The Wire
CAN-SPAM Set the Floor in 2003
The CAN-SPAM Act of 2003 — its statutory requirements for commercial email (opt-out mechanism, sender identification, subject-line accuracy), the penalties it set and the enforcement record in its first decade.

CAN-SPAM set the floor for commercial email: a working opt-out, accurate headers, an identified sender.
The first federal law governing commercial email established minimum conduct rules — and left opt-in entirely to the sender's discretion.
The Statute and What It Required
The Controlling the Assault of Non-Solicited Pornography and Marketing Act — signed by President George W. Bush on 16 December 2003 and effective 1 January 2004 — was the first federal statute to impose uniform requirements on commercial email in the United States. It did not prohibit unsolicited email; it regulated the conditions under which it could be sent.

Navigator, 1994.
Photo: Ruben Boekeloo / Pexels
The Act required that every commercial message carry an accurate "From" field and a subject line that did not misrepresent the content. The physical postal address of the sender had to appear in the body. Each message had to include a functioning opt-out mechanism — a reply address or comparable method — and the sender was required to honor opt-out requests within ten business days. Once a recipient had opted out, the sender was barred from transferring that address to another party for use in further mailings.
Penalties under the Act ran to substantial civil penalties per violation under FTC authority, with criminal provisions — up to five years' imprisonment — reserved for fraudulent header manipulation or harvesting addresses by automated means. Enforcement authority was divided among the Federal Trade Commission, the Federal Communications Commission ↗, and state attorneys general.

Two statutes, 2018 and 2020, both drafted with the third-party cookie in view.
The FTC brought its first significant action under the Act in 2004 against Phoenix Avatar, a spammer operating deceptive weight-loss email campaigns, securing a judgment that established the FTC's willingness to pursue civil penalties. Subsequent enforcement reached larger operators; a 2008 judgment against Jumpstart Technologies extracted $900,000 in civil penalties.
Critics noted from the outset that the Act pre-empted stricter state anti-spam laws — including California's opt-in statute, which had been passed but had not yet taken effect — and that its opt-out architecture allowed the initial unsolicited message to be sent legally, a structural limit that distinguished CAN-SPAM from the opt-in frameworks later adopted in Europe under the General Data Protection Regulation ↗.