- B2B cold email is legal in 2026 — but you're answering to three rulebooks at once: the law (CAN-SPAM, GDPR, CASL), the mailbox providers (Google/Yahoo/Microsoft bulk sender rules), and the recipient's patience.
- US: no consent required, but every email needs accurate headers, a physical address, and a working opt-out. Violations run up to ~$53,088 per email.
- EU/UK: cold B2B email is possible under GDPR's legitimate interest basis — if the outreach is relevant to the recipient's role and you've documented a Legitimate Interest Assessment. Fines reach €20M or 4% of global turnover. Several countries (notably Germany) are stricter than GDPR baseline.
- Providers: since Feb 2024 (tightened Oct 2025), bulk senders need SPF + DKIM + aligned DMARC, one-click unsubscribe (RFC 8058), and spam complaints under 0.1% (0.3% = enforcement). Microsoft joined with hard rejections in May 2025.
- Below: each regime in plain English, the per-country nuances, and a pre-send checklist.
"Is cold email legal?" is the wrong question — it's legal almost everywhere, under conditions. The right question is "which of the three rulebooks am I about to break?" Legal compliance keeps you from fines; provider compliance keeps you out of the spam folder; and list discipline keeps the first two achievable. This guide covers the law and the provider rules; the infrastructure side (domains, warmup, DNS) lives in our cold email infrastructure guide.
The usual disclaimer: this is practitioner guidance, not legal advice — for regulated industries or large EU campaigns, run your setup past counsel.
The Three Rulebooks at a Glance
| Regime | Consent needed? | Core requirements | Penalty for getting it wrong |
|---|---|---|---|
| CAN-SPAM (US) | No | Accurate headers, no deceptive subject, physical address, opt-out honored ≤10 days | Up to ~$53,088 per email |
| GDPR + ePrivacy (EU/UK) | No, if legitimate interest holds | Documented LIA, role-relevant outreach, disclosure of data source, easy objection | Up to €20M or 4% of global turnover |
| CASL (Canada) | Yes (express or implied) | Implied consent via published business contact + relevance; ID + unsubscribe | Up to CA$10M per violation |
| Google/Yahoo/Microsoft | n/a | SPF + DKIM + aligned DMARC, one-click unsub, spam rate <0.1% | Rejection/spam-foldering (Microsoft: 550 5.7.15) |
CAN-SPAM: The US Baseline
The US is the most permissive major market: no prior consent needed for commercial email. What CAN-SPAM does demand, in every single message:
- Truthful headers and sender identity. Your "from" name and reply address must be real. Spoofing or misleading sender names is the fastest route to liability.
- No deceptive subject lines. "Re:" on a thread that doesn't exist and fake forwards are violations, not growth hacks — and they torch reply quality anyway (our subject line data shows honest specificity wins).
- A physical postal address in the footer. A registered agent or virtual office address counts.
- A working opt-out, honored within 10 business days — and you can't charge, require login, or ask for anything beyond an email address to process it. Suppress the address permanently; that includes future campaigns from new domains.
Each non-compliant email is a separate violation at up to ~$53,088 — a 1,000-send campaign is theoretical eight-figure exposure. In practice the FTC pursues egregious senders, but "we're too small to notice" is not a compliance strategy.
GDPR: Legitimate Interest, Done Properly
The persistent myth is that GDPR killed cold email in Europe. It didn't — it killed lazy cold email. B2B outreach to EU contacts generally runs on the legitimate interest lawful basis (Article 6(1)(f)), and it holds up when:
- The outreach is relevant to the recipient's professional role. Pitching a RevOps platform to a Head of RevOps passes; blasting the whole company directory does not. This is where a tight ICP definition is literally a compliance control.
- You've documented a Legitimate Interest Assessment (LIA) — a short written three-part test (purpose, necessity, balancing) showing why your interest doesn't override their privacy rights. Do it once per campaign type, before sending.
- You disclose and enable rights. Say who you are, be able to explain where you got their data (they can ask under Article 14), and make objecting effortless. An objection is a permanent suppression, not a different sequence.
- You minimize data. Name, role, company, business email — enough to personalize relevantly. Scraping personal social profiles into your CRM weakens the balancing test.
Country nuance matters: ePrivacy rules layer on top of GDPR and vary by member state. Germany is the strictest (competition law effectively requires opt-in for email marketing — many senders route German prospects to LinkedIn instead, which is one more argument for a multi-channel view); the Netherlands and the UK are workable under legitimate interest for corporate email addresses. Segment your sequences by country, not by continent.
The Provider Rulebook: Google, Yahoo, Microsoft
Since February 2024 — with requirements tightened again in October 2025 — the mailbox providers enforce what amounts to a private regulatory regime for anyone sending at volume (Google's bulk threshold: 5,000+/day to Gmail):
- Full authentication: SPF and DKIM passing, plus a DMARC policy whose domain aligns with your from-address. Microsoft began hard-rejecting unauthenticated bulk mail in May 2025 (bounce code 550 5.7.15).
- One-click unsubscribe (RFC 8058) via list-unsubscribe headers — Gmail renders it as a native button. Your sequencer should inject these headers; if it can't, change sequencers (our 2026 software comparison flags which ones handle this properly).
- Spam complaint rate under 0.3% — but treat 0.1% as the real ceiling; sustained 0.3% means outright rejection. At cold-email volumes, one complaint per thousand sends is your budget. List quality is the only lever that reliably keeps you under it.
Note the practical inversion: the law is why you won't get fined, but the provider rules are why you'll get read. A legally perfect campaign with 0.4% complaint rates is dead. Full setup lives in the deliverability guide.
The Pre-Send Compliance Checklist
- ☐ SPF, DKIM, DMARC passing and aligned on every sending domain
- ☐ One-click unsubscribe headers active; plus a plain-text opt-out line in the copy
- ☐ Physical address in the footer
- ☐ Sender name and subject line honest (no fake "Re:")
- ☐ List segmented by country; Germany and other opt-in markets routed out of email
- ☐ LIA written and filed for EU/UK segments; data source answerable on request
- ☐ Global suppression list applied across all domains and sequencers, opt-outs processed ≤10 days
- ☐ Complaint rate monitored per domain against the 0.1% ceiling
Frequently Asked Questions
Is cold email legal in 2026?
Yes, in most major markets. The US allows it without consent under CAN-SPAM's disclosure rules; the EU/UK allow relevant B2B outreach under GDPR's legitimate interest basis with a documented assessment; Canada requires express or implied consent under CASL. Germany is the notable near-exception, effectively requiring opt-in.
Do I need consent to cold email in Europe?
Not necessarily. For B2B outreach to corporate addresses, legitimate interest is the standard lawful basis — provided the pitch is relevant to the recipient's role, you've documented a Legitimate Interest Assessment, and objecting is easy. Some member states (Germany especially) layer stricter national rules on top.
What are the Google and Yahoo bulk sender requirements?
For senders over 5,000 emails/day: SPF and DKIM authentication with an aligned DMARC policy, one-click unsubscribe via RFC 8058 headers, and spam complaint rates kept below 0.3% (with 0.1% as the working target). The rules took effect February 2024 and were tightened in October 2025; Microsoft enforces equivalents since May 2025.
Does CAN-SPAM apply to B2B email?
Yes — CAN-SPAM covers all commercial email regardless of whether the recipient is a business or consumer. Every message needs accurate sender information, a physical address, and a working opt-out honored within 10 business days.
Can I keep emailing someone who didn't reply?
Legally, yes (in the US and under legitimate interest in the EU) until they opt out or object — but a silent prospect after a full sequence belongs in a re-engagement cycle, not perpetual touches. Our follow-up cadence guide covers where persistence stops paying.
Want outbound that's compliant by construction? GenFlows builds campaigns with authentication, suppression, and country routing baked in — so scale never comes at the cost of the sender reputation. See how we build the infrastructure or talk to our team.
By the GenFlows GTM engineering team. Practitioner guidance, not legal advice. Last updated July 2026.
The GenFlows team builds AI-powered cold outbound systems for B2B teams.