Skip to content

Spam Act Compliance: What US Email Advice Gets Wrong

Australian email marketing laws differ sharply from CAN-SPAM. No B2B exemption, stricter consent, real unsubscribe rules. The operational checklist for marketers.

28 Aug 202610 min read
  • Compliance

Verified as of August 2026: Australian regulation is actively changing. This is operational orientation, not legal advice; confirm with ACMA, OAIC, ASQA or your legal adviser.

If you run email marketing into Australia using advice written for the US market, you are almost certainly non-compliant. The single biggest reason: the Spam Act 2003 has no blanket B2B exemption. CAN-SPAM effectively lets you cold-email a business address as long as you identify yourself and offer an opt-out. Australia does not work that way. Under the Spam Act, a commercial electronic message sent to an Australian address needs consent, express or inferred, regardless of whether the recipient is a person at home or a procurement manager at an enterprise. Scraped lists, purchased lists and "we found your email on LinkedIn" are not consent. That one difference invalidates most of the outbound playbooks circulating in growth communities.

The rest of the Act is more forgiving than people fear, but only if you actually implement it. There are three obligations: consent, sender identification, and a functional unsubscribe. Everything else is detail.

Key Takeaways

  • Australia's Spam Act 2003 requires consent (express or inferred) for every commercial electronic message. There is no general B2B carve-out equivalent to CAN-SPAM's.
  • Inferred consent requires a genuine existing relationship and an address the person gave you directly or published without a "no unsolicited email" notice. Buying or scraping a list creates neither.
  • Every message must accurately identify the business that authorised it: legal name, or trading name plus ABN, plus current contact details.
  • Unsubscribe must be clear, free, honoured within five working days, functional for at least 30 days after sending, and must not require a login or extra personal information.
  • The Act covers email, SMS, and instant messaging, not voice calls or fax.
  • Penalties are set by ACMA and change; do not rely on figures quoted in old blog posts. Check acma.gov.au for current enforcement outcomes.

The compliance gap is rarely intent. It is a US-written SOP running unmodified against an Australian list.

Why US-Centric Email Advice Actively Misleads

CAN-SPAM is an opt-out regime. You may send a first message to anyone, provided you don't lie about who you are and you honour the opt-out. Every American growth tactic: cold outbound sequences, list enrichment, "we scraped your competitors' followers", descends from that permission structure.

Australia's Spam Act is an opt-in regime with a narrow inferred-consent path. The starting position is that you may not send. You then need to establish why you may. That is a fundamentally different mental model, and swapping "add an unsubscribe link" into an American workflow does not bridge it.

The B2B assumption is the expensive one

Because CAN-SPAM's practical effect is that B2B cold email is legal in the US, an entire tooling industry has been built on it: data providers, sequencers, "verified work email" databases. Those tools are not illegal in Australia, but using their output to send unsolicited commercial email to Australian addresses generally is a breach. The tool doesn't create the consent. Your relationship does.

The Three Rules, Stated Plainly

Express consent is someone actively agreeing to receive marketing from you: ticking an unticked box, entering their email into a form that clearly says what they'll get, verbally agreeing and it being recorded. Pre-ticked boxes and bundled consent buried in T&Cs are weak at best.

Inferred consent is narrower than most marketers assume. It generally requires both:

  • an existing business or personal relationship where receiving that kind of message is reasonably expected, and
  • an address the person gave you directly, or one published in a work-related capacity relevant to what you're sending, and not accompanied by a statement that unsolicited commercial email is not wanted.

A "Contact us" address published on a company website may support inferred consent for a message genuinely relevant to that person's role. It does not support a generic 12-touch drip about an unrelated product. And if the page says "no unsolicited marketing emails," inferred consent is off the table.

2. Sender identification

The message must clearly and accurately identify the individual or organisation that authorised the sending: which may not be the same entity as the one whose product is being advertised. Include legal or registered business name, and make the contact information accurate and reasonably current. Adding an ABN is good practice and makes identification unambiguous.

This matters when agencies send on behalf of clients, or when a lead vendor emails on your behalf. Identify the authorising business, not just the brand in the creative.

3. Unsubscribe

The functional-unsubscribe rule is where audits most often fail, because the mechanics are specific:

  • The opt-out must be presented clearly and be easy to find.
  • It must be honoured within five working days.
  • It must be at no cost to the recipient.
  • It must remain functional for at least 30 days after the message was sent.
  • It must not require the recipient to log in, create an account, or supply additional personal information.

That last point kills the common pattern of "click unsubscribe → land on a preference centre requiring email confirmation and a reason." A one-click, no-friction opt-out is the safe design. Preference centres are fine as an additional option beside an unconditional unsubscribe.

Translation Table: US Assumption vs Australian Reality

US CAN-SPAM assumptionAustralian reality (Spam Act 2003)What to change
B2B cold email is fine with an opt-outNo blanket B2B exemption; consent is still requiredRebuild outbound around inbound consent, events, referrals, or genuinely inferred consent from an existing relationship
Purchased/enriched lists are usablePurchase or scraping creates no consent of any kindDelete purchased AU segments; do not "warm them up" via email, that first send is the breach
Opt-out within 10 business days is fineOpt-out must be honoured within 5 working daysTighten suppression sync; automate rather than batching weekly
Unsubscribe can route to a preference centre requiring loginMust not require login or extra personal informationAdd a true one-click unsubscribe before any preference options
Physical mailing address satisfies identificationMust accurately identify the authorising business: name, or name plus ABN, with current contact detailsAdd legal entity name + ABN to the footer; check who legally authorised the send
Implied consent from "publicly available" emailPublication alone is not enough; relevance to role required, and a no-unsolicited notice defeats itCheck the source page for a no-unsolicited statement; log where every address came from
Only email is regulatedEmail, SMS and instant messaging are all coveredApply the same consent/ID/unsubscribe standard to SMS and WhatsApp-style channels

What Compliant Growth Actually Looks Like in Australia

The honest consequence of no B2B exemption: Australian pipeline is built on permission, not interruption. That reshapes the channel mix.

Inbound and organic carry more weight

Search, LinkedIn, and content do more of the pipeline work in Australia than in the US, because the outbound shortcut is largely closed. When I have worked on edtech growth: for example Masai School, where organic social moved from 26K to 117K on Instagram and 50K to 160K on LinkedIn, the value of that audience is that it produces consented list growth. Every follower who opts in is an address you can legally email forever.

Trade shows, webinars, and co-marketing produce addresses given directly, with an obvious relationship. Document the source. Store the consent record with a timestamp and the wording shown at the point of collection.

LinkedIn outreach is not covered by the Spam Act

Direct messages within a platform are generally treated differently to commercial electronic messages sent to an address. That makes LinkedIn a legitimate first-touch channel where email is not: but platform terms and privacy obligations still apply, so it is not a free-for-all.

Permission-first markets reward audience building. The cost of cold email being closed is that organic compounds harder.

If ACMA ever asks, "why did you send this?", you need an answer per address, not per campaign. A workable minimum:

  • Source: form, event, import, referral, integration
  • Timestamp, when consent was captured
  • Wording, exactly what the person agreed to
  • Scope, which brands/products the consent covers
  • Evidence: form ID, event name, screenshot of the sign-up state

Most CRMs will store these as custom fields. The discipline is capturing them at import time, not reconstructing later.

Common Failure Patterns

Agency sends without checking provenance

The client hands over a spreadsheet. Nobody asks where it came from. The agency is now the sender. Ask the provenance question in writing before the first send, every time.

Buying a company does not automatically transfer consent to market under a new brand. If the sender identity changes materially, the consent may not stretch. Get advice.

Cross-border sending

The Spam Act applies to messages with an Australian link: sent from Australia, or sent to an address accessed in Australia. Sending from Singapore or Bengaluru does not exempt you.

Suppression lists that don't sync

Unsubscribing in one tool and staying live in another is the most common technical breach. One suppression source of truth, propagated to every sending system.

Where SMS Fits

SMS carries the same three obligations and generally attracts more complaints, because the intrusion is higher. Practical guidance: use SMS only for people who expressly opted into SMS specifically, keep sender ID identifiable, and include a working reply-STOP or short-link opt-out. Do not migrate an email list into SMS on the assumption that consent transfers.

A 30-Minute Compliance Audit

  1. Pull a live campaign. Can you name the legal entity that authorised it? Is that entity in the footer?
  2. Click your own unsubscribe from a fresh browser. Did it require a login or any extra field? If yes, fix today.
  3. Check suppression latency: how long between opt-out and full propagation across every sending system?
  4. Sample 20 addresses from your largest AU segment. For each, can you state the consent source? If more than a couple are unknown, stop sending to that segment.
  5. Check whether unsubscribe links from messages sent 29 days ago still resolve.
  6. Review any lead-vendor contract for a warranty that addresses were collected with Spam Act-compliant consent, with indemnity.

Frequently Asked Questions

Does the Spam Act really apply to B2B email in Australia?

Yes. There is no general business-to-business exemption comparable to CAN-SPAM. Consent, express or inferred, is required for commercial electronic messages regardless of whether the recipient is acting in a business capacity.

Can I email an address published on a company's website?

Sometimes. Inferred consent may apply where the address is published in a work-related capacity and your message is directly relevant to that role, provided the publication is not accompanied by a statement that unsolicited commercial messages are not wanted. Generic marketing sequences to a general info@ address are a poor fit.

Is a purchased list ever usable in Australia?

Purchase itself creates no consent. If the vendor genuinely obtained express consent for your brand to email that person, that consent may be valid: but you need evidence, not assurances. In practice, most list purchases fail this test.

How quickly must I action an unsubscribe?

Within five working days. Practically, automate it to near-instant; five days is a ceiling, not a target.

Can my unsubscribe page ask why they're leaving?

Only optionally, after the unsubscribe has already taken effect. It must not require additional personal information or a login to complete the opt-out.

Does the Spam Act cover SMS and WhatsApp-style messages?

It covers email, SMS and instant messaging. It does not cover voice telemarketing or fax, which sit under different rules.

What are the penalties?

ACMA administers enforcement and figures change over time. Rather than relying on numbers in blog posts, check ACMA's current guidance and enforcement register directly at acma.gov.au.

I'm based overseas, does this apply to me?

If the message has an Australian link (sent to an address accessed in Australia, for example), yes. Location of the sender does not create an exemption.

How does this interact with the Privacy Act?

They are separate. The Spam Act governs sending; the Privacy Act governs how you collect, use, store and disclose personal information, including the reform obligations landing through 2026. See oaic.gov.au and my companion piece on privacy reform for marketers.

Does an existing customer relationship mean I can email anything?

No. Inferred consent extends to messages a person would reasonably expect given the relationship. A wildly unrelated offer stretches beyond that.


If you are running growth into Australia off a playbook written for the US, the email layer is usually the first thing that breaks: and the last thing anyone audits. I work with edtech and startup teams on organic-first growth systems where consented list building is the engine rather than an afterthought. If you want a second set of eyes on your channel mix before your next quarter, you can find how I work at younusfardeen.com.