Questions about CAN SPAM.

In the US, the law governing the sending of commercial email is CAN SPAM. I’ve seen a number of questions about CAN SPAM recently.
One came from twitter, where someone was asking if just having an email address meant permission to send to it. Clearly, just being able to dig up an email address doesn’t imply permission to send marketing or commercial email to it. I can promise you April23@contact.wordtothewise.com did not sign up to receive information on increasing Facebook followers.
CAN SPAM doesn’t prohibit unsolicited email. All it says is that if you send unsolicited email you must do a few things.

  1. The recipient must be able to opt-out of future messages.
  2. The opt-out process needs to be easy for the recipient. No more than a single click to an opt-out page and the recipient does not need to provide more than an email address and an email preference.
  3. The sender must identify their organization through a physical address.
  4. The sender can’t fake or forge any part of the headers.

And, really, that’s it. Meet those few criteria and senders can send as much spam as they want.
Another person asked if there is a risk that CAN SPAM violators will have their door broken down by the CAN SPAM police. And, no, CAN SPAM police aren’t going to break down your door. But they’re not the only thing to consider when making a decision to avoid complying with CAN SPAM.
It’s breaking the law, and I won’t recommend my clients knowingly break the law. Not because I think they’re going to end up fined or in jail, but because meeting the law is such a low bar. I mean, even the worst senders don’t claim they want to keep people on their list who don’t want to stay on the list. Putting in a physical address may seem like a bit much for some groups, but it makes you look like a real company. This is part of running an effective business email marketing program.
There are also other penalties for not complying with CAN SPAM. I know that there are people who make filtering decisions that treat mail that violates CAN SPAM as filter targets. Many filter groups also treat the lack of an opt-out link as a sign of spam. In a much more extreme case, I recently had a SBL listing that centered around a problem in the opt-out process. My client was a brick and mortar sender that collected the email address of a spamhaus volunteer at the point of purchase. The SBL rep told me this happens quite a bit with that particular address, and that she normally just opts-out. But in this case the sender didn’t honor the opt-out, so my client was listed. And stayed listed for a couple weeks and lost a lot of money — all because they didn’t honor an opt-out.
While a small business is probably not going to be subject to FTC penalties, there are consequences to violating CAN SPAM.

Related Posts

Marketing to businesses

“If you do stupid things, you’re going to get blocked,” says Jigsaw CEO Jim Fowler in an interview with Ken Magill earlier this week.
Jigsaw is a company that rewards members to input their valuable business contacts. Once the addresses are input into Jigsaw, they are sold to anyone who wants them. Jigsaw gets the money, the people providing information get… something, the people who provided business cards to Jigsaw members get spammed and the people who downloaded the lists get to deal with a delivery mess. Sounds like a lose for everyone but Jigsaw.
Except that now Jigsaw is listed on the SBL for spam support services. Well, that’s going to cause some business challenges, particularly given how many companies use the SBL as part of their filtering scheme.
It’s hard to think of a situation where I would appreciate someone I gave a business card to providing my information to a site that then turns around and lets anyone download it to send email to. I know, I know, there are a million companies out there I’ve never heard of that have The Product that will Solve All my Problems. But, really, I don’t want them in my work mailbox. The address I give out on my business cards is, for, y’know, people to contact me about what I’m selling or to contact me about things they’ve already purchased from me. That address is not for people to market to. I have other addresses for vendors, and even potential vendors, to contact me.
Jigsaw clearly facilitates spam to businesses by collecting email addresses and then selling them on. This is a drain on small businesses who now have inboxes full of valuable offers to wade through. Perhaps their stint on the SBL will make them reconsider their spam support services.
HT: Al

Read More

Spamhaus and Gmail

Today’s been chock full of phone calls and dealing with clients, but I did happen to notice a bunch of people having small herds of cows because Spamhaus listed www.gmail.com on the SBL.
“SPAMHAUS BLOCKS GOOGLE!!!” the headlines scream.
My own opinion is that Google doesn’t do enough to police their network and their users, and that a SBL listing isn’t exactly a false positive or Spamhaus overreaching. In this case, though, the headlines and the original article didn’t actually get the story right.
Spamhaus blocked a range of IP addresses that are owned by Google that included the IP for www.gmail.com. This range of IP addresses did not include the gmail outgoing mailservers.
Spamhaus says

Read More

Spamhaus dDOS

I got mail late last night from one of the Spamhaus peeps telling me that they were under a distributed Denial of Service (dDOS) attack. This is affecting email. Incoming email is delayed and they’re having difficulty sending outgoing email. This is affecting their responses to delisting queries.
They are working on mitigation and hopefully will be fully up and running soon.
Updates when I get them.
Update (8/29/2012): mail to Spamhaus should be back.

Read More