Check a cold email

Generate a compliant footer

How it works

what each law wants in the message
USCAN-SPAM: honest From and subject, postal address, opt-out honoured in 10 daysOPT-OUT
EUGDPR + ePrivacy: legitimate interest for B2B in most states, identify yourself, easy objectionVARIES
UKPECR: corporate addresses fine, sole traders need consent, identity + opt-outB2B OK
CACASL: implied consent only if the address is published for that roleSTRICT
None of them ban cold email outright. All of them fine the ones who leave the footer off.
01

Pick the jurisdiction

Where the recipient sits decides the law. The tool loads the rule set for the US, EU, UK, Canada or Australia, and shows the consent basis that applies to business recipients there.

02

Scan the copy

Subject, body and signature are searched for a postal address, an opt-out or objection route, sender identification, and the subject-line tricks that count as deceptive — fake RE:, fake invoices, fake urgency.

03

Grade each requirement

Every requirement is pass, fail or “cannot tell from the copy” — for things like the ten-day opt-out window that live in your process, not your text.

04

Generate the footer

Give the company name and postal address and the tool writes the two-line footer that satisfies the identification and opt-out requirements, in a tone that does not read as a newsletter.

What CAN-SPAM actually requires

The US law is an opt-out regime: you may send commercial email to someone who never asked, provided the header and From are accurate, the subject line is not deceptive, the message says it is an advertisement in some reasonable way, it includes a valid physical postal address, it offers a clear way to opt out, and opt-outs are honoured within ten business days and never sold on. The fine is per email, up to about $53,000 at the current inflation-adjusted figure, and the FTC pursues volume offenders rather than one-person outreach — but the same requirements are what Gmail's filters look for, and a message with no address and no opt-out reads as spam to a machine before any regulator sees it. The postal address is the item most cold emails miss; a PO Box or a registered agent address counts.

Europe, the UK and the myth that cold email is illegal there

GDPR governs personal data, and a named business email address is personal data; ePrivacy governs unsolicited marketing. For business-to-business email, most member states and the UK allow contact with corporate addresses on the basis of legitimate interest, provided you identify yourself, explain why you are contacting them, keep it relevant to their role, and give an easy way to object — which you must honour. Sole traders and partnerships are treated as individuals under UK PECR and need consent. Germany, Austria and a few others are stricter and effectively require consent for any marketing email, so a German list is a different campaign. The List-Unsubscribe checker covers the header side of the opt-out; this page covers the words.

Canada and Australia

CASL is the strict one. You need express or implied consent before sending; implied consent exists for an address that is conspicuously published — on a website or LinkedIn, say — with no statement that unsolicited mail is unwelcome, and only for messages relevant to the person's role. Identification, contact details and an unsubscribe that works for 60 days are mandatory, and penalties reach millions. Australia's Spam Act is similar in shape with inferred consent for published business addresses, and requires accurate sender identification and a functional unsubscribe honoured within five business days.

Writing the footer without killing the reply rate

A newsletter-style unsubscribe block at the bottom of a one-to-one email is a tell that it is not one-to-one. The footer the tool generates is two short lines in the signature area: the company name and address, and a plain sentence — “If this isn't relevant, reply and I'll stop.” That satisfies the opt-out requirement in every jurisdiction above as long as you actually stop, and the tool's suppression list is where you record it. Pair it with the one-click header so the machine-readable route exists too. This page is a checklist, not legal advice; for a regulated industry or a consumer list, ask a lawyer.

Frequently asked questions

Does a reply-to-opt-out count as an unsubscribe mechanism?

Under CAN-SPAM, yes — the law requires a clear and conspicuous way to opt out, and a reply works if you honour it. CASL and PECR also accept it. Pair it with the List-Unsubscribe header so mail clients can offer it too.

Do I have to write “this is an advertisement”?

CAN-SPAM requires that the message be identifiable as an ad, not that it carries a label; a message from a company offering a service, with a company footer, satisfies that. Explicit ADV labels are only mandated for sexually explicit content.

Is a first email that starts with “Re:” illegal?

In the US a subject line that misleads about the content or context is a violation, and a fake reply prefix is exactly that. In the UK and EU it is a fairness problem under the same rules. Beyond the law, it is the single fastest way to earn a spam report.

Whose law applies — mine or the recipient's?

The recipient's, in practice. Regulators act on complaints from their own residents, and the sending tool will suspend you either way. Segment the list by country and run this against each segment.

Is my copy uploaded?

No. The checks run in your browser and nothing is stored. This is not legal advice.

Last reviewed

Related tools

What to run next

The checks that most often follow this one.

Email content

More in this category

Read more

Guides that go deeper

Services

When the tools tell you something is wrong

The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.

Get in touch

Start with a call

Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.

Thirty minutes, no pitch

We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.

Based inRangpur, Bangladesh — all time zones
RepliesWithin one business day
LicensingWorkspace below list price
Back to top