CAN-SPAM Opt-Out Requirements: The Mechanism, the Ten-Day Clock and the Suppression List
Key Takeaways
- 15 U.S.C. 7704(a)(3) requires an internet-based opt-out channel in every commercial email that keeps accepting requests for at least 30 days after that message is sent
- Sending within the scope of a request is unlawful more than 10 business days after it is received; the FTC proposed cutting that to three business days and declined to in 2008, and declined again in 2019
- 16 CFR 316.5 bars fees, requests for information beyond an email address and opt-out preferences, and any step beyond a reply email or a visit to a single web page
- Once a request is made, the address may not be sold, leased, exchanged or otherwise transferred except for compliance, and the FTC has refused to set an expiry date on opt-outs
- The FTC's 2024 Verkada order, which it called its largest CAN-SPAM penalty at $2.95 million, included allegations of unhonored unsubscribe requests
Where the Opt-Out Right Comes From
Nothing in CAN-SPAM requires consent before a first commercial message is sent. The recipient's control is a right to object, assembled from three provisions of 15 U.S.C. § 7704(a) that each do a separate job. Paragraph (3) requires every commercial message to carry a working channel for objecting. Paragraph (5)(A)(ii) requires "clear and conspicuous notice of the opportunity" to use it. Paragraph (4) makes particular conduct unlawful once an objection arrives. The FTC's rule at 16 CFR § 316.5 adds a fourth layer that limits what a sender may ask of the person objecting.
All of these attach to commercial electronic mail messages. Whether a particular email is one depends on the primary purpose criteria, covered separately in an explainer on commercial and transactional messages.
What the Channel Has to Be
Section 7704(a)(3)(A) makes it unlawful to initiate a commercial message that lacks "a functioning return electronic mail address or other Internet-based mechanism, clearly and conspicuously displayed." The recipient must be able to use it "to submit, in a manner specified in the message, a reply electronic mail message or other form of Internet-based communication requesting not to receive future commercial electronic mail messages from that sender at the electronic mail address where the message was received."
Three features of that sentence shape the rest of the scheme:
- The channel is internet-based. The statute names a return email address or another internet mechanism, not a postal address or a telephone line.
- The objection runs to a sender. It covers future commercial mail "from that sender," a term 7702(16) defines as the person that initiates a message and whose product, service or website the message promotes.
- The objection attaches to an address. It covers mail "at the electronic mail address where the message was received," and section 7702(14) provides that a person with more than one address "shall be treated as a separate recipient with respect to each such address."
Paragraph (3)(B) allows a more granular design. The initiator may offer "a list or menu from which the recipient may choose the specific types of commercial electronic mail messages the recipient wants to receive or does not want to receive from the sender," provided the menu "includes an option under which the recipient may choose not to receive any commercial electronic mail messages from the sender." The FTC's compliance guide restates the condition as a menu that keeps an option to stop all marketing messages.
Paragraph (3)(C) excuses a short outage. A mechanism does not fail the requirement "if it is unexpectedly and temporarily unable to receive messages or process requests due to a technical problem beyond the control of the sender if the problem is corrected within a reasonable time period." The guide adds a point the statute does not make expressly, that a sender's spam filter should not be blocking incoming opt-out requests.
Thirty Days From Each Message
The same subparagraph fixes how long the channel must stay open: it has to remain "capable of receiving such messages or communications for no less than 30 days after the transmission of the original message." The period runs from the transmission of each message, not from the end of a campaign, so an unsubscribe link in an email sent on March 1 is required to be accepting requests through at least March 31.
The FTC's guide phrases this as being able to process opt-out requests for at least 30 days after the message is sent. The rule for sexually oriented commercial email, 16 CFR 316.4(a)(2)(iv)(B), repeats the thirty-day floor for the mechanism that must appear in the initially viewable part of those messages.
Ten Business Days, and the Attempt to Shorten Them
Section 7704(a)(4)(A) lists four prohibitions that apply once a recipient has used the mechanism. The first two concern sending. Clause (i) makes it unlawful for the sender to initiate a message "that falls within the scope of the request" more than 10 business days after receiving it. Clause (ii) extends the same bar to anyone acting on the sender's behalf who has actual knowledge, or knowledge fairly implied from objective circumstances, that the message falls within the request. Because paragraph (3)(B) permits partial objections through a menu, the scope of a request can be narrower than all commercial mail.
Congress did not fix the ten-day figure permanently. Section 7704(c)(1) directs the Commission to modify it by regulation "if the Commission determines that a different period would be more reasonable," weighing the purposes of subsection (a), the interests of recipients, and "the burdens imposed on senders of lawful commercial electronic mail."
The Commission proposed to use that power and then declined. Its May 2005 proposal would have cut the period to three business days. The final rule, published at 73 FR 29654 on May 21, 2008, kept ten. The Statement of Basis and Purpose reports that roughly 100 commenters addressed the point and "over 85 percent" opposed a shorter period. It records three conclusions: that three days "would not necessarily advance the privacy interests of consumers"; that the time legitimate senders need "varies, and often exceeds three business days," depending on business size, third-party marketing agreements and the number of databases involved; and that neither the record nor the Commission's experience showed post-opt-out "email bombing" to be "a wide-scale tactic deployed by lawful commercial emailers."
The question returned in the rule review concluded at 84 FR 13115, effective April 4, 2019. Twelve comments addressed it and they split six and six. Those favoring change pointed to automated processing, and some proposed one day or one business day. Those opposed described burdens on small businesses that handle requests by hand. The Commission found that no comment showed "how or to what extent the current ten business-day time-period has negatively affected consumers," and declined to propose a change.
What Section 316.5 Rules Out
The statute describes what the channel must do; the rule describes what it may not demand. Section 316.5 provides that neither a sender nor any person acting on its behalf may require a recipient to "pay any fee, provide any information other than the recipient's electronic mail address and opt-out preferences, or take any other steps except sending a reply electronic mail message or visiting a single Internet Web page," either to submit a request through the paragraph (3) mechanism or to have it honored.
The provision was adopted in the 2008 rulemaking, and the Statement of Basis and Purpose explains the reasoning behind its limbs:
- Verification. Commenters argued that fraud and identity theft justified asking for more than an email address. The Commission was not persuaded, reasoning that requiring additional personal information "would increase the risk of that information being intercepted by a hacker or rogue third party."
- Accounts and passwords. Some commenters keyed suppression to account records, and others asked the Commission to confirm that passwords or profile updates were permitted. The Commission repeated that "opt-out requests are specific to a recipient's email address, not his or her name," and "certainly not" to account information, and was not persuaded that members could be required to update profiles to opt out.
- Retention offers. One commenter asked to show an advertisement or incentive before an unsubscription completed. The Commission described sales pitches placed ahead of a completed opt-out as "an unacceptable encumbrance on a consumer's ability to opt out."
The FTC's guide gives the plain-language version: no fee, no personally identifying information beyond an email address, and no step other than a reply email or a visit to a single page on a website, as a condition of honoring an opt-out request.
What Happens to the Address Afterwards
The remaining two prohibitions in section 7704(a)(4)(A) concern the address itself. Clause (iii) makes it unlawful for anyone acting for the sender to assist in initiating a barred message "through the provision or selection of addresses." Clause (iv) makes it unlawful for the sender, "or any other person who knows that the recipient has made such a request," to "sell, lease, exchange, or otherwise transfer or release" the address, including through any mailing list transaction, "for any purpose other than compliance with this chapter or other provision of law." The guide identifies the transfer that remains available, to a company hired to help with CAN-SPAM compliance.
The 2008 Statement of Basis and Purpose looked at a misuse of that exception. Two commenters reported that third parties had obtained suppression lists and used them to send mail, one describing sellers who posted text versions of their lists on affiliate networks. The Commission found too little evidence to designate the practice an aggravated violation under section 7704(c)(2), but stated that "depending on the facts, some of these practices may violate section 7704(a)(4)(A)(iv)."
An opt-out does not lapse with time. The same document states that the Commission "reaffirms its refusal to impose a limit on the duration of opt-out requests at this time." The statute's release is section 7704(a)(4)(B), under which the prohibitions do not apply "if there is affirmative consent by the recipient subsequent to the request." Affirmative consent is defined in section 7702(1) as express consent given in response to a clear and conspicuous request or on the recipient's own initiative, with an added notice condition where mail comes from a party other than the one that received the consent.
Subscribers and Members Keep the Right
The compliance guide addresses a common assumption about existing customers. It states that recipients of email from a subscription service or membership program "still have the right to opt out of marketing messages," and that although no consent is needed to send members marketing email, "subscribers and members don't lose their ability to opt out of marketing emails ... simply because they have a subscription or membership." The guide ties any message sent to members without an unsubscribe link to the question of whether its primary purpose falls within one of the five transactional or relationship categories.
What the FTC Has Charged
Two recent federal actions turned in substantial part on the opt-out provisions.
- Experian Consumer Services, 2023. The FTC's August 14, 2023 release describes a Department of Justice complaint charging that promotional emails sent to people who had opened accounts to manage their credit information had no unsubscribe link, and that the company "failed to provide clear and conspicuous notice of consumers' ability to opt out of receiving additional marketing messages and a mechanism for doing so." The proposed order required a $650,000 payment and barred marketing emails without an opt-out mechanism.
- Verkada, 2024. The August 30, 2024 release announced a proposed order with a $2.95 million penalty, which the FTC described as "the largest penalty obtained by the FTC for a CAN-SPAM violation." The complaint alleged more than 30 million commercial emails over three years that violated the Act "in four ways," including failing to include an option to unsubscribe, failing to honor opt-out requests and omitting a physical postal address. The same action resolved separate data security and review-disclosure allegations.
Both releases describe complaint allegations and stipulated orders filed for court approval rather than contested findings.
Proposals the Commission Turned Down
The 2019 review also recorded requests to make the mechanism more uniform. Commenters asked for more specific rules on what makes an opt-out notice clear and conspicuous, standardized wording such as "unsubscribe" or "remove," guidance on placement, color contrast and type size, a requirement that opt-out links be text rather than images, a bar on opt-out pages setting unrelated tracking cookies, a standardized unsubscribe box at the foot of every email, and a one-click method. The Online Trust Alliance cited its own audit, in which the share of top retailers with good opt-out practices fell from 96 percent to 88 percent between 2015 and 2016.
The Commission declined each of them. It found "no evidence in the record" supporting the changes and no information on their costs and benefits, and described its authority to require specific language or labels as "somewhat circumscribed," citing 15 U.S.C. 7711(b). The opt-out requirement therefore remains defined by function rather than by format: an internet channel displayed clearly and conspicuously, available for thirty days after each message, honored within ten business days, and free of fees, extra data demands and extra steps.
Frequently Asked Questions
Can an unsubscribe page require the recipient to log in?
Does one opt-out request cover every email address a person uses?
Does a CAN-SPAM opt-out ever expire?
Can a preference center replace a single unsubscribe link?
Has the FTC ever tried to shorten the ten business days?
What happens if an unsubscribe link stops working for a few days?
Sources
Everything above is reported from these documents. Follow them to verify.
- 15 U.S.C. § 7704, Other protections for users of commercial electronic mail statute
- 15 U.S.C. § 7702, Definitions (CAN-SPAM Act) statute
- 16 CFR Part 316, CAN-SPAM Rule (including § 316.5) regulation
- FTC, Definitions and Implementation Under the CAN-SPAM Act, final rule, 73 FR 29654 (May 21, 2008) regulation
- FTC, Controlling the Assault of Non-Solicited Pornography and Marketing Rule, rule review, 84 FR 13115 (April 4, 2019) regulation
- FTC, CAN-SPAM Act: A Compliance Guide for Business agency guidance
- FTC, FTC Charges Experian with Spamming Consumers Who Signed Up for Company Accounts with Marketing Emails They Couldn't Opt Out Of (August 14, 2023) agency release
- FTC, FTC Takes Action Against Security Camera Firm Verkada over Charges it Failed to Secure Videos, Other Personal Data and Violated CAN-SPAM Act (August 30, 2024) agency release
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.