Skip to content

CAN-SPAM Liability: Your Cold Email Agency Cannot Absorb It

Your cold email agency cannot take on your legal risk. There is no clause, indemnity or master services agreement that moves it, because the FTC wrote the rule specifically to stop that from working.

Under the CAN-SPAM Act, both the company whose product is promoted in a commercial email and the company that actually sends it may be held legally responsible. The FTC states in its own compliance guide for business that even if you hire another company to handle your email marketing, you cannot contract away your legal responsibility to comply with the law. Hiring an agency adds a second liable party. It does not remove the first one.

Here is the part that should bother you more than the liability itself. The FTC does not stop at telling you that you remain responsible. The eighth item on its list of CAN-SPAM requirements is not a rule about your email at all. It is an instruction to monitor what others are doing on your behalf. That is an active duty, and a duty to monitor is not discharged by signing someone who promised in writing to be compliant.

I have built cold email infrastructure across 500+ projects in 30 countries. The founders who get caught are almost never the ones who hired a bad agency. They are the ones who hired a good agency and then stopped looking.

Every founder asks whether the agency is compliant. The regulator asks whether you checked.

The mistake: treating the contract as a shield

An indemnity clause is a private agreement about who pays afterward. It is not a transfer of liability to a regulator, and a regulator is not a party to it. The FTC can proceed against the company whose product was promoted no matter what your paperwork says. All the contract decides is whether you get to sue your agency later to recover what you already paid.

Two things follow from that, and both are about timing. First, you pay first and argue second. Second, an indemnity is worth exactly what the agency is worth on the day you need to collect on it, and cold email agencies are small, asset light and easy to dissolve. The clause that felt like protection during onboarding is a claim against a company that may not exist by the time the claim matures.

What the contract does

"We are indemnified, so we are covered."

It allocates cost between two private parties after the fact. It does not bind the FTC, it does not stop an action against you, and it is only collectable if the counterparty is still solvent when you need it.

What decides your exposure

Whether the messages going out under your name actually comply, and whether you can show you checked. Pull ten live sends this month and verify the from line, the postal address and the opt-out link yourself. That evidence is the thing the eighth requirement is asking for.

The clause that looks like protection, and when it fails

The FTC does publish a mechanism that looks like the thing everyone wants. When one email advertises the goods, services or websites of more than one marketer, those marketers may designate one of them as the "sender" for CAN-SPAM purposes. It is the closest thing in the statute to moving sender duties onto somebody else.

It carries three conditions. The designated sender has to meet the Act's definition of a sender, meaning it initiates a message promoting its own goods, services or website. It has to be identified in the from line. And it has to comply with the initiator provisions: truthful transmission information and subject heading, a valid postal address, a working opt-out link, and clear identification of the message as an advertisement.

Then comes the sentence that decides the whole thing. If the designated sender does not comply with the responsibilities the law gives to initiators, all marketers in the message may be held liable as senders.

So the designation holds while the designated party is compliant, which is exactly the situation in which nobody needed it, and stops holding the moment something goes wrong, which is the only situation in which it would have mattered. It is not a shield. It is a label that lasts as long as the underlying behaviour is clean.

There is a simpler problem underneath it. A normal outbound campaign promotes one company: yours. There is no second marketer to designate, so the mechanism does not apply at all. Your agency is an initiator, you are the sender, and that is what the definitions say rather than something you negotiated.

0
conditions a designated sender must meet
0
business days to honour an opt-out
0
days your opt-out link must keep working

The penalty is priced when you are assessed, not when you sent

Each separate email in violation of CAN-SPAM is subject to a civil penalty of up to $53,088. Per email, not per campaign, which is why the arithmetic on a list of any size stops being a rounding error quickly.

The number itself is the part almost nobody reads correctly. It is set by 16 CFR 1.98, and that section says the maximum amounts apply only to penalties assessed after 17 January 2025, including penalties whose associated violation predated 17 January 2025. The figure is adjusted for inflation and it attaches at assessment, not at send. So the exposure sitting on a campaign you ran last year is priced at whatever rate is in force on the day someone assesses it. You cannot write today's number into a risk register and treat it as fixed.

There is a second clock most contracts ignore. Any opt-out mechanism you offer has to keep processing requests for at least 30 days after you send the message, and you have to honour a request within 10 business days. If your agency switches off its sending infrastructure the day the contract ends, the unsubscribe links inside messages already delivered stop working while your obligation is still running. Offboarding an email vendor is a compliance event with a deadline, not an administrative one.

Four moves before your next campaign goes out

01
Hold the suppression list yourself
Once someone opts out you cannot sell or transfer their address, with one exception written into the rule: you may transfer it to a company you have hired to help you comply. That exception is the whole design. Own the list, lend it to the vendor, take a copy back every month. It is the first thing we set up on any cold email infrastructure engagement.
02
Turn monitoring into evidence, not a promise
Every month, pull a sample of messages that actually went out. Check the from line, the physical postal address, the advertisement disclosure, and click the opt-out link to confirm it resolves. Save the screenshots with dates. A promise in a contract is not monitoring. A dated file is.
03
Read your own from line
Header information, including the originating domain name and email address, must be accurate and identify the person or business who initiated the message. If your agency sends from domains you do not control, under names you cannot verify, requirement number one is already in question before anyone reads the copy. This is where most outbound programmes quietly go wrong.
04
Set the offboarding clock in the contract
Write it in before the first send: the opt-out endpoint survives termination by at least 30 days, opt-out requests received in that window get honoured within 10 business days, and the postal address in the footer is one you still control after the relationship ends. Cheap to add on day one, impossible to add on the last day.

The bottom line

You can buy competence. You cannot buy the responsibility off your own company. CAN-SPAM attaches to the business whose product is being promoted, the rule was written that way on purpose, and the one mechanism that shifts sender duties only holds while the other party is behaving. What is actually available to you is a suppression list you control, a from line you can verify, an opt-out endpoint that outlives the contract, and a monthly file showing you looked.

I am not your lawyer and none of this is legal advice. The FTC's compliance guide for business and 16 CFR 1.98 are the authorities here, both are short, and if you are running outbound at any volume you should read them yourself. State law can add requirements on top, and this covers the United States only. For the country by country picture, start with our breakdown of cold email law in the United States.

See what we build in cold email infrastructure and B2B lead generation, or read more about how we work.

Book a 30 minute call: cal.com/zeeshanwaheed/30min or email [email protected].

Frequently Asked Questions

Yes, you can be. The FTC's compliance guide states that both the company whose product is promoted in the message and the company that actually sends the message may be held legally responsible, and that even if you hire another company to handle your email marketing you cannot contract away your legal responsibility to comply with the law. Hiring a vendor adds a liable party rather than replacing one. The guide also lists monitoring what others are doing on your behalf as one of the Act's main requirements, so the expectation is that you check rather than assume.
An indemnity allocates cost between you and your agency after the fact. It is a private contract and the regulator is not a party to it, so it does not prevent an action against your company and it does not change who the law treats as responsible. In practice it also depends entirely on whether the agency is still solvent when you try to collect. Treat it as a recovery mechanism, not as protection.
Each separate email in violation is subject to a civil penalty of up to $53,088, set by 16 CFR 1.98. The detail that matters is in that section itself: the maximum amounts apply to penalties assessed after 17 January 2025, including penalties whose associated violation predated that date. The figure is adjusted for inflation and attaches at assessment, so the exposure on messages you have already sent is priced on the day it is assessed rather than the day you sent them. Aggravated violations can carry additional fines, and some conduct carries criminal penalties.
Only in a narrow case, and it fails when you would need it. When an email promotes more than one marketer, those marketers may designate one as the sender, provided the designated party meets the Act's definition of sender, is identified in the from line, and complies with the initiator provisions. But if the designated sender does not comply with the initiator responsibilities, all marketers in the message may be held liable as senders. A typical outbound campaign also promotes only one company, so there is no second marketer to designate and the mechanism does not apply at all.

Not sure what is actually going out under your name?

Bring your sending domains, your vendor contract and one week of live sends to the call. I will tell you which requirements you are already meeting, which ones your agency is answering for you, and what to fix before the next campaign.

Book a 30-Minute Call