Blog/ Unsolicited & sales email

Is It Illegal to Send Unsolicited Emails? A Recipient's Guide

Nafiul HasanNafiul Hasan· 8 min read
Illustration explaining whether it is illegal to send unsolicited emails and the rights a recipient has under CAN-SPAM and GDPR

The short answer

Mostly no. In the US, unsolicited commercial email is legal under CAN-SPAM if the sender identifies itself, shows a real postal address, and honours your opt-out within 10 business days. In the EU and UK, marketing usually needs your consent, so you can object at any time and complain to a regulator.

Is it illegal to send unsolicited emails? Usually no — but you have real rights. What CAN-SPAM and GDPR give the recipient, and how to use them.

On this page
  1. 01The short answer
  2. 02Before you start: know which law covers you
  3. 03Steps: what to do about an unsolicited email
  4. 04Your rights by region: CAN-SPAM vs GDPR
  5. 05How much trouble is the sender actually in?
  6. 06What to do when the opt-out doesn't work
  7. 07A faster way: stop them reaching your inbox at all

"Is it illegal to send unsolicited emails?" is one of those questions where the honest answer is "it depends where you are." This guide explains what the law gives you as the person receiving the mail — not the company sending it.

It is general information, not legal advice. For a specific situation, talk to a qualified lawyer in your own country. The short version: a single marketing email from a real business is usually legal. What the law regulates is how they send it, and what they must do the moment you ask them to stop. Those obligations are your rights — and most people never use them.

The short answer#

In the United States, unsolicited commercial email is legal. The CAN-SPAM Act does not require a company to get your permission before the first message. It is an opt-out regime, not an opt-in one.

What CAN-SPAM does require is honesty and an exit. The sender must not use false or misleading headers or subject lines, must identify the message as an advertisement, must include a valid physical postal address, and must give you a working way to opt out — then honour that opt-out within 10 business days.

In the European Union, the EEA and the UK, the default flips. Marketing email to individuals generally needs your consent up front, and you can object to direct marketing at any time. Different rules, same underlying idea: the sender carries the duties, and you hold the rights.

Before you start: know which law covers you#

Which rules apply depends less on where the sender sits and more on where you are and what data they used. A US company emailing an EU resident can be on the hook for EU rules; an EU company emailing a US inbox is usually judged by CAN-SPAM.

Two named regimes cover most readers of this page, and they work in opposite directions:

  • United States — CAN-SPAM Act. Opt-out based. No consent needed first, but strict rules on identification, headers and honouring your opt-out.
  • EU / EEA — GDPR plus the ePrivacy rules. Opt-in based. Marketing to individuals normally needs consent, and you can object and complain to a regulator.
  • Other countries add their own, often stricter, consent-based regimes — the UK's PECR (enforced by the ICO) and Canada's CASL (enforced by the CRTC). If one of those covers you, its consent rules apply, not CAN-SPAM's opt-out model.

Steps: what to do about an unsolicited email#

  1. 1

    Confirm it is actually commercial email

    A newsletter, a sales pitch or a promotion is commercial mail and carries these rules. A receipt, a password reset or a shipping update is transactional and is treated differently. Anything trying to trick you into clicking or paying is likely phishing — report it, do not engage.

  2. 2

    Use the unsubscribe link

    Legitimate marketing mail must include one. On a real company's message, clicking it is the fastest, cleanest way to stop the mail and creates a record that you asked.

  3. 3

    Give it the legal window

    Under CAN-SPAM the sender has up to 10 business days to stop. Under GDPR your objection to direct marketing takes effect at any time and should be actioned without undue delay. Note the date you asked.

  4. 4

    Keep the evidence

    Save the original email, including full headers, and the date you unsubscribed. If it keeps coming, the message plus your opt-out date is exactly what a regulator or the sender's mailbox provider will want to see.

  5. 5

    Escalate if it continues

    Still getting mail after the window? That is where the sender has crossed from annoying into non-compliant, and you have somewhere to take it. The table below shows who.

Your rights by region: CAN-SPAM vs GDPR#

Here is what each regime actually gives the person receiving the mail. The biggest practical difference is the last two rows — whether you can act against the sender yourself, and where a complaint goes.

Diagram bridging the sender's legal duties on one side to the recipient's rights and reporting routes on the other
Every duty on the sender's side of the bridge is a right on yours. The gap most people never cross is the reporting route on the far end.
Your right as recipientUnited States (CAN-SPAM)EU / EEA (GDPR + ePrivacy)
Consent before the first emailNot required — it is an opt-out regimeUsually required — marketing needs consent or a narrow lawful basis
Sender must identify itself and give a postal addressYes — required in every commercial messageYes — and must identify the data controller behind it
Right to opt out or objectYes — sender must honour it within 10 business daysYes — you can object to direct marketing at any time (GDPR Art. 21)
Can you personally sue the sender?No private right of action — the FTC, state attorneys general and ISPs enforce itYes — you can seek compensation in court and lodge a complaint (GDPR Art. 77)
Where to report itThe FTC and your state attorney generalYour national data protection authority (find it via the EDPB)

How much trouble is the sender actually in?#

The penalties are real, but they are not something you collect. CAN-SPAM violations can draw steep civil penalties, and the FTC sets a per-email figure that it adjusts for inflation each year — so check the FTC's current amount rather than trusting an old number in a blog post.

Under GDPR the ceiling is far higher: fines can reach up to €20 million, or 4% of the company's total worldwide annual turnover, whichever is higher (GDPR Art. 83). Both are enforced by regulators, not paid to you — which is why the practical goal for a recipient is to make the mail stop, and report the sender who won't.

Penalty figures move — check the source

The CAN-SPAM per-email maximum is inflation-adjusted annually by the FTC, so any specific dollar amount ages quickly. Verify the current figure on the FTC's own guidance before you rely on it. This page states only the GDPR ceiling, which is fixed in the regulation itself.

What to do when the opt-out doesn't work#

Sometimes the unsubscribe link is broken, ignored, or the mail simply keeps arriving under a new sender name. At that point you have three routes, and they stack.

  • Report it to your mailbox provider. Gmail's "Report spam" and Outlook's "Junk" do more than move one message — they feed the provider's filters and count against the sender's reputation.
  • File a complaint with the regulator. In the US that is the FTC; in the EU or UK it is your national data protection authority. Attach the saved email and your opt-out date.
  • Filter it at your end. Regulators are slow and cross-border enforcement is hard. The reliable, same-day fix is to stop the mail reaching your inbox in the first place.

Don't unsubscribe from mail you don't recognise

On a real company's message, the unsubscribe link is safe. But on unsolicited mail from an unknown sender — especially anything that looks like phishing — clicking "unsubscribe" can simply confirm your address is live and invite more. When in doubt, mark it as spam instead of unsubscribing.

A faster way: stop them reaching your inbox at all#

Unsubscribing works, but it is reactive. You handle one sender at a time, and a fresh company starts the cycle over. The reason a plain block doesn't hold is that a block matches a single address, while bulk senders rotate addresses inside one domain.

AI Emaily's cold-email filter matches on sender behaviour and domain rather than one address, so unsolicited outreach is set aside before it lands in your inbox — and a rotated address doesn't reset it. Nothing is deleted; the mail is filed where you can still find it, unsubscribe, or report it, so you keep every legal right above. We build AI Emaily.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Keep unsolicited email out without lifting a finger

AI Emaily files cold outreach before it reaches your inbox — nothing deleted, you stay in control, with undo and audit.

  • 7-day free trial
  • Cancel anytime
  • Every provider