The sixty-second answer
You can email customers directly, and for genuine correspondence you should. The line is not list size - it is whether the message is a commercial electronic message, because CASL section 6 then demands consent, sender identification, working contact details and an unsubscribe mechanism. A tool exists to make those provable at scale.
The wrong question and the right one
Small business owners usually frame this as a number. "Is fifty people a mailing list?" "What if I just Bcc everybody?"
Canadian law does not care about the number. Section 6(1) of CASL prohibits sending, or causing or permitting to be sent, a commercial electronic message to an electronic address unless two things are true: the recipient consented, expressly or by implication, and the message complies with subsection 6(2) [1]. There is no threshold. One recipient is enough to engage it.
So the right question is: is this message a commercial electronic message, and if so, can I satisfy 6(2)? Everything else - whether you need software, and which - follows from the answer.
Where the line actually sits
The statute draws several bright lines that matter far more to a small business than any general theory.
Solicited messages are outside it. By regulation, section 6 does not apply to a message "sent in response to a request, inquiry or complaint or otherwise solicited by the person to whom the message is sent" [3]. Answering a customer is not a compliance event.
Business-to-business inquiries are outside it. Section 6 does not apply to a message sent to a person engaged in commercial activity that "consists solely of an inquiry or application related to that activity" [1]. Writing to a supplier to ask if they stock something is not covered.
Internal messages are outside it. The regulations exclude messages sent by an employee, representative, consultant or franchisee of an organisation to another within the same organisation where the message concerns its activities, and between two organisations that have a relationship, where the message concerns the activities of the receiving organisation [3].
Legal and transactional messages are outside it. Messages sent to satisfy a legal or juridical obligation, to give notice of an existing or pending right, obligation, court order, judgment or tariff, or to enforce one, are excluded by regulation [3].
Several commercial messages need no consent, but still need the rest. Section 6(6) removes the consent requirement - not the 6(2) requirements - for messages that solely provide a quote or estimate the recipient requested, facilitate or confirm a transaction the recipient already agreed to, provide warranty, recall or safety information about something they use or bought, give factual notification about an ongoing subscription, account or similar relationship, or deliver a product or update they are entitled to [1]. Read that list carefully: your receipts and appointment confirmations are in it. Your "while you're here, have you seen our new service" is not.
Consent: express and implied
Once a message is a commercial electronic message and none of the exclusions apply, you need consent - and implied consent is narrower than most people assume.
Consent is implied only in the listed circumstances [2]. The three that matter to a small business:
An existing business relationship. Defined to arise from, among other things, a purchase or lease of a product, goods, service, land or an interest in land within the two-year period immediately before the message is sent; acceptance of a business, investment or gaming opportunity in the same period; bartering in that period; or a written contract currently in existence or expired within that period [2]. The two-year clock is the part people miss. A customer from 2021 does not carry implied consent into 2026.
A conspicuously published address. Consent is implied where the recipient "has conspicuously published, or has caused to be conspicuously published, the electronic address to which the message is sent", the publication is not accompanied by a statement that they do not wish to receive unsolicited commercial electronic messages, and the message is relevant to that person's business, role, functions or duties [2]. Three conditions, all of which must hold - and the relevance condition is not a formality.
A disclosed address. The same test applies where the person handed you the address directly without indicating they did not want unsolicited commercial messages, and the message is relevant to their business role [2].
Express consent is stronger and does not expire on a two-year clock. If you are collecting it, the regulations prescribe what the request must contain: the name you carry on business under, the equivalent for anyone on whose behalf consent is sought, a statement identifying that relationship, a mailing address plus a telephone number, email address or web address, and a statement that consent can be withdrawn [4].
What every commercial message must carry
Consent alone is not compliance. Subsection 6(2) requires the message to identify the sender, give information enabling the recipient to readily contact them, and set out an unsubscribe mechanism [1]. Contact information must stay valid for a minimum of 60 days after the message is sent [1].
The unsubscribe has hard mechanics. Under 11(1) it must let the recipient indicate, at no cost to them, that they no longer wish to receive messages, using the same electronic means the message was sent by or - where that is not practicable - another electronic means, and it must specify an electronic address or a link to a web page where the indication can be sent [2]. That address or page must remain valid for at least 60 days [2]. And you must give effect to the request "without delay, and in any event no later than 10 business days after the indication has been sent, without any further action being required on the part of the person" [2].
The prescribed identifying details, and the regulation that lets some of them live behind a link, are set out in what your business email signature must include.
So when do you actually need a tool?
Three tests. If you answer yes to any of them, stop using Bcc.
Can you prove consent for each address, individually, two years from now? A spreadsheet you update by hand will not survive that question.
Can you honour every unsubscribe within ten business days, automatically, without further action? That is the statutory standard [2], and it is a systems requirement, not a diligence one.
Are you sending to enough people that bounces matter? The mail plumbing itself changes here. A mailing list operates "by redistribution rather than by forwarding", and the envelope return address is changed "so that all error messages generated by the final deliveries will be returned to a list administrator, not to the message originator" [5]. That is a different mechanism from an alias, where the rest of the envelope and the message body are left unchanged [5]. Sending bulk from a personal mailbox means every bounce lands on you personally, and your normal correspondence pays the deliverability price - the wider version of that problem is in why your business email goes to spam.
A proper tool also gets you one-click unsubscribe, which receiving systems surface as a button. That requires a List-Unsubscribe header carrying an HTTPS URI plus a List-Unsubscribe-Post header, and the message must carry a valid DKIM signature covering both headers - without it, the receiver should not offer one-click at all [6]. You cannot bolt that onto a Bcc.
The privacy layer underneath
CASL governs the sending. PIPEDA governs the list. Purposes must be identified at or before the time of collection, knowledge and consent are required for collection, use and disclosure, and personal information "shall not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual" [7]. An address given to you for a quote was not given to you for a newsletter. If you run two ventures, the same principle stops you merging the lists - see running two businesses from one email setup and business email privacy obligations in Canada.
Where we sit
MapleMail is a mailbox, not a campaign platform. That distinction is deliberate and we would rather say it plainly than sell you the wrong thing: your day-to-day correspondence, quotes, confirmations and replies belong in hosted business email on your own domain, and a marketing list belongs in something built to prove consent and process unsubscribes automatically.
What we contribute is the foundation both rest on - a domain you own, and SPF, DKIM and DMARC records handed to you in writing so that whatever you send from authenticates as you.
Plans and what each mailbox includes are on the pricing page. One limit worth stating: this article describes what the statute and regulations say. It is not legal advice, and a campaign to a list of uncertain origin is a conversation for a lawyer, not a hosting provider.