CAN-SPAM Compliance Checklist for B2B Email Outreach to Attorneys
This article is a general summary of public CAN-SPAM Act requirements for informational purposes and is not legal advice. Consult a qualified attorney about your specific email marketing compliance obligations.
The CAN-SPAM Act is the primary US federal law governing commercial email, enforced by the FTC. It applies to any email whose primary purpose is commercial advertising — which includes most B2B outreach built on a purchased contact list. Here are its core requirements, in plain English.
1. Don't use false or misleading header information
Your "From," "To," and routing information — including the domain name and email address — must accurately identify who is sending the message. Don't spoof a different sender identity.
2. Don't use deceptive subject lines
The subject line must reflect the actual content of the message. "Re: your inquiry" as a cold-outreach subject line to someone who never inquired is the kind of thing that draws complaints and violates this requirement.
3. Identify the message as an advertisement
The law requires disclosure that the message is an advertisement, though it doesn't mandate specific wording. Many senders handle this with a brief line in the footer.
4. Include your physical postal address
Every commercial email must include a valid physical postal address — this can be your current street address, a registered post office box, or a commercial mail-receiving agency address.
5. Tell recipients how to opt out — and make it easy
You must provide a clear, conspicuous way to opt out of future emails. It can't require the recipient to pay a fee, provide more than an email address, or take any step beyond sending a reply or visiting a single web page.
6. Honor opt-out requests within 10 business days
Once someone opts out, you have 10 business days to stop emailing them, and you can't sell or transfer their email address to anyone else after that point (except to a service acting on your behalf to ensure compliance).
7. Monitor what others do on your behalf
If you hire another company to handle your email marketing, you're still legally responsible for compliance. Both the company whose product is advertised and the company that sends the message can be held liable.
What this means when you're emailing from a purchased database
- Use a real sending domain and identity — don't spoof.
- Write honest subject lines that describe your actual offer.
- Add a footer with a one-line ad disclosure, your postal address, and an unsubscribe link.
- Process opt-outs immediately, not just within the 10-day legal minimum.
- Keep your own suppression list so someone who opts out never ends up back on a future list.
None of this is unique to using a purchased database like the USA Lawyer Database — the same rules apply whether your list came from a purchase, a trade show, or your own CRM. Good compliance hygiene is also good deliverability hygiene: fewer spam complaints keeps your sending domain's reputation intact for every future campaign.
Ready to put this into practice? Get the complete USA Lawyer Database — 128,245 records, $399 one-time.
Get Instant Access — $399