Email Compliance
CAN-SPAM, GDPR, CASL, consent, unsubscribe, and provider bulk-sender rules.
- Consent and opt-in
- Unsubscribe requirements
- Gmail and Yahoo bulk sender requirements
- Data retention and DSARs
- HIPAA-compliant email
- Apple Mail Privacy Protection
Consent and opt-in
Consent is the documented permission a recipient gives to receive marketing email. Laws differ on whether it must be express (opt-in) or may be implied (existing relationship), and on how long it lasts.
26 more for specific providers, platforms, industries, and regions
Unsubscribe requirements
Unsubscribe compliance covers the legal and provider requirements for letting recipients opt out: a visible link, one-click List-Unsubscribe headers (RFC 8058), and processing within a defined window.
26 more for specific providers, platforms, industries, and regions
Gmail and Yahoo bulk sender requirements
Since February 2024, Gmail and Yahoo require senders of 5,000+ daily messages to authenticate with SPF, DKIM, and DMARC, support one-click unsubscribe, and keep spam complaint rates under 0.3%.
16 more for specific providers, platforms, industries, and regions
Data retention and DSARs
Data retention policy defines how long mailbox data and marketing records are kept and when they are deleted. DSARs (data subject access requests) require producing or erasing a person's data on request.
11 more for specific providers, platforms, industries, and regions
HIPAA-compliant email
HIPAA-compliant email protects electronic protected health information (ePHI) in transit and at rest, with access controls, audit logs, and a Business Associate Agreement (BAA) with any vendor that handles the mail.
16 more for specific providers, platforms, industries, and regions
Apple Mail Privacy Protection
Mail Privacy Protection (MPP) is an Apple Mail feature that preloads message content, including tracking pixels, through Apple proxies, hiding the recipient's IP and making opens appear whether or not the person read the message.