Is cold email legal? A founder's answer
Yes, in most places, and the part that changes by country is not the part founders worry about. Whether you may send the first message varies a lot. What has to be inside that message barely varies at all: say who you are, truthfully, and carry a working way to stop it. Both are below, with the sources.
By Kshitij Maheshwari, co-founder · Updated August 2026 · 13 min read
What has to be in a cold email
Eight things go in the message. The middle column names where each one is a legal requirement rather than a nicety, so you can see which rows apply to the people you are writing to.
| What goes in the email | Where it is required by law | In practice |
|---|---|---|
| A truthful sender name, From and Reply-To | US, UK, EU, Canada | Every regime asks for it. Germany states it again in its own competition law. |
| A subject line that matches the message | US | Elsewhere this is a deliverability problem, not a legal one. |
| Wording that identifies it as an advertisement | US | Not a banner. The message just cannot pretend to be something else. |
| A valid physical postal address | US | A street address, a registered PO box or a commercial mailbox. |
| A working way to stop it, inside the message | US, UK, EU, Canada | A reply address counts in the US and Canada. Germany asks the same. In the UK it binds even for company addresses. |
| Where you got their address | EU and UK, on the first email | The row every other guide leaves out. One clause covers it. |
| That they can object, said plainly and on its own | EU and UK, on the first email | Not folded into a footer with four other links. |
| Contact details that still work after you send | Canada, 60 days. US, an opt-out live 30 days | It has to still reach you once the campaign is over. |
Sources, all as of August 2026: the FTC's CAN-SPAM compliance guide; the ePrivacy Directive, Article 13(4); the GDPR, Articles 14 and 21; the ICO's business-to-business marketing guidance and PECR regulation 22; Canada's anti-spam law, sections 6 and 11; and Germany's Act Against Unfair Competition, section 7. We are operators, not lawyers, and none of this is legal advice.
Two questions, not one
"Is it legal" is really two questions wearing one coat. Almost every guide answers the first and stops, which is why founders finish reading with a statute name and no next move.
Opt-in countries want permission before your first email. Opt-out countries let you send, then require you to stop the moment someone asks.
May you send it at all?
This is the one that moves. It turns on where the person sits, whether they are a company or a sole trader, and how the address reached you. Four answers cover most of it.
What has to be in it?
This one barely moves. Four separate laws, written on three continents, land on the same two mechanics: say who you are truthfully, and carry a working way to stop it.
Question one is a research task you do once per market. Question two is a writing task you do once, in a template, and then stop thinking about.
The permission question changes at every border. The contents question does not. Say who you are, truthfully, and give them a way to stop.
Where you need permission first, and where you do not
Read the row for where your recipient sits, not the row for where you sit. That is the single most common mistake in this category.
| Where the recipient is | Permission before the first email? | What that turns on |
|---|---|---|
| United States | No. | CAN-SPAM governs how you send, not whether you may start. The FTC's guide is explicit that the law makes no exception for business-to-business email. |
| United Kingdom | Not for companies. Yes for sole traders. | PECR regulation 22 covers individual subscribers. The ICO says the electronic mail rule does not reach corporate bodies. UK GDPR still applies to a named person's address. |
| European Union | Each member state decides. | ePrivacy Article 13(5) hands business subscribers to national law. Germany requires prior express consent for email, business or not. France allows business prospecting on legitimate interest, with a right to object. |
| Canada | Yes, and it can be implied. | Consent is implied where the person published the address, did not refuse unsolicited mail, and your message is relevant to their role. All three limbs, or none of it holds. (CASL section 10(9)(b)) |
For a file you bought rather than built, the question moves upstream to where the records came from. Our page on buying lead lists carries that country by country.
In Europe and the UK, the first email is a deadline
This is the obligation founders miss, and it does not live in a privacy policy somewhere. It lands on the first message you send, and it costs one clause.
The deadline is the first message
If you did not get the address from the person, you owe them an explanation, and the law fixes the moment: at the latest when you first contact them. In the EU and the UK, that is your cold email.
Who you are, and where you got it
Your name, why you are writing, what you are relying on to do it, and the source the address came from. A sentence like "I found you on your team page" does most of that work on its own.
The right to object, said separately
The same deadline applies to telling them they can object. The text asks for it clearly and separately, which rules out burying it in a footer alongside four other links.
The odd part is how ordinary that sounds once written down. The sentence that discharges a European duty is the same sentence that stops a cold email reading like a scrape.
What legitimate interest actually gets you
It is the phrase every vendor page reaches for, and it does less work than they suggest.
The wording is careful. Direct marketing may be regarded as a legitimate interest, in a passage that turns twice on whether the person would expect to hear from you. A door, not a pass.
France's regulator, the CNIL, attaches a test in June 2026 guidance that reads like copy advice: business prospecting can rest on legitimate interest where the subject relates to the person's job, its own example being software pitched to an IT director. So an off-target email is a worse email and a thinner basis at once.
A lawful basis says you may hold and use the address. Whether you may send the first email is a separate rulebook, written member state by member state. The test itself is set at sourcing time, and our guide to building a lead list runs it.
I used to treat targeting as a performance question and compliance as a checklist somewhere else. They are the same question. The off-target email is both the one that reads as spam and the one whose basis I would struggle to defend.
The opt-out, and the clock to use
When somebody asks to be left alone, stop that day. By hand if that is what it takes. It is correct in every country on this page, and the reputational cost never waited for a statute anyway.
You are two people and one file. Doing it the moment you read the reply costs a minute and removes the whole question, which is why the rule below is a floor rather than a target.
In the US the Federal Trade Commission gives you ten business days to honor an opt-out, and asks the mechanism to keep working for thirty days after you send.
In Canada the law asks for effect to be given without delay, with ten business days named only as the outer limit. In the EU and the UK, the right to object to direct marketing carries no grace period in the text at all.
The catch is that none of it arrives as a click. It arrives as a sentence in a reply, so nothing logs it and nothing suppresses anybody on its own.
One list, at domain level, updated the same day, owned by a named person. Our guide to reply management runs that as an operation.
- !The person, not only the sequence they replied to
- !The domain, when the reply speaks for the company
- !An EU or UK objection, which has no expiry to wait out
- !The next list refresh, which will add them back
Want outbound that reads as one-to-one and still clears the rules?
Book a Fit CheckPublic is not the same as permitted, except where it is
Finding an address on a company website answers where it came from. It does not answer whether you may use it, and two regulators give opposite answers.
"It is on their website, so it is fair game."
- ✕Reads publication as agreement to be marketed to
- ✕Assumes the person chose to publish it themselves
- ✕Leaves the responsibility with whoever posted it
"You cannot assume that simply because an individual's personal data is in the public domain they are agreeing to it being used for direct marketing purposes."
- ✓Use it for your own purposes and you become the controller
- ✓You still need a basis and you still say where you got it
- ✓Workable in a business context, and never automatic
India answers the same question the other way. Its 2023 data protection act does not apply to personal data the person made public themselves, and it carries a worked illustration about someone publishing their own details on social media.
Timing matters there. The rules that operationalize it were notified in November 2025 with an eighteen-month phased compliance period, so the deadline lands in 2027 rather than today.
The realistic risk is the mailbox, not the regulator
One number gets quoted at founders here. The tens-of-millions figures beside it come from Europe's top fine band for the gravest breaches, not from a cold email.
In the US, the Federal Trade Commission's guide sets penalties of up to $53,088 for each email in violation, current as of August 2026 and re-adjusted for inflation most Januarys. "Up to" is a ceiling, and the FTC describes the provision behind it as covering knowing violations.
What actually costs a small sender is quieter. Complaints accumulate, the mailbox providers notice, and mail from your domain stops arriving. Google and Yahoo publish those thresholds, and our page on the sender requirements carries them.
Compliance does not scale with volume. Every rule on this page binds at forty emails a day exactly as it binds at forty thousand. What scales is the chance somebody minds, and that gets settled in the inbox rather than by a regulator.
Write the compliant version, not the cautious one
The lines the law wants at the end of a cold email are the same lines that stop it reading like a blast. Founders reach for a footer instead, and the footer does neither job.
Bolt on a mailing-list footer
You are receiving this because you opted in to communications from Acme. Unsubscribe | Manage preferences | Privacy | Acme Ltd, Reg. 09283746
- ✕Claims an opt-in that never happened
- ✕Looks like every newsletter in the inbox
- ✕Buries the stop line among three other links
Say it in your own voice
I found you on Acme's engineering page. If this is not for you, reply "no thanks" and I will not write again. Kshitij, Real Good GTM, 6 Rue Anatole, 92400 Courbevoie
- ✓Names where the address came from
- ✓Offers a stop that takes one word to use
- ✓Carries the postal address without a footer
Two plain sentences do both jobs better than a footer does either. Writing into the US, the message also has to read as what it is, which an honest opening line already handles.
Running this as a two-person team
None of this needs a compliance function. It needs four things written down once, and one person who owns them.
Before the next send
4 checks
-
The stop line is in every template
In the last two sentences, in the sender's own words, not in a footer.
-
One suppression list, at domain level
One file, one owner, updated the same day a reply lands.
-
Every row says where it came from
A source column, so the first-email clause writes itself.
-
The recipient's country is on the row
It decides which rules you are under, and it is not where you sit.
- 1 The contents rules barely move. Learn those once.
- 2 Permission changes at the border. Check the recipient's country.
- 3 A role address like info@ is a simpler object than a named one.
- 4 Stop the day they ask. Nowhere asks for less.
The teams that get this wrong are never the careless ones. They are the ones with three tools, two inboxes and a suppression list that lives in whoever happened to read the reply that morning.
If the suppression file is the part that keeps slipping, that is the job our reply automation add-on does.
Five ways founders get this wrong
Four of these cost you a little. The fifth is the one worth writing on a wall.
It governs the personal data. Whether you may send an unsolicited message sits in a separate European directive that each member state implemented itself.
The US asks for no permission and Canada does. A list that puts them in the same column has told you nothing you can act on.
Ten business days was written for a company processing thousands through a system. You saw the reply. The person who asked is counting in hours.
Use the data for your own purposes and the responsibility is yours. A supplier's assurance does not travel with the file.
"We are GDPR compliant" does not cover Europe
Germany treats advertising by email without prior express consent as an unacceptable nuisance, and its email rule draws no line between a consumer and another business. Same continent, opposite answer, because Europe handed this question to each member state.
Questions founders ask
Is cold email legal?
Does the GDPR ban cold email?
Does CAN-SPAM apply to B2B email?
Do I need consent to cold email someone in the EU?
Can I email a company in the UK without permission?
How fast do I have to honor an unsubscribe?
What is the fine for cold email?
Co-founder of Real Good GTM. He has been the first business hire and Chief of Staff at seed-stage B2B startups, building outbound pipeline before any playbook existed. This post comes from reading the statutes and the regulators' own guidance instead of the vendor blogs about them, and from writing the last two lines of a cold email often enough to know they do two jobs.
Connect on LinkedInThe three pages this one hands off to
The judgment call the rules do not make for you, the inbox routine behind the opt-out, and the mailbox machinery this page calls the real risk.
Personalization without being creepy
Legal and comfortable are different tests. The hard cases sorted, with the reason behind each one.
Read the postReply management
Triage, the suppression file, and the four decisions that turn a busy inbox into meetings.
Read the guideCold email deliverability
The machinery that decides whether your mail arrives at all, which is the risk that actually bites.
Read the guideWant outbound that clears the rules and still gets replies?
Book a fit check. We'll look at where your buyers actually sit, what the first email has to carry for them, and tell you straight if outbound is not the right motion for you yet.
Book a Fit CheckNo hard sell. No fake numbers. Real good work speaks for itself.