Note what the law does not require, because it surprises people. Prior consent is not needed for commercial email in the United States. You may contact somebody who has never heard of you, provided the message is honest about who sent it and gives them a way to stop it.

Note also what it does require that people omit. A physical postal address is mandatory and a post office box that meets the relevant requirements is acceptable. Most cold email sent by small businesses lacks it, and its absence is the single most common breach.

The opt out must be genuine. A working link or a plain instruction to reply, honoured within ten business days, with no fee, no login, and no requirement to give any information beyond the address being removed. Once somebody opts out you may not sell or transfer their address either.

Deception is the other category the law addresses. Misleading subject lines, a false sender name, a fake reply address, or a subject beginning with Re to imply an earlier exchange are all breaches as well as being ineffective. Anybody who has received one recognises it immediately.

Outside the United States the position is considerably stricter and consent based. The European Union under its data protection regime, the United Kingdom, and Canada under its anti spam legislation each require a lawful basis or prior consent for most commercial email, with penalties that are substantial. If any recipient is in those jurisdictions, take advice before sending rather than assuming the American rules travel.

Business to business contact has some accommodation in several of those regimes, and the detail varies enough that it is not safe to generalise from a summary. A single conversation with somebody qualified, recorded for future reference, is cheaper than discovering the position afterward.

Keep records of what you sent, to whom, and when, along with any opt out you received and the date you actioned it. If a complaint arises, the record is what demonstrates compliance, and reconstructing it later is not possible.

Understand that platform rules apply on top of the law. Email providers enforce their own standards, and a sending pattern that is legal can still get an account suspended or a domain filtered. Legality is the floor rather than the objective.

Then treat the requirements as a default rather than a checklist. A signature block carrying your business name, postal address, and an opt out line on every message means you never have to remember, and it costs three lines.

Check the rules again periodically rather than once, since this area has changed repeatedly and enforcement priorities shift. What was acceptable three years ago is not a safe guide to what is acceptable now.

Apply the strictest standard you are likely to encounter rather than the minimum required where you sit. Consent based practice is more work and it is defensible everywhere, which removes the need to track which recipient is covered by which regime.

Keep a suppression list of everybody who has opted out and check every send against it, because contacting somebody after they asked you to stop is both a breach and the fastest way to attract a complaint.

Take advice once from somebody qualified and write down what they tell you, since the cost of that conversation is trivial against the cost of getting it wrong at volume.