Plenty of marketers quietly assume CAN-SPAM is a legacy law — the kind of thing you read once, nod at, and never think about again. Then they see the number: up to $53,088 per non-compliant email, assessed per message rather than per campaign.
And the FTC has not stopped bringing cases. A security camera company paid $2.95 million. A credit bureau's consumer arm paid $650,000. A sweepstakes giant settled for $18.5 million. These are real orders, with real consent decrees attached.
This article is the concrete version: the cases, what triggered them, and the structural rule that catches senders out — especially the one buried in the Experian action, which decides whether your "account update" is legally a marketing email.
What you will learn:
- The current penalty and why it stayed flat in 2026
- The FTC's most consequential CAN-SPAM cases, with numbers
- The primary-purpose test that decides if an email is commercial
- The seven requirements the FTC actually checks
- How to stay out of the crosshairs
The Short Version
- CAN-SPAM penalties are up to $53,088 per email, not per campaign.
- The FTC keeps enforcing, including a record $2.95 million CAN-SPAM penalty against Verkada in 2024.
- Labeling marketing as "account information" does not work — the Experian case turned on exactly that.
- The deciding factor is the email's primary purpose, tested under 16 C.F.R. § 316.3.
- Most violations are boring: missing unsubscribe, ignored opt-outs, no postal address.
- There is no private right of action, but the FTC, state attorneys general and ISPs can all enforce.
The Penalty: $53,088 Per Email
Start with the number, because it is the whole reason this law still matters.
| Fact |
Detail |
| Maximum civil penalty |
$53,088 per non-compliant email |
| Assessed per |
Individual email, not campaign or list |
| Set by |
FTC 2025 inflation adjustment, effective January 17, 2025 |
| 2026 status |
Unchanged — the annual adjustment was cancelled |
| Enforcers |
FTC, state attorneys general, ISPs |
| Private right of action |
No |
| Criminal exposure |
Up to 5 years' imprisonment for aggravated violations |
A note on the 2026 figure, because it trips people up. Each year, federal agencies adjust civil penalties for inflation. In 2026, that did not happen: the Office of Management and Budget cancelled the adjustment (Memo M-26-11, April 17, 2026) because a government shutdown disrupted the underlying inflation data. The FTC confirmed in September 2026 that it would keep the 2025 penalty levels — so $53,088 remains the ceiling.
What the Penalty Actually Means
The ceiling is not a flat rate, and the FTC has never collected anywhere near it across a campaign. But the per-email structure is what gives the agency leverage:
| Emails in violation |
Theoretical maximum |
| 1,000 |
$53,088,000 |
| 10,000 |
$530,880,000 |
| 100,000 |
$5,308,800,000 |
Settlements land far below those numbers. Verkada's $2.95 million resolved more than 30 million emails. But the gap between the ceiling and the settlement is exactly why the FTC can negotiate from strength — and why the first question in any enforcement matter is how many emails are in scope.
The Cases That Matter
This is the part most compliance content skips. These are the actual actions.
Verkada — $2.95 Million (August 2024)
The largest CAN-SPAM penalty the FTC had ever obtained.
- What happened: The FTC, through the DOJ, alleged that security camera firm Verkada sent more than 30 million commercial emails over three years.
- The email violations: No unsubscribe links or clear opt-out notice, failure to honor opt-out requests, and no valid physical postal address.
- The twist: The case was primarily about data security under Section 5 of the FTC Act — a 2021 breach exposed feeds from over 150,000 cameras. The CAN-SPAM charges were the source of the monetary penalty.
- The outcome: A $2.95 million civil penalty, a 20-year consent order, a comprehensive information security program with third-party audits, and a prohibition on further CAN-SPAM violations.
- The lesson: CAN-SPAM charges can ride alongside a completely separate regulatory problem — and become the part that costs money.
Experian Consumer Services — $650,000 (August 2023)
The most instructive case for marketers, because it is about how an email is framed.
- What happened: Consumers who signed up to manage their Experian credit information were then sent emails promoting products like Experian Boost and a "Dark Web scan."
- The framing: The emails carried footers saying "This email was sent because it contains important information about your account" and "This is not a marketing email — you're receiving this message to notify you of a recent change to your account."
- The problem: The FTC alleged those statements were false — the emails were primarily promotional — and they lacked an opt-out mechanism. Because the messages were commercial, CAN-SPAM's opt-out requirements applied.
- The outcome: A $650,000 civil penalty and an order prohibiting the company from treating a primarily commercial message as transactional.
- The lesson: The label does not control. The content does.
Publishers Clearing House — $18.5 Million (2023)
A sweepstakes case with a CAN-SPAM component.
- The FTC alleged deceptive sweepstakes marketing, and the order included a prohibition on sending commercial email with a subject heading likely to mislead a reasonable recipient about a material fact.
- The $18.5 million judgment was monetary relief for the broader deception, not a pure CAN-SPAM penalty — but the email conduct was part of the order.
- The lesson: A deceptive subject line can be charged under CAN-SPAM even when the headline allegation is something else.
Effen Ads and Related Work-at-Home Scheme — $11.3 Million (2023)
- The FTC alleged a work-at-home scheme promoted through false celebrity endorsements and fabricated news reviews.
- The order included CAN-SPAM prohibitions covering misleading subject headings and "from" lines.
- The lesson: Header and subject-line deception draws CAN-SPAM liability on top of the underlying fraud claims.
The Pattern Across the Cases
| Case |
Year |
Monetary amount |
CAN-SPAM conduct |
| Verkada |
2024 |
$2.95M |
No opt-out notice, ignored opt-outs, no postal address |
| Experian |
2023 |
$650K |
Marketing disguised as transactional; no opt-out |
| Publishers Clearing House |
2023 |
$18.5M (broader) |
Misleading subject headings |
| Effen Ads / work-at-home |
2023 |
$11.3M (broader) |
Misleading subject lines and from lines |
The common thread: the FTC's CAN-SPAM cases are rarely about clever spam. They are about ordinary operational failures at scale — missing unsubscribe mechanisms, ignored requests, absent addresses, and mislabelled message types.
The Structural Rule: "Primary Purpose"
This is the most valuable idea in the whole body of CAN-SPAM enforcement, and it comes straight from the Experian case.
CAN-SPAM only imposes its opt-out and labelling requirements on a commercial electronic mail message — one whose primary purpose is the commercial advertisement or promotion of a product or service. Transactional or relationship messages are treated differently. So everything turns on one question: what is the email's primary purpose?
The FTC's CAN-SPAM Rule (16 C.F.R. § 316.3) answers it:
- If a message contains only commercial content, its primary purpose is commercial.
- If a message mixes commercial and transactional content, it is commercial if either:
- A reasonable recipient reading the subject line would likely conclude the message advertises or promotes a product or service, or
- The transactional or relationship content does not appear in whole or in substantial part at the beginning of the body.
For a mixed email to count as transactional, both conditions must fail — the subject line must not look commercial, and the transactional content must lead the message.
Why This Matters in Practice
The Experian emails failed that test. They had promotional subject lines, promotional layout, and the "account information" text was boilerplate in the footer. Saying "this is not a marketing email" in small print at the bottom does not change the primary purpose.
Put simply:
- Tone and layout matter. If the email is built to sell, it is commercial — regardless of the disclaimer.
- Position matters. Transactional content has to come first, not after the pitch.
- The subject line is decisive. A promotional subject line can make an otherwise mixed email commercial on its own.
The Seven Requirements the FTC Checks
CAN-SPAM's obligations are short. Most enforcement comes from just a few of them.
- Accurate header information. The "from," "to," "reply-to" and routing information must not be materially false or misleading.
- Non-deceptive subject line. The subject must not mislead a reasonable recipient about a material fact.
- Identify the message as an ad. Commercial email must be clearly identifiable as an advertisement or solicitation.
- A valid physical postal address. A current street address, PO box, or registered commercial mail box.
- A clear and conspicuous opt-out notice. Recipients must be told, clearly, how to stop receiving future messages.
- Honor opt-outs within 10 business days. The mechanism must remain active for at least 30 days after the message is sent.
- Monitor your vendors. If an agency or ESP sends on your behalf, you can still be held responsible.
The first three are content and header rules. The last four are the operational ones that produced Verkada and Experian.
Common Defences That Don't Work
Senders reach for the same arguments in enforcement matters. Most fail.
- "We labelled it as account information." The label does not control; the primary purpose does.
- "The recipient agreed to receive account emails." A membership does not waive CAN-SPAM's opt-out rights for marketing content.
- "Our ESP handles compliance." You are still responsible for mail sent on your behalf.
- "It was only a few emails." The penalty is per email, and the FTC looks at patterns over time.
- "The subject line was technically true." It must not be misleading about a material fact — accuracy alone is not the standard.
- "We're B2B, so CAN-SPAM doesn't apply." It does. There is no B2B exception.
- "We fixed it after the complaint." Remediation helps, but the violations already occurred.
How to Stay Out of the Crosshairs
The good news: none of this is hard to comply with. The cases above failed on basics.
- Audit every recurring template for the postal address, the opt-out notice, and a working unsubscribe link.
- Test the unsubscribe flow end to end. Click it, confirm it works, and confirm the request is honored within 10 business days.
- Classify each email by primary purpose. If it sells something, treat it as commercial — no matter what the footer says.
- Check the subject line against the content. If it promises an account update but delivers a pitch, fix one or the other.
- Keep transactional content first. If an email must mix content, lead with the transactional part.
- Document opt-out processing. Logs are your evidence if a complaint arrives.
- Review vendor and affiliate email. You inherit the liability for how they represent you.
- Score your sends before they go out. A spam score checker catches technical issues; a deliverability calculator shows how the mailbox providers are treating you.
For the underlying requirements in more depth, see the CAN-SPAM requirements and CAN-SPAM overview references, and our broader email marketing laws in 2026 guide. If you send internationally, the GDPR compliance checker and anti-spam laws entry cover the opt-in regimes that apply alongside CAN-SPAM.
Key Takeaways
- CAN-SPAM's maximum penalty is $53,088 per non-compliant email, and it stayed at that level for 2026 after the annual adjustment was cancelled.
- The FTC keeps bringing cases: Verkada ($2.95M), Experian ($650K), Publishers Clearing House ($18.5M) and others.
- Verkada shows CAN-SPAM charges can attach to an unrelated regulatory problem and become the monetary penalty.
- Experian establishes the structural rule: if the primary purpose is commercial, CAN-SPAM's opt-out requirements apply — regardless of how the email is labelled.
- The primary-purpose test turns on the subject line and whether transactional content leads the body.
- Most violations are operational: missing opt-out notice, ignored opt-outs, no physical address.
- Compliance is cheap. The penalty is not.
Sources and Further Reading
Related Articles
Related tools: Check sends with the spam score checker, monitor reputation with the sender reputation checker, review domain health with the blacklist checker, and size deliverability impact with the deliverability calculator.
This article summarises public enforcement actions for informational purposes and is not legal advice. Penalty amounts and case status can change; consult qualified counsel for your own compliance programme.