Skip to content

Do Cold Email Laws Apply to LinkedIn Messages? Read the Definitions

Yes, in most of the markets you sell into. Canada’s CASL, Australia’s Spam Act, the UK’s PECR and the EU’s ePrivacy Directive define the message they regulate by the account it lands in, or by whether it is stored until opened, not by whether it is email, and a LinkedIn direct message fits. In the United States, two federal courts have applied CAN-SPAM to messages inside MySpace and Facebook.

Do cold email laws apply to LinkedIn messages? Four regimes define the message by where it lands

I read the five texts, the CRTC’s FAQ and LinkedIn’s legal pages on 26 September 2026 because adding a LinkedIn step to a sequence built on our email infrastructure raises exactly this question. It does not move the message out of the consent rules.

The law never asked whether it was email. It asked where the message landed.

The mistake: treating LinkedIn as the channel the law forgot

A common playbook builds the cold email to the letter of CAN-SPAM or PECR, then sends the same offer as a LinkedIn DM with no identification and no way to opt out, on the theory that anti-spam law is about email. Four of the five texts never limit themselves to email; the fifth, CAN-SPAM, is narrow on its face, and two district courts widened it.

The second half is assuming the B2B carve-outs travel with you. They turn on who holds the account, and a LinkedIn account is registered to a person.

Four regimes define the message by where it lands

Canada. Section 6 of CASL prohibits sending a commercial electronic message “to an electronic address” without consent; section 1 defines that address as one used to reach an electronic mail account, an instant messaging account, a telephone account “or any similar account”. The CRTC’s FAQ adds that a one-way broadcast on social media is not covered, but “messages sent directly to users through a social media closed two-way direct messaging system” are, “and CASL would apply”. So the DM carries section 6’s consent, identification and unsubscribe duties; our Canada guide covers implied consent.

Australia. Section 5 of the Spam Act 2003 defines an electronic message as one sent over an internet carriage service to an electronic address in connection with an email account, an instant messaging account, a telephone account “or a similar account”. I cannot read that as excluding a two-way inbox on LinkedIn. The ACMA page I read does not name social platforms, so the statute is what you have (consent rules in our Australia guide).

United Kingdom. Regulation 2 of PECR defines electronic mail as a message sent over a public network “which can be stored in the network or in the recipient’s terminal equipment until it is collected by the recipient”. The ICO’s guide says the rule covers “direct messages via social media or any similar message that is stored electronically”. A LinkedIn message sits on LinkedIn’s servers until you open it.

European Union. Article 2(h) of the ePrivacy Directive uses the same stored-until-collected wording, and Article 13(1) allows electronic mail for direct marketing only with prior consent. Member states differ in the detail, which is what the country map is for.

Where the B2B carve-out stops

Regulation 22’s consent rule applies to “individual subscribers”, and the ICO says you can email “any corporate body” without consent, with identification and a valid address; Article 13(5) of the directive draws the same line at natural persons. A LinkedIn account is held by the person who accepted the User Agreement, not by their employer, and I found no ICO or EU line extending the corporate route to social messaging, so I design a DM to a European contact for consent. That is my reading, not a ruling.

The United States got there by court, not by text

CAN-SPAM has the narrow definition: an electronic mail message is one “sent to a unique electronic mail address”, a destination “consisting of a unique user name or mailbox” and “a reference to an Internet domain”. A LinkedIn profile has no domain part, and MaxBounty, an affiliate network, argued exactly that when Facebook sued it in 2011: the messages “are not e-mail and therefore cannot give rise to a claim under the CAN-SPAM Act”.

Judge Jeremy Fogel of the Northern District of California disagreed on 28 March 2011: the Act “should be interpreted expansively and in accordance with its broad legislative purpose”, following two 2007 MySpace rulings that refused to require “a traditional e-mail address or inbox”. The order denied a motion to dismiss, so the claim proceeded rather than the case being decided; both plaintiffs were platforms; no court has ruled on LinkedIn by name that I could find. But the FTC’s guide says the law “makes no exception for business-to-business email”, each violating message carries up to $53,088, and a covered DM needs an ad identification, a physical postal address and an opt-out honored within 10 business days.

What the LinkedIn playbook assumes

LinkedIn is outside the cold email laws, so the DM can skip the consent check and the unsubscribe line.

An assumption, not a reading of any statute. None of the five texts says it.

What the texts say

Four regimes reach the DM by definition, two US courts read CAN-SPAM the same way, and LinkedIn’s contract makes anti-spam law a term of membership.

CASL s. 1 and the CRTC FAQ, Spam Act s. 5, PECR reg. 2 and the ICO guide, ePrivacy Art. 2(h), Facebook v. MaxBounty, LinkedIn User Agreement s. 8.1, all read 26 September 2026.

4of the five regimes I read define the regulated message by where it lands or how it is stored, which reaches a LinkedIn DM
50InMail credits a month on every Sales Navigator plan, per LinkedIn Help, and you cannot buy more
$53,088the FTC’s stated maximum penalty per message that violates CAN-SPAM
Bar chart of monthly LinkedIn InMail credits by plan, from 5 on Premium Career to 50 on Sales Navigator Core
Monthly InMail credit allocation by subscription. Source: LinkedIn Help, September 2026.

LinkedIn's own rules and its cap are the tighter limit

LinkedIn does not wait for a regulator. Section 8.1 of its User Agreement, effective 3 November 2025, has every member agree to “comply with all applicable laws, including, without limitation, privacy laws, intellectual property laws, anti-spam laws”, so a breach of anti-spam law is also a breach of your contract with the platform. Section 8.2 bans “bots or other unauthorized automated methods” to “send or redirect messages”, as I covered in AI SDR disclosure, and the Professional Community Policies add “Do not spam members or the platform”.

The platform also meters reach. Per LinkedIn Help today, Premium Career gets 5 InMail credits a month, Premium Business 15, Premium All-in-One 30 and Sales Navigator Core 50; Sales Navigator adds that you cannot purchase more, can bank at most 150, and get a credit back when the recipient responds within 90 days. Fifty messages to strangers is a month of Sales Navigator; a warmed email setup sends that before lunch. LinkedIn is the precision layer, email the volume layer, and the consent record sits above both.

Three moves before your next LinkedIn sequence

01

Put the DM under the same consent record as the email

Log the basis for each contact once, whether that is a conspicuously published business address, an existing relationship or express consent, and let both channels read it. If the email would need consent in that country, so does the DM.

02

Run one suppression list across both channels

An unsubscribe from the email sequence removes the person from the LinkedIn sequence the same day, and a not-interested reply on LinkedIn removes them from email. Send yourself both sequences and test the removal before launch.

03

Carry the identification into the message

Real name, real company, a way to reach you, and the offer to stop. It costs one line, it is what CASL section 6 and Article 13(4) of the directive demand of the email anyway, and it survives whichever way a US court reads the Act.

The bottom line

Moving a sequence to LinkedIn moves it onto a platform with stricter rules and a smaller quota, not out of the law. Four of five regimes define the message by where it lands; the fifth has been read that way in two federal districts.

I have built outbound systems for more than 200 businesses, and the rule that keeps them out of trouble is one consent record for every channel. If your LinkedIn and email sequences do not share a suppression list, send me both and I will show you the gap. I am not a lawyer and this is not legal advice; it is what the texts say today.

Frequently Asked Questions

Yes, for direct messages. CASL regulates commercial electronic messages sent to an electronic address, which section 1 defines to include an instant messaging account or any similar account. The CRTC’s FAQ says a one-way broadcast on social media is not covered, but “messages sent directly to users through a social media closed two-way direct messaging system” are, so a LinkedIn DM needs consent, sender identification and an unsubscribe mechanism under section 6.
The statute defines an electronic mail address as a user name plus an Internet domain, and no court has ruled on LinkedIn by name as far as I could find. But in Facebook v. MaxBounty (N.D. Cal., 28 March 2011) the court refused to limit the Act to traditional email, followed two 2007 MySpace rulings, and let a CAN-SPAM claim over messages inside Facebook proceed. Treat a commercial LinkedIn DM as if the Act’s rules apply: truthful header and subject, identification as an advertisement, a physical postal address and an opt-out honored within 10 business days.
I would not rely on it. PECR’s consent rule in regulation 22 protects individual subscribers, and the ICO says you may email or text any corporate body without consent. The same ICO guide says the electronic mail rules cover direct messages via social media. A LinkedIn account is registered to the individual member, not to their employer, and I found no ICO statement extending the corporate route to social messaging, so I design a DM to a UK contact for consent.
Per LinkedIn’s help pages read on 26 September 2026: Premium Career 5, Premium Business 15, Premium All-in-One 30 and Sales Navigator Core 50 credits a month. Sales Navigator caps accumulation at 150 credits, does not sell extra credits, and returns a credit when the recipient responds within 90 days. InMail is the message type for members you are not connected to.

Want one consent record and one suppression list across email and LinkedIn?

Send me your email sequence and your LinkedIn sequence and I will show you where a contact can fall through the gap between them, and how the infrastructure should be built so an unsubscribe on one channel closes both. Book a 30-minute call: cal.com/zeeshanwaheed/30min.

Book a 30-Minute Call

Or email [email protected].