Back to insights
Checking Compliance Practices

What information must be included in CASL emails?

CASL requires sender ID, mailing address + second contact, and a working unsubscribe in every email — miss one and it's non-compliant. Fines up to $10M;...

What information must be included in CASL emails?

What information must be included in CASL emails?

Key Facts

  • CASL penalties reach $10 million per violation for organizations, with first-offense settlements commonly landing between $100,000 and $200,000 according to enforcement data
  • Every CASL email must include sender identification, a mailing address plus a second contact method, and a working unsubscribe link — miss one and the message is non-compliant per the CRTC
  • Contact information and unsubscribe links must stay live for at least 60 days after sending, or the email remains in violation per ANA compliance guidance
  • Unsubscribe requests must be honored within 10 business days, free of charge, with no logins or confirmation screens per the CRTC
  • The sender always bears the burden of proving consent — date, method, and wording must be documented for every contact per the CRTC
  • Even confirmation and transactional emails count as commercial messages requiring full identification and unsubscribe mechanisms per the CRTC
  • When an agency sends on your behalf, your organization remains fully liable for CASL compliance — the risk does not transfer per Global Relay

Every commercial email you send to a Canadian address carries a legal obligation most businesses discover only after a complaint lands. Under Canada's Anti-Spam Legislation, in force since July 1, 2014, each commercial electronic message must contain specific mandatory elements — and compliance guidance is blunt about what happens if you miss one: the message is non-compliant, even if everything else is perfect.

The CRTC itself requires three things in every message: valid consent, clear sender identification, and a working unsubscribe mechanism. But even with consent in hand, the message body must carry specific content. According to legal analysis from Gowling WLG, a compliant email includes:

  • Sender identification — your business name, plus the on-behalf-of party and the relationship between them if you send for someone else
  • A valid mailing address plus at least one secondary contact method: a phone number with voicemail or agent access, an email address, or a web address
  • An unsubscribe mechanism that is clearly worded, free, and honored within 10 business days
  • Accurate "from" lines and subject lines — no misleading headers of any kind

There is a detail most senders overlook: your contact information and unsubscribe link must stay valid for at least 60 days after sending, per the ANA's compliance guidance. A footer that links to a dead page two months later is still a violation.

The financial exposure is not theoretical. Organizations face penalties of up to $10 million per violation, and enforcement data shows settlements of $100,000 to $200,000 are common even for first offenses. In 2025, CRTC enforcement actions included fines ranging from $5,000 to $250,000.

Equally important: the burden of proving consent always falls on the sender. The CRTC states plainly that "the sender of a CEM has the onus of proving consent." If the regulator asks why you emailed someone, "I assumed it was fine" is not a defense — you need records of the date, method, and wording of consent.

If a vendor or agency sends email on your behalf, you remain liable. Global Relay's analysis is clear: the primary organization still must comply with CASL, regardless of who hits send. This is why Worqd treats permission-aware outreach as a baseline practice rather than an add-on — and why any business hiring a growth partner should verify that partner's consent records, unsubscribe handling, and identification practices directly, rather than assuming the sender absorbs the risk.

The Three Non-Negotiable Elements Every CASL Email Must Contain

Getting consent right is only half the battle. Even a perfectly permissioned email becomes non-compliant the moment it's missing a single required element — and the CRTC, Canada's enforcing regulator, is explicit about what every commercial electronic message must contain.

The regulator's own guidance states that businesses must "obtain consent, provide identification information, and include an unsubscribe mechanism in each message" (per the CRTC). Legal experts echo this three-pillar framework, and as one compliance analysis puts it bluntly: miss any one of these and the message is non-compliant, even if the other two are perfect. With penalties reaching $10 million per violation for organizations, the details matter.

1. Sender identification. Your email must identify the name under which you carry on business — or your legal name. If the message is sent on behalf of another party, legal guidance from Gowling WLG confirms you must include both names plus a statement of the relationship between them. This matters for agencies: even when a vendor sends on your behalf, the primary organization remains liable under CASL, according to Global Relay — so if you outsource outreach, verify your partner's practices directly rather than assuming they absorb the risk.

2. Valid contact information. Every message needs a real mailing address plus at least one secondary contact method: a phone number with access to an agent or voicemail, an email address, or a web address.

3. A working unsubscribe mechanism. The mechanism must be clearly worded, easy to use, and free of charge — no "are you sure?" screens, fees, or logins. Once someone opts out, you have 10 business days to honor the request.

Three supporting rules complete the picture:

  • No misleading headers or subject lines — the "from" line, subject, and body must accurately represent the message.
  • 60-day validity — contact information and the unsubscribe link must remain live for at least 60 days after sending, per the ANA.
  • Transactional emails count too — even a consent-confirmation email is itself a commercial electronic message requiring identification and an unsubscribe option (CRTC guidance).

At Worqd, we treat these elements as a fixed template skeleton in every outreach sequence — sender name, mailing address, secondary contact, and a working unsubscribe link are never optional line items. If you're evaluating any outreach partner, ask to see their email footer and consent records before signing. The burden of proving compliance always rests with the sender, and "I assumed it was fine" is not a defense.

The Traps That Catch Even Careful Senders

Most CASL violations don't come from careless spammers — they come from careful marketers who assumed an exception that doesn't exist. The law draws its lines in places that surprise even experienced senders, and the penalties are steep: up to $10 million per violation for organizations, with settlements of $100,000–$200,000 CAD common even for first offenses.

Confirmation and transactional emails count as commercial messages too. The CRTC states plainly that even a consent-confirmation email — say, one documenting implied consent after a tradeshow business card exchange — "may be considered a CEM" and must carry identification and an unsubscribe mechanism. The ANA notes that both transactional and marketing emails need footer links to a privacy policy and an unsubscribe process.

Purchased lists are worse. Envoke calls a purchased email list "the highway to CASL fines," and the math explains why: under CASL, the sender bears the onus of proving consent for every contact. You can't prove consent you never collected, and "I assumed it was fine" is not a defense.

Pre-ticked checkboxes fail for the same reason. Treadstone Law is direct: a pre-ticked checkbox does not count as express consent. The recipient must take a deliberate action — checking a box, typing an email — before you can treat consent as valid.

Implied consent also expires on a clock many senders never track:

  • 2 years after a purchase or written contract, per the CRTC's guidance
  • 6 months after an inquiry or application — a much shorter window than most teams realize
  • Once it lapses, you need fresh express consent before the next send

Finally, geography doesn't protect you. CASL applies based on sender or server location in Canada, not recipient location — and Envoke points out it reaches businesses outside Canada whose databases simply contain Canadian addresses. If your outreach touches Canadian inboxes, the law applies to you.

One more trap for agencies and their clients: Global Relay warns that the primary organization remains liable even when a vendor sends on its behalf. That's why Worqd treats permission-aware outreach as a baseline practice — and why you should verify any partner's consent records, unsubscribe handling, and identification practices directly rather than assuming they absorb the risk.

Build Your CASL-Compliant Email Checklist: A Practical Template

A compliant email isn't built at send time — it's built into the skeleton you reuse. The CRTC's enforcing guidance makes it clear: every commercial electronic message must carry valid consent, clear sender identification, and a working unsubscribe mechanism, and missing any one element makes the message non-compliant even if the others are perfect.

Start with a reusable footer that never changes. It must include the sender's legal or business name (plus the on-behalf-of party and relationship statement when applicable), a valid Canadian mailing address, and at least one additional contact method — phone with live answer or voicemail, email, or a website — per the requirements set out by Gowling WLG. The unsubscribe link itself must be clearly worded, free, require no login, and stay live for at least 60 days after the message is sent. Opt-outs have to be honored within 10 business days without friction or fees.

  • Sender name and on-behalf-of details (if sent by a third party)
  • Physical mailing address plus a second contact channel
  • One-click unsubscribe that works for 60+ days
  • No misleading "from" lines or subject lines

Consent records are your only defense if the regulator asks. The sender bears the onus of proving consent for every address, so log the date, time, method, and exact wording of consent — and track implied consent windows (two years after a purchase, six months after an inquiry) so you can convert to express consent before they lapse. Treadstone Law recommends retaining these records at least three years beyond last use.

Apply the same footer to every message type — marketing, transactional, even the confirmation email you send after collecting a business card at a tradeshow. The CRTC notes that a consent-confirmation email may itself be a CEM and must carry identification and an unsubscribe mechanism. The ANA reinforces that both transactional and marketing emails need footer links to a privacy policy and an unsubscribe process.

If you work with an agency or vendor, the liability stays with you. Global Relay emphasizes that the primary organization remains liable for CASL compliance even when a partner sends on its behalf, so verify their identification practices, unsubscribe handling, and consent record-keeping directly rather than assuming the risk transfers. At Worqd, we build CASL-compliant outreach into every B2B cold email and lead-generation program we run — because the cost of a missed footer detail can reach $10 million per violation for organizations, and settlements of $100,000–$200,000 are common even for first offenses.

Audit your sending process against this checklist before every launch. The 37% drop in Canadian-based spam during CASL's first year shows the law works — but only when the skeleton is solid and the records are current.

If an Agency Sends Your Emails, You're Still Liable — How to Vet Them

Here's a fact that surprises most business owners: when an agency or vendor sends emails on your behalf, the primary organization remains liable for CASL compliance. The risk doesn't transfer with the work — it stays with you.

That matters because the exposure is real. Penalties reach $10 million per violation for organizations, and settlements of $100,000 to $200,000 are common even for first offenses. If your outreach partner cuts corners, you pay the price.

So before you sign with any agency, vet their practices directly. Here are the questions that separate compliant partners from risky ones.

How do you handle sender identification? CASL requires every message to name the sender — and when an email goes out on behalf of another party, both names plus a statement of the relationship between them must appear. Ask to see a sample email footer. If their name and yours aren't both there, walk away.

How do you process unsubscribes? Requests must be honored within 10 business days, free of charge, with no login hoops or "are you sure?" friction. The mechanism must also stay live for at least 60 days after sending. A good partner will show you exactly how their opt-out flow works and how quickly it syncs across campaigns.

Don't forget contact details: every message needs a valid mailing address plus at least one other way to reach you — phone, email, or web address. If your agency's templates skip this, every email they send is non-compliant.

Can you prove consent for every contact? This is the big one. Under CASL, the sender bears the onus of proving consent — and "the agency handled it" is not a defense. Ask any partner these specifics:

  • What records do you keep for each contact — date, time, method, and wording of consent?
  • How do you track implied consent expiry (two years after a purchase, six months after an inquiry)?
  • Where did this list come from — and can you document that it wasn't purchased?
  • Do your confirmation and transactional emails also include identification and unsubscribe links?

That last question catches many agencies off guard. Even a confirmation email documenting consent may itself be considered a commercial electronic message with its own disclosure requirements.

Be especially wary of volume-first promises. As one compliance vendor puts it, a purchased email list is "the highway to CASL fines" — and template blasts to scraped contacts are the same road with a different vehicle.

At Worqd, this is why our B2B outreach is built as personalized, permission-aware outreach to relevant accounts — the opposite of a template blast. Consent is captured explicitly, follow-up is fast and documented, and every message carries the identification and unsubscribe elements CASL demands. Compliance isn't a checkbox we hand back to you; it's built into how the work gets done.

Whatever partner you choose, remember: the CRTC will come to you with questions, not your vendor. Make sure you like the answers before the first email ever sends.

Frequently Asked Questions

What information is legally required in every CASL-compliant email?
Every commercial electronic message needs three things: valid consent, clear sender identification, and a working unsubscribe mechanism. The message body must also include your business name (plus the on-behalf-of party and their relationship if you send for someone else), a valid mailing address with at least one secondary contact method, and accurate from/subject lines — per legal guidance from Gowling WLG. Miss any one element and the message is non-compliant, even if the rest is perfect.
How long do I have to honor an unsubscribe request under CASL?
You must process opt-outs within 10 business days, free of charge, with no logins or "are you sure?" friction. Also note that your contact information and the unsubscribe link must stay live for at least 60 days after sending — a footer linking to a dead page two months later is still a violation, per the ANA's compliance guidance.
Do transactional or confirmation emails need an unsubscribe link too?
Yes. The CRTC states that even a consent-confirmation email — say, one documenting implied consent after a tradeshow business card exchange — may itself be considered a commercial electronic message requiring identification and an unsubscribe mechanism. The ANA also notes that both transactional and marketing emails need footer links to a privacy policy and an unsubscribe process.
What are the penalties for a non-compliant CASL email?
Organizations face penalties of up to $10 million per violation, and settlements of $100,000 to $200,000 are common even for first offenses. In 2025, CRTC enforcement actions included fines ranging from $5,000 to $250,000, so the exposure is very real.
If my agency sends emails for me, who is liable under CASL?
You are. The primary organization remains liable for CASL compliance even when a vendor or agency sends on its behalf — the risk doesn't transfer with the work, per Global Relay's analysis. Before signing with any partner (Worqd included), ask to see their email footer, consent records, and unsubscribe handling directly rather than assuming they absorb the risk.
Does CASL apply if my business is outside Canada?
Yes. CASL applies based on sender or server location in Canada, not recipient location, and it reaches businesses outside Canada whose databases simply contain Canadian addresses. If your outreach touches Canadian inboxes, the law applies to you — which is why Envoke calls a purchased email list "the highway to CASL fines," since you can't prove consent you never collected.

Compliance Is a Footer Away — Or a $10 Million Mistake

Every CASL-compliant email comes down to the same short list: sender identification, a valid mailing address plus a second contact method, and a working unsubscribe link that stays live for 60 days and gets honored within 10 business days. Miss any one of these and the message is non-compliant — even if the rest is perfect — with penalties reaching $10 million per violation for organizations. And remember: the burden of proving consent always falls on you, even when an agency hits send on your behalf. Your next step is simple — pull up your last outreach email and check it against the checklist above. If you outsource your email, ask to see your partner's footer and consent records before the next campaign goes out. At Worqd, we build permission-aware outreach into every B2B cold email program we run, so compliance is never an afterthought. Want a second set of eyes on your sending practices? Book a growth call and we'll walk through it with you.

Want help putting this into action?

Book a Growth Call

Stay in the Loop