Ask a founder what makes an email spam and the answer is usually a feeling: unsolicited, a bit much, the kind of thing that makes you wince. Feelings are a bad place to draw a line you're going to make legal and financial decisions against. There's a sharper one available, and it isn't about how the message sounds.
What the law actually requires, precisely
In the US, the CAN-SPAM Act does not require you to get permission before emailing someone. That surprises most founders, who assume unsolicited automatically means unlawful. It doesn't. What the law requires is narrower and more mechanical: an accurate "From" line that doesn't disguise who's sending, a subject line that isn't deceptive about the content, your real physical postal address somewhere in the message, and a clear, working way to opt out that you honor within ten business days. It also bars harvesting addresses off the web with a bot or generating them by guessing common combinations and sending to whatever doesn't bounce.
That's the entire legal bar for a single message to a single business contact, researched by a human being. A well-run startup clears it without trying, because none of those requirements ask you to be careful about who you're writing to. They ask you to be honest about who's writing.
That is American law, and it is not the only law
Everything above describes CAN-SPAM, which governs mail sent to recipients in the United States. It is the most permissive of the major regimes, and if you read only that one you will draw the wrong conclusion about everywhere else. In the UK and the EU, PECR and the GDPR treat unsolicited email quite differently: business-to-business contact is possible on a legitimate-interest basis, but that basis has to be documented and balanced, and the recipient's right to object is not optional. Canada's CASL is stricter again, works from consent rather than opt-out, and carries penalties large enough that it is worth an hour of proper reading before your first send.
The practical point is that the rules follow your recipient, not your company. A startup incorporated in Delaware emailing a procurement manager in Munich is in European territory for that message. If your list crosses borders — and any list built from a job board or a review site probably does — find out which rules apply to the people actually receiving it. That is a question for someone qualified, not for an article, and certainly not for a vendor's blog.
The legal line and the good-sender line are different lines
You can clear CAN-SPAM and still be the kind of sender a mailbox provider quietly routes to spam anyway, because inbox placement runs on a separate judgment: whether people who received your message wanted it. That judgment gets made by aggregate behavior, not by a lawyer reading your header. A message that gets deleted unread is a miss. A message that gets reported as spam is a mark against your name that follows you, and it's the one signal in this whole category that means exactly what it says, because a human had to press an actual button to register it.
Which means the legal question ("can I send this without breaking the law") and the practical question ("will sending this get me marked as the kind of sender who shouldn't be trusted") are answered differently, and a startup that only checks the first one is going to get surprised by the second.
Three questions that sort outreach from spam faster than any definition
Before a message goes out, run it against these. They're blunt on purpose.
- Could I say, out loud, why I picked this exact person? Not "companies like this," a real reason tied to them specifically.
- Did a human choose this recipient, or did a query choose them and nobody looked afterward?
- Is opting out genuinely one click, and will it actually be honored the same day, not eventually?
A message that passes all three is outreach, whatever the recipient's mood happens to be when they read it. A message that fails even one is spam with better manners, and manners are not the part anyone's filter is checking.
What outreach looks like next to spam, side by side
Spam is sent at a volume that has nothing to do with the sender's actual capacity to have a conversation with the people on the list; it comes from a purchased or scraped set of addresses nobody re-checked before hitting send; it opens with a sentence that would fit unchanged into five hundred other emails; and the reply-to address either bounces or reaches someone who never reads what comes back.
Outreach is sent at a volume the sender can plausibly follow up on personally; it goes to a list somebody actually looked at, name by name, even briefly; it opens with something true of this specific recipient that couldn't have been said about the next one on the list; and a real person reads and answers whatever comes back, including the annoyed replies.
Notice that none of the four differences is about wording, warmth, or how polite the copy sounds. All four are about whether a specific, accountable human being is behind the send and stays behind it after the reply arrives.
A worked example, since "a real reason" is easy to fake with adjectives
"I noticed you're a fast-growing company in the SaaS space" is not a reason. It's a compliment shaped like a reason, and it would survive being sent to ten thousand companies unchanged, which is the actual test. "I noticed your job posting for a first customer success hire last week" is a reason, because it's true of this company on this date and would be false for most others on the list. The first sentence is the one spam filters and skeptical humans have both learned to recognize on sight. The second is the one that gets read to the end.
Small volume is a compliance strategy, not just a taste preference
A startup writing to forty people a week, each chosen for a stated reason, structurally cannot commit most of what makes a message spam in the ways that matter. You can't scrape-and-blast at forty a week; the economics don't make sense at that size. You can't skip reading the names; there are only forty of them. What's left is closer to sending forty individual letters than to running a campaign, and that's exactly the shape a startup can sustain without a legal team or a deliverability specialist on staff.
This is also why tools built around free searching and free previewing of names before anything gets sent tend to produce cleaner lists than tools that meter the reveal from the first click: when looking costs nothing, looking actually happens, and a list somebody looked at is a list that passes the second of the three questions above by construction. Rocketship works that way on purpose, and it suppresses bounces and checks a sending domain before your first message leaves it, which is the mechanical half of staying on the right side of this line.
The guilt is optional once the line is clear
A lot of founders avoid cold email entirely because they can't articulate what separates it from spam, and avoiding the discomfort of a fuzzy category feels safer than testing it. The category isn't fuzzy. It's a real reason, a real look at the recipient, and a real opt-out honored on time. Clear all three and the thing you're doing has a name, and the name is outreach, not spam with a longer disclaimer.
