Your cold email agency cannot take on your legal risk. There is no clause, indemnity or master services agreement that moves it, because the FTC wrote the rule specifically to stop that from working.
Under the CAN-SPAM Act, both the company whose product is promoted in a commercial email and the company that actually sends it may be held legally responsible. The FTC states in its own compliance guide for business that even if you hire another company to handle your email marketing, you cannot contract away your legal responsibility to comply with the law. Hiring an agency adds a second liable party. It does not remove the first one.
Here is the part that should bother you more than the liability itself. The FTC does not stop at telling you that you remain responsible. The eighth item on its list of CAN-SPAM requirements is not a rule about your email at all. It is an instruction to monitor what others are doing on your behalf. That is an active duty, and a duty to monitor is not discharged by signing someone who promised in writing to be compliant.
I have built cold email infrastructure across 500+ projects in 30 countries. The founders who get caught are almost never the ones who hired a bad agency. They are the ones who hired a good agency and then stopped looking.
Every founder asks whether the agency is compliant. The regulator asks whether you checked.
The mistake: treating the contract as a shield
An indemnity clause is a private agreement about who pays afterward. It is not a transfer of liability to a regulator, and a regulator is not a party to it. The FTC can proceed against the company whose product was promoted no matter what your paperwork says. All the contract decides is whether you get to sue your agency later to recover what you already paid.
Two things follow from that, and both are about timing. First, you pay first and argue second. Second, an indemnity is worth exactly what the agency is worth on the day you need to collect on it, and cold email agencies are small, asset light and easy to dissolve. The clause that felt like protection during onboarding is a claim against a company that may not exist by the time the claim matures.
"We are indemnified, so we are covered."
It allocates cost between two private parties after the fact. It does not bind the FTC, it does not stop an action against you, and it is only collectable if the counterparty is still solvent when you need it.
Whether the messages going out under your name actually comply, and whether you can show you checked. Pull ten live sends this month and verify the from line, the postal address and the opt-out link yourself. That evidence is the thing the eighth requirement is asking for.
The clause that looks like protection, and when it fails
The FTC does publish a mechanism that looks like the thing everyone wants. When one email advertises the goods, services or websites of more than one marketer, those marketers may designate one of them as the "sender" for CAN-SPAM purposes. It is the closest thing in the statute to moving sender duties onto somebody else.
It carries three conditions. The designated sender has to meet the Act's definition of a sender, meaning it initiates a message promoting its own goods, services or website. It has to be identified in the from line. And it has to comply with the initiator provisions: truthful transmission information and subject heading, a valid postal address, a working opt-out link, and clear identification of the message as an advertisement.
Then comes the sentence that decides the whole thing. If the designated sender does not comply with the responsibilities the law gives to initiators, all marketers in the message may be held liable as senders.
So the designation holds while the designated party is compliant, which is exactly the situation in which nobody needed it, and stops holding the moment something goes wrong, which is the only situation in which it would have mattered. It is not a shield. It is a label that lasts as long as the underlying behaviour is clean.
There is a simpler problem underneath it. A normal outbound campaign promotes one company: yours. There is no second marketer to designate, so the mechanism does not apply at all. Your agency is an initiator, you are the sender, and that is what the definitions say rather than something you negotiated.
The penalty is priced when you are assessed, not when you sent
Each separate email in violation of CAN-SPAM is subject to a civil penalty of up to $53,088. Per email, not per campaign, which is why the arithmetic on a list of any size stops being a rounding error quickly.
The number itself is the part almost nobody reads correctly. It is set by 16 CFR 1.98, and that section says the maximum amounts apply only to penalties assessed after 17 January 2025, including penalties whose associated violation predated 17 January 2025. The figure is adjusted for inflation and it attaches at assessment, not at send. So the exposure sitting on a campaign you ran last year is priced at whatever rate is in force on the day someone assesses it. You cannot write today's number into a risk register and treat it as fixed.
There is a second clock most contracts ignore. Any opt-out mechanism you offer has to keep processing requests for at least 30 days after you send the message, and you have to honour a request within 10 business days. If your agency switches off its sending infrastructure the day the contract ends, the unsubscribe links inside messages already delivered stop working while your obligation is still running. Offboarding an email vendor is a compliance event with a deadline, not an administrative one.
Four moves before your next campaign goes out
The bottom line
You can buy competence. You cannot buy the responsibility off your own company. CAN-SPAM attaches to the business whose product is being promoted, the rule was written that way on purpose, and the one mechanism that shifts sender duties only holds while the other party is behaving. What is actually available to you is a suppression list you control, a from line you can verify, an opt-out endpoint that outlives the contract, and a monthly file showing you looked.
I am not your lawyer and none of this is legal advice. The FTC's compliance guide for business and 16 CFR 1.98 are the authorities here, both are short, and if you are running outbound at any volume you should read them yourself. State law can add requirements on top, and this covers the United States only. For the country by country picture, start with our breakdown of cold email law in the United States.
See what we build in cold email infrastructure and B2B lead generation, or read more about how we work.
Book a 30 minute call: cal.com/zeeshanwaheed/30min or email [email protected].