Skip to content
Your Rights

Your rights when 'unsubscribe' doesn't stop the emails

You unsubscribed. They kept emailing. Under CAN-SPAM and GDPR you have legal recourse, and the FTC's settlement record proves senders take it seriously.

Email Unsubscriber Team 5 min read
Flat vector illustration of a dated clipboard with day 11 circled, a fan of three dated envelopes beside it, a magnifying glass over one date, and a calendar pinned at day 10.

You unsubscribed last week. The emails kept coming. Under U.S. and EU law, the sender broke the rules. The penalties for ignoring an unsubscribe request are big enough that real companies pay millions to settle.

If a company keeps emailing after you unsubscribe, it is likely breaking the law. Under U.S. CAN-SPAM, senders must honor an opt-out within 10 business days or face FTC penalties. Under EU GDPR, withdrawing consent must be as easy as giving it. Document the dates, block the sender, and report them.

If you haven’t clicked yet, see Is it safe to click unsubscribe? first.

What CAN-SPAM requires

Many readers assume unsubscribing is a courtesy. In the U.S., the sender owes you the unsubscribe by law.

Under CAN-SPAM, commercial senders must:

  • Include a working opt-out mechanism in every commercial email.
  • Honor the opt-out request within 10 business days.
  • Require nothing more than your email address to process it.
  • Not charge a fee, demand additional personal information, or force you through more than a single web page.

Violations carry real penalties. The FTC’s official guidance puts the maximum civil penalty at $53,088 per non-compliant email (the 2025 inflation-adjusted ceiling). The FTC re-publishes the figure each January. The figure is the statutory ceiling, and the FTC uses it as leverage in settlement negotiations.

Settlements that prove it has teeth

Settlements come in well below the per-email rate. They motivate compliance:

  • Experian paid $650,000 in 2023 for sending marketing emails without an unsubscribe option.
  • Verkada paid $2.95 million in 2024 (the largest CAN-SPAM penalty the FTC has ever imposed).

The FTC opens cases when patterns emerge from individual complaints, including yours.

What the EU adds

EU rules go further. Under GDPR and the ePrivacy Directive, a sender needs your explicit consent before mailing you at all (narrow exceptions for existing customer relationships). Pulling that consent must take the same single step as giving it. If a sender forces you to log in, fill out a form, or contact support to unsubscribe, that breaks the rule on its own.

Why you still get spam after unsubscribing

Three things might be happening. The right next step depends on which. Seven reasons you’re still getting emails covers the full list; the three below are the ones with a legal angle.

You unsubscribed from one list, but the company has several. A retailer might run a promotional list, a “back in stock” list, a loyalty list, and a “we miss you” win-back list (all separate). Unsubscribing from one doesn’t touch the others. Look for “manage preferences” instead of a single “unsubscribe” link. A preferences page exposes all of them in one place.

You’re inside the legal grace period. The 10-business-day clock means up to two weeks of legitimate continued sending after a perfect unsubscribe. Mark the date you clicked. If emails keep arriving past that window, you’ve moved from grace period to violation.

The sender is non-compliant. Block, report, file a complaint.

Tracking pixels

Before you click anything, the sender knows you opened the email. Most marketing emails contain a 1×1 transparent image (a tracking pixel) that reports the open back to the sender along with your IP address, device type, and rough location.

Under GDPR, embedding a tracking pixel without prior consent counts the same as sending the email itself without consent. CAN-SPAM doesn’t address pixels, but if a sender ignores your unsubscribe request and keeps firing pixel pings, you can report them on the unsubscribe violation alone. Unsubscribing stops future pixel pings at the source. One more reason to clear out senders you don’t want. For how pixels work and how to block them, see spy pixels: the invisible trackers in more than half of your emails.

How to file a complaint

U.S.: the FTC

Forward the offending email (full headers included) to reportfraud.ftc.gov. Include:

  • The original “From” address.
  • The date you first unsubscribed.
  • The dates of every email received after the 10-business-day window.
  • A screenshot of the unsubscribe page if it required more than your email address.

The FTC doesn’t act on individual complaints, but enough complaints against the same sender build a case file. The FTC built the Experian and Verkada cases from accumulated complaints.

EU: your national DPA

EU residents can file a complaint with their national Data Protection Authority. The European Data Protection Board maintains the directory of national DPAs. The same evidence applies: original email, full headers, timestamps. DPAs investigate individual complaints and have direct enforcement power against companies operating in their jurisdiction.

Block, report, repeat

The practical order of escalation:

  1. Unsubscribe through the proper channel. Your email client’s native top-bar button is best (see the safe-click guide for what to look for).
  2. Wait 10 business days. Mark your calendar.
  3. Block the sender at the email-provider level if they keep emailing. This stops the messages from reaching you regardless of compliance.
  4. Report to the FTC (U.S.) or your DPA (EU) if you can identify the sender and prove non-compliance.
  5. Document every step. Timestamps, screenshots, original emails. Without records, no agency can act on your complaint.

The takeaway

Senders know the law. That’s why the unsubscribe button exists at all. Most legitimate companies stop within the 10-day window. The ones who don’t are the ones the FTC and DPAs are looking for.

Document each step, and use the channels that exist for it.

If you’re tired of clicking ‘unsubscribe’ again and again and your inbox keeps being bombarded with all kinds of ‘exciting news’ from services and products you no longer care about, you should jump to our Homepage to learn how we could help you.

Or check out our Email Unsubscriber App.

Frequently asked questions

Is it illegal for a company to keep emailing me after I unsubscribe?

In the U.S., yes. CAN-SPAM requires commercial senders to honor an opt-out within 10 business days, and ignoring it is a violation the FTC can penalize. In the EU, GDPR and the ePrivacy Directive go further: withdrawing consent must be as easy as giving it, so a sender that keeps mailing you after you opt out breaks the rule.

How long does a sender legally have to stop emailing me?

Ten business days under CAN-SPAM. That means up to roughly two weeks of legitimate continued sending after a clean unsubscribe. Mark the date you clicked. If emails are still arriving past that window, you have moved from the grace period into a violation, and you can start documenting it for a complaint.

Why do I still get spam after unsubscribing?

Usually one of three things. The company runs several lists and you left only one, so look for a 'manage preferences' page that exposes them all. Or you are still inside the 10-business-day grace period. Or the sender is simply non-compliant, in which case you block them, report them, and file a complaint.

What are the penalties for breaking CAN-SPAM?

The FTC's 2025 inflation-adjusted ceiling is $53,088 per non-compliant email, republished each January and used as settlement leverage. Actual settlements land lower: Experian paid $650,000 in 2023 for sending marketing email with no unsubscribe option, and Verkada paid $2.95 million in 2024, the largest CAN-SPAM penalty the FTC has ever imposed.

How do I report a company that ignores my unsubscribe request?

In the U.S., forward the offending email with full headers to reportfraud.ftc.gov, including the original From address, the date you first unsubscribed, and the dates of every email received after the 10-business-day window. EU residents file with their national Data Protection Authority via the EDPB directory. The FTC builds cases from accumulated complaints, so yours counts.

Do email tracking pixels have anything to do with unsubscribing?

Yes. Most marketing emails hide a 1x1 transparent pixel that reports your open, IP address, device type, and rough location back to the sender. Under GDPR, a pixel without consent counts the same as sending the email without consent. Unsubscribing stops future pixel pings at the source, one more reason to clear out senders you do not want.