Stacked Creator

An independent publication on cold email, lead data and sales CRMs, edited in Japan.

No. 06 Guides, filed under Guide

CAN-SPAM and B2B Cold Email (2026): Who’s Liable and When Recipients Can Sue

CAN-SPAM has no B2B exception, even one-to-one: what each email needs, who’s liable when an agency sends, the $53,088 cap kept for 2026 and state lawsuits.

On this page 13 sections

A one-to-one sales email to a work address is “commercial” under CAN-SPAM when its primary purpose is to promote what you sell, and business recipients get no exemption. What changes from team to team is who sends, whose product the email promotes and where the recipient is, because those decide whose postal address goes in the footer, whose opt-out list applies and whether a state law lets the recipient sue.

Quick answer

CAN-SPAM covers B2B cold email primarily promoting what you sell, even one-to-one. Consent isn’t needed first; each email needs honest headers and subject, an ad notice, the advertiser’s postal address and an opt-out. Agency and client each risk up to $53,088 per email, an FTC cap kept for 2026. Only state laws, like Washington’s, California’s and Maryland’s, let recipients sue.

Not legal advice. This is a plain-English reading of the federal Act, the FTC’s rule and guide, and three state laws as last read on October 2, 2026; no lawyer has reviewed it. It covers email to US recipients, which the same rules generally reach even if you send from the UK, Canada or Australia (see the FAQ), but not texts or calls. For recipients outside the US, start with which country’s law applies to a cold email. Before you rely on it for a campaign, put your facts to a US attorney.

Six questions decide what you owe, and the sections below answer them in order: is the email commercial, who is the sender, what each email must carry, how opt-outs work, whether the address source matters, and which state laws let recipients sue. Fines come next, and then all six are answered at once for a founder, a small agency and a freelance SDR.

Does CAN-SPAM cover a one-to-one B2B sales email?

Yes, if its primary purpose is to promote your product or service. Writing to one named person at a time doesn’t change that: the FTC’s guide says the Act “doesn’t apply just to bulk email” and “makes no exception for business-to-business email.”

The Act defines a commercial email as one whose primary purpose is “the commercial advertisement or promotion of a commercial product or service” (15 U.S.C. 7702(2)(A)2). Being covered doesn’t mean you need permission: none of the FTC’s main requirements is prior consent, and the Act instead gives recipients “the right to have you stop emailing them” (FTC guide1).

When an email mixes a pitch with other content, the FTC’s rule decides by what’s in it and where (16 CFR 316.34). Three invented emails show how its tests apply to a single message:

Email (invented example)Test in 16 CFR 316.3Result
Only a pitch: “Hi Dana, we build Shopify stores for outdoor brands. Worth a 15-minute call next week?”(a)(1): a message that “consists exclusively of” promotion is commercialCommercial
A question, then a pitch: “Saw your post about switching warehouses. How has the move gone? We help brands like yours cut shipping costs, happy to show how.”(a)(3): commercial if a reader “reasonably interpreting” the subject line would likely conclude the email contains an ad, or if one reading the body would conclude its primary purpose is promotionCommercial if the subject line suggests an ad. Otherwise it turns on the body test; here the question leads into the pitch, so treat it as commercial
Deal details plus one line of promotion: “Confirming the kickoff call for the website project you signed on Monday: Thursday at 10. P.S. We now run SEO audits too.”(a)(2): commercial if the subject line suggests an ad, or if the transactional content doesn’t appear “at the beginning of the body”Transactional if the subject is about the project and the kickoff details come first. Not a cold email, but it marks the line

Examples written for this page.

For the body test, the rule looks at whether the pitch comes first, how much of the email it takes and how it’s highlighted.

A company name or a link doesn’t make an email commercial by itself when “the contents or circumstances of the message indicate a primary purpose other than” promotion (7702(2)(D)). So a genuine request for an interview quote doesn’t become commercial just because your business signature sits under it.

Who counts as the sender when an agency or SDR sends for a client?

The client is the “sender”; the agency or SDR that transmits the email “initiates” it, and both can be liable.

In plain terms, whoever sends an email, or pays someone to send it, initiates it, and more than one company can do that for the same email. The sender is the initiator whose product the email promotes, so an agency is a sender only when its own services are advertised.

Those are the Act’s definitions. “Initiate” covers originating, transmitting or procuring an email, and “more than one person may be considered to have initiated” it (7702(9)). “Procure” means paying or inducing another person to send “on one’s behalf” (7702(12)), and the sender is an initiator “whose product, service, or Internet web site is advertised or promoted” by the email (7702(16)(A)).

Hiring someone doesn’t shift the duty. The FTC’s guide says “you can’t contract away your legal responsibility,” and that the company whose product is promoted and the company that sends “may be held legally responsible.”

Your setupRole under the ActWhose postal address and opt-out list
Founder emailing prospects for your own companyYou initiate and you’re the senderYours
Agency sending for a client from domains the agency set upThe agency initiates (it transmits); the client initiates (it procures) and is the senderThe client’s. Anyone acting for the client who knows, or should know, of an opt-out must stop too
Freelance SDR sending from the client’s own mailboxesThe SDR initiates; the client procures and is the senderThe client’s; opt-out replies land in the client’s mailbox
One email promoting two companies, such as an agency and a software partnerEach is a sender, unless one is designated: it must meet the sender definition, be named in the From line as the only sender, and follow the header, subject, opt-out and footer rules (16 CFR 316.2(m)4)The designated sender’s. If it doesn’t comply, the FTC says “all marketers in the message may be held liable as senders”
A company that pays a partner for referrals or leads, and the partner emails prospects about itThe FTC’s guide says a seller that pays “for any form of referral” is “likely to have compliance obligations”; the partner initiatesThe advertised company’s

One more route to liability doesn’t depend on who sent. A business promoted in an email with false header information can be liable if it knew or should have known, expected to benefit and “took no reasonable action” to prevent or report it. Only the FTC enforces that rule (15 U.S.C. 77052).

What must each email carry, and whose details go in it?

Five things, and when you send for a client, the postal address in them is the client’s, because the Act asks for the sender’s address and the sender is the advertiser.

The five are accurate header information, a subject line that won’t mislead, a clear notice that the email is an ad, a clear notice of how to opt out with a working way to do it, and “a valid physical postal address of the sender” (15 U.S.C. 7704(a)2). What trips up small teams is whose details go where:

  • The address. The rule accepts “the sender’s current street address, a Post Office box the sender has accurately registered with the United States Postal Service, or a private mailbox the sender has accurately registered with a commercial mail receiving agency” (16 CFR 316.2(p)). If you work from home, the PO box and the private mailbox are the rule’s own alternatives. An agency’s own address doesn’t meet the rule for a client’s email unless the agency is also being advertised.
  • The From line. A From line that “accurately identifies any person who initiated the message” isn’t false or misleading (7704(a)(1)(B)), so the SDR’s name or the client’s name both work when true. The FTC’s guide says the rest of the routing information, “including the originating domain name and email address,” must be accurate and identify who initiated the email.
  • The ad notice. The FTC says the law gives you “a lot of leeway” in how you word it, “but you must disclose clearly and conspicuously that your message is an advertisement.” You can leave it out only if the recipient gave “prior affirmative consent” (7704(a)(5)(B)), which a cold prospect normally hasn’t.
  • The subject line. Sending is unlawful when you know, or it’s “fairly implied,” that the subject “would be likely to mislead a recipient, acting reasonably under the circumstances, about a material fact regarding the contents” (7704(a)(2)). A first email headed “Re: our call” when there was no call is the kind of line to drop, and the state laws below target it too.

Example, not legal advice: how a freelance SDR might close a plain-text email sent for a client.

[Your name], writing for [Client company]
[Client company], [street address, or a PO box or private mailbox registered to the client]
This email is an advertisement for [Client company]. Not interested? Reply “stop” and we won’t email you again.

The address and the ad notice are the client’s, because the client is the advertiser, and the reply line is the opt-out. The Act doesn’t prescribe wording, so this is one way to give the ad notice, the address and the opt-out, not wording a court or the FTC has approved.

How must opt-outs work, and whose list do they go on?

An opt-out ends email “from that sender,” so when you send for a client it has to reach every mailbox, domain and tool you use for that client within 10 business days.

  • It must work for 30 days. The reply address or link has to stay “capable of receiving” requests “for no less than 30 days after the transmission of the original message” (7704(a)(3)(A)(ii)).
  • A reply is enough. The Act accepts “a functioning return electronic mail address” (7704(a)(3)(A)). The FTC’s rule bars fees and asks for nothing beyond a reply or a visit to one web page, with no information beyond the email address and preferences (16 CFR 316.54). A line such as “Reply ‘stop’ and I won’t email you again” works if someone reads and logs the replies.
  • Who else must stop. Anyone who sends for the sender, or supplies or picks the addresses, must also stop once they know, or should know, about the opt-out (7704(a)(4)(A)). That’s why an agency should get a client’s existing opt-outs before the first send.
  • The list stays put. Nobody who knows of the request may sell or transfer the address “for any purpose other than compliance” (7704(a)(4)(A)). The FTC names the one exception as “a company you’ve hired to help you comply,” so a client can give its suppression list to the agency that sends for it, and the agency can pass new opt-outs back.

The request is tied to the sender and to “the electronic mail address where the message was received.” On its own, it doesn’t bar your other clients, which are different senders, from emailing that person.

Does it matter how you found the address?

Only on top of another violation: harvesting addresses from a site that says it won’t share them, or generating them by combining names and letters, turns a CAN-SPAM violation into an aggravated one.

An address isn’t off-limits just because you bought it or looked it up in a data tool. The only ways of getting an address the Act names are those two automated ones, and they count only for an email that already breaks the rules above, when you knew or should have known how the address was obtained (7704(b)(1)).

The effect is on the bill: a court may triple the damages a state attorney general or an internet access provider wins (15 U.S.C. 7706(f) and (g)2). The FTC’s guide also lists harvesting and dictionary attacks among conduct for which the law “provides for criminal penalties.” The Act doesn’t mention email-finder tools, so keep a record of where each address came from.

How you register your sending domains matters too. Registering two or more domains, or five or more email accounts, with information “that materially falsifies the identity of the actual registrant” and then sending multiple commercial emails from them is a federal crime, punishable by up to a year in prison and more in aggravated cases (18 U.S.C. 10373).

“Multiple” means more than 100 emails in 24 hours, 1,000 in 30 days or 10,000 in a year. Register the secondary domains and mailboxes you use for cold email under your real business details.

Which state laws let a recipient sue over a cold email?

At least three do: Washington, California and Maryland let recipients sue over a commercial email that uses someone else’s domain, hides where it came from or has a false or misleading subject line. CAN-SPAM itself gives recipients no lawsuit, but it leaves standing state rules against “falsity or deception in any portion of a commercial electronic mail message” (15 U.S.C. 7707(b)(1)2).

This page covers those three states; it doesn’t survey every state.

WashingtonCaliforniaMaryland
LawRCW 19.190.0207, .0307, .0407Bus. and Prof. Code 17529.59 (definitions in 17529.19)Commercial Law 14-300210 and 14-300310
Covers emailSent from a computer in the state, or to an address you know or have reason to know is a resident’sSent from California, or to a California address: billed there, usually opened there, or given to a residentSent from a computer in the state, or to an address you know or should have known is a resident’s
Subject lineFalse or misleading information, judged on what you actually knew or what’s “fairly implied”One you know would likely mislead a reasonable recipient about a material factFalse or misleading information that can deceive the recipient
ReachesAnyone who sends, conspires to send or assistsAnyone who advertises in the email, not only whoever sendsAnyone who sends, conspires to send or assists
Who can sueThe recipient; an interactive computer serviceThe recipient of an unsolicited ad; an email service provider; the Attorney GeneralThe recipient; a third party whose domain or address was used without permission; an interactive computer service provider
Recipient gets$100 per email or actual damages, whichever is greaterActual damages, $1,000 per email up to $1,000,000 per incident, or both$500 or actual damages, whichever is greater, plus reasonable attorney’s fees

From the Washington State Legislature, California Legislative Information and Maryland General Assembly websites.

In California, “unsolicited” means sent without the recipient’s direct consent or a prior business relationship with the advertiser, which describes a cold email (17529.1(o)). A court cuts the $1,000 to at most $100 per email and $100,000 per incident if you had careful procedures to prevent violations, and a violation is also a misdemeanor (17529.5(b)(2), (c)).

Washington and Maryland treat you as knowing that a recipient lives in the state if the registrant of the recipient’s email domain would say so on request (RCW 19.190.020(2); Md. Commercial Law 14-3002(c)). So not asking doesn’t help.

Washington changed in 2026. A 2026 law cut a recipient’s damages from $500 to $100 per email and added the knowledge test to the subject-line rule in .020. It applies to lawsuits filed on or after June 11, 2026, even over older emails (ESHB 22747, and the note under RCW 19.190.020).

A year earlier, Washington’s Supreme Court held that the rule reaches “any false or misleading information” in a subject line, such as a promotion’s end date, not only whether the email is an ad. “Mere puffery,” meaning opinions and hyperbole, isn’t covered (Brown v. Old Navy, LLC, April 17, 20258). The 2026 law kept the words “false or misleading information in the subject line.”

The consumer-protection version in .030 wasn’t amended, so its subject-line rule still has no knowledge wording. The text alone doesn’t settle how the two versions fit together after 2026; for a Washington dispute, that’s a question for a Washington lawyer.

What all three target: someone else’s domain, a false or hidden origin, and false or misleading subject lines. Send from domains you own or are authorized to use, keep the From and routing details true, and keep subject lines accurate and consistent with the email.

What can a violation cost, and who enforces CAN-SPAM?

Up to $53,088 per email in an FTC case, the 2025 level the FTC said on September 15, 2026 it would keep for 2026.

The FTC’s guide applies that cap to “each separate email in violation.” It’s the figure in the FTC’s penalty table for penalties assessed after January 17, 2025 (16 CFR 1.98(d)5).

Why there was no 2026 increase: the cap is normally adjusted every year using the October consumer price index. The government shutdown kept the Bureau of Labor Statistics from producing the October 2025 figure, so the Office of Management and Budget cancelled the 2026 adjustment (memorandum M-26-11, April 17, 2026). The FTC’s notice says it “will continue to apply the 2025 penalty levels” (91 FR 584466).

If you see a lower figure quoted, it belongs to an earlier year: $46,517 applied to penalties assessed after January 10, 2022, $50,120 after January 11, 2023 and $51,744 after January 10, 2024 (earlier versions of 16 CFR 1.98 in the eCFR). Check the amount again in early 2027.

  • The FTC enforces the Act as an unfair or deceptive practice. Other federal agencies enforce it for the businesses they oversee, such as banks and securities brokers (7706(a)–(b)).
  • State attorneys general can sue over header or subject-line violations, or a “pattern or practice” of breaking the opt-out and footer rules. They can recover residents’ actual losses or up to $250 per email, whichever is greater, capped at $2,000,000 except for header violations. A court can triple that for willful and knowing or aggravated violations, or reduce it if you had “commercially reasonable practices and procedures” in place (7706(f)).
  • Internet access providers that are harmed can sue for up to $100 per email for header violations and up to $25 for others, capped at $1,000,000 except for header violations, and also subject to tripling (7706(g)).
  • Recipients get no lawsuit under the Act: its enforcement section names only the agencies, states and providers above (7706). The state laws are where recipients can sue.

How do the six answers change for a founder, an agency and a freelance SDR?

The same rules land differently depending on who sends for whom; pick the role closest to yours.

Founder sending about 20 emails a week from Gmail

  • Commercial? Yes, when the email pitches your service.
  • Sender: You.
  • Address: Your business address, a PO box or a registered private mailbox.
  • Opt-out list: One list, yours.
  • Address sources: Note where each address came from.
  • State law: An honest domain, From line and subject line, since recipients in Washington, California and Maryland can sue.
  • After the last send: Keep the reply mailbox open for 30 days.

Three-person agency, four clients, its own secondary domains

  • Commercial? Yes, each campaign promotes a client.
  • Sender: Each client (it procures); the agency initiates too.
  • Address: Each client’s, in that client’s emails.
  • Opt-out list: Four lists, one per client, each covering every mailbox and domain used for that client. Collect each client’s existing opt-outs first.
  • Address sources: The same, per client, including any list a client hands you. Register the domains under the agency’s real details.
  • State law: The same. California’s law also reaches each client as the advertiser.
  • After the last send: When a client leaves, keep accepting its opt-outs for 30 days after its last send and hand the list back.

Freelance SDR in the client’s Google Workspace

  • Commercial? Yes, it promotes the client.
  • Sender: The client (it procures); you initiate too.
  • Address: The client’s.
  • Opt-out list: The client’s. Log opt-out replies that land in the client’s mailbox and stop within 10 business days.
  • Address sources: Ask the client where its list came from.
  • State law: The same; you send from the client’s domain with its permission.
  • After the last send: The client keeps the mailbox and the list when your contract ends.

If your role isn’t here, go back to the question it turns on. Two companies in one email? Start with the designated-sender test in who counts as the sender.

How this page was checked

Everything was checked on September 29, 2026 against the text itself, and checked again on October 2, 2026. That means the CAN-SPAM Act (15 U.S.C. 7702 and 7704–7707) with 18 U.S.C. 1030 and 1037 on govinfo, the FTC’s CAN-SPAM Rule (16 CFR 316), its penalty table (16 CFR 1.98, current and 2022–2024 versions), its business guide and its September 15, 2026 Federal Register notice. The eCFR and Federal Register texts were read through those sites’ official data services.

State law comes from the Washington, California and Maryland legislatures’ own websites, including Washington’s 2026 amending law, plus the Washington Supreme Court’s opinion in Brown v. Old Navy. Tool features and plan conditions come from Instantly’s and Smartlead’s help centers and pricing pages, plus Smartlead’s FAQ page, read the same day and rechecked on September 30 and October 2, 2026.

Search results for “can spam b2b” and “can spam act cold email” were read on September 28 and 29, 2026 to find which penalty figures and state-law claims had gone out of date; every legal figure here is taken from the statute, rule or notice itself. This page is research-based: no test emails were sent, neither tool was used for it, and no attorney reviewed it.

Tools that keep each client’s opt-outs separate

An opt-out binds one sender, so for an agency most of the day-to-day CAN-SPAM work is list-keeping: every “stop” from a client’s prospect has to reach every mailbox used for that client, and it shouldn’t leak into another client’s campaigns. Instantly and Smartlead both document how they scope suppression when you send for several clients, and they scope it in opposite ways. A sheet per client does the same job by hand. Whichever you pick, the client’s address and the ad notice in the footer, and the call on who the sender is, stay your job.

Instantly: a workspace per client

Each workspace keeps its own campaigns, contacts and analytics; leads, campaigns and stats can’t be shared between workspaces, and an email account connects to one workspace at a time (help, September 14, 202611). The Global Blocklist is “workspace-wide,” takes addresses or whole domains, and is checked at upload and across running campaigns (help, July 13, 202611), so one client’s list covers that client’s mailboxes and no one else’s. Which plans include the blocklist, and its switch that adds unsubscribed leads automatically, isn’t settled: the feature table on Instantly’s pricing page12 and its plan comparison11 disagree on the first, and the blocklist article leaves the plan for the second unclear. Our UK guide sets out what each of Instantly’s three pages says about the blocklist’s plan.

  • Footer: “Insert unsubscribe link” in each email step; a lead who clicks and confirms shows as “Unsubscribed,” but the link doesn’t work in test emails sent from Preview mode (help, July 8, 202611). Add the client’s address to the copy or signature yourself.
  • Not in the help center: whether, without that switch, a lead who unsubscribes in one campaign is dropped from the workspace’s other campaigns, or what happens to the link after a subscription ends. Check both in your account.
  • Best fit if: you want each client’s leads, mailboxes and opt-outs kept apart by design.
  • Not for: sending only for yourself or for one client, where a workspace per client adds nothing, or an agency that doesn’t want a separate subscription for every client.

Smartlead: one account, block entries tagged by client

Smartlead assigns each Global Block List entry to a client or leaves it unassigned. An unassigned entry “does not carry over into any client-specific campaigns,” so blocking a lead for four clients takes four entries (help13). A click on the unsubscribe link marks the lead “unsubscribed,” and it’s skipped if it turns up in a new list for another campaign; a lead who replies “not interested” you add to the block list yourself (help13). That article doesn’t say how either interacts with client assignment, or what happens to the link after a subscription ends.

  • Footer: “Add unsubscribe message in all emails” in campaign settings, or a %unsubscribe-text% placeholder. “Optimize Email Delivery” strips HTML, including the link, and can’t be changed once the campaign has started. Add the client’s address yourself.
  • Best fit if: you’d rather run every client from one account and will assign each block entry to every client it applies to.
  • Not for: a team that won’t assign block entries client by client, since an unassigned entry doesn’t reach any client’s campaigns.

A sheet per client, by hand

Keep one sheet per client and check it against every mailbox’s send list before each batch. You read the replies, add each “stop” to that client’s sheet, and the signature carries a reply line and the client’s address. A reply-based opt-out meets the 30-day rule for as long as the mailbox stays open and someone reads it, even after you cancel a sending tool; neither Instantly’s nor Smartlead’s help center says whether its unsubscribe link keeps working once you cancel. Sending only for your own business, this is a single sheet with your own address in the signature. For how a sequencer fits with domains, mailboxes and a CRM once you outgrow it, see where a sequencing tool sits in a small outbound stack.

  • Best fit if: you send for yourself or a single client, a few dozen emails a week, from one or two mailboxes.
  • Not for: several clients across several mailboxes, where checking every sheet by hand before each batch gets slow.

What changes as clients are added: on Instantly each client workspace is a separate subscription, and Instantly’s own pages disagree on which plans can add one; on Smartlead every client sits on one plan from Pro up, but its pricing page14, FAQ page14 and client-access article13 give three different answers on what each client adds. Compare at your own client count and volume, and get the vendor’s answer in writing before a client budget depends on it. For the Instantly side, see what an agency pays for one Instantly workspace per client.

Help-center articles, pricing pages and Smartlead’s FAQ page read September 29, 2026 and rechecked September 30 and October 2, 2026; dates are the articles’ own, and Smartlead’s articles show none. Vendors change features and plans often, so confirm each point in your own account.

The List-Unsubscribe header is a mailbox-provider feature, not a CAN-SPAM requirement: the Act asks for a reply address or other mechanism “clearly and conspicuously displayed,” not for the header (for the providers’ own rules, see Gmail’s and Yahoo’s one-click unsubscribe rules for bulk senders).

Instantly

Best fit if you send for several US clients and want each client’s leads and opt-outs kept in a workspace of its own; not needed if you send only for yourself or one client. Instantly’s help center says each workspace needs its own subscription, and its pages disagree on which plans can add one (checked October 2, 2026).

Visit Instantly

Direct link to Instantly. We don’t earn anything from it.

FAQ

Is CAN-SPAM still in effect in 2026?

Yes. The FTC’s guide describes the Act and the CAN-SPAM Rule as law it enforces, the rule is in the current eCFR (16 CFR 316), and the FTC’s September 15, 2026 notice set its penalty levels for 2026 (see what a violation can cost).

Does every follow-up in a sequence need the opt-out notice and the address?

Yes, every one that’s commercial. The footer rule applies to “any commercial electronic mail message” (7704(a)(5)(A)), and a follow-up that bumps or restates your pitch is still promoting your offer. A reply answering a question the prospect asked you is judged on its own content (16 CFR 316.3).

Do the US rules apply if I send from outside the US?

For email to US recipients, generally yes. The rules apply to email sent “to a protected computer” (7704(a)), a term the Act takes from 18 U.S.C. 1030(e)(2)(B)3: a computer “used in or affecting interstate or foreign commerce or communication.” Section 7704 applies to “any person,” with no exception for senders abroad, and the Washington, California and Maryland laws also turn on where the recipient is, not only where you send from. If your list also has UK or EU prospects, see whether UK rules reach a sender outside the UK and which EU countries require consent before you email a business.

Can a coworking space or “virtual office” be my postal address?

Only if it fits one of the rule’s three forms: your current street address, a PO box you’ve “accurately registered” with the USPS, or a private mailbox you’ve “accurately registered with a commercial mail receiving agency” (16 CFR 316.2(p)). The rule doesn’t name coworking or virtual-office services, so ask the provider whether the address is a private mailbox registered in your business’s name.

Sources

  1. CAN-SPAM Act: A Compliance Guide for Business — Federal Trade Commission (August 2023, “Edited January 2024 to reflect Inflation-Adjusted Civil Penalty Maximums”), accessed October 2, 2026
  2. 15 U.S.C. 7702, Definitions, 7704, Other protections for users of commercial electronic mail, 7705, Businesses knowingly promoted by electronic mail with false or misleading transmission information, 7706, Enforcement generally and 7707, Effect on other laws — United States Code, 2023 edition, US Government Publishing Office (govinfo.gov), accessed October 2, 2026
  3. 18 U.S.C. 1037, Fraud and related activity in connection with electronic mail and 18 U.S.C. 1030(e)(2) (“protected computer”) — United States Code, 2023 edition, govinfo.gov, accessed October 2, 2026
  4. 16 CFR 316.2, Definitions, 316.3, Primary purpose and 316.5, Prohibition on charging a fee or imposing other requirements on recipients who wish to opt out — Legal Information Institute, Cornell Law School, checked against the current eCFR text of part 316, accessed October 2, 2026
  5. 16 CFR 1.98, Adjustment of civil monetary penalty amounts (current version, 90 FR 5581, and the versions in effect on June 1 of 2022, 2023 and 2024) — eCFR, National Archives, accessed October 2, 2026
  6. Civil Penalty Inflation Adjustments, 91 FR 58446 (September 15, 2026) — Federal Trade Commission, Federal Register, accessed October 2, 2026
  7. RCW 19.190.020, 19.190.030 and 19.190.040, and Engrossed Substitute House Bill 2274, chapter 135, Laws of 2026 — Washington State Legislature, accessed October 2, 2026
  8. Brown v. Old Navy, LLC, No. 102592-1 (April 17, 2025), certified question from the US District Court for the Western District of Washington — Washington State Supreme Court, Washington Courts, accessed October 2, 2026
  9. Business and Professions Code section 17529.1 and section 17529.5 — California Legislative Information, accessed October 2, 2026
  10. Commercial Law 14-3001, Definitions, 14-3002 and 14-3003 — Maryland General Assembly, accessed October 2, 2026
  11. Global Blocklist and Email Outreach Plans Comparison (both July 13, 2026), Manage Workspaces and Team Members (September 14, 2026), How to Add Unsubscribe Link (July 8, 2026) — Instantly Help Center, accessed October 2, 2026
  12. Pricing (the “Compare features” table) — Instantly, accessed October 2, 2026
  13. What is Global Block List?, How does unsubscribing work? and Agency View & Client Access — Smartlead Help Center (undated), accessed October 2, 2026
  14. Pricing (the “Clients / Workspace” row and the FAQ on whitelabeling and client workspaces) and Smartlead FAQs (whitelabeling pricing) — Smartlead, accessed October 2, 2026