Suped

How long does email consent last, and what are the rules?

Published 22 Jul 2025
Updated 7 Aug 2026
12 min read
Summarize with
Email consent duration and unsubscribe rules illustrated with a consent form, clock, envelope, and switch.
Updated on 7 Aug 2026: We clarified consent lifetimes, added current soft opt-in rules, and corrected regional unsubscribe deadlines.
Email consent lasts only as long as the permission still fits the purpose, source, jurisdiction, and legal basis behind the message. It also ends when the person withdraws it. There is no universal lifetime for consent, so old consent carries more risk when the sender cannot prove when it was collected, what the person agreed to, and whether the current use still matches that agreement.
The practical answer depends on the permission route. Express consent often lasts until withdrawn, but stale records become weak evidence. Implied consent has fixed clocks in some countries. Canada is the clearest example, with common implied consent windows of 2 years after a qualifying transaction and 6 months after an inquiry. In the United States, CAN-SPAM generally does not require prior opt-in for commercial email, but it requires accurate sender information, a valid postal address, honest subject lines, and compliant opt-out handling. EU ePrivacy rules and UK PECR usually require consent for marketing to individuals unless a local exception applies. When consent is the basis under the GDPR or UK GDPR, it has no fixed expiry but must remain freely given, specific, informed, unambiguous, and easy to withdraw.
  1. Express consent: Keep it until withdrawal, a purpose change, a stated end point, or insufficient proof makes it unusable.
  2. Implied or inferred consent: Track the legal conditions and any clock by country, relationship type, and last qualifying activity.
  3. Opt-outs: Treat them as durable suppression records, not temporary preferences.
  4. Old lists: Do not assume a badge scan, conference chat, business card, public address, or website registration permits marketing years later.

The short answer

Consent is not a one-time asset that can be stored forever and used whenever marketing needs volume. A stricter operational rule works better: if the sender cannot prove permission or another valid basis, cannot explain the purpose, or cannot match the current message to the original scope, the address should not receive marketing. Low engagement should trigger a risk review, but it does not by itself create or cancel legal permission.
Operational rule
Consent remains usable when the permission record, message purpose, sender identity, jurisdictional rule, and unsubscribe status still match. If any of those fail, stop marketing sends to that address and move it into a permitted refresh, suppression, or legal review path.
  1. Proof: Store timestamp, source, form text, IP or session details, and consent version.
  2. Scope: Record which brand, list, topic, channel, and message category the person accepted.
  3. Withdrawal: Suppress the address quickly and keep enough data to prevent future sends.
This matters because consent and deliverability fail together. A stale consent claim creates complaints, low engagement, spam-trap exposure, and bad sender reputation. Authentication records still need to pass, but SPF, DKIM, and DMARC do not turn a stale list into a permission-based list.

Rules by region

The rules differ by jurisdiction, and the safest retention policy stores the legal basis per contact. Do not keep one global consent flag for every region. A field that says yes tells you almost nothing unless it also includes source, scope, country, date, and withdrawal status.

Region

Consent duration

Action rule

United States
CAN-SPAM generally uses opt-out
Honor within 10 business days
Canada
Express until withdrawn; implied is time-limited
Track the basis and implied clock
EU and UK
Consent has no fixed expiry; limited exceptions apply
Prove consent or the exact exception
Australia
Express or inferred consent
Honor within 5 working days
B2B contacts
Varies by country and entity type
Do not assume a blanket exemption
Common consent duration rules, simplified for marketing operations.
For the United States, the CAN-SPAM guide explains the 10 business day opt-out window and the requirement to keep the opt-out mechanism working for at least 30 days after sending. For Canada, the CASL guidance explains express consent, the common 2 year and 6 month implied consent periods, and the sender's burden to prove the basis.
In practice, the strictest applicable rule often becomes the operating rule. A global list that includes Canadian, EU, UK, Australian, and US recipients should not use the US opt-out model for everyone. Segment by country, subscriber type, and legal basis instead.
Email consent validity flowchart covering permission records, regional rules, suppression checks, and send decisions.
Email consent validity flowchart covering permission records, regional rules, suppression checks, and send decisions.

Soft opt-in and B2B exceptions

Consent is not the only permission route in every jurisdiction, but an exception needs the same level of documentation. In the EU, electronic marketing rules come from national laws implementing the ePrivacy Directive, so details vary by country. In the UK, PECR has specific soft opt-in rules and distinguishes individual subscribers from corporate subscribers.
  1. UK customers: The products and services soft opt-in can apply when details were collected directly during a sale or genuine negotiation, the sender markets its own similar products or services, and the person could opt out at collection and in every message.
  2. UK charities: Since 5 February 2026, a separate charitable-purpose soft opt-in can apply when a charity meets its specific conditions, including clear opt-out opportunities.
  3. UK B2B: The PECR consent rule generally does not apply to corporate subscribers such as limited companies, but sole traders and some partnerships are individual subscribers. Data protection rules still apply to named work addresses.
  4. Canada and Australia: CASL implied consent and Australian inferred consent have their own conditions. A public work address does not create blanket permission; the message must meet the local relevance and notice rules.
Do not relabel a missing electronic marketing permission as legitimate interests. A GDPR or UK GDPR lawful basis does not replace a consent requirement under national ePrivacy rules or PECR. Store the exact exception, the facts supporting it, the subscriber type, and the date those facts were checked.
Valid consent has evidence. A person giving you an email address is not the same as permission to send marketing. A business card, badge scan, old sales demo, webinar attendee list, conference directory, or one-to-one exchange can prove contact, but each needs separate facts before it can support marketing. A direct event form with clear marketing language can record consent; an organizer's attendee export usually cannot.
Strong evidence
  1. Form copy: The exact wording showed marketing permission and the sender brand.
  2. Timestamp: The record includes the date, time, source page, and consent version.
  3. Choice: The person took a clear action that was not bundled into unrelated terms.
Weak evidence
  1. Old contact: The address came from an event, meeting, export, or past staff handoff.
  2. Missing source: The team says the form existed, but no one can produce the form copy.
  3. Changed scope: The person agreed to one brand, but another brand now wants to mail them.
A consent ledger should be boring and exact. It does not need clever scoring. It needs records that marketing, legal, privacy, and abuse teams can read without guessing.
Consent event recordJSON
{ "email": "person@example.com", "country": "CA", "legal_basis": "express_consent", "consent_source": "newsletter_signup_form", "consent_text_version": "newsletter_v4_2026_01", "brand": "Example Brand", "topics": ["product_updates", "events"], "collected_at": "2026-01-18T09:42:11Z", "last_marketing_sent_at": "2026-05-14T16:02:00Z", "withdrawn_at": null, "proof_url": "internal://consent-record/abc123" }
Consent goes stale when the recipient can no longer reasonably connect the email to the permission they gave. That can happen because too much time passed, the sender changed, the topic changed, the business relationship ended, or the list sat unused through several staff changes. Staleness is a context and evidence problem, not a universal statutory expiry date.
Consent review bands
An operational list-risk model when the law does not set a fixed expiry date; these bands do not override local rules.
Low risk
0-12 months
Recent consent, clear proof, matching topic, and normal sending cadence.
Review
12-24 months
Permission still has proof, but activity or engagement has weakened.
Refresh first
24+ months
Old permission with low engagement, vague source data, or changed purpose.
The 24 month line is not a legal rule for every country. It is a practical checkpoint. If someone opted in 3 years ago and has not bought, logged in, replied, or otherwise engaged, a new promotional campaign has higher complaint risk. Engagement data is incomplete, and open tracking is especially unreliable, so use it as a risk signal rather than proof that consent expired.
Before reactivating a dormant segment, send the campaign sample to the email tester, not to unreviewed dormant recipients. Check the headers, authentication result, content signals, and inbox placement indicators. This does not validate legal consent, but it catches technical issues before an approved reactivation creates reputation damage.

Email tester

Send a real email to this address. Suped shows a results button when the test is ready.

?/43tests passed

Unsubscribe rules and suppression

Withdrawal ends marketing permission. Unsubscribe handling is a compliance system, not a campaign preference buried in a marketing platform. If a contact unsubscribes in one tool and a later migration loses that status, the sender owns the mistake.
Suppression is a permanent control
  1. Keep proof: Store enough unsubscribe data to prove and enforce the withdrawal.
  2. Sync systems: Push suppression status to every sending system and enrichment workflow.
  3. Block imports: Reject list uploads that try to re-add unsubscribed or complained contacts.
  4. Audit vendors: Confirm partners honor your suppression file before they send.
The unsubscribe clock is separate from consent age. The US rule allows up to 10 business days and requires the mechanism to process requests for at least 30 days after sending. CASL also allows up to 10 business days, while its unsubscribe link must remain valid for at least 60 days. Australia allows up to 5 working days and requires the mechanism to work for at least 30 days. Many senders process withdrawals immediately because delayed suppression creates avoidable complaints. For more country timing, use the legal timeframe guide.
Opt-outs do not expire in the way marketing consent can become stale. A person who opted out should stay suppressed unless they later take a clear, documented action to opt back in. The related opt-out expiry guide covers that distinction in more detail.
A request for consent can itself be a regulated marketing message. Under CASL and Australia's spam rules, a sender generally cannot email a contact only to obtain consent unless another permission route already allows that message. Use a permitted channel, such as an account setting or an in-person form, and record the new choice.
Consent is legal and operational permission. Deliverability is whether mailbox providers accept and place the mail. The two overlap because recipients react to stale or unwanted mail with spam complaints, deletes without opens, and inactivity. Those signals damage future campaigns even when the original send technically passed authentication.
Suped DMARC dashboard showing email volume, authentication health, and source breakdown
Suped's product covers the authentication and reporting gate around a consent workflow. DMARC monitoring, SPF, DKIM, hosted DMARC, hosted SPF, MTA-STS, and blocklist monitoring (blacklist monitoring) help teams verify approved sources and investigate authentication or reputation changes. Suped does not make a stale list lawful, but its reports show whether authenticated domains are being used as expected.
Keep two separate gates. First, decide whether the recipient has current permission or another valid basis. Second, decide whether the sending domain, envelope path, authentication, and reputation are healthy enough to send. A pass on one gate never overrides a fail on the other.
Practical Suped workflow
  1. Verify domains: Confirm SPF, DKIM, and DMARC pass before any permitted consent refresh send.
  2. Watch sources: Find unapproved senders before they mail old or migrated contact lists.
  3. Check reputation: Monitor blocklist and blacklist signals during approved reactivation campaigns.
  4. Fix issues: Use issue detection and corrective steps before scaling volume.
A good retention policy gives marketers a clear answer without asking legal to review every campaign. It should define when permission is usable, when it needs refresh, when it must be suppressed, and when the contact data should be deleted or minimized.
  1. Capture evidence: Save consent source, wording, timestamp, country, brand, and topic.
  2. Classify basis: Separate express consent, implied consent, soft opt-in, customer notice, and no permission.
  3. Set review dates: Review stale records before reactivation, especially after 12 to 24 months of no engagement.
  4. Protect suppression: Keep unsubscribe and complaint records out of normal deletion jobs.
  5. Block bad imports: Reject lists with missing source, expired implied consent, or mismatched brand permission.
Minimum retention policyTEXT
Express consent: Use until withdrawn, a stated end point, a purpose change, or insufficient proof. Implied or inferred consent: Use only while the local conditions and any legal clock remain satisfied. Dormant contacts: Review after 12-24 months without engagement; do not treat inactivity as automatic legal expiry. Unsubscribed contacts: Keep suppression records for as long as needed to prevent future sends. Unknown source contacts: Do not send marketing. Seek consent only through a permitted channel.
The hardest cases are old inherited databases. If a company acquisition, CRM migration, agency handoff, or staff turnover breaks the proof chain, do not treat the list as opted in. Treat it as unknown until the record proves otherwise. A business acquisition can transfer some permissions under local rules, but buying only a list does not create the same basis. The related acquired list guide explains why the brand, purpose, original notice, and transaction structure matter.

Views from the trenches

Best practices
Keep consent proof with the address, not in a form builder that later gets deleted.
Review event and conference leads before importing them into marketing automation.
Treat abuse desk replies as audit data and use them to fix broken consent controls.
Common pitfalls
Assuming a business card or speaking slot grants broad marketing permission years later.
Removing a person from one list but leaving them active in another sending platform.
Blaming staff changes instead of fixing the source, suppression, and import process.
Expert tips
Create a no-proof segment and require consent refresh before any promotional send.
Block list uploads unless source, date, country, and consent basis are populated.
Test campaign content internally, then send only where the permission basis remains valid.
Marketer from Email Geeks says having an email address does not create permission to send promotional email years later.
2019-06-03 - Email Geeks
Marketer from Email Geeks says old event contact records need proof of consent, not assumptions about implied interest.
2019-06-04 - Email Geeks

The safest working rule

Email consent lasts until the person withdraws it, a stated end point arrives, the legal basis expires, the purpose changes, or the sender can no longer prove the permission. Build that rule into list governance, CRM imports, campaign approvals, and reactivation programs.
For most senders, the operating system needs a consent ledger, suppression control, country-based rules, engagement checks, and domain monitoring. Suped's product handles the authentication and reputation side of that workflow, including DMARC reporting, SPF, DKIM, hosted records, alerts, and blocklist (blacklist) monitoring. Consent records remain the sender's separate responsibility.

Frequently asked questions

DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing