Is It Illegal to Send Unsolicited Emails? A Recipient's Guide

The short answer
Mostly no. In the US, unsolicited commercial email is legal under CAN-SPAM if the sender identifies itself, shows a real postal address, and honours your opt-out within 10 business days. In the EU and UK, marketing usually needs your consent, so you can object at any time and complain to a regulator.
Is it illegal to send unsolicited emails? Usually no — but you have real rights. What CAN-SPAM and GDPR give the recipient, and how to use them.
On this page
"Is it illegal to send unsolicited emails?" is one of those questions where the honest answer is "it depends where you are." This guide explains what the law gives you as the person receiving the mail — not the company sending it.
It is general information, not legal advice. For a specific situation, talk to a qualified lawyer in your own country. The short version: a single marketing email from a real business is usually legal. What the law regulates is how they send it, and what they must do the moment you ask them to stop. Those obligations are your rights — and most people never use them.
The short answer#
In the United States, unsolicited commercial email is legal. The CAN-SPAM Act does not require a company to get your permission before the first message. It is an opt-out regime, not an opt-in one.
What CAN-SPAM does require is honesty and an exit. The sender must not use false or misleading headers or subject lines, must identify the message as an advertisement, must include a valid physical postal address, and must give you a working way to opt out — then honour that opt-out within 10 business days.
In the European Union, the EEA and the UK, the default flips. Marketing email to individuals generally needs your consent up front, and you can object to direct marketing at any time. Different rules, same underlying idea: the sender carries the duties, and you hold the rights.
Before you start: know which law covers you#
Which rules apply depends less on where the sender sits and more on where you are and what data they used. A US company emailing an EU resident can be on the hook for EU rules; an EU company emailing a US inbox is usually judged by CAN-SPAM.
Two named regimes cover most readers of this page, and they work in opposite directions:
- United States — CAN-SPAM Act. Opt-out based. No consent needed first, but strict rules on identification, headers and honouring your opt-out.
- EU / EEA — GDPR plus the ePrivacy rules. Opt-in based. Marketing to individuals normally needs consent, and you can object and complain to a regulator.
- Other countries add their own, often stricter, consent-based regimes — the UK's PECR (enforced by the ICO) and Canada's CASL (enforced by the CRTC). If one of those covers you, its consent rules apply, not CAN-SPAM's opt-out model.
Steps: what to do about an unsolicited email#
- 1
Confirm it is actually commercial email
A newsletter, a sales pitch or a promotion is commercial mail and carries these rules. A receipt, a password reset or a shipping update is transactional and is treated differently. Anything trying to trick you into clicking or paying is likely phishing — report it, do not engage.
- 2
Use the unsubscribe link
Legitimate marketing mail must include one. On a real company's message, clicking it is the fastest, cleanest way to stop the mail and creates a record that you asked.
- 3
Give it the legal window
Under CAN-SPAM the sender has up to 10 business days to stop. Under GDPR your objection to direct marketing takes effect at any time and should be actioned without undue delay. Note the date you asked.
- 4
Keep the evidence
Save the original email, including full headers, and the date you unsubscribed. If it keeps coming, the message plus your opt-out date is exactly what a regulator or the sender's mailbox provider will want to see.
- 5
Escalate if it continues
Still getting mail after the window? That is where the sender has crossed from annoying into non-compliant, and you have somewhere to take it. The table below shows who.
Your rights by region: CAN-SPAM vs GDPR#
Here is what each regime actually gives the person receiving the mail. The biggest practical difference is the last two rows — whether you can act against the sender yourself, and where a complaint goes.

| Your right as recipient | United States (CAN-SPAM) | EU / EEA (GDPR + ePrivacy) |
|---|---|---|
| Consent before the first email | Not required — it is an opt-out regime | Usually required — marketing needs consent or a narrow lawful basis |
| Sender must identify itself and give a postal address | Yes — required in every commercial message | Yes — and must identify the data controller behind it |
| Right to opt out or object | Yes — sender must honour it within 10 business days | Yes — you can object to direct marketing at any time (GDPR Art. 21) |
| Can you personally sue the sender? | No private right of action — the FTC, state attorneys general and ISPs enforce it | Yes — you can seek compensation in court and lodge a complaint (GDPR Art. 77) |
| Where to report it | The FTC and your state attorney general | Your national data protection authority (find it via the EDPB) |
How much trouble is the sender actually in?#
The penalties are real, but they are not something you collect. CAN-SPAM violations can draw steep civil penalties, and the FTC sets a per-email figure that it adjusts for inflation each year — so check the FTC's current amount rather than trusting an old number in a blog post.
Under GDPR the ceiling is far higher: fines can reach up to €20 million, or 4% of the company's total worldwide annual turnover, whichever is higher (GDPR Art. 83). Both are enforced by regulators, not paid to you — which is why the practical goal for a recipient is to make the mail stop, and report the sender who won't.
Penalty figures move — check the source
What to do when the opt-out doesn't work#
Sometimes the unsubscribe link is broken, ignored, or the mail simply keeps arriving under a new sender name. At that point you have three routes, and they stack.
- Report it to your mailbox provider. Gmail's "Report spam" and Outlook's "Junk" do more than move one message — they feed the provider's filters and count against the sender's reputation.
- File a complaint with the regulator. In the US that is the FTC; in the EU or UK it is your national data protection authority. Attach the saved email and your opt-out date.
- Filter it at your end. Regulators are slow and cross-border enforcement is hard. The reliable, same-day fix is to stop the mail reaching your inbox in the first place.
Don't unsubscribe from mail you don't recognise
A faster way: stop them reaching your inbox at all#
Unsubscribing works, but it is reactive. You handle one sender at a time, and a fresh company starts the cycle over. The reason a plain block doesn't hold is that a block matches a single address, while bulk senders rotate addresses inside one domain.
AI Emaily's cold-email filter matches on sender behaviour and domain rather than one address, so unsolicited outreach is set aside before it lands in your inbox — and a rotated address doesn't reset it. Nothing is deleted; the mail is filed where you can still find it, unsubscribe, or report it, so you keep every legal right above. We build AI Emaily.
Frequently asked
See it in AI Emaily
Keep reading
Sources
- FTC — CAN-SPAM Act: A Compliance Guide for Business
- 15 U.S.C. § 7704 — CAN-SPAM sender requirements
- 15 U.S.C. § 7706 — CAN-SPAM enforcement (no private right of action)
- GDPR Article 21 — Right to object to direct marketing
- GDPR Article 77 — Right to lodge a complaint with a supervisory authority
- GDPR Article 83 — Administrative fines
- European Data Protection Board — find your national authority

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.