
else: # purchase, contract
expires = consent.grantedAt + 2 years
if now > expires:
# Must stop sending or upgrade to express consentDon't wait until consent expires to act. Start a consent renewal campaign 30-60 days before expiry.
When someone unsubscribes, bounces, or files a complaint, they go on a suppression list. Compliance requires you to check this list before every send.
| Reason code | What triggered it | Can you remove it? | |---|---|---| | complaint | Recipient clicked "Report Spam" | No - honor permanently | | hard_bounce | Address doesn't exist | No - remove from lists | | manual_dnc | Unsubscribe request or manual addition | Only if recipient re-consents | | legal_request | Erasure request, legal demand | No - honor permanently | | role_account | Address is a role account (info@, admin@) | Generally avoid sending to role accounts | | no_engagement | No opens/clicks over extended period | Yes, but consider if re-engagement is appropriate |
GDPR says you must delete personal data on request. But if you delete the email address entirely, you might accidentally re-import it and send again - which violates the erasure request.
Solution: Keep a hashed (one-way) suppression record. Hash the email address (SHA-256), store the hash on your suppression list, delete all other personal data. Before every send, hash the recipient address and check against the suppression list. This satisfies both the erasure requirement (you don't store the email in plaintext) and the suppression requirement (you won't send to them again).
CAN-SPAM is the most permissive of the three. If you have any EU or Canadian recipients (and you probably do - you often can't know where someone is), build for GDPR/CASL compliance from the start. Retrofitting consent is painful.
Transactional emails are exempt from most marketing rules, but they still must have accurate header information (From, Reply-To, routing) under CAN-SPAM, and they're still covered by GDPR data processing rules. You need a lawful basis (contractual necessity) even for transactional sends.
"By creating an account, you agree to receive marketing emails" is invalid under GDPR. Consent for marketing must be separate from consent for terms of service. Use a separate, unchecked checkbox.
Invalid under both GDPR and CASL. The checkbox must start unchecked. The recipient must take an affirmative action to consent.
"They signed up on our website" is not proof of consent. You need the timestamp, the source URL, the IP address, and ideally the exact wording they agreed to. Under CASL, you must retain this for 3 years.
Implied consent from a purchase expires after 2 years. From an inquiry, 6 months. Many senders set up consent tracking at the start and never build expiry logic. Two years later, they're sending to expired-consent addresses - which is a CASL violation.
Multi-step unsubscribe flows ("Are you sure? Tell us why. Log in to confirm.") violate CAN-SPAM's requirement for a simple opt-out mechanism. They also violate GDPR's requirement that withdrawal be as easy as giving consent. One click. Done.
Adding only List-Unsubscribe without List-Unsubscribe-Post doesn't satisfy the RFC 8058 one-click requirement. You need both headers, and both must be covered by your DKIM signature.
"We're sorry to see you go!" emails sent after an unsubscribe are a violation if they contain any commercial content. If you want to send a confirmation of unsubscribe, make it purely informational with no promotional elements.
Sending marketing and transactional email from the same domain/IP means a compliance issue with marketing email (complaints, blocks) affects your transactional delivery. Use separate subdomains: mail.example.com for transactional, news.example.com for marketing.
List-Unsubscribe and List-Unsubscribe-Post headers (for bulk senders)Other measured skills in the registry, with their headline benchmark lift.