Cold email without opt in is legal for B2B in most markets, with conditions. The two-jurisdiction test and what each regime requires.
Yes, you can send cold email without opt in to business contacts in most major markets, but the rules differ sharply by where the recipient sits. In the US, CAN-SPAM is an opt-out regime: no prior permission needed, but you must identify yourself honestly, include a real postal address, and honor unsubscribes fast. In the EU, B2B cold email is lawful under GDPR's "legitimate interest" basis, but only if you can document a three-part test and disclose your data source. This is not legal advice, and this post is about the "no opt-in" question specifically, distinct from our broader guide to whether B2B email databases are legal.
Cold email without opt in is B2B outreach sent to a recipient who never subscribed or gave prior consent. It is permitted in opt-out jurisdictions such as the US under CAN-SPAM, and in the EU for business contacts under GDPR's legitimate interest basis, provided the sender meets that regime's disclosure, opt-out, and documentation requirements.
For B2B, generally yes, with conditions that vary by jurisdiction. Overloop's 2026 legal overview and Instantly's compliance guide both note that no major market bans B2B cold email outright. What each market bans is deception, ignored opt-outs, and, in the EU, processing personal data without a lawful basis.
The distinction that matters is opt-out versus opt-in. The US, Canada in practice for certain B2B relationships, the UK for corporate-body recipients, and Australia for role-based business addresses lean opt-out or carve out B2B. Most of the EU treats a named person's work email as personal data, so you need a lawful basis, and for cold outreach that basis is legitimate interest, not consent. B2C is stricter almost everywhere and usually requires prior consent. See how to stay GDPR compliant in cold outreach and GDPR compliant lead generation explained.
The penalties are not small. CAN-SPAM violations can run up to $53,088 per email as of early 2025, per Overloop. GDPR fines reach €20 million or 4% of global annual revenue. The risk is real, but it is manageable if you meet the requirements below.
CAN-SPAM lets you email business contacts with no prior opt in. In exchange it requires five things: accurate "From" and header information, a subject line that is not misleading, identification of the message as an outreach message, a valid physical postal address in the email, and a working opt-out that you honor within 10 business days. Miss any of these and each email is a potential violation.
Practically, for cold sales email, that means a real sender name, a truthful subject, a one-line opt-out or reply-to-unsubscribe mechanism, and your company's mailing address in the footer. You do not need a formal unsubscribe management system for low volume, but you must actually stop emailing anyone who asks. See how to maintain list hygiene in B2B outreach.
In the EU, emailing a named person at work is processing their personal data, so you need a lawful basis. For cold B2B outreach that basis is Article 6(1)(f), legitimate interest. To rely on it you run and document a Legitimate Interest Assessment, or LIA, which has three parts: the purpose (is there a genuine business reason to contact this person), necessity (is email the least intrusive way), and balancing (do your interests outweigh the recipient's rights and reasonable expectations).
You also have to process only the minimum data needed, disclose where you got the contact's details, offer an easy objection or opt-out, and honor objections immediately. Sales Force Europe notes that applying legitimate interest without a documented LIA is one of the most common outbound compliance mistakes. Some member states also apply stricter national rules for electronic marketing, so check the specific country. See how to find GDPR-safe email addresses.
The UK sits between the two regimes. Post-Brexit UK GDPR mirrors EU GDPR, so a named person's work email is personal data and you need a lawful basis, usually legitimate interest with a documented assessment. But UK PECR rules treat email to a "corporate subscriber," a limited company or a public body, more permissively than email to a sole trader or partnership, so a role-based address at a limited company is a stronger position than a named individual's.
Canada's CASL is one of the strictest anti-spam laws in the world and is closer to opt-in. It generally requires consent, express or implied, before sending commercial email. Implied consent can arise from an existing business relationship or from a business contact who has "conspicuously published" their address without a notice refusing unsolicited mail. Relying on published-address implied consent has a two-year window and specific conditions, so document why each contact qualifies.
Australia's Spam Act also leans toward consent but recognizes inferred consent for business addresses where the role and the message are clearly related, for example emailing a "purchasing@" address about a procurement-relevant offer. You still must identify the sender and include a functional unsubscribe.
The practical takeaway: opt-out is really a US-style position, and most other developed markets require either a documented lawful basis or some form of consent. Segment by country, not by continent, and keep a note on why each contact clears that country's bar. See is it legal to use B2B email databases for cold outreach.
Emailing someone's personal address without opt in is a different, weaker position. CAN-SPAM still applies but the message looks more like consumer spam, and under GDPR a personal Gmail has a stronger expectation of privacy than a corporate address, which makes the balancing test harder to pass. Stick to role-based or named business addresses at the company domain. See how to get a personal email from a business email for why you usually should not.
There is also a grey zone: a person's name at a personal domain that they clearly use for work, common with founders, consultants, and small agencies. Treat these as personal for risk purposes. The safer read is that if the domain is not the company's, the expectation of privacy is higher, so you need a stronger legitimate-interest justification and a very relevant, minimal message. When the company has its own domain, use the address at that domain instead.
The Two-Jurisdiction Test: before sending any cold email without opt in, answer two questions. Which regime governs this recipient, opt-out like the US or lawful-basis like the EU, and can you meet that regime's specific bar for this send?
The test forces the question that actually determines legality: where is the recipient. A list that mixes US and EU contacts cannot be sent under one set of rules. Split it.
For the opt-out branch, the bar is procedural: honest identity, truthful subject, physical address, working and honored opt-out. If your footer has those and your headers are not spoofed, a no-opt-in send to a US business contact is compliant.
For the lawful-basis branch, the bar is documentary: a written LIA that passes purpose, necessity, and balancing, plus source disclosure and immediate handling of objections. If you cannot produce the LIA, you are not compliant even if the email is polite and relevant.
The quotable version: "Cold email without opt in is not a yes or no question. It is a where question, and each where has a checklist."
The test also depends on data you can stand behind: knowing the recipient's location and being able to say where the contact came from. A scraped list with no provenance fails the EU branch on disclosure alone. See CCPA and B2B data compliance guide and cold email greeting lines for the message-level details.
Sending cold email without opt in legally depends on two things: knowing where each contact is based, and being able to state where the data came from. Guesswork on either point is where compliance problems start.
InboundLabs is a sales intelligence platform built on a database of 280M verified B2B contacts with 98% email deliverability on verified contacts. It lets you filter by industry, headcount, region, and title, so you can segment recipients by jurisdiction before you send and reach verified business addresses rather than scraped personal ones. Monthly plans, no annual lock-in. Free to start, no credit card required.
See how InboundLabs finds verified contacts instantly → inboundlabs.app
Cold email without opt in is legal for B2B in most markets, but "legal" means "compliant with the regime that governs the recipient." In the US, that is CAN-SPAM: honest headers, a postal address, and an opt-out you honor. In the EU, it is GDPR legitimate interest: a documented LIA, source disclosure, and immediate handling of objections. Split your list by jurisdiction, meet the right checklist, and email business addresses, not personal ones. When in doubt, get legal advice for your situation.
Do I need permission before sending a B2B cold email?
Not in opt-out jurisdictions like the US, where CAN-SPAM allows outreach without prior consent as long as you identify yourself honestly, include a postal address, and honor opt-outs. In the EU you do not need consent for B2B either, but you need a documented legitimate interest basis instead.
Is cold email without opt in legal under GDPR?
Yes, for business contacts, under the legitimate interest basis in Article 6(1)(f). You must run and document a Legitimate Interest Assessment covering purpose, necessity, and balancing, disclose your data source, minimize the data you process, and honor objections immediately. Some EU countries apply stricter national rules.
What has to be in a compliant cold email footer?
Under CAN-SPAM: a valid physical postal address and a working opt-out mechanism. Under GDPR: a way to object, and ideally a short statement of why you are contacting them and where you got their details. A truthful sender name and subject line are required in both.
Can I cold email personal email addresses without opt in?
It is a weaker legal position. CAN-SPAM still applies, and under GDPR a personal address carries a higher expectation of privacy, making the legitimate interest balancing test harder to pass. Use named or role-based addresses at the company domain instead.
How fast do I have to honor an opt-out?
Under CAN-SPAM, within 10 business days, though sooner is better and expected. Under GDPR, an objection should be actioned without undue delay, effectively immediately. In both cases, suppress the address permanently so it is not re-added in a future list.
What are the penalties for getting this wrong?
CAN-SPAM violations can reach $53,088 per email as of early 2025. GDPR fines can reach €20 million or 4% of global annual revenue. In practice, most enforcement targets deceptive senders and ignored opt-outs rather than a single relevant B2B email, but the exposure is real.
LSI keywords: cold email without opt in, CAN-SPAM compliance, GDPR legitimate interest, B2B cold email legality, opt-out regime, legitimate interest assessment, source disclosure, unsubscribe, postal address requirement, jurisdiction, data provenance, lawful basis
Video in cold email only lifts replies when the thumbnail earns the click. Seven rules, real Wistia and Instantly benchmarks, and where video backfires.
Seven annotated cold email examples built to survive the 2-second skim, the 10-second relevance scan, and the 30-second read of the ask.
Six case study cold email templates that lead with the result and pass a four-axis match test before you send.
No commitment. No credit card. Just 50 free verified contact lookups.