Skip to main content
Back to blog
7 min read

CAN-SPAM and TCPA Basics for Cold Outreach to Local Businesses

complianceoutreach

This isn't legal advice — but you need to know the shape of it

If you're reaching out to home-service businesses at any volume, two U.S. laws matter most: CAN-SPAM for email and the TCPA for phone/text. Neither is hard to comply with, but both have real penalties for ignoring them. This post covers the shape of each — confirm specifics with a lawyer before you send anything at scale.

CAN-SPAM, in practice

CAN-SPAM applies to commercial email, including B2B cold outreach — there's no exemption just because you're emailing a business instead of a consumer.

The core requirements: don't use misleading subject lines or sender info, identify the message as an ad if it is one, include your physical postal address, and provide a working way to opt out — then honor opt-outs within 10 business days.

In practice: use a real reply-to address, don't spoof the sender name, keep a suppression list, and process unsubscribes immediately rather than batching them.

TCPA, in practice

The TCPA governs calls and texts, and it's stricter than most people expect — especially around autodialers and prerecorded messages, which generally require prior express consent.

Manual, one-to-one calls to a business's published number are lower-risk than automated dialing campaigns, but state-level mini-TCPA laws and do-not-call registries can still apply. Cell numbers carry more risk than published business landlines.

Where the data comes from matters

Using contact information that a business has published itself — on its own About, Team, or Contact page — is meaningfully different from buying a list of scraped or inferred personal emails. It doesn't eliminate your compliance obligations, but it does mean you're not starting from a list built on guesses.

This is why loclay never generates an email from a name-and-domain pattern. A decision maker's email is only stored when it's published next to their name on the business's own site, and every email and phone is labelled with where it was found — so you can show where a contact came from if you're ever asked. It's a lower-risk starting point, not a compliance guarantee.

A practical checklist before you send anything

Keep a real unsubscribe/opt-out process and honor it fast. Don't misrepresent who you are or what you're selling. Prefer manual outreach over automated dialing for cold contacts. Keep records of consent where you have it. And when in doubt on anything state-specific, ask a lawyer — this post is a starting point, not a substitute.

Prospecting outside the U.S.? Different rules apply — for example GDPR in the EU and UK, and CASL in Canada, which is stricter than CAN-SPAM about emailing without consent. Check the rules for the country you're contacting, not just the one you're in.