Back to insights
Checking Compliance Practices

Is email harvesting illegal?

Email harvesting triggers criminal penalties under CAN-SPAM and violates GDPR/CASL. Learn compliant outreach that outperforms scraped lists.

Is email harvesting illegal?

Is email harvesting illegal?

Key Facts

  • Email harvesting carries criminal penalties — including imprisonment — under CAN-SPAM, per the FTC's official compliance guide.
  • Each violating email can cost up to $53,088 in civil penalties, according to the FTC.
  • A single harvested list can trigger fines under CAN-SPAM, CASL (CAD$10M), and GDPR (€20M or 4% of turnover) simultaneously, per a cross-framework comparison.
  • Hiring an agency cannot contract away your legal responsibility — the FTC holds both sender and promoted company liable.
  • Small targeted campaigns of 50 or fewer recipients average 5.8% response versus 2.1% for 500+ blasts, per cold email benchmarks.
  • Gmail now rejects non-compliant bulk email outright, and Microsoft followed for Outlook.com in May 2025, per deliverability research.
  • CNIL fined Orange SA €50 million — the largest cold email fine ever — showing jurisdiction follows the recipient, not the sender.

Yes, Email Harvesting Can Be a Crime — Here's the Law

Yes — and not just in a "you might get fined" way. The FTC's official CAN-SPAM compliance guide states that the law provides for criminal penalties, including imprisonment, for harvesting email addresses or generating them through a dictionary attack — the practice of blasting messages at addresses made up of random letters and numbers in the hope of hitting real inboxes.

To be fair, there is a nuance worth stating plainly. CAN-SPAM itself is an opt-out law that regulates the content of commercial messages, not the act of collecting addresses, as privacy law researchers note. Harvesting is not a standalone civil violation under CAN-SPAM — but it is a criminal trigger, and that distinction rarely saves anyone in practice.

Here's why: a harvested list almost inevitably produces a non-compliant campaign. You can't know whether recipients previously opted out, you have no documented consent, and you have no lawful basis for contacting anyone in the EU or Canada. Each violating email carries civil penalties of up to $53,088, according to the FTC. Send a few thousand messages from a scraped list, and the arithmetic gets frightening fast.

The exposure multiplies across jurisdictions:

  • Canada's CASL allows fines up to CAD$10 million per violation for organizations
  • The EU's GDPR reaches €20 million or 4% of global annual turnover
  • A single purchased or harvested list can trigger enforcement under all three frameworks at once, per a compliance comparison of the major email laws
  • Your obligations follow the recipient's location, not yours — so a sender in Halifax or Houston answers to EU and Canadian regulators when their lists cross borders

One more point that surprises many businesses: you cannot outsource this liability. The FTC is explicit that hiring another company to handle your email marketing doesn't remove your legal responsibility — both the company promoted in the message and the company that sends it can be held accountable. Under GDPR, controllers are fully liable for infringements caused by non-compliant third parties unless they can prove they bore no responsibility at all.

This is exactly why checking compliance practices belongs on your provider-selection checklist. If an agency can't explain where its contact lists come from and how consent is documented, that risk lands on your balance sheet, not theirs. It's the standard we hold ourselves to at Worqd — personalized, permission-aware outreach to relevant accounts, the opposite of a template blast to a scraped list.

And here's the twist: the legal answer and the performance answer are the same. Cold email benchmarks show small, targeted campaigns of 50 or fewer recipients average a 5.8% response rate, while blasts of 500+ average just 2.1% — and Gmail now rejects non-compliant bulk email outright. Harvested lists fail on every axis that matters.

One spreadsheet. Three regulatory regimes. Zero safe harbor.

A single purchased or harvested list puts you in simultaneous violation of CAN-SPAM, Canada's CASL, and the EU's GDPR because each law reaches the recipient, not the sender. The FTC makes clear that criminal penalties — including imprisonment — apply to "harvesting email addresses or generating them through a dictionary attack," and civil penalties reach $53,088 per violating email. Under GDPR, the same campaign lacks a lawful basis, exposing you to fines up to €20 million or 4% of global turnover. CASL adds up to CAD$10 million per violation for organizations when valid consent is missing.

  • CAN-SPAM: unknown prior opt-outs make every send a potential violation
  • CASL: no express or implied consent for bought-in lists
  • GDPR: no lawful basis, no legitimate interest that survives a purchased list

Jurisdiction follows the inbox. If your list contains one French prospect, CNIL can act — as it did with a €50 million fine against Orange SA. If it contains Canadian contacts, the CRTC can pursue a $1.1 million CAD penalty for a purchased-list campaign. The FTC has also made clear that hiring an agency does not contract away your legal responsibility; both the promoted company and the sender can be held liable. GDPR mirrors this: controllers are fully liable for non-compliant processors unless they prove they were not responsible.

This is why Worqd builds outreach around publicly posted, role-relevant contacts — the same standard CASL's "conspicuous publication" test requires — and documents consent at every step. The alternative isn't just risky; it's mathematically worse. Targeted campaigns of 50 or fewer recipients average a 5.8% response rate, while blasts of 500+ fall to 2.1%. Google now rejects non-compliant bulk email outright, so a harvested list doesn't just invite fines — it kills deliverability.

You Can't Outsource the Liability — So Vet Your Provider's Practices

Hiring an agency to run your outreach doesn't move the legal risk off your plate — it just adds another party to it. The FTC's CAN-SPAM compliance guide says it plainly: "Even if you hire another company to handle your email marketing, you can't contract away your legal responsibility to comply with the law."

Both the company whose product is promoted and the company that sends the message can be held legally responsible. Under GDPR, the exposure is even sharper: controllers are fully liable for infringements caused by a non-compliant third party unless they can prove they were not in any way responsible. With fines reaching €20 million or 4% of global turnover, "our vendor handled it" is not a defense — it's an admission.

That makes vetting your outreach partner's compliance practices a legal necessity, not a nice-to-have. Here is a concrete checklist to work through before you sign anything:

  • How are lists built? Ask directly whether contacts come from scraping, purchased lists, or dictionary-style generation. Harvested addresses carry criminal exposure under CAN-SPAM and no lawful basis under GDPR or CASL. The compliant standard is publicly posted, role-relevant contacts — the same three-part "conspicuous publication" test Canada's CASL uses for B2B outreach.
  • How is consent documented and retained? CASL requires consent records be kept at least three years after the last commercial message, and implied consent expires — two years from a transaction, six months from an inquiry. If your provider can't produce records on demand, you have no proof when a regulator asks.
  • How are opt-outs honored? CAN-SPAM requires opt-outs to be processed within 10 business days, and the opt-out mechanism must keep working for at least 30 days after send. The FTC's 2024 Verkada enforcement action — a $2.95 million fine — cited a non-functional opt-out mechanism.
  • Is GDPR-equivalent record-keeping applied everywhere? Email security engineer Marek Novák calls applying one global unsubscribe flag "the worst approach — and the most common." His recommendation, per a CAN-SPAM, GDPR, and CASL comparison: use GDPR-standard consent and record-keeping as the baseline across all segments, since it satisfies CASL and exceeds CAN-SPAM.

There's a performance argument hiding inside the compliance one. Small, targeted campaigns of 50 or fewer recipients average a 5.8% response rate, versus 2.1% for blasts of 500 or more, according to cold email performance data. The same practices that keep you legal — relevance, targeting, restraint — are the ones that get replies.

This is the standard Worqd builds its B2B outreach around: personalized, permission-aware messages to relevant accounts, the opposite of a template blast. But whoever you work with, treat the checklist above as table stakes. If a provider gets vague about where their lists come from or how they document consent, the liability they're being vague about is yours.

The Compliant Alternative Outperforms the Blast Anyway

The numbers tell a story that legal warnings alone can't: small, targeted campaigns (≤50 recipients) average a 5.8% response rate, while 500+ blasts languish at 2.1% according to outreach performance data. Signal-based personalization pushes that further — 15–25% reply rates versus 1–3% for generic sends per the same analysis. Meanwhile, Gmail now rejects non-compliant bulk email outright, and Microsoft followed for Outlook.com in May 2025 as deliverability enforcement has hardened. Harvested-list blasting fails on legal, deliverability, and conversion grounds at once.

Canada's CASL defines what compliant B2B outreach looks like through a three-part "conspicuous publication" test: the address is publicly posted, no refusal notice accompanies it, and the message is role-relevant per a cross-framework compliance guide. That framework aligns with the practical rule of thumb — reference only information that is publicly available and professionally relevant as email security engineers advise. Worqd builds its B2B outreach on exactly this foundation: personalized, permission-aware outreach to relevant accounts, not template blasts.

  • Publicly posted, role-relevant contacts only
  • Signal-based personalization, not merge tags
  • Campaigns small enough to stay human
  • Consent records retained and auditable

The compliant path isn't safer at the cost of results — it's the only path that still reaches the inbox.

What Compliant Outreach Looks Like in Practice

Knowing the rules is one thing. Running outreach that actually follows them — every list, every message, every opt-out — is where most companies quietly fall short, especially when a third party does the sending. And remember, the FTC is blunt on this point: you can't contract away your legal responsibility, so your provider's habits become your liability.

Compliant outreach starts with where the addresses come from. Canada's CASL offers a useful model with its "conspicuous publication" test: an address that is publicly posted, carries no refusal notice, and receives a role-relevant message can be contacted legitimately. The practical rule of thumb from deliverability research is similar — reference information that is publicly available and professionally relevant, never anything that feels like surveillance.

From there, compliant practice comes down to a short discipline list:

  • Build lists from publicly posted, role-relevant contacts — never scraped, purchased, or dictionary-generated addresses.
  • Capture explicit consent at every form and keep records of when and how it was given.
  • Honor opt-outs fast — CAN-SPAM allows up to 10 business days, but best practice is immediate.
  • Keep sensitive form data out of public analytics tools.
  • Personalize every message so it reads as relevant outreach, not a template blast.

This is exactly how Worqd runs B2B outreach: personalized, permission-aware outreach to relevant accounts — the opposite of a template blast. The booking flow requires explicit consent ("I agree to be contacted about my request"), states that details are used only to prepare for the call, and keeps sensitive form fields out of public analytics. Opt-outs are honored quickly, because being legally allowed to send means nothing if you make it hard to stop.

The performance case for this approach is as strong as the legal one. According to cold email performance data, small targeted campaigns of 50 or fewer recipients average a 5.8% response rate, while blasts of 500 or more average just 2.1% — and signal-based personalization pushes replies into the 15–25% range. Meanwhile, Gmail now rejects non-compliant bulk email outright, so the spray-and-pray list doesn't just risk fines; it stops reaching inboxes at all.

The practical takeaway comes from email security engineer Marek Novák: rather than juggling separate rules per country, apply a GDPR-equivalent consent and record-keeping baseline everywhere. Those records satisfy CASL and exceed CAN-SPAM, so one standard covers every jurisdiction your recipients live in.

If you're not sure your current outreach — or your provider's — would survive that check, book a free growth call with Worqd. We'll review how your lists are built, how consent is captured, and where your follow-up leaks, then show you what compliant, higher-converting outreach looks like for your business.

Frequently Asked Questions

Is email harvesting actually illegal?
Yes — the FTC's CAN-SPAM compliance guide states the law provides for criminal penalties, including imprisonment, for harvesting email addresses or generating them through dictionary attacks. Harvesting isn't a standalone civil violation under CAN-SPAM, but it's a criminal trigger, and a harvested list almost inevitably produces non-compliant campaigns. See the FTC's official compliance guide.
How much can I be fined for emailing a scraped or purchased list?
Each violating email under CAN-SPAM carries civil penalties of up to $53,088, according to the FTC. The exposure stacks across jurisdictions: up to CAD$10 million per violation under Canada's CASL and €20 million or 4% of global turnover under GDPR — and one list can trigger all three frameworks at once.
If I hire an agency to send my emails, am I still legally responsible?
Yes. The FTC is explicit that you can't contract away your legal responsibility — both the company promoted in the message and the company that sends it can be held liable. Under GDPR, controllers are fully liable for infringements caused by non-compliant third parties unless they prove they bore no responsibility at all.
Do email laws apply to me if I'm not sending from the recipient's country?
Your obligations follow the recipient's location, not yours — a sender in Halifax or Houston answers to EU and Canadian regulators when their lists cross borders. A cold email that is legal in France can be illegal in Germany, as compliance research on cold email laws notes.
What's a legal way to do B2B cold outreach?
Cold email itself isn't banned — the laws target spam behaviors like deception, ignoring opt-outs, and irrelevant bulk sends. Canada's CASL permits B2B outreach under a three-part "conspicuous publication" test: the address is publicly posted, no refusal notice accompanies it, and the message is role-relevant, per a CAN-SPAM, GDPR, and CASL comparison guide.
Does compliant outreach actually perform better than bulk blasts?
Yes — small, targeted campaigns of 50 or fewer recipients average a 5.8% response rate versus 2.1% for blasts of 500+, and signal-based personalization pushes replies into the 15–25% range, according to cold email performance data. Gmail now rejects non-compliant bulk email outright, so a harvested list doesn't just risk fines — it stops reaching inboxes at all.

The Legal Answer and the Smart Answer Are the Same One

So, is email harvesting illegal? The FTC's own words say yes — criminal penalties, including imprisonment, for harvesting addresses or dictionary attacks, plus civil fines up to $53,088 per violating email. And because jurisdiction follows the recipient, one scraped list can trigger CAN-SPAM, CASL, and GDPR at once, with no way to outsource the liability to an agency. The good news: the compliant path isn't a consolation prize. Targeted campaigns of 50 or fewer recipients average a 5.8% response rate versus 2.1% for 500+ blasts, per cold email performance data — and Gmail now rejects non-compliant bulk email outright. Your next steps are simple: audit where your current lists come from, ask your provider how consent is documented and opt-outs are honored, and adopt a GDPR-equivalent baseline everywhere. If you're unsure your outreach would pass that check, Worqd will review your lists, consent capture, and follow-up on a free growth call — and show you what compliant, higher-converting outreach looks like for your business.

Want help putting this into action?

Book a Growth Call
Topicsemail harvesting illegalCAN-SPAM criminal penaltiesGDPR email complianceCASL consent requirementscompliant B2B outreach

Stay in the Loop