California’s anti-spam law, found in Business and Professions Code Sections 17529 through 17529.9, targets deception in commercial email rather than banning unsolicited marketing outright. Violations of the operative provision can trigger civil damages of up to $1,000 per email, capped at $1 million per incident, plus misdemeanor charges carrying up to six months in county jail. The law runs alongside the federal CAN-SPAM Act, and a single deceptive campaign can create liability under both.
What the Law Prohibits
The provision that actually drives enforcement is Section 17529.5. It makes it unlawful to advertise in a commercial email sent from or to California if the message does any of the following:
- Comes from a third-party domain or address without the owner’s permission.
- Contains falsified or forged header information, routing data, or domain information that disguises who sent it.
- Has a subject line likely to mislead a reasonable person about the contents of the email.1California Legislative Information. California Business and Professions Code 17529.5
These three triggers are the basis for both the civil and criminal penalties the statute imposes. The law also prohibits automated harvesting of email addresses and dictionary attacks, where a sender generates random addresses in hopes of hitting valid ones.2Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business
A separate provision, Section 17529.2, appears to ban all unsolicited commercial email sent from California or directed to a California email address.3California Legislative Information. California Business and Professions Code 17529.2 On its face that is one of the broadest anti-spam rules in any state, but some federal courts have found it goes beyond prohibiting fraud and is therefore preempted by CAN-SPAM. Do not assume Section 17529.2 alone creates liability for sending truthful, properly formatted unsolicited email. The real risk under California law lives in 17529.5’s deception provisions.
One common misconception: California law does not itself require an opt-out link in every commercial email. That requirement comes from federal CAN-SPAM. Senders still need one, but the legal basis is federal.
How CAN-SPAM Interacts With California Law
Federal CAN-SPAM preempts most state commercial email regulation but carves out an exception for state laws prohibiting “falsity or deception in any portion of a commercial electronic mail message.”4Federal Trade Commission. Text of the CAN-SPAM Act Section 17529.5 fits squarely in that carveout, which is why California appellate courts have kept it enforceable.
CAN-SPAM also layers its own baseline requirements on every commercial email:
- Header information (from, to, and routing data) cannot be materially false or misleading.5Office of the Law Revision Counsel. 15 U.S.C. 7704 – Other Protections for Users of Commercial Electronic Mail
- Subject lines cannot mislead a reasonable recipient about content.
- Every message must include a working opt-out mechanism that stays functional for at least 30 days.2Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business
- Opt-out requests must be honored within 10 business days, without fees, personal information demands, or steps beyond a reply email or single webpage visit.
Federal penalties can run up to $53,088 per violating email, and that exposure stacks on top of California’s own penalties.2Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business
Civil Damages
Any recipient of an email that violates Section 17529.5 can sue for liquidated damages of $1,000 per offending message, capped at $1,000,000 per incident. Email service providers and the Attorney General can also file suit. The prevailing plaintiff recovers reasonable attorney’s fees and costs on top of statutory damages, and actual damages are available as an alternative when they exceed the liquidated figure.6Justia. California Business and Professions Code 17529-17529.9
Per-email damages compound quickly. A blast to 10,000 California addresses with falsified headers could hit the $1 million cap in a single suit, before fees.
The 90% Reduction for Compliance Programs
If a court finds the sender established and implemented practices reasonably designed to prevent violations, the maximum liquidated damages drop to $100 per email, capped at $100,000 per incident. That is a 90% reduction. The statute uses the phrase “with due care,” so a defensible program needs documented email marketing policies, training records for staff running campaigns, automated header checks, and a process for investigating complaints. A paper policy no one follows will not qualify.
Criminal Penalties
Violating Section 17529.5 is a misdemeanor punishable by a fine of up to $1,000, up to six months in county jail, or both.1California Legislative Information. California Business and Professions Code 17529.5 Criminal charges are typically reserved for clear deception: systematically forging headers, running phishing operations, or similar conduct. Prosecutors do not generally pursue criminal cases over technical compliance slips.
Defenses
Because Section 17529.5 targets deception rather than unsolicited email in general, the strongest defense is showing the emails were truthful. If header information accurately identifies the sender and subject lines honestly describe the content, the statute is not violated, regardless of whether the recipient asked to receive the message. Using multiple domains you own and can be traced back to is not the same as forging someone else’s identity.
Transactional and relationship messages sit outside the statute entirely. The law reaches “commercial e-mail advertisements,” meaning messages whose primary purpose is promoting a product or service. Purchase confirmations, account updates, requested receipts, and communications tied to an existing business relationship are not commercial advertisements under the law.
A documented compliance program will not eliminate liability on its own, but as noted above it can cut damages by 90%.6Justia. California Business and Professions Code 17529-17529.9
Who Enforces the Law
The California Attorney General’s Cybercrime Section investigates and prosecutes technology-related crimes, including deceptive practices carried out through electronic communications.7State of California Department of Justice. Cybercrime Section But public prosecution is only part of the picture. The statute grants a private right of action to individual recipients and to email service providers. In practice, ISPs and platforms like Google and Yahoo have been among the most active plaintiffs, because they absorb the infrastructure cost of filtering and storing spam. The result is enforcement pressure from both the Attorney General and private plaintiffs.
Text Messages Fall Under a Different Law
California’s anti-spam statute covers commercial email. Marketing text messages and SMS campaigns are governed by the federal Telephone Consumer Protection Act, which requires prior express written consent before sending marketing texts to mobile phones and imposes statutory damages of $500 per message, tripled to $1,500 for willful violations.8Federal Communications Commission. Stop Unwanted Robocalls and Texts Complying with California’s email rules does not satisfy the TCPA, and vice versa.