Full guide
Email is still one of the most profitable channels in digital marketing, but it is also one of the most heavily regulated. Send the wrong message to the wrong person, or skip a few technical basics, and you can find your emails landing in junk folders, your domain flagged by spam databases, and a regulator asking questions. The good news is that the rules are clear, the fixes are practical, and following them happens to be the same thing that keeps your campaigns landing in the inbox. This guide walks Australian businesses through what the law actually requires and how to stay both compliant and effective.
Much of the advice floating around online is written for the United States or Europe, citing rules that do not apply here. If you market to Australians, the law you need to know is the Spam Act 2003, supported by the Privacy Act 1988. Let us start there, then move on to the deliverability traps that quietly sink so many campaigns.
Which law actually applies to Australian email marketing?
In Australia, the headline legislation is the Spam Act 2003, administered and enforced by the Australian Communications and Media Authority (ACMA). It covers commercial electronic messages, which includes marketing emails, SMS and instant messages. Alongside it, the Privacy Act 1988 governs how you collect, store and handle the personal information that sits behind your list. American frameworks such as CAN-SPAM and the European GDPR may also reach you if you email contacts in those regions, but for an Australian audience the Spam Act is the rulebook that matters most. Penalties for serious or repeated breaches can run into substantial figures, so this is not a box-ticking exercise.
What are the three rules every email must follow?
The Spam Act distils into three obligations that apply to every commercial message you send. Master these and you have covered the core of the law.
- Consent. You need permission before you send. Consent can be express, where someone actively opts in, or inferred from an existing business relationship. Either way you should be able to show how and when it was given.
- Identify yourself. Every message must clearly state who is sending it and include accurate contact details that stay valid for a reasonable period.
- Unsubscribe. You must offer a functional, low cost or free way to opt out, and you must honour requests promptly.
It is worth seeing each rule next to what satisfies it and what lands senders in trouble, because the line between compliant and breaching is usually obvious once it is spelled out.
| Spam Act rule | What satisfies it | What breaches it |
|---|---|---|
| Consent | Express opt-in, or inferred from a genuine business relationship, with a record kept | Bought, scraped or rented lists, or addresses harvested with no relationship |
| Identify yourself | Clear sender name and accurate contact details that stay valid | Hidden, fake or no sender identity, or contact details that go dead |
| Unsubscribe | Functional, low cost or free opt-out honoured within five working days | Missing or broken link, logins demanded, or requests ignored |
None of this is onerous for a legitimate business. The senders who get into trouble are almost always the ones cutting corners on consent or making it hard to leave.
What counts as proper consent in 2026?
Consent is where most compliance problems begin. Express consent means a person knowingly agreed to receive your messages, for example by ticking an unchecked box or filling in a signup form. Inferred consent can exist where someone has bought from you, or where they have published a relevant business address without indicating they do not want to be contacted. What does not count is a list you bought, scraped or rented, or addresses harvested without any relationship. Treat your list as something you earn rather than acquire, keep a record of where each contact came from, and you build an asset that is both legal and genuinely engaged.
How should you handle unsubscribes correctly?
A working unsubscribe is not just good manners, it is a legal requirement with specific timing. Under the Spam Act, you must action an opt-out within five working days, and the unsubscribe facility must remain functional for at least 30 days after the message was sent. The process has to be simple: a single click or a short reply, with no demand that the recipient log in, pay a fee or hand over extra information. Beyond the legal duty, fast and frictionless unsubscribes protect your sender reputation, because frustrated recipients who cannot leave easily tend to hit the spam button instead, and spam complaints are one of the surest paths to blacklisting.
How does email blacklisting actually happen?
Blacklisting is when mailbox providers or independent spam databases decide your sending domain or IP address is a likely source of unwanted mail. Once flagged, your emails may be quietly diverted to junk or blocked outright, often without any notice to you. The common triggers are predictable: high spam complaint rates, sending to invalid or purchased addresses that bounce, a sudden spike in volume from a cold domain, and missing authentication. Poor deliverability is a real and costly problem, with industry research from email deliverability specialists consistently showing that a meaningful share of legitimate commercial email never reaches the inbox. Recovering a blacklisted domain can take weeks of careful remediation, which is why prevention through consent and clean lists is always the cheaper option.
Why do SPF, DKIM and DMARC matter so much now?
Email authentication is the technical proof that a message genuinely came from your domain, and it has moved from nice-to-have to essential. The three standards work together: SPF lists the servers allowed to send for your domain, DKIM adds a cryptographic signature, and DMARC tells mailbox providers what to do when a message fails the first two checks. Major providers now expect bulk senders to have all three correctly configured, and unauthenticated mail is far more likely to be filtered or rejected. Setting these records up protects your brand from spoofing and impersonation, and it is one of the strongest signals you can send that you are a trustworthy sender rather than a spammer.
What does a compliant, high-performing program look like?
The reassuring truth is that compliance and performance pull in the same direction. The practices that keep you on the right side of the law are the same ones that keep you in the inbox and your audience engaged. Build your foundations around a few habits and revisit them each quarter.
- Grow your list with genuine opt-ins and keep evidence of consent for each contact.
- Clean your list regularly, removing hard bounces and unengaged contacts to lift deliverability.
- Configure SPF, DKIM and DMARC, and monitor your sender reputation over time.
- Make unsubscribing effortless and process every request well within five working days.
- Watch your complaint and engagement metrics, and slow down if either heads the wrong way.
Treat email as a relationship rather than a megaphone and the rest follows. Permission-based sending, clear identification, easy exits and solid authentication keep you compliant, keep you out of the blacklists, and keep the people who actually want to hear from you opening your messages. That is a strategy worth building on rather than one that puts your reputation at risk.
Watch: email compliance and deliverability explained
In short
Could your email marketing get you blacklisted, and is it legal?
Key takeaways
- The Spam Act 2003 requires consent, sender identification and a working unsubscribe on every commercial email.
- Unsubscribe requests must be honoured within five working days, and the link must stay live for at least 30 days.
- Buying lists, ignoring complaints and skipping SPF, DKIM and DMARC are the fastest routes to blacklisting.
- Compliance and deliverability are the same job: good practice keeps you legal and keeps you in the inbox.