CAN-SPAM and Review Requests: What the Law Actually Requires
Review requests feel exempt from spam law because nothing is being sold. The FTC's own test does not carve out that exception. Here is what applies.
The short version
- CAN-SPAM applies to any commercial email regardless of volume or B2B status, and its 'transactional or relationship' exemption is a narrow, six-item list that a review request does not obviously fit.
- The FTC has not published guidance specifically on review-request emails, but its 2023 case against Experian shows it penalizes businesses that label marketing as account-related to skip the opt-out requirement.
- The safe posture costs nothing extra: accurate sender identity, a truthful subject line, a real postal address, and a one-click opt-out honored within 10 business days — the same things a well-built review request already needs.
A review request does not look like spam. It is not selling anything, it goes to someone who already paid you, and it asks for five minutes of their time, not their credit card. That is exactly why most small businesses assume it sits outside CAN-SPAM, the federal law that governs commercial email. Nothing in the statute says that.
This is general information, not legal advice. Rules vary and change; talk to a lawyer about your own situation.
CAN-SPAM does not care that you are not "marketing"
The FTC's compliance guide defines the law's scope in one sentence: it covers "any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service." Two details in that guide surprise people who assume the law is about bulk marketing blasts.
First, there is no volume threshold. The guide is explicit that "the law makes no exception for business-to-business email," and a single message can be a violation — the FTC's own example is one email to a former customer announcing a new product line. Second, coverage is decided by the content and purpose of the message, not by whether the sender thinks of it as marketing.
Under 15 U.S.C. § 7704, the statute that sits under CAN-SPAM, every commercial email has to carry:
- Header information (From, Reply-To, routing) that is not materially false or misleading
- A subject line that does not mislead about "a material fact regarding the contents or subject matter of the message"
- "Clear and conspicuous identification that the message is an advertisement or solicitation"
- "A valid physical postal address of the sender"
- A working, one-step opt-out mechanism, honored within 10 business days of the request, that keeps working for at least 30 days after the message was sent
Penalties reach $53,088 per violating email, per the FTC's 2025 inflation-adjusted penalty schedule, effective 17 January 2025 under a rule published in the Federal Register. There was no increase for 2026: an April 2026 OMB memorandum froze federal civil penalty adjustments government-wide after a lapse in appropriations left the Bureau of Labor Statistics unable to produce the October 2025 inflation data the formula requires, so $53,088 remains the figure to plan around, confirmed as of 2026. "Per violating email" is doing real work in that sentence — a batch of a few hundred non-compliant requests is a few hundred separate exposures, not one, and an automated follow-up sequence that resends the same broken message multiplies the count again.
How much leeway do you get on the "this is an ad" disclosure
The advertisement-disclosure requirement sounds like it demands a literal "ADVERTISEMENT" banner, and it does not. The FTC's guide says plainly: "the law gives you a lot of leeway in how to do this," and in practice most compliant commercial email satisfies it through plain, honest framing in the subject line and opening lines rather than a formal label. The part businesses get wrong is not the wording — it is assuming the disclosure does not apply at all because the message does not feel like an ad. If a message's primary purpose is commercial under the test above, the disclosure requirement travels with it regardless of tone.
The exemption everyone reaches for, and why it is narrower than it sounds
CAN-SPAM exempts messages whose entire content is "transactional or relationship" in nature. The FTC's guide lists what qualifies, and the list is short and specific — a message counts only if it does nothing but:
| Category | Does a review request fit? |
|---|---|
| Facilitate or confirm a transaction the recipient already agreed to | No — the transaction is already complete |
| Provide warranty, recall, safety, or security information about something they bought | No |
| Notify of a change in terms, features, or standing on an ongoing membership, subscription, account, or loan | No — there is no ongoing account relationship in most small-business purchases |
| Provide periodic account balance information | No |
| Provide information about an employment relationship or benefits | No |
| Deliver goods or services already agreed to | No |
None of the six categories describes "please tell other people what you thought of your visit." That is not a technicality — the FTC's own guide warns against assuming any message to an existing customer is automatically transactional, and instructs businesses to ask whether "a reasonable consumer reading your email would understand" it as one of the six listed purposes. I could not find an FTC advisory opinion, rulemaking comment, or enforcement action that addresses review-request emails specifically, so treat the table above as the conservative reading of the rule as written, not a settled ruling. On the reading the rule supports, a review request looks like commercial email by default, which means it owes the full checklist above, not just the ones that feel relevant.
What happens when a business calls marketing something else
The FTC does have a recent, on-point case for the general move of relabeling a message to dodge the rule. In August 2023 the FTC and the Department of Justice reached a $650,000 settlement with Experian Consumer Services over emails that told recipients the message "contains important information about your account" while actually pitching credit cards, credit-score upsells, and paid membership programs — and that, in some cases, went to people who had already opted out. The Department of Justice's own announcement frames the allegation the same way: the emails were commercial in substance no matter what the header claimed. The FTC's position was straightforward — what the message actually promotes decides its category, not what the subject line calls it.
That is the exact failure mode to avoid with review requests. Calling the message "feedback" or "your recent visit" in the subject line does not change what it is if the FTC's test would classify it as commercial. The safer approach is to build the request so it complies either way — the checklist costs nothing extra if you were already running a legitimate outreach.
Does state law add anything on top?
CAN-SPAM was written to end a patchwork of over 30 different state anti-spam statutes, and it mostly succeeded: the Act supersedes state laws "that expressly regulate the use of electronic mail to send commercial messages," so a business that meets the federal checklist does not also need to track a separate state email-marketing statute. The carve-out is narrow but real — state laws against fraud, deception, trespass, contract violations, or computer crime keep applying on top of CAN-SPAM, because those laws are not specific to email in the first place. In practice, that means the federal checklist above is close to the whole compliance picture for a review-request email, with ordinary fraud and deception law sitting underneath it as it would for any business communication.
If a vendor sends the email for you, you are still on the hook
Most small businesses do not run their own mail server for this — they use a review-request tool, a CRM, or an email platform. CAN-SPAM's multi-party rule (in the same FTC compliance guide) says that when a message is sent by a third party on a business's behalf, both the business and the platform can be treated as "initiators," and the business whose product or service is being promoted can still be held liable if the platform does not follow the rules. Vendors can agree on a single "designated sender" to carry the compliance burden, but that only works if the designated party actually meets every requirement — it is not a liability shield by itself.
Practically: know who owns your sending domain, whether the Reply-To address reaches a real inbox at your business, and whether opt-outs are actually suppressed going forward rather than just acknowledged. A platform sending review requests under your business's name from a branded domain — ReviewHero's messages go out as "[Business] via ReviewHero" with Reply-To set to the business's own address, for example — gets you accurate header identity by default, but the physical address and opt-out honoring still need to be true in practice, not just in the platform's marketing copy.
What to do next
- Add a real, current physical mailing address to the footer of every review-request email — a street address, a USPS-registered PO box, or a registered private mailbox all qualify.
- Make sure the "From" name and Reply-To address are your business's real identity, not a noreply address that bounces replies.
- Write the subject line to describe what the email actually is. Do not use "your account" or "important information" language unless the email genuinely is about the recipient's account.
- Confirm your opt-out link works in one click, with no login and no extra form fields, and that a suppressed contact stays suppressed — test it yourself before your customers do.
- If a vendor sends on your behalf, ask them directly how fast opt-outs are honored and who is contractually the "sender" of record. Get the answer in writing, not just a feature-page claim.
Put this on autopilot
ReviewHero asks every customer once, follows up politely, and stops the moment they open the review link. Free to download, and you can set it up from your phone.


