Hmm, the short and straight answer: no. Cold emailing is not illegal in the United States, the UK or most of the EU. It is regulated, though, and the rules change a lot from one country to the next.
I get this question constantly, usually from someone about to send their first campaign. They worry a regulator will knock on the door. In reality, a short list of habits keeps you safe in most markets.
This guide covers the law in the main regions, what actually turns a cold email illegal, and the inbox rules from Gmail, Yahoo and Microsoft that hit you long before a regulator does. I am not a lawyer, and this is not legal advice.
Cold emailing is legal in most places, but what counts is where the recipient lives, not where you do.
A cold email is a first message to someone who has not asked to hear from you. Most laws do not ban that. They ask you to be honest about who you are, give people a way out and respect local consent rules.
Here is how the main regions compare for B2B outreach.

In the US, CAN-SPAM sets the rules, and it works on an opt-out basis.
You can email a stranger without asking first. The FTC publishes a CAN-SPAM compliance guide with the main requirements, and these are the ones I check on every campaign.
No. CAN-SPAM covers commercial email, and that includes messages sent to business addresses. People often assume B2B is exempt, and that is a mistake.
The FTC can fine each separate email, and the amount is adjusted every year. There is no private right to sue under the act, but the FTC, state attorneys general and internet providers can all enforce it.
Europe cares less about the email itself and more about the personal data behind it.
A work email address that names a person is personal data. B2B cold email can still be lawful under legitimate interest, as long as you document why the outreach is relevant to that person's role.
That means a written legitimate interest assessment, a clear opt-out, and honesty about where you found the contact. For a deeper look at consent and data handling, see this guide to data privacy rules for email campaigns.
The UK treats corporate subscribers differently from individuals. You can email an employee at a limited company without prior consent if you identify yourself, give a valid contact address and offer an easy opt-out.
Sole traders and some partnerships count as individuals, so consent rules are stricter for them. Recent UK reforms also raised the maximum fines for PECR breaches to match GDPR levels.
Germany's unfair competition law expects prior consent, even for business contacts. If Germany is a target market, I treat cold email there as a different channel with different rules and ask a local lawyer first.
Outside the US and Europe, the consent rules get tighter, and Canada is the one I see trip people up most.
CASL needs express or implied consent. Implied consent can apply when someone has openly published their work address with no notice against unsolicited messages, and your email relates to their role.
Penalties under CASL are among the heaviest anywhere, so I would not guess. Australia also expects consent, which can sometimes be inferred. Before your first send to any new country, read that country's rules or ask a local adviser.
Most legal trouble comes from a handful of repeat mistakes, not from the act of cold emailing itself.
Notice that none of these is "sending an unsolicited email". The problem is deception and ignored requests.

Gmail, Yahoo and Microsoft enforce their own rules, and they act faster than any regulator.
Senders who reach 5,000 messages a day to Gmail or Yahoo addresses must authenticate with SPF, DKIM and DMARC, offer one-click unsubscribe and keep spam complaints low. Microsoft began enforcing similar rules for Outlook in May 2025, and I explain them in this guide to Microsoft bulk sender guidelines.
Gmail asks senders to stay under 0.3% spam complaints, and I aim for under 0.1%. If you want the full picture, here is how the spam complaint rate works and why it matters.
Set up SPF, DKIM and DMARC before you send a single cold email. Then run an email validity check on your list, because high bounces look like careless sending to mailbox providers.
A compliant email still lands in spam if your sender reputation is poor. If that is happening, this post on why emails go to spam is a good place to start.
Warmforge does not make a cold email legal, but it protects the part of compliance that decides whether anyone sees your email.
To be clear, Warmforge is a deliverability tool, not a legal one. It cannot give you a lawful basis or write your unsubscribe link. What it does is keep the mailboxes you send from healthy.
I recommend about 14 days of warmup on a new mailbox, as covered in this email warm-up process guide. Warmforge is included free with every Salesforge plan with unlimited slots, and you can also try it on its own with 1 free warmup slot and 1 free placement test each month.

Most teams pair warmup with the rest of the stack. Mailforge provides domains and mailboxes, Primeforge covers Google and Microsoft mailboxes, and Leadsforge helps you find contacts with a clear reason to reach out. Salesforge handles the sending.
The same legal rules apply when your team runs outreach, when Agent Frank runs it, or when a Forge Expert agency runs it. Whoever sends, your name and your domain carry the risk.
Run through this list before every new campaign, and again whenever you enter a new country.
A summary of where cold emailing stands, and what I would do next.
Cold emailing is not illegal, but careless cold emailing can be. Follow the local consent rules, be honest about who you are and make opting out easy.
Then look after deliverability, because inbox providers punish bad habits long before a regulator does. Warm your mailboxes, watch Heat Score™ and keep complaints low.
No. The CAN-SPAM Act allows commercial email without prior consent. You must use accurate sender details, a truthful subject line, a physical postal address and a working opt-out, and you must honor opt-outs promptly.
Often yes. Many EU countries accept legitimate interest under GDPR for relevant business outreach, but you need a documented assessment, a clear opt-out and transparency about your data source. Some countries, including Germany, expect prior consent even for business contacts.
It depends on the country. The US does not require prior consent. The UK allows opt-out outreach to corporate subscribers. Canada requires express or implied consent, and Germany generally requires consent. Check the recipient's country before you send.
Yes. Regulators can fine senders who break CAN-SPAM, GDPR, PECR or CASL, and penalties can be large. In practice, mailbox providers act first, because high spam complaints can push your emails to spam or get you blocked.
Yes, but only with consent. CASL accepts express consent or implied consent, such as a work address published openly with no notice against unsolicited messages, and the email must relate to the recipient's role. Identification and unsubscribe details are required.
No. Warmup is a deliverability practice and has no effect on legal compliance. Warmforge helps your emails reach the inbox, but you still need a lawful basis, honest sender details and a working opt-out.