Does CASL apply to emails sent from outside Canada to Canadian recipients?

Updated on 9 Aug 2026: We clarified how CASL applies across borders and added the compliance records foreign senders should keep.
Yes. CASL applies to commercial electronic messages sent from outside Canada when a computer system located in Canada is used to access the message. Treat recipients who are expected to access the message in Canada as in scope unless legal counsel has documented a specific exception.
The CRTC FAQ says commercial electronic messages sent to recipients in Canada from another country must comply with CASL. Section 12 supplies the cross-border test: section 6 is contravened only if a computer system in Canada is used to send or access the message. Canada does not have to be the sending location.
- Bottom line: Mailing from the United States, Europe, Australia, or an overseas sending platform does not remove CASL duties when the message will be accessed in Canada.
- Main duties: Have express or valid implied consent, identify the sender, keep contact details valid, and include a working unsubscribe mechanism.
- Main caveat: CASL regulates commercial electronic messages. Personal or family messages, solicited responses, and specific statutory or regulatory exemptions need separate review.
What the rule actually says
Commercial electronic messages sent to recipients in Canada from another country must comply with CASL.
CRTC FAQ
Section 6 is the main CASL rule for commercial electronic messages, usually shortened to CEMs. It prohibits sending or causing a CEM to be sent unless the recipient has consented and the message includes the required identification and unsubscribe details. CASL also covers commercial messages sent to other electronic addresses, including SMS and instant messaging accounts, although this page focuses on email.
Section 12 gives the cross-border hook. For section 6, the key test is whether a computer system located in Canada is used to send or access the electronic message. If a computer system in Canada is used to access the message, the Canadian connection exists even when the sender, CRM, mail server, and staff are outside Canada.
|
|
|
|---|---|---|
Foreign company emails a lead in Canada | Treat as in scope | Prove consent and message compliance |
Canadian company emails abroad | Depends on the sending system | Check the limited foreign-state exemption |
Message only routes through Canada | Section 6 uses send or access | Verify the sending and access locations |
Canadian recipient is abroad | Citizenship is not the test | Check access and sending-system location |
Common cross-border CASL scenarios
Outside Canada is not a safe workaround
An overseas sender or server does not avoid CASL when a computer system in Canada is used to access the CEM. If campaign data indicates that recipients will access a commercial message in Canada, build the send around CASL duties.
What enforcement means outside Canada
CASL does not create a general exemption for foreign senders. The CRTC investigates complaints, can require records, and cooperates with regulatory partners in other countries on unlawful commercial messaging. Being hard to locate does not turn a non-compliant campaign into a lawful one.
- Maximum penalties: Administrative monetary penalties can reach CAD $1 million for an individual and CAD $10 million for any other person per violation. These are statutory maximums, not automatic fines.
- Evidence: Keep consent records, the message and audience export, unsubscribe events, suppression actions, staff training, and third-party instructions.
- Due diligence: A documented compliance program can support a due-diligence defence, but a policy that was never implemented will not prove reasonable preventive steps.
- Escalation: Obtain Canadian legal advice when access location, consent, or an exemption depends on disputed facts.
Assign responsibility before launch
Name an owner for CASL approval, suppression processing, consent expiry, and evidence retention. A foreign head office should be able to reconstruct why each Canadian segment was eligible to receive the campaign.
A practical scope test
Decide scope before the campaign is built. Review likely access location, message purpose, consent basis, and unsubscribe readiness. If reliable data indicates that a recipient will access the message in Canada, handle that recipient under CASL rather than trying to reconstruct the decision after complaints arrive.

Flowchart for deciding whether CASL applies to a campaign
- Likely access location: Use country fields, billing and shipping data, event registration, signup IP, CRM notes, and sales context to predict Canadian access. No single field conclusively decides the section 12 test.
- Message purpose: If the message encourages a product, service, trial, sale, partnership, event, or business opportunity, treat it as commercial. Review its content, hyperlinks, and contact information as a whole.
- Consent basis: Record whether consent is express, implied through a qualifying relationship, or tied to a specific exception or exemption.
- Identification details: Name the sender and any person on whose behalf the message is sent, then provide the required mailing address and contact method.
- Unsubscribe proof: Keep evidence that the unsubscribe was present, clear, working, and honoured within the required unsubscribe timeframes.
Whether CASL applies
This is the legal scope question. It looks at the message type, the Canadian computer-system connection, and any statutory or regulatory exception.
- Access test: A computer system in Canada used to access the message creates the main cross-border concern.
- Message test: A sales or marketing purpose usually pushes the message into CEM analysis.
Whether enforcement happens
This is the practical risk question. It looks at complaints, campaign scale, records, cooperation between regulators, and whether the sender can show a documented compliance process.
- Records test: Consent logs and unsubscribe logs matter more than informal intent.
- Responsibility test: The organization should know who approved the audience and who actioned suppression requests.
What to include before sending to Canada
When CASL applies, the campaign file should show the consent basis, sender identity, contact details, and unsubscribe path before a single message leaves the platform. Express consent does not expire unless it is withdrawn. Common implied-consent periods are two years after a qualifying transaction or the end of a written contract and six months after an inquiry, subject to the precise facts. Keep a separate playbook for consent duration.
|
|
|
|---|---|---|
Consent | Express or unexpired implied consent | Time-stamped form or relationship record |
Identity | Sender and any person on whose behalf named | Final message copy |
Contact | Mailing address plus one contact method, valid for 60 days | Footer and contact-page record |
Unsubscribe | No-cost mechanism valid for 60 days; action within 10 business days | Link test and suppression log |
Segmentation | Likely Canadian access tagged | Audience export and selection rules |
CASL send checklist
Simple compliant footer patterntext
Sender: Acme Inc. Mailing address: 123 Example Street, Toronto, ON Contact: privacy@example.com You are receiving this because you requested product updates. Unsubscribe: https://example.com/preferences
Consent is not the same as deliverability
A compliant footer does not fix bad authentication, poor list quality, or reputation problems. Keep CASL records and delivery checks in the same launch review, but do not treat one as a substitute for the other.
How DMARC and deliverability fit in
CASL is a legal compliance question. Authentication is a delivery and domain protection question. Check both before Canadian campaigns because a legally compliant email can fail authentication, land in junk, or hit a blocklist (blacklist). Before launch, an email tester helps inspect the message that mailbox providers actually receive.
For the authentication side, pair DMARC monitoring with domain health checks and blocklist monitoring. This catches technical issues that legal review will not catch, such as a new sender failing DKIM or a sending IP appearing on a blacklist.
Suped's product brings DMARC aggregate reporting, SPF and DKIM investigation, domain issues, and blocklist (blacklist) status into one workflow. It does not decide whether CASL applies. It helps the team responsible for sending verify that authorized services authenticate and investigate changes before a campaign expands.

Issue steps to fix dialog showing the issue overview, tailored fix steps, and verification action
The launch sequence is simple: confirm who can legally receive the message, then confirm that the message authenticates correctly. If SPF, DKIM, or DMARC breaks, Suped's issue detection and remediation steps make the fault visible before it affects a wider campaign.
Common edge cases
The risky cases are rarely obvious newsletter sends. Sales sequences, partner emails, acquired lists, event uploads, and mixed-purpose operational notices need a decision based on evidence rather than the sender's preferred label.
|
|
|
|---|---|---|
Cold B2B outreach | High | Organization relationship or publication proof |
Customer upsell | Medium | Consent basis and expiry |
Event upload | Medium | Form language and source record |
Acquired list | High | Verifiable consent scope and transfer basis; seller assurances are not enough |
Receipt email | Lower | Factual content and any promotion |
CASL edge-case handling
A work address alone is not a B2B exemption. A narrow organization-to-organization exemption can apply to a CEM between employees, representatives, consultants, or franchisees of organizations that have a relationship when the message concerns the recipient organization's activities. When relying on a conspicuously published address instead, document where it appeared, confirm that no statement barred CEMs, and match the message to the person's role.
Do not relabel marketing as operational
Certain factual messages about a transaction, account, warranty, recall, safety, or security can be exempt from the consent requirement while identification and unsubscribe duties remain. Adding a coupon, demo pitch, referral offer, or unrelated product promotion can remove that consent exception.
Views from the trenches
Best practices
Treat likely Canadian access as in scope, even when the sending system sits abroad today.
Store the consent source with signup timestamp and full form text for later audits.
Separate legal consent checks from inbox placement checks; both affect the final send plan.
Common pitfalls
Relying on sender location alone misses the Canada access test in section 12 entirely.
Adding an unsubscribe link without consent still leaves most promotional sends exposed.
Assuming B2B outreach is exempt creates risk when relevance and consent proof are weak.
Expert tips
Keep Canadian segments tagged so preference rules stay consistent across campaigns and teams.
Review templates after each acquisition because inherited consent needs proof before sending.
Monitor authentication separately so CASL fixes are not confused with delivery issues.
Marketer from Email Geeks says CASL should be treated as applying when a commercial email is sent to someone who reads it in Canada.
2017-05-31 - Email Geeks
Marketer from Email Geeks says the key distinction is application versus enforcement, since overseas sending does not remove the Canadian recipient issue.
2017-05-31 - Email Geeks
The practical answer
If the email is commercial and campaign data indicates that it will be accessed using a computer system in Canada, treat CASL as applying even when the send originates elsewhere. Prove consent or a valid exception, identify the sender, keep contact information valid, include a working unsubscribe path, and retain records.
The sender's location matters less than many teams assume. A Canadian computer system used to send or access the CEM is the statutory connection. Clear legal scope, consent evidence, unsubscribe handling, and authentication checks before launch.

