đ¤ Wait, Whatâs the Big Deal With Cross-Border Email?
So you're a U.S.-based business, and youâve got some Canadian customers or newsletter subscribers on your email list. You send them updates, offers, onboarding info, and all the usual stuff.
No harm, right?
Well... not unless you're violating Canadaâs Anti-Spam Legislation (CASL) â and in 2025, regulators are taking it way more seriously.

âď¸ What Changed in 2025?
A few things:
- CASL enforcement has picked up, especially after major spam/phishing attacks targeting Canadian inboxes in early 2025.
- U.S. companies are being audited for how they obtain and manage consent.
- Privacy regulations globally (think GDPR, CPRA) are tightening, and email laws are overlapping.
If you're not paying attention, you could be sending non-compliant emails to Canadian users â even if your intentions are good.
This article breaks down what you need to know (and do) if you're emailing anyone in Canada.
đ First, What Is CASL? And Why Should You Care?
CASL (Canadaâs Anti-Spam Legislation) is one of the toughest anti-spam laws in the world. It applies to:
- Commercial Electronic Messages (CEMs)
- Sent to or from a computer in Canada
- That promote products, services, or businesses
And yes â this includes emails from your Mailchimp, HubSpot, or Salesforce account to Canadian addresses.
â ď¸ Violating CASL = Fines Up to $10M CAD Per Violation
Yeah, you read that right.
There have already been high-profile cases where companies were fined millions for things like:
- Not having proper consent
- Sending messages with misleading info
- Failing to provide an unsubscribe mechanism
đ Are You a U.S. Business That Needs to Worry About This?
Ask yourself:
- Do you have any Canadian customers or subscribers?
- Do you collect leads or sign-ups from Canadian websites or events?
- Are you sending automated email flows, onboarding sequences, or newsletters globally?
If you answered yes to any of these â yep, CASL applies to you.
â Quick Breakdown: CASL vs. U.S. CAN-SPAM
| Feature | CASL (Canada) | CAN-SPAM (U.S.) |
|---|---|---|
| Consent | Required before sending | Can send until they opt out |
| Opt-In | Must be express or implied | Not required |
| Penalties | Up to $10M CAD per violation | ~$50,000 per violation |
| Unsubscribe | Must be easy + processed within 10 days | Same |
Basically, CASL is stricter, especially about how and when you collect consent.
đ§ Key Terms You Should Know
- CEM (Commercial Electronic Message): Any email promoting your biz.
- Express Consent: User actively opted in (form, checkbox, double opt-in).
- Implied Consent: Thereâs an existing relationship (past customer, inquiry, etc.).
- Sender Identification: Your real business name, address, contact info â must be visible in the email.
- Unsubscribe Mechanism: Obvious, working, and honored quickly.
đ But Itâs Not Just About Consent â Itâs Also About Email Security
Canadian privacy regulations donât stop at consent. Your emails should also meet basic email security compliance, especially after the surge of phishing attacks in Q1 2025.
Best practices include:
- Setting up DMARC, SPF, and DKIM to prevent spoofing
- Using TLS encryption where supported
- Not sending sensitive data (like personal health info or tax info) via email
- Having a clear security and privacy policy on your site
đĄ YourDMARC can help you monitor your domainâs email security posture to stay compliant across borders.
đ§Ş Real Example: A U.S. Brand Got Flagged in 2025
In February 2025, a U.S. eCommerce company emailed a promotional discount to thousands of Canadian customers who bought from their store in 2022.
They hadnât emailed those users in over a year â which expired their implied consent window.
Because they didnât get express opt-in, and there was no working unsubscribe button, the campaign triggered multiple CASL complaints, and an audit followed.
A reminder: CASLâs implied consent expires after 2 years of no interaction â after that, you must stop emailing unless they opt in again.
đ ď¸ 7 Things You Need to Do If Youâre Emailing Canadians in 2025
1. Segment Your List by Country (or Email Domain)
You canât treat all subscribers the same anymore.
đ¨đŚ Canadian emails should be in a separate list or tagged appropriately. That way, you can control what flows go out to whom â and apply CASL-specific logic.
2. Collect Express Consent Proactively
Any time you run a lead form, pop-up, or quiz â include:
-
A clear checkbox (unchecked by default)
-
A statement like:
"By subscribing, you agree to receive emails from [Company Name]. You can unsubscribe anytime."
And if possible? Use double opt-in for Canadian subscribers. Itâs not required but highly recommended.
3. Track Consent Sources
Keep records of:
- When consent was given
- How it was given (form, site, webinar)
- IP address and timestamp
Use your CRM or email platform to log this info â in case youâre ever audited.
4. Add Proper Identification to Every Email
Your emails should clearly state:
- Your business name
- A physical mailing address
- A working contact method (email or phone)
- A visible unsubscribe link (that works for at least 60 days)
5. Use a Compliant ESP (Email Service Provider)
Most big-name ESPs (like Mailchimp, Klaviyo, ActiveCampaign, etc.) support CASL compliance tools â but you have to configure them.
Things to check:
- Can you tag contacts by location?
- Can you enforce double opt-in?
- Can you manage unsubscribes automatically?
6. Implement DMARC, SPF & DKIM for Email Authentication
Canadian ISPs (and users) are extra sensitive to spam, spoofing, and phishing.
By publishing DMARC records and aligning your sending domains, you:
- Improve deliverability
- Prevent your domain from being spoofed
- Signal to regulators that you're playing by the rules
â Use YourDMARC to visualize, monitor, and enforce email authentication without breaking your sends.
7. Build a âRe-Consentâ Flow
If youâre unsure about some older Canadian contacts on your list â create a re-permission campaign.
Subject line ideas:
- âStill Want Our Emails?â
- âWeâd Love to Stay in Touch đ¨đŚâ
- âConfirm Your Subscription for Future Updatesâ
Those who re-opt-in = youâre covered. Those who donât? Itâs time to part ways (and stay compliant).
đ§ Bonus: Tools to Help With CASL Compliance
Here are a few tools to make this easier:
| Tool | What It Does |
|---|---|
| YourDMARC | Email authentication and anti-spoofing protection |
| Mailchimp / Klaviyo | List segmentation, consent tracking |
đ TL;DR (Too Long; Didnât Read)
If you're a U.S. company emailing people in Canada:
- â You must follow CASL (even if you're not based there)
- â Express or implied consent is required
- â Emails must have a working unsubscribe and business info
- â Implement DMARC, SPF, DKIM for secure delivery
- â Segment your list and build proper re-consent flows
And if youâre not sure where to start?
đ Talk to YourDMARC. Weâll help you navigate email security and compliance â without the jargon.
đď¸ Save & Share This Guide With:
- đ§ Your marketing team
- đ§âđť Your developers setting up email infrastructure
- âď¸ Your legal or compliance manager
- đ Anyone managing international subscriber data









