Skip to content
Your Rights

Do transactional emails need an unsubscribe link?

Genuinely transactional emails like receipts and password resets are exempt from the unsubscribe rule under CAN-SPAM, GDPR, and CASL. Marketing is not.

Email Unsubscriber Team 8 min read
Flat vector illustration of a cream receipt whose lower half becomes a promotional megaphone and price tag, a divider sorting a padlock and shipping box from promo envelopes, and a magnifying glass over the seam.

You scroll to the bottom of a shipping confirmation hunting for the unsubscribe link, and there is none. A week later a “receipt” lands that is three-quarters product recommendations, and it has no way out either. One of those is perfectly legal. The other one might not be.

No. Genuinely transactional emails like receipts, shipping notices, password resets, and security alerts are exempt from the unsubscribe requirement under U.S. CAN-SPAM, and from the consent rules under GDPR and Canada’s CASL. Marketing email needs an opt-out. If a “receipt” is mostly promotion, the primary-purpose test reclassifies it as marketing and the exemption falls away.

This is an educational overview of email marketing rules, not legal advice. For a specific situation, check the regulator linked below or consult a lawyer in your jurisdiction.

No. Under U.S. law, the unsubscribe requirement lands on commercial email, not on transactional email. The FTC’s CAN-SPAM compliance guide sorts every message into three buckets by its content: commercial content that advertises or promotes a product or service, transactional or relationship content that facilitates or follows up a transaction you already agreed to, and everything else.

Only commercial email carries the full weight of the law. A commercial message must include a working opt-out mechanism and honor your request within 10 business days. A transactional message must still use accurate routing and header information, so it cannot forge who it came from, but it is exempt from the opt-out rule entirely. That is why your bank’s fraud alert and your carrier’s delivery notice reach you with no unsubscribe link, and reach you legally.

What counts as a transactional email?

A transactional or relationship email is one whose only real job is to service a deal you already entered into. The FTC draws the line by content, not by who sent it, and lists five kinds of message that qualify:

  1. It completes or confirms a transaction you agreed to. Order confirmations, receipts, and booking confirmations.
  2. It delivers goods or services you are owed. A download link, a ticket, a subscription you paid for.
  3. It gives warranty, recall, safety, or security information about something you bought, including fraud and login alerts.
  4. It updates an ongoing account. A change to the terms, your standing, or your balance on a membership, subscription, loan, or account.
  5. It covers an employment relationship or the benefits attached to one.

Read that list and a pattern shows: none of it is trying to sell you something new. A password reset protects an account you already hold. A shipping notice finishes an order you already placed. You would not want to unsubscribe from any of them, so the law does not force the sender to offer the option.

Because you cannot opt out of mail you actually need. The exemption exists so a company can send you the message a transaction requires without asking permission first or bolting on an exit you would never use. Imagine unsubscribing from your bank’s security alerts and then getting quietly locked out of a warning about fraud on your card. The carve-out protects you as much as the sender.

This is also why these messages tend to look bare in your inbox. Gmail draws its Unsubscribe button only for mail that carries a valid List-Unsubscribe header and clears its trust checks, and transactional senders usually skip the header because the rules never asked them for it. If you have wondered why the Gmail Unsubscribe button is missing on some emails, a receipt or a reset is one of the most common answers. No button there is normal, not a bug.

The moment marketing becomes the email’s real point. A sender cannot dodge the opt-out rule by wrapping an ad in transactional clothing, and the FTC has a specific tool for catching it: the primary-purpose test. When a single message mixes transactional and commercial content, the FTC decides which one governs by looking at two things.

First, the subject line. If a reasonable person reading it would conclude the message is an ad, the email is commercial. Second, placement. If the transactional part does not appear at or very near the beginning of the body, and the promotion dominates, the email is commercial. Fail either test and the full opt-out requirements apply, no matter what the footer claims.

The FTC has enforced exactly this. In 2023 it charged Experian over emails sent to people who had opened accounts to manage their credit information. The messages carried a line at the bottom saying they contained “important information about your account,” but the FTC alleged they were really marketing new products and services, and they offered no way to opt out. Experian paid a $650,000 civil penalty and agreed to stop sending commercial email without an unsubscribe option. Calling a message transactional does not make it transactional.

Do GDPR and CASL treat transactional email the same way?

Yes, with the same logic under different labels. Both regimes exempt genuine service messages and both revoke the exemption the second a sender smuggles in promotion.

In the UK and EU, the test turns on whether a message is “direct marketing.” The ICO’s guidance treats routine service correspondence, such as a delivery update or a change to your contract terms, as outside direct marketing, so it needs no consent and no opt-out. But the ICO is explicit that any significant promotional material pushing you to buy more or renew turns the whole message into marketing. Canada’s CASL works the same way: a purely transactional message is exempt from the consent requirement, yet the moment a delivery confirmation carries a promotional banner, it can become a commercial electronic message subject to the full rules.

RegimeTransactional emailWhat breaks the exemption
CAN-SPAM (US)Exempt from the opt-out requirementPrimary purpose becomes commercial
GDPR + PECR (EU / UK)Service messages are not direct marketingSignificant promotional content added
CASL (Canada)Purely transactional exempt from consentAny promotional content added

The bottom line holds across all three: the exemption is for the message, not the sender. A company you do business with can email you a receipt freely, and the instant that receipt starts selling, the marketing rules switch on. For the full picture of how these regimes differ on deadlines and penalties, see unsubscribe laws by country.

What can you do when a “receipt” is really an ad?

Treat it as marketing, because in the eyes of the law it is. Work through these steps in order.

  1. Judge the primary purpose yourself. Read the subject line and the first few lines of the body. If it leads with a sale, a “you might also like,” or a coupon rather than the transaction it claims to confirm, it is commercial mail wearing a costume.
  2. Look for the footer opt-out. Commercial email must carry a working unsubscribe mechanism. If a promotion-heavy “receipt” offers none, that missing link is itself the violation, not just an annoyance.
  3. Document the sender and the dates. Save the message with full headers and note when it arrived. Timestamps and the original email are what any regulator needs to act.
  4. Report it, then block. In the U.S., file with the FTC; in the EU or UK, file with your data protection authority. The step-by-step filing walkthrough covers each regulator, and your rights when ‘unsubscribe’ doesn’t stop the emails covers the penalties that make a complaint worth filing.

Expected outcome: a genuine service message you leave alone, and a disguised marketing email you either escape through its buried footer link or report as the non-compliant mail it is.

How do you tell transactional mail from marketing when you clean your inbox?

The tedious part is doing this across hundreds of senders at once. A single inbox mixes real newsletters you can leave, promotions dressed as receipts, and genuine transactional mail you need to keep, and sorting them by hand is slow.

That is the sort the Email Unsubscriber app is built for. It scans your inbox in your browser and reads each sender’s List-Unsubscribe header, so it surfaces the senders that actually offer an opt-out and dispatches a one-click unsubscribe where the sender supports it, while leaving your receipts and security alerts where they belong. Your email content never reaches our servers, the access is read-only, and we never read, analyze, or monetize your email content. It is a one-off payment, with nothing to cancel.

Knowing the transactional line is what keeps a cleanup honest. You clear the marketing you never asked for and keep the messages a real transaction depends on.

Frequently asked questions

Do transactional emails need an unsubscribe link?

No. Under U.S. CAN-SPAM, only commercial email must carry a working opt-out. Genuinely transactional messages like receipts, shipping notices, password resets, and security alerts are exempt because they facilitate or follow up a transaction you already agreed to. They still must use honest sender and routing information, but the law does not require them to offer an unsubscribe link.

What is considered a transactional email?

The FTC defines transactional or relationship content as email that completes or confirms a transaction you agreed to, delivers goods or services you are owed, gives warranty, recall, safety, or security information, updates the terms or your standing in an ongoing account, or covers an employment relationship. Order confirmations, shipping notices, password resets, and fraud alerts all qualify.

Are receipts and order confirmations exempt from CAN-SPAM?

Mostly. Receipts, order confirmations, and shipping notices count as transactional messages, so they are exempt from the CAN-SPAM opt-out requirement and can reach you without an unsubscribe link. They still cannot use false or misleading header and routing information. The exemption only holds while the message stays transactional and does not turn into a product pitch.

Can a company avoid the unsubscribe rule by calling an email transactional?

No. CAN-SPAM uses a primary-purpose test that looks at content, not the label a sender attaches. If the subject line reads like an ad, or the transactional part does not appear at the start of the message, the FTC treats it as commercial. In 2023 the FTC fined Experian $650,000 for marketing emails dressed up as account messages.

Do password reset and security alert emails need an opt-out?

No. Password resets, fraud warnings, and security alerts are transactional messages that protect an account you already hold, so CAN-SPAM, GDPR, and CASL all exempt them from consent and opt-out rules. You would not want to unsubscribe from them anyway. This is also why Gmail rarely shows its Unsubscribe button on that kind of mail.

What is the primary-purpose test under CAN-SPAM?

It is how the FTC decides whether a mixed email is commercial or transactional. When a message carries both, it counts as commercial if a reasonable reader would judge the subject line to be an ad, or if the transactional content does not appear at or near the beginning of the body. A commercial verdict triggers the full opt-out rules.

Do GDPR and CASL exempt transactional emails too?

Yes, in effect. Under UK PECR and the ICO's guidance, routine service messages are not direct marketing, so they need no consent or opt-out. Canada's CASL exempts purely transactional messages from its consent requirement. Both exemptions collapse the moment the sender adds promotional content, at which point the full marketing rules apply.

What should I do if a receipt email is actually marketing?

Treat it as marketing, because legally it is. Scroll to the footer for the opt-out that commercial email must include; if a promotion-heavy receipt offers none, that is the violation. Document the sender and the dates, report it to the FTC in the U.S. or your data protection authority in the EU, then block the sender.