Guide

CAN-SPAM Rules for Real Estate Email Marketing in the United States

By Marc M, CEO · Updated

The US CAN-SPAM Act governs any commercial email connected to the United States, and it starts from a different place than Canada's law does: it doesn't require permission before your first message, only honest identification and a real way to opt out. This guide walks through what CAN-SPAM actually regulates, including the business-to-business email many senders wrongly assume is exempt, what every message needs regardless of whether the recipient consented, and what actually gets senders in trouble in practice. It also covers the trap that catches realtors working both sides of the border: a Canadian recipient brings Canada's stricter opt-in law into play regardless of where the sender is, so being CAN-SPAM compliant is not the same as being compliant for that part of a list.

What CAN-SPAM actually covers

The CAN-SPAM Act has governed commercial email in the United States since 2004, enforced primarily by the FTC. It regulates any message whose primary purpose is advertising or promoting a product or service, with a connection to the United States, most commonly, sent to someone here. That covers ordinary marketing blasts outright, and it also covers a short, personal-sounding note to a single real estate agent about a single listing, if promoting that listing is a purpose of sending it.

The line that trips people up is the assumption that business-to-business email doesn't count. It does. CAN-SPAM makes no carve-out for messages between two companies, or between two licensed professionals in the same industry. A listing email from one agent to another is a commercial message under the Act the same way a mailer to a homeowner is, because the test is the purpose of the message, not who happens to be on the receiving end.

What sits outside the Act's marketing rules is narrower than people expect: transactional and relationship messages, things like a receipt, a delivery notification, or an account update, get their own lighter treatment because their primary purpose isn't commercial. A listing notice sent to generate interest in a property doesn't fit that category. It's built to promote something, which is exactly what CAN-SPAM is written to reach.

An opt-out regime, not an opt-in regime

This is the structural fact that trips up realtors who've read about Canada's law and assume the same rule applies at home. CAN-SPAM does not require someone to opt in before you send them a first commercial email. You generally don't need the recipient's prior consent to send that first message, which is a different starting point than an opt-in law like Canada's, not just a looser version of the same one.

Opt-out does not mean no rules attach. Every commercial message, consented to or not, still has to meet every requirement CAN-SPAM sets out: honest headers, a subject line that doesn't mislead, a real postal address, and a working way to stop future messages. The absence of a consent requirement covers whether you can send the first email, not what that email has to contain or how you have to behave afterward.

The moment someone opts out, the calculation flips. Continuing to email them after a valid opt-out request is the violation, not the original unsolicited message. That's the trade CAN-SPAM makes: permission is assumed until it's withdrawn, and withdrawing it has to be fast, free, and honored without exception.

What every message must include

Every commercial email connected to the United States needs to clear the same short list of requirements, whether the recipient has any relationship with you or not. None of these are optional add-ons; each one is a separate basis the FTC can act on if it's missing.

The identification requirement is the one senders most often skip, mostly because it feels unnecessary for a message that's obviously a listing notice. The rule doesn't ask whether the content is self-evidently commercial, it asks whether the message discloses that plainly, and skipping that disclosure on a cold, unconsented message is a real gap even when the listing itself is the whole point of the email.

The opt-out requirement carries the most operational weight day to day. It has to keep working for at least 30 days after the message goes out, it can't route someone through multiple steps or a login screen, and once a request comes in, the clock on honoring it starts immediately, not when it's convenient to process a batch.

  • Accurate header information: the From, To, and routing data have to identify who actually sent the message, not a disguised or spoofed address
  • A subject line that doesn't misrepresent the content: it can be direct about a listing, it just can't promise something the email doesn't deliver
  • Clear identification that the message is an advertisement, unless the recipient has already given affirmative consent to receive it
  • A valid physical postal address for the sender, not a stripped-down signature or a generic contact page
  • A working opt-out mechanism the recipient can use without creating an account, paying a fee, or doing anything beyond replying or clicking through
  • Processing of opt-out requests within 10 business days, with no exceptions carved out for a busy week

What actually gets senders in trouble

Enforcement rarely comes from the bare fact that someone sent an unsolicited business email. It comes from the pattern around it: how the address was obtained, whether the message was honest about what it was, and whether the sender actually stopped when asked to.

The Act also gives the FTC authority to pursue civil penalties calculated per email, not per campaign, which is one reason a large, sloppy list carries more risk than a small, clean one. A single misleading subject line sent to one agent is a mistake to fix. The same subject line sent across a purchased list of thousands is a different category of problem entirely.

  • A subject line built to get the email opened rather than to describe what's actually inside
  • A list built from harvested addresses, whether scraped from websites or guessed using common name patterns, both of which the Act treats as an aggravated violation, not just a data-quality problem
  • Opt-out requests that get ignored, delayed past the 10-business-day window, or routed through extra steps designed to discourage the click
  • No real postal address on the message, or one that turns out not to be a working address at all
  • Header or sender information that obscures who's actually behind the message

The cross-border trap for a mixed list

CAN-SPAM's opt-out default only describes what US law expects. It says nothing about what happens the moment a recipient is in Canada, and that's the gap that catches realtors who work both sides of the border with one list and one set of habits.

Canada's law, CASL, applies whenever a message has a connection to Canada, sent from a computer there, sent to one, or accessed through one, regardless of where the sender's own business is registered. That means a Canadian agent on your list is governed by CASL's stricter opt-in standard even if you're sending from a US brokerage and every other recipient on the list is in the US. Being CAN-SPAM compliant covers the US portion of that list. It does not cover the Canadian portion.

In practice, this means treating the two as separate compliance problems rather than one blended list. A US recipient can generally receive a first cold message under CAN-SPAM's rules. A Canadian recipient needs a consent basis first, most often implied consent through conspicuous publication of a professional address, the same standard covered in the CASL guide. Sorting a list by where the recipient actually is, not just where your own business operates, is the step that keeps a cross-border campaign from quietly breaking the stricter of the two laws.

How Sendehm is built around this

Every campaign sent through Sendehm carries the realtor's own identity as the sender and a working opt-out link, on every message, in both countries, regardless of which consent basis would apply to a given recipient. That isn't a setting to remember to turn on.

The audience for a US campaign is licensed, verified real estate agents whose professional contact information is tied to their business role, and the message itself is a listing notice, the kind of content that's relevant to another agent's work regardless of which side of the border they're on. Anyone who opts out or bounces is suppressed from future sends automatically, not just excluded from the one campaign they responded to.

None of this replaces judgment on your side. The platform keeps the structural requirements, identification, a real opt-out, a verified and business-relevant audience, in place on every send, but whether a given campaign's content stays honestly about the listing is still a decision you make when you write it.

This is general information, not legal advice

Everything above describes CAN-SPAM's structure as generally understood and publicly documented by the FTC. It isn't legal advice, and it isn't a substitute for reviewing your own specific situation, especially a cross-border list, an unusual sending arrangement, or anything connected to an active complaint, with an attorney familiar with CAN-SPAM or with the FTC's own published guidance directly.

CAN-SPAM is primarily an FTC matter. Internet service providers and other regulators also have standing to act under the Act in certain circumstances. Enforcement has consistently focused on the pattern behind a message, deceptive practices, harvested lists, ignored opt-outs, rather than the bare fact that a cold commercial email was sent, so a message that's honest about who sent it and easy to opt out of starts from a fundamentally different position than one that isn't.

Common questions

Can real estate agents send cold email to other agents under CAN-SPAM?
Yes. CAN-SPAM doesn't require the recipient's consent before a first commercial email, so a cold listing notice to another agent is allowed on its own. What the law requires instead is that the message be honest about who sent it, identify itself as an advertisement when required, include a real postal address, and give the recipient a working way to opt out that gets honored within 10 business days.
Does CAN-SPAM apply to business-to-business email, or just consumer marketing?
It applies to both. CAN-SPAM makes no exception for messages between two businesses or two licensed professionals in the same industry. The test is whether promoting something is a purpose of the message, not whether the recipient happens to be a consumer or another business, so a listing email from one agent to another is commercial email under the Act the same way a mailer to a homeowner would be.
How fast do I have to process an opt-out request under CAN-SPAM?
Within 10 business days of receiving it, with no fee, no login, and no step required beyond what it took to reply or click through. The opt-out mechanism itself also has to keep working for at least 30 days after the message was sent, so a link that dies right after send doesn't meet the standard.
If my emails are CAN-SPAM compliant, does that cover recipients in Canada too?
No. CASL applies whenever a message is sent to, sent from, or accessed through a computer in Canada, regardless of where the sender's business is based, and it generally requires consent before that first message goes out. A list that mixes US and Canadian agents needs to meet CAN-SPAM's opt-out standard for the US recipients and CASL's stricter opt-in standard for the Canadian ones. Meeting one doesn't automatically satisfy the other.

See the verified agent count for your city, sent under your own identity with a working opt-out built into every message.

About the author. Marc is the CEO of Sendehm, where he builds the email platform realtors use to put their listings in front of verified agents across Canada and the US.

Keep reading