CAN-SPAM (Controlling the Assault of Non-Solicited Pornography And Marketing Act) has governed commercial email in the United States since 2003. Unlike GDPR, CAN-SPAM does not require prior consent to send marketing emails. Instead, it sets rules about how commercial emails must be constructed and provides recipients the right to opt out.
The core requirements include: do not use false or misleading header information (your From, To, and Reply-To must be accurate), do not use deceptive subject lines, identify the message as an advertisement, include your valid physical mailing address, provide a clear opt-out mechanism, honor opt-out requests within 10 business days, and do not sell or transfer email addresses of people who have opted out.
Marketing automation platforms can help add a postal address and unsubscribe link and suppress contacts who opt out. Those controls still need to be configured and tested. The sender remains responsible for accurate header information, truthful subject lines, a working opt-out process, and the actions of vendors sending email on its behalf.
A practical audit should verify the postal address, sender identity, subject line, unsubscribe link, and suppression behavior for every sending system. It should also confirm that opt-out requests from other channels reach the same suppression process.
GDPR consent practices do not establish CAN-SPAM compliance by themselves. CAN-SPAM separately regulates header information, subject lines, postal-address disclosure, opt-out notices, and how quickly opt-out requests are honored. The FTC's CAN-SPAM compliance guide is the primary source for the current requirements and penalty.