"Is cold email legal?" is the wrong question — it's legal almost everywhere, under conditions. The right question is "which of the three rulebooks am I about to break?" Legal compliance keeps you from fines; provider compliance keeps you out of the spam folder; and list discipline keeps the first two achievable. This guide covers the law and the provider rules; the infrastructure side (domains, warmup, DNS) lives in our cold email infrastructure guide.
The usual disclaimer: this is practitioner guidance, not legal advice — for regulated industries or large EU campaigns, run your setup past counsel.
| Regime | Consent needed? | Core requirements | Penalty for getting it wrong |
|---|---|---|---|
| CAN-SPAM (US) | No | Accurate headers, no deceptive subject, physical address, opt-out honored ≤10 days | Up to ~$53,088 per email |
| GDPR + ePrivacy (EU/UK) | No, if legitimate interest holds | Documented LIA, role-relevant outreach, disclosure of data source, easy objection | Up to €20M or 4% of global turnover |
| CASL (Canada) | Yes (express or implied) | Implied consent via published business contact + relevance; ID + unsubscribe | Up to CA$10M per violation |
| Google/Yahoo/Microsoft | n/a | SPF + DKIM + aligned DMARC, one-click unsub, spam rate <0.1% | Rejection/spam-foldering (Microsoft: 550 5.7.15) |
The US is the most permissive major market: no prior consent needed for commercial email. What CAN-SPAM does demand, in every single message:
Each non-compliant email is a separate violation at up to ~$53,088 — a 1,000-send campaign is theoretical eight-figure exposure. In practice the FTC pursues egregious senders, but "we're too small to notice" is not a compliance strategy.
The persistent myth is that GDPR killed cold email in Europe. It didn't — it killed lazy cold email. B2B outreach to EU contacts generally runs on the legitimate interest lawful basis (Article 6(1)(f)), and it holds up when:
Country nuance matters: ePrivacy rules layer on top of GDPR and vary by member state. Germany is the strictest (competition law effectively requires opt-in for email marketing — many senders route German prospects to LinkedIn instead, which is one more argument for a multi-channel view); the Netherlands and the UK are workable under legitimate interest for corporate email addresses. Segment your sequences by country, not by continent.
Since February 2024 — with requirements tightened again in October 2025 — the mailbox providers enforce what amounts to a private regulatory regime for anyone sending at volume (Google's bulk threshold: 5,000+/day to Gmail):
Note the practical inversion: the law is why you won't get fined, but the provider rules are why you'll get read. A legally perfect campaign with 0.4% complaint rates is dead. Full setup lives in the deliverability guide.
Yes, in most major markets. The US allows it without consent under CAN-SPAM's disclosure rules; the EU/UK allow relevant B2B outreach under GDPR's legitimate interest basis with a documented assessment; Canada requires express or implied consent under CASL. Germany is the notable near-exception, effectively requiring opt-in.
Not necessarily. For B2B outreach to corporate addresses, legitimate interest is the standard lawful basis — provided the pitch is relevant to the recipient's role, you've documented a Legitimate Interest Assessment, and objecting is easy. Some member states (Germany especially) layer stricter national rules on top.
For senders over 5,000 emails/day: SPF and DKIM authentication with an aligned DMARC policy, one-click unsubscribe via RFC 8058 headers, and spam complaint rates kept below 0.3% (with 0.1% as the working target). The rules took effect February 2024 and were tightened in October 2025; Microsoft enforces equivalents since May 2025.
Yes — CAN-SPAM covers all commercial email regardless of whether the recipient is a business or consumer. Every message needs accurate sender information, a physical address, and a working opt-out honored within 10 business days.
Legally, yes (in the US and under legitimate interest in the EU) until they opt out or object — but a silent prospect after a full sequence belongs in a re-engagement cycle, not perpetual touches. Our follow-up cadence guide covers where persistence stops paying.
Want outbound that's compliant by construction? GenFlows builds campaigns with authentication, suppression, and country routing baked in — so scale never comes at the cost of the sender reputation. See how we build the infrastructure or talk to our team.
By the GenFlows GTM engineering team. Practitioner guidance, not legal advice. Last updated July 2026.