Skip to main content
Deliverability toolRuns in your browserFree · No signup

Cold Email Compliance Checker

Pick where you send from and where your prospects sit, paste the email, and see which legal requirements it meets and which it misses. Free, instant, and nothing leaves your browser.

Your email and sender details

Checks update as you type. Nothing leaves your browser.

Where your business is established.

The law of the recipient's country applies too. Both sets of rules are checked.

This is a reply in an existing thread
0 words

Not legal advice

This checker applies published requirements of CAN-SPAM, GDPR/PECR, CASL and the Spam Act using text heuristics. It cannot see your data sources, consent records or national variations. Confirm your setup with counsel before scaling.

Compliance score

Paste an email to check it

You will get a 0–100 score, a checklist grouped by regulation, and a ready-to-paste compliant footer.

Nothing leaves your browserNo account or email requiredUnlimited use
How it works

How to use the Compliance Checker

  1. 01

    Set the regions

    Choose your business location and your recipients' region. The checker applies both sets of rules, since the recipient's law applies even when you are abroad.

  2. 02

    Paste the email and sender details

    Add your from name, from email, business name and postal address, then paste the subject and body including the signature.

  3. 03

    Fix and copy the footer

    Work through the failed and warned checks, then copy the generated footer with your address, data-source line and opt-out instruction.

What each cold email law actually requires

CAN-SPAM in the United States does not require permission to send. It requires that the message be honest and escapable: header information that accurately identifies the sender, a subject line that reflects the content, a valid physical postal address (a PO Box or registered agent address is acceptable), a clear way to opt out, and opt-outs honored within 10 business days. Each non-compliant email can draw a civil penalty of more than $50,000, and the company whose product is promoted is liable alongside whoever pressed send.

In the EU and UK, a named person's work email is personal data, so GDPR applies before any anti-spam rule does. B2B outreach usually relies on legitimate interest, which the regulation itself recognizes for direct marketing, but only if you document a balancing test, keep the message relevant to the person's role, tell them where you got their data (within one month or at first contact under Article 14), and stop when they object. UK PECR permits email to corporate subscribers; several EU states, Germany among them, require prior consent under national law even for B2B.

Canada's CASL is the strictest of the four. Consent is required, but it can be implied when the address was conspicuously published without a no-solicitation notice, or given to you directly, and the message relates to the recipient's business role. You must identify yourself, include a mailing address plus a phone number, email or web address, and process unsubscribes within 10 business days. The burden of proving consent sits with the sender. Australia's Spam Act works the same way: express or inferred consent, accurate sender identification with contact details, and a functional unsubscribe honored within 5 business days.

How the compliance score is calculated

The checker runs a fixed set of text heuristics against your email and the sender details you enter, then shows each check under every regulation that imposes it. Mandatory elements carry the most weight: an opt-out instruction, a postal address, accurate sender identification and an honest subject line are worth 3 points each. Deceptive claims, a business-owned from address and a clear commercial purpose are worth 2. The role-relevance sentence that supports legitimate interest, implied consent and inferred consent is worth 1. A pass earns full points, a warning earns half, a fail earns none, and the score is the percentage earned across the checks that apply to your selected regions.

  • Opt-out detection looks for unsubscribe, opt out, reply stop, remove me and similar phrasing anywhere in the body.
  • Postal address detection matches street numbers with a street word, PO Boxes, and US, UK, Canadian, Australian and continental European postcode patterns.
  • Subject checks fail on Re: or Fwd: prefixes when the email is not a reply, and on bait such as your invoice, action required or as discussed.
  • Deceptive claims cover guarantees, fake prior contact, prize framing and the phrase this is not spam.
  • Informational notes (consent records, opt-out deadlines) are shown but never scored, because no text check can verify them.

The compliant footer, line by line

A cold email footer only needs four lines. First, the sender: a real name and the legal or trading name of the business. Second, the postal address. Third, a data-source and relevance sentence such as "You are receiving this because your role looked relevant to what we do, I found your details on your company website." That single sentence satisfies the Article 14 transparency duty under GDPR and documents the basis for implied or inferred consent under CASL and the Spam Act. Fourth, the opt-out: a plain instruction to reply with a word like unsubscribe, and a promise to act within the legal window.

Reply-based opt-outs are valid under all four regimes as long as they work. CAN-SPAM allows any internet-based mechanism; CASL and the Spam Act require it to be functional and free to use. What is not acceptable is asking for a login, a form with more than an email address, or a mailbox nobody reads. ColdBox appends an opt-out line to every sequence email and turns any reply containing unsubscribe into a suppression entry automatically.

Compliance beyond the copy: suppression, records and secondary domains

Most enforcement actions are not about a missing footer, they are about opt-outs that were ignored. Keep one suppression list shared by every inbox, domain and tool you send from, and add every opt-out, bounce complaint and "not interested" reply to it within a day. If you run five secondary domains with three inboxes each, a person who opted out on one must never hear from the other fourteen mailboxes. The legal deadline is 10 business days in the US and Canada and 5 in Australia, but the practical standard is same day.

Keep records too. Under CASL you must be able to show where each address came from; under GDPR you need a written legitimate interest assessment and a record of the data source. A simple column in your lead sheet noting the source URL and the date is enough. Finally, secondary domains are fine under every regime as long as the header is honest: the domain must be one you control, replies must reach you, and the business name in the footer must be the one that actually benefits from the email. Using a lookalike domain to impersonate someone else's brand is the one thing that turns a deliverability trick into a legal problem.

FAQ

Compliance Checker questions

Straight answers, no fluff. Still stuck? Our deliverability team replies within a couple of hours.

Ask a human

Yes. CAN-SPAM permits unsolicited commercial email as long as the header and subject are accurate, the message includes a physical postal address, a working opt-out is provided, and opt-outs are honored within 10 business days. There is no requirement for prior consent, which is why the US is the easiest market for cold outreach.

It can be. GDPR requires a lawful basis for processing a person's work email, and legitimate interest is available for B2B direct marketing if you document a balancing test, keep the message relevant to the person's role, tell them where you got their data, and stop when they object. Some EU countries add a consent requirement under national law, so check the recipient's country.

Consent, identification and an unsubscribe. Implied consent covers a business address that is conspicuously published without a no-solicitation notice, provided the message relates to the person's role. Every message must name the sender, include a mailing address plus a phone number, email or website, and offer an unsubscribe that is processed within 10 business days.

Under CAN-SPAM and CASL, yes, in every message. A PO Box, a registered agent address or a private mailbox registered with a commercial receiving agency all count in the US. Under GDPR and the Spam Act the requirement is that the sender be identifiable with contact details, and a postal address is the simplest way to meet it.

Not unless the email is actually a reply. A fake Re: or Fwd: prefix misrepresents the message as part of an existing conversation, which is a deceptive subject line under CAN-SPAM and misleading content under CASL and the Spam Act. It also trains recipients to distrust you and tends to raise spam complaints, so it hurts on both fronts.

Yes, as long as it works. All four regimes accept any mechanism that lets the recipient opt out easily and free of charge, and a reply with a single word qualifies. The obligation is on you to read those replies and suppress the address within the legal window, and to apply that suppression across every inbox and domain you send from.

Neither. The analysis runs entirely in your browser and nothing is sent to a server. The checks reflect the published requirements of CAN-SPAM, GDPR/PECR, CASL and the Spam Act, but they are text heuristics, not a legal review. Confirm your data sources, consent basis and national variations with counsel before scaling a campaign.

Start Free Today

Compliant footers and suppression, handled on every send.

ColdBox adds the opt-out line, keeps one global suppression list across all your inboxes and domains, and authenticates every sending domain. Free 7-day trial, no credit card.

Free trialNo credit cardSetup in 5 minutes