DMA15

Direct marketing, 1872 to the cookie

The Wire

CAN-SPAM Set the Floor in 2003

The CAN-SPAM Act of 2003 — its statutory requirements for commercial email (opt-out mechanism, sender identification, subject-line accuracy), the penalties it set and the enforcement record in its first decade.

More in The Wire

A desk lamp illuminates stacked paperwork beside an old CRT monitor in a dim office

CAN-SPAM set the floor for commercial email: a working opt-out, accurate headers, an identified sender.

The first federal law governing commercial email established minimum conduct rules — and left opt-in entirely to the sender's discretion.

The Statute and What It Required

The Controlling the Assault of Non-Solicited Pornography and Marketing Act — signed by President George W. Bush on 16 December 2003 and effective 1 January 2004 — was the first federal statute to impose uniform requirements on commercial email in the United States. It did not prohibit unsolicited email; it regulated the conditions under which it could be sent.

An early Netscape Navigator browser window on a mid-1990s CRT monitor, an adult seated at the keyboard

Navigator, 1994.

Photo: Ruben Boekeloo / Pexels

The Act required that every commercial message carry an accurate "From" field and a subject line that did not misrepresent the content. The physical postal address of the sender had to appear in the body. Each message had to include a functioning opt-out mechanism — a reply address or comparable method — and the sender was required to honor opt-out requests within ten business days. Once a recipient had opted out, the sender was barred from transferring that address to another party for use in further mailings.

Penalties under the Act ran to substantial civil penalties per violation under FTC authority, with criminal provisions — up to five years' imprisonment — reserved for fraudulent header manipulation or harvesting addresses by automated means. Enforcement authority was divided among the Federal Trade Commission, the Federal Communications Commission ↗, and state attorneys general.

Hands typing on a laptop beside an open printed document on a wooden desk

Two statutes, 2018 and 2020, both drafted with the third-party cookie in view.

The FTC brought its first significant action under the Act in 2004 against Phoenix Avatar, a spammer operating deceptive weight-loss email campaigns, securing a judgment that established the FTC's willingness to pursue civil penalties. Subsequent enforcement reached larger operators; a 2008 judgment against Jumpstart Technologies extracted $900,000 in civil penalties.

Critics noted from the outset that the Act pre-empted stricter state anti-spam laws — including California's opt-in statute, which had been passed but had not yet taken effect — and that its opt-out architecture allowed the initial unsolicited message to be sent legally, a structural limit that distinguished CAN-SPAM from the opt-in frameworks later adopted in Europe under the General Data Protection Regulation ↗.