Ask an outbound team whether their sending is compliant and you will usually get an answer about authentication records and unsubscribe links. Both of those are real requirements. Neither of them answers the question, because the question has two halves that people keep collapsing into one.
The first half is legal. It asks whether you are permitted to send an unsolicited commercial message to this person in this jurisdiction, and it is answered by statute. The second half is operational. It asks whether a mailbox provider will place your message in an inbox, and it is answered by policy that the provider writes and can change without notice. Cold email compliance means clearing both. Most programs we audit are clearing one and assuming it covers the other.
Two rulebooks, not one
The legal rulebook varies by the recipient's country and, in some cases, by whether the recipient is a company or a sole trader. It carries real penalties, enforced rarely but publicly. Its remedy when you get it wrong is a complaint, an investigation, or a fine.
The provider rulebook is written by Google, Microsoft and Yahoo, applies to their consumer mailboxes, triggers on volume rather than on geography, and carries no legal penalty at all. Its remedy when you get it wrong is that your mail stops arriving. That is a worse outcome for most outbound programs than any fine they will realistically face, which is why teams optimize for it and then assume the legal question is handled.
Two more framing notes before the table. Jurisdiction usually follows the recipient rather than the sender, so a United States company emailing a prospect in Toronto is operating under Canadian rules. And none of this is legal advice. It is the decision structure we use to scope a program and to know when a real lawyer needs to be in the room, which for most teams is at the point of entering a new market rather than at every campaign.
Cold email compliance by jurisdiction, in one table
| JURISDICTION | GOVERNING RULE | PRIOR CONSENT FOR B2B | ALWAYS REQUIRED | PENALTY CEILING |
|---|---|---|---|---|
| United States | CAN-SPAM Act | No | Accurate sender identity, honest subject line, physical postal address, working opt-out honored within 10 business days | Up to $53,088 per email |
| Canada | Anti-spam legislation, enforced by the CRTC | Yes, express or implied. A conspicuously published business address can supply implied consent when the message is relevant to the role | Sender identification, contact information, functional unsubscribe | Up to $1M individuals, $10M organizations, in Canadian dollars |
| European Union | Data protection law plus each member state's electronic communications rules | Varies by state. Several permit business contact outreach on a legitimate interest basis, others require prior consent | A documented lawful basis, identity disclosure, opt-out, and the ability to answer a data subject request | Up to 4% of global annual turnover at the highest tier |
| United Kingdom | Electronic communications regulations plus data protection law | No for corporate subscribers such as companies and limited liability partnerships. Yes for sole traders and unincorporated partnerships, who are treated as individuals | Identity disclosure, opt-out, lawful basis for the personal data | Data protection fines at the same top tier as the European Union |
| Australia | Spam Act 2003, enforced by the ACMA | Yes, express or inferred. A work address published without a no-unsolicited statement can supply inferred consent when the message relates to the role | Sender identification, accurate contact details, functional unsubscribe | Civil penalties per contravention, escalating with repetition |
| India | Digital Personal Data Protection Act 2023 | Yes, processing requires a lawful purpose and notice | Notice, purpose limitation, a route to withdraw | Penalties set per contravention under the Act |
Read down the consent column and the pattern is clear. The United States is the outlier that most outbound tooling was designed around, and the United Kingdom's corporate subscriber carve out is the other genuinely permissive position. Canada and Australia both allow a form of consent you do not have to collect, which is the detail teams miss most often, because the phrase implied consent sounds like a loophole and is in fact a specific, documented, and auditable condition.
That condition is worth stating carefully, because it is the difference between a defensible program and an indefensible one in two large markets. The address has to be published where you found it, published without any statement refusing unsolicited commercial messages, and your message has to be relevant to the role that address represents. Guidance on the Canadian version is published by the CRTC and the United Kingdom's business to business position is set out by the ICO. Both are short and worth reading in full once.
The word published is doing enormous work in that sentence. An address you inferred from a naming pattern was not published. An address a data vendor sold you may or may not have been published, and you cannot demonstrate which. That distinction is not academic once someone complains, and it is the reason we treat guessed addresses as a separate risk category entirely, which we set out in what a guessed address costs you under European rules.
Where the mailbox providers draw a different line
Now the other rulebook. Google, Yahoo and Microsoft each publish bulk sender requirements that bite at roughly 5,000 messages a day to their consumer mailboxes. They require authentication records, alignment, one click unsubscribe, and a spam complaint rate kept below a published ceiling. None of that is law. All of it is enforced far more aggressively than any statute in this article, because the enforcement is automatic and immediate.
The overlap between the two rulebooks is smaller than people assume. Authentication is not a legal requirement anywhere in the table above. A physical postal address is a legal requirement in the United States and is not something any provider checks. One click unsubscribe is a provider requirement whose legal cousin, a functional opt-out, is satisfied by a plain link. Teams that built their compliance checklist from provider documentation therefore have gaps in exactly the places the law cares about, and teams that built it from statute have gaps in exactly the places their delivery rate cares about.
| REQUIREMENT | SOURCE | TRIGGER | CONSEQUENCE OF FAILURE |
|---|---|---|---|
| Prior or implied consent | Statute, varies by country | Recipient location and entity type | Complaint, investigation, fine |
| Physical postal address in the message | Statute, United States | Any commercial message | Per message civil penalty |
| Opt-out honored within a set window | Statute, most jurisdictions | Any commercial message | Per message civil penalty |
| SPF, DKIM and DMARC alignment | Provider policy | Volume to consumer mailboxes | Filtering or rejection |
| One click unsubscribe header | Provider policy | Bulk sending | Filtering or rejection |
| Spam complaint rate under the published ceiling | Provider policy | All sending | Reputation damage, then filtering |
One nuance that saves a lot of wasted effort. The provider bulk thresholds are written against consumer mailboxes, and most business to business outbound is landing in corporate tenants rather than in personal accounts. That does not make the requirements optional, because filtering decisions still draw on the same reputation signals, but it does mean the specific 5,000 a day trigger is often not the constraint teams think it is. We took that argument apart separately in why the sending domain threshold most teams use is the wrong one.
Where teams actually get caught
In practice, enforcement and damage rarely come from the exotic edge of the rules. Four patterns account for nearly everything we see.
Notice that three of those four are record keeping failures rather than legal misunderstandings. That is the general shape of this problem at the scale most outbound teams operate. The rules are not especially hard. Proving after the fact that you followed them is hard, and it is only hard because nobody built the field that would have made it easy.
Running cold email compliance without a lawyer on retainer
Four controls. They are cheap, they are one time work with a quarterly review, and together they cover the realistic risk for a business to business program.
For most teams that is the whole program, and the residual risk left over is acceptable and understood. Bring in actual counsel for three situations: entering the European Union at volume, any consumer facing sending, and any market not in the table above. Those are the cases where the general shape stops being a reliable guide and the specifics start to matter more than the pattern.
It is worth saying plainly that compliance work of this kind has a return beyond risk. Provenance fields improve targeting. Regional segmentation improves relevance. A global suppression list stops the single most reliable way to annoy a prospect, which is emailing them again after they asked you not to. The credibility cost of getting this wrong is now higher than it used to be, because a prospect who is unsure about you increasingly checks in an answer engine rather than on your site, which we covered in what happens to sender credibility when buyers verify you in AI answers.
See where you are cited today
A free snapshot audit of your rankings and AI citations before we ever talk.
Tyler leads work at the intersection of SEO and generative engines at Something Inc., helping B2B brands get ranked and cited across every major AI engine.