What each cold email law actually requires
CAN-SPAM in the United States does not require permission to send. It requires that the message be honest and escapable: header information that accurately identifies the sender, a subject line that reflects the content, a valid physical postal address (a PO Box or registered agent address is acceptable), a clear way to opt out, and opt-outs honored within 10 business days. Each non-compliant email can draw a civil penalty of more than $50,000, and the company whose product is promoted is liable alongside whoever pressed send.
In the EU and UK, a named person's work email is personal data, so GDPR applies before any anti-spam rule does. B2B outreach usually relies on legitimate interest, which the regulation itself recognizes for direct marketing, but only if you document a balancing test, keep the message relevant to the person's role, tell them where you got their data (within one month or at first contact under Article 14), and stop when they object. UK PECR permits email to corporate subscribers; several EU states, Germany among them, require prior consent under national law even for B2B.
Canada's CASL is the strictest of the four. Consent is required, but it can be implied when the address was conspicuously published without a no-solicitation notice, or given to you directly, and the message relates to the recipient's business role. You must identify yourself, include a mailing address plus a phone number, email or web address, and process unsubscribes within 10 business days. The burden of proving consent sits with the sender. Australia's Spam Act works the same way: express or inferred consent, accurate sender identification with contact details, and a functional unsubscribe honored within 5 business days.
How the compliance score is calculated
The checker runs a fixed set of text heuristics against your email and the sender details you enter, then shows each check under every regulation that imposes it. Mandatory elements carry the most weight: an opt-out instruction, a postal address, accurate sender identification and an honest subject line are worth 3 points each. Deceptive claims, a business-owned from address and a clear commercial purpose are worth 2. The role-relevance sentence that supports legitimate interest, implied consent and inferred consent is worth 1. A pass earns full points, a warning earns half, a fail earns none, and the score is the percentage earned across the checks that apply to your selected regions.
- Opt-out detection looks for unsubscribe, opt out, reply stop, remove me and similar phrasing anywhere in the body.
- Postal address detection matches street numbers with a street word, PO Boxes, and US, UK, Canadian, Australian and continental European postcode patterns.
- Subject checks fail on Re: or Fwd: prefixes when the email is not a reply, and on bait such as your invoice, action required or as discussed.
- Deceptive claims cover guarantees, fake prior contact, prize framing and the phrase this is not spam.
- Informational notes (consent records, opt-out deadlines) are shown but never scored, because no text check can verify them.
The compliant footer, line by line
A cold email footer only needs four lines. First, the sender: a real name and the legal or trading name of the business. Second, the postal address. Third, a data-source and relevance sentence such as "You are receiving this because your role looked relevant to what we do, I found your details on your company website." That single sentence satisfies the Article 14 transparency duty under GDPR and documents the basis for implied or inferred consent under CASL and the Spam Act. Fourth, the opt-out: a plain instruction to reply with a word like unsubscribe, and a promise to act within the legal window.
Reply-based opt-outs are valid under all four regimes as long as they work. CAN-SPAM allows any internet-based mechanism; CASL and the Spam Act require it to be functional and free to use. What is not acceptable is asking for a login, a form with more than an email address, or a mailbox nobody reads. ColdBox appends an opt-out line to every sequence email and turns any reply containing unsubscribe into a suppression entry automatically.
Compliance beyond the copy: suppression, records and secondary domains
Most enforcement actions are not about a missing footer, they are about opt-outs that were ignored. Keep one suppression list shared by every inbox, domain and tool you send from, and add every opt-out, bounce complaint and "not interested" reply to it within a day. If you run five secondary domains with three inboxes each, a person who opted out on one must never hear from the other fourteen mailboxes. The legal deadline is 10 business days in the US and Canada and 5 in Australia, but the practical standard is same day.
Keep records too. Under CASL you must be able to show where each address came from; under GDPR you need a written legitimate interest assessment and a record of the data source. A simple column in your lead sheet noting the source URL and the date is enough. Finally, secondary domains are fine under every regime as long as the header is honest: the domain must be one you control, replies must reach you, and the business name in the footer must be the one that actually benefits from the email. Using a lookalike domain to impersonate someone else's brand is the one thing that turns a deliverability trick into a legal problem.