Table of Contents
"Her Contact record has HasOptedOutOfEmail unchecked, so she stays on the send list," your marketing ops lead says.

"Then why did she file a GDPR complaint yesterday saying she opted out in April?" the compliance lead replies.
That exchange is what email marketing compliance looks like when it breaks. A form-to-CRM sync failed weeks ago. Every campaign since has shipped to people who unsubscribed, and every dashboard logged those sends as a success. Salesforce fires no warning. The CAN-SPAM Act, the GDPR, and CASL do not care that your intent was clean. Before your next send, know which laws apply, what each demands, and where records fall short. This guide covers the laws that govern email marketing in 2026, what counts as valid consent, what every message must include, and how to prove compliance at the record level.
What is email marketing compliance?
Email marketing compliance is the per-send obligation to prove valid consent, identify yourself correctly, and honor every opt-out under whichever laws govern your recipients. That definition is straightforward. Applying it inside a CRM, where consent flows in from web forms, integrations, and imports, is where most compliance actually breaks.
Four requirements sit under every major email law:
- Consent: proof the recipient actively agreed to receive commercial email from you, with a timestamp and a source.
- Sender identification: your legal business name, a valid postal address, and headers that trace back to you.
- Opt-out mechanism: a working unsubscribe link, honored within 10 business days under CAN-SPAM and without undue delay under GDPR.
- Data rights: on request, the ability to show what personal data you hold on a recipient, delete it, and log the change.
The technical requirements are the easy half. Proving them at audit is the hard half. One dropped opt-out from a broken form-to-CRM sync turns a lawful campaign into a documented violation. So does a stale segment or a workflow that ignores HasOptedOutOfEmail. Compliance lives in your records. Whatever they show on the day a regulator, a lawyer, or a complaint arrives is what counts.
Which laws govern email marketing compliance?
Four laws set the rules for email marketing compliance: CAN-SPAM in the United States, GDPR in the European Union, CASL in Canada, and CCPA and CPRA in California. The applicable law follows the recipient. A US-based Salesforce org sending to a European contact list falls under all four at once.
| Law | Jurisdiction | Consent standard | Maximum penalty |
|---|---|---|---|
| CAN-SPAM | United States | Opt-out; no prior consent required | $53,088 per email (FTC, 2024) |
| GDPR | European Union and EEA | Express opt-in: freely given, specific, informed, unambiguous | €20M or 4% of global annual turnover |
| CASL | Canada | Express or documented implied consent | CAD $10M per violation for organizations |
| CCPA and CPRA | California residents | Opt-out for sale or sharing; opt-in for minors under 16 | $7,500 per intentional violation |
CAN-SPAM Act
The CAN-SPAM Act does not require prior consent to send commercial email in the US. Every message must identify the sender, carry a truthful subject line, list a valid postal address, and offer a working opt-out honored within 10 business days. In January 2024, the FTC raised the maximum civil penalty to$53,088 per non-compliant email under 16 CFR 316.5. A single non-compliant broadcast to 5,000 contacts carries $265 million in maximum theoretical exposure.
GDPR
The GDPR applies whenever an EU or EEA resident receives your email, regardless of where your servers sit. Consent must be freely given, specific, informed, and unambiguous underArticle 7 of the GDPR, and you must be able to prove it on demand. Withdrawal has to be as easy as consent, and honored without undue delay. Enforcement has stepped up in the last two years. The Irish Data Protection Commission fined LinkedIn€310 million in October 2024 for consent failures in behavioral advertising, and the Dutch DPA fined Uber€290 million in August 2024 for unlawful cross-border data transfers.
CASL
Canada's Anti-Spam Legislation requires express or documented implied consent before you send a commercial electronic message to a Canadian address. Implied consent is narrow: it covers a two-year window after an existing business relationship or six months after an inquiry, and both windows are strictly enforceable. Every message must identify the sender and include a working unsubscribe honored within 10 business days. Maximum administrative monetary penalties reach CAD $10 million per violation for organizations underCRTC enforcement.
CCPA and CPRA
California's Consumer Privacy Act and its 2023 expansion, the California Privacy Rights Act, grant California residents the right to know what personal data you hold, delete it, correct it, and opt out of its sale or sharing. Commercial email that uses purchased or shared contact data triggers the sale-and-sharing rules. Civil penalties reach $2,500 per unintentional violation and $7,500 per intentional violation or one involving a minor, perCal. Civ. Code §1798.155. The California Privacy Protection Agency has been the enforcement body since 2023.
What counts as valid email opt-in consent?
Valid email opt-in consent is a recipient's active, provable agreement to receive commercial email from you, captured with a timestamp, a source URL, and enough detail to reproduce what they saw when they said yes. Silence, a pre-ticked box, or a purchase that did not include an email subscription option all fail the test.
Two consent standards apply, depending on the recipient's jurisdiction:
- Express opt-in (required under GDPR and CASL, best practice under CAN-SPAM): the recipient took a deliberate action, such as ticking an unchecked box or entering an email on a form specifically labeled for marketing.
- Implied consent (allowed only under CASL within strict windows): a two-year window after an existing business relationship, or a six-month window after a direct inquiry.
Double opt-in adds a verification email that the recipient must click before joining your list. No law requires it, but it produces the cleanest audit trail and filters typos and bot signups before they reach your CRM.
Consent you cannot reproduce is not consent. At audit, a compliant record needs four things: the exact form or page URL where consent was captured, and the UTC timestamp of the submission. It also needs the IP address (required for GDPR audit trails underArticle 30) and the exact wording the recipient saw at the moment of the click.
Store these on the Contact or Lead record itself, in dedicated custom fields, so a data subject request can be answered from one record instead of a spreadsheet reconstruction.
What must every marketing email include?
Every commercial marketing email needs the same core elements no matter which law applies. Miss any one, and the same message can violate multiple laws at once.
- Sender identification: an accurate From line and a Reply-To address that reaches you
- Physical postal address: a real street address, a USPS-registered P.O. box, or a private mailbox at a Commercial Mail Receiving Agency
- Truthful subject line: an accurate description of what the message contains
- Advertising disclosure: a clear signal that the message is commercial, placed anywhere in the message the reader will see
- Working unsubscribe mechanism: honored within 10 business days under CAN-SPAM and without undue delay under GDPR and CASL
Two of these deserve a closer look, because they are where most senders slip. On subject lines, CAN-SPAM bans anything that materially misleads the recipient about what is inside. A promotional email disguised as an internal notice or an order confirmation is a per-message violation, even if every other element is correct.
The unsubscribe mechanism is the second common failure point. Under CAN-SPAM (16 CFR §316.5), it must stay functional for at least 30 days after the send date, and it cannot require the recipient to log in, pay, or provide anything beyond an email address.
In Salesforce, the HasOptedOutOfEmail field on the Contact record stops list emails and mass emails to that person. Manual emails from the Activity panel ignore it. Workflow-triggered email alerts ignore it too. That is where quiet violations start.
The 2024 Google and Yahoo bulk sender rules
SinceFebruary 2024, Gmail and Yahoo require three things from senders shipping more than 5,000 messages per day. The first is SPF and DKIM authentication with a DMARC policy set to at least p=none.
The second is a working one-click unsubscribe header, perRFC 8058. The third is a spam complaint rate kept under 0.3%. Non-compliance triggers throttling first, then hard rejection. These rules come from the mailbox providers themselves. Ignore them, and your sends stop reaching Gmail and Yahoo entirely.
What are the penalties for email marketing non-compliance?
Penalties for email marketing non-compliance land in two layers: the statutory fine, and the operational fallout from a regulator action or a mailbox-provider block. The second layer usually costs more, and it hits first.
Enforcement is not theoretical. In February 2024, DoorDash paid a$375,000 CCPA settlement to California's Attorney General for selling personal data without notice or opt-out. The UK's ICO fined HelloFresh£140,000 in December 2023 for 79 million unsolicited emails and 1 million spam texts over seven months. Both cases began with a single consumer complaint. That is how enforcement usually starts.
The operational layer arrives faster than any legal notice. A spike in complaint rate past Gmail's 0.3% threshold triggers throttling within days. ESPs suspend or terminate accounts carrying sustained complaint rates or attached legal notices. Rebuilding a sender reputation after either takes months of low-volume warmup, during which your campaign schedule stops.
One non-compliant campaign carries three costs: a per-email fine, a reputational block that halts sends, and a warmup period worth weeks of revenue. A working consent record, an honored unsubscribe, and a valid postal address prevent all three.
What is the email marketing compliance checklist?
The email marketing compliance checklist is the set of nine checks that verify a single send meets CAN-SPAM, GDPR, CASL, CCPA, and 2024 mailbox-provider rules before it ships. Run it against the current campaign, not the template, since consent state and suppression lists change between sends.
- Every recipient has a documented, timestamped opt-in on their Contact or Lead record, with source URL and IP captured
- HasOptedOutOfEmail is respected on the send path, including list email, mass email, workflow email alerts, and manual Activity-panel sends
- Suppression list is synced with the latest form and preference-center changes from the last 24 hours
- From line, Reply-To, and a valid physical postal address are present and accurate in the message body
- Subject line describes the actual content, with no deceptive or misleading claims
- Commercial nature of the message is clear from the subject, the sender line, or a disclosure at the top of the body
- Unsubscribe link works, requires no login or fee, and includes a one-click List-Unsubscribe header for bulk sends
- SPF, DKIM, and DMARC (p=none or stricter) are passing for the sending domain
- Spam complaint rate over the trailing 30 days is under 0.3%
If any item fails, hold the send. A single non-compliant campaign risks per-email fines, ESP suspension, and weeks of sender reputation warmup. The 15 minutes to run the checklist prevents all three.
How do you prove email compliance from your CRM?
Proving email compliance from your CRM comes down to one question: can a single Contact or Lead record show, on demand, what consent that person gave, when they gave it, and what has changed since? Dashboards, reports, and ESP logs are all downstream of that answer.
What Salesforce tracks out of the box
Salesforce ships with three fields relevant to email compliance out of the box:
- HasOptedOutOfEmail on the Contact or Lead record: a Boolean that blocks list emails and mass emails.
- EmailBouncedReason and EmailBouncedDate: populated automatically when a hard bounce is returned.
- Suppression lists at the Organization-Wide Email Address level: apply globally but do not attach to the individual record.
That is where the standard setup stops. Nothing in the box captures the consent event itself. No native field records the form URL, the timestamp, the IP address, or the exact wording of the consent text. No native field logs when a data subject request was received or fulfilled. Answering an audit means reconstructing that history from form-platform exports, marketing automation logs, and ticket systems, and hoping the timestamps line up.
What the record needs to prove at audit
The record has to carry the proof itself. That means custom fields on Contact and Lead for the consent form URL, the UTC timestamp of opt-in, the source IP, the exact consent copy, and separate date fields for any opt-out or deletion request. A workflow or Flow updates these fields on every consent-relevant event, so the record's history is the audit trail.
The send layer has to respect that same record.MassMailer is a Salesforce-native email sending tool built directly on Contact and Lead records. It honors HasOptedOutOfEmail on every send type, including the paths where the built-in tools quietly ignore it.
MassMailer reads the current Contact or Lead record at each send, so any custom consent fields you add reflect their live values. A contact who unsubscribes this morning does not receive today's afternoon campaign.
Keener Financial Planning applied the same approach to a different regulator. Under SEC rules, the firm must distribute policy documents to every client account at least once a year and archive them. After switching from Redtail CRM to Salesforce in 2017, Keener adopted MassMailer to send those documents and archive them directly on the client's Salesforce record. The archive lives with the account, so a compliance auditor sees the send, the recipient, and the timestamp from one place. Email marketing audits work the same way, on a different rule set.
Build email marketing compliance into your CRM records
Compliance breaks quietly, and it breaks at the record layer. Keeping it whole means moving the proof of consent, opt-out, and audit history onto the Contact and Lead records themselves. It also means sending from a tool that respects that record on every send. That is what MassMailer does inside Salesforce, and it is why Keener meets SEC compliance from one archive on one record.
See it work on your own contacts. Book a MassMailer demo and walk through a real GDPR-style deletion request on your Salesforce data: one contact, full consent history, deletion flow triggered, audit trail intact, all from one record view.
Frequently Asked Questions
1. Are cold emails legal under email marketing laws?
2. Does CAN-SPAM apply to B2B email marketing?
3. Do transactional emails have to comply with CAN-SPAM and GDPR?
4. How long should you keep email consent records?
5. What is legitimate interest under GDPR for email marketing?
6. Do you need a privacy policy for email marketing?
Related Blogs
Email Deliverability Best Practices to Reach the Inbox
Best Time to Send Marketing Emails (2026 Data)
Email Scoring: The Formula Most Guides Leave Out
MassMailer Resources