emailmarketing.net

OECD Anti-Spam Toolkit (2006)

The OECD's cross-border anti-spam policy framework: eight elements, the Council Recommendation on enforcement co-operation, and the BIAC/MAAWG ISP and email-marketing best practices.

Foundational11 min read

Who it is for Compliance teams

If you need to compare national anti-spam laws, or to understand how enforcement authorities in different countries work together, the Organisation for Economic Co-operation and Development (OECD) Anti-Spam Toolkit is the closest thing to an internationally agreed reference design for national anti-spam policy.

The Anti-Spam Toolkit of Recommended Policies and Measures was produced by the OECD Task Force on Spam, which the OECD Council approved in 2004 and whose mandate ended in June 2006. The ICCP and CCP committees declassified the Toolkit on 29 March 2006. The OECD Council adopted the accompanying Council Recommendation on Cross-Border Co-operation in the Enforcement of Laws Against Spam on 13 April 2006. The OECD then had 30 member countries, and the Recommendation also invites non-member economies to take account of it.

The Toolkit is a policy and enforcement framework. It does not itself impose obligations on senders. It includes two industry best-practice documents as Annexes: one from BIAC and MAAWG for ISPs, and one from BIAC for email marketers.

What still holds and what is dated

The Toolkit predates mature SPF, DKIM and DMARC, the 2024 bulk-sender requirements from Gmail and Yahoo, mobile-first messaging, and modern reputation systems. Its technical sections (Element IV) refer to SPF, "DKIM/META", Sender-ID, greylisting, BATV and SES, and PTR checks. These are of historical interest, and current practice is covered in dedicated articles on each topic.

What remains directly useful today is the framework for policy and cross-border enforcement: the checklist for designing legislation, the types of consent, the reasoning about who is liable, the model for enforcement co-operation, and the best-practice lists for ISPs and senders, which the M3AAWG documents later expanded. Use the Toolkit for the framework, and the linked references for current technical practice.

The eight elements

The Toolkit is organised around eight related elements of a comprehensive public-policy framework:

# Element Core proposition
I Regulatory approaches Clear, simple anti-spam legislation that sets out what is and is not allowed
II Enforcement Empowered authorities, fast sanctions, cross-border co-operation
III Industry-driven initiatives Self-regulation, codes of conduct, and acceptable use policies that work together with the law
IV Technical measures Layered anti-spam tools. No single method is enough on its own
V Education and awareness Educate both recipients and senders. Target users, groups and small and medium-sized enterprises (SMEs)
VI Co-operative partnerships Public-private collaboration in design and enforcement
VII Spam metrics Measure the effectiveness of policy and technical measures (the MAAWG Email Metrics Program is noted)
VIII Global co-operation (Outreach) Extend the framework to non-OECD economies, with bilateral and multilateral aid

Element I: Regulatory design

Legislation should aim to preserve the benefits of electronic communication, to prohibit and sanction spamming as defined by national law, and to reduce the amount of spam by targeting different stages of sending. The value of legislation depends on the certainty that sanctions will be applied.

Four general legislative principles:

  • Policy direction: set out the main objectives early. They should underlie the whole strategy.
  • Regulatory simplicity: the legislation should be short and simple.
  • Enforcement effectiveness: pair the law with an effective system of sanctions, appropriate standards of proof, and authorities with resources. Poor enforcement makes good legislation useless.
  • International linkages: spam crosses borders, so plan for co-operation and information exchange with foreign authorities.

Legislative best-practice checklist

The Toolkit's table for the regulatory element is a useful design checklist for any jurisdiction that is drafting or comparing anti-spam law:

Issue Recommended approach
Services concerned (scope) Choose a technology-specific law (aimed at the media that cause problems today) or a technology-neutral one (flexible and future-proof). Real-time voice could be regulated separately.
Commercial purpose Decide whether the law covers only commercial and transactional messages, or also non-commercial ones (political, religious). Specific categories may be expressly excluded (for example, academic institutions writing to their alumni).
Consent Three approaches, often combined: expressed (active permission, which is opt-in); inferred or implicit (from conduct or an existing business relationship); assumed (presumed until withdrawn, which is opt-out).
Unsubscribe address Messages should carry a working opt-out. This implies a valid return address, and a postal address may also be required. Leaving these out, or failing to stop sending within the legal period, should be sanctionable.
Information about message origins Prohibit falsified or concealed headers and sender identification. Require the marketer behind the sender to be clearly identified.
Not bulk Email may be classified as spam only above a volume threshold, typically 50–100 messages over 24 hours, so that legitimate bulk mail such as newsletters is not caught.
Labelling The law may require a specific label for advertising or pornographic content.
Person authorising or benefiting Sanction not only the person who physically sends, but also whoever commissioned or authorised the sending or profited financially from it. That person is easier to identify, which helps enforcement.
Harvesting and dictionary attacks Add sanctions where address-harvesting software, harvested lists, or automatic address generation are used.
Illegal access Forbid the unauthorised use of protected computer resources (compromised machines used to send).
Misleading or fraudulent content Scams and phishing may be ordinary computer-related crimes. Anti-spam law may add bans on deceptive subject headings and work together with anti-fraud and consumer law.
Security threats (malware) Often made a crime by statute or through the Council of Europe Convention on Cybercrime.
Cross-border jurisdiction Cover messages sent to or from the jurisdiction, and messages commissioned from within it or benefiting someone within it. Give authorities the power to co-operate across borders.

The checklist maps onto the national regimes: CAN-SPAM (US) follows the opt-out, assumed-consent model; CASL (Canada) and UK PECR follow the expressed, opt-in model. See also EU ePrivacy & GDPR and Australia's Spam Act.

Element II: Enforcement and the Council Recommendation

The Recommendation on Cross-Border Co-operation in the Enforcement of Laws Against Spam (Annex I) is the core of the Toolkit, binding in spirit. It covers serious violations only: conduct that (a) causes or may cause injury, financial or otherwise, to a significant number of recipients, (b) affects particularly large numbers of recipients, or (c) causes substantial harm. The decision to assist always rests with the Spam Enforcement Authority that receives the request.

Governments should improve their legislation to:

  1. Establish a domestic framework of laws, enforcement authorities and practices.
  2. Improve the authorities' ability to co-operate with foreign counterparts (share information, provide investigative assistance).
  3. Improve procedures for co-operation, by prioritising requests and using common resources and networks.
  4. Develop co-operative models between enforcement authorities and private-sector entities.

The Recommendation has four operative parts:

Part Obligation on member countries
(a) Domestic framework Maintain effective laws and Spam Enforcement Authorities. Give those authorities the power to obtain evidence, investigate and act in a timely manner against violations committed from their territory or affecting it. Enable action against both senders and those who profit from the sending. Review frameworks periodically. Consider redress for financial injury.
(b) Ability to co-operate Provide ways to share information with foreign authorities on request, subject to safeguards. Enable investigative assistance (obtaining information, documents and records, and locating persons and things). Designate a contact point and register it with the OECD Secretariat, which keeps and publishes the list.
(c) Procedures Before requesting assistance, do preliminary investigation to confirm that a request is warranted. Prioritise requests. Use common resources (the OECD spam website, informal channels, existing enforcement networks).
(d) Private-sector co-operation Authorities, businesses, industry groups and consumer groups should co-operate on user education, referral of complaint data, and sharing of investigation tools, analysis and trend information. Encourage co-operation to locate and identify spammers, reduce inaccurate domain-registration data, and make the Internet more secure.

The OECD instructed its ICCP and CCP committees to monitor progress within three years. This model of designated contact points, prioritised mutual assistance and private-sector data sharing is the ancestor of today's practical escalation and referral channels, described in Cross-Provider Escalation & Mitigation Channels, and of abuse-report intake, described in Abuse Desk.

Element III: Industry-driven initiatives

Anti-spam law should work together with private-sector self-regulation. The Task Force welcomed the best-practice work of BIAC and MAAWG. It noted that in some jurisdictions such codes could be formally registered with the national enforcement agency, so that the authority can compel compliance where the industry association cannot.

The actors and their duties:

  • Providers of online services or goods: respect customer privacy. Adopt clear company email policies and apply them consistently (for example, never ask for personal information, or ideally never put a clickable link in an email). Authenticate mail or use digital signatures. Prevent phishing with clear domain names and defensive domain registration, monitoring of look-alike sites, and control of "bounced" messages. Tell customers what mail the company will and will not send.
  • Direct marketers: adopt and implement a code of conduct for electronic marketing. Build closer relationships with ISPs to reduce false positives. Align codes with anti-spam law nationally and internationally.
  • ISPs and network operators: implement self-regulation. Adopt and enforce Acceptable Use Policies (AUPs) as contract terms whose breach allows suspension or termination. Inform subscribers about anti-spam and anti-virus filtering.

BIAC and MAAWG best practices for ISPs and network operators (Annex II)

Here "ISPs and network operators" means any entity operating an SMTP server connected to the Internet. Each practice applies only where national law does not contradict it:

# Practice
1 Address compromised end-user equipment, with timely processes to manage it or stop it as a source of spam
2 Use industry-standard authentication for email, for sources, or for both
3 Block potentially infecting attachments. Where content is filtered, obtain the customer's prior agreement as the law requires
4 Actively monitor inbound and outbound volume to detect unusual activity and its source, and respond
5 Establish inter-company processes for reacting to other operators' incident reports, and accept end-user complaints
6 Communicate security policies and procedures to subscribers
7 Send non-delivery notices (NDNs) only for messages originated by their own account holders, which avoids backscatter
8 Ensure that only their account holders use their mail submission servers (submission authentication)
9 Maintain accurate WHOIS, DNS and IP registration records (WHOIS, SWIP, RWHOIS), with role contacts (postal, phone, email) for resolving abuse
10 Ensure that all public IP addresses have correct forward and reverse DNS and WHOIS or SWIP entries, and that private address space complies with RFC 1918

These practices are the direct precursors of the M3AAWG Senders BCP and of the operational controls in Sending Infrastructure Practices. Abuse Desk expands on role accounts and WHOIS hygiene, and IPv6 Reverse DNS on PTR expectations.

BIAC best practices for email marketing (Annex III)

This is a voluntary code for marketers. Where national law is stricter, the law governs. It contains nine recommendations and a set of technical tips:

# Recommendation
1 Respect the consent requirements of the country from which the marketer operates, unless the marketer knowingly or intentionally targets consumers in another country
2 Keep records of opt-in and opt-out requests so that lists can be cleaned before broadcasts. Record proof of consent, including the date and time, the originating IP address, and the collection URL or medium, and provide it on request
3 In all marketing mail (not transactional mail), provide an obvious, clear and efficient opt-out by email or on the web. Do not bury it. Confirm the opt-out without requiring further action from the consumer
4 Every message must clearly identify the sender. The subject line and body must accurately reflect the content, origin and purpose, and the sender's identity should appear above the fold where possible. Avoid subject lines about "free offers" or "winning prizes", which trigger spam filters. Include the sender's main postal address.
5 Provide a link to the sender's privacy policy
6 Marketers, list brokers and list owners must ensure that list addresses were obtained legally. Review the broker's privacy policy and collection procedures, and obtain a contractual warranty that collection was legal
7 Use great discretion when marketing to children and young people. Adult content (sexually explicit material, gaming and gambling, tobacco, alcohol, firearms) needs age-appropriate handling and, where applicable, the tag "SEXUALLY EXPLICIT" at the start of the subject line. Seek parental permission where required
8 Have a fair, effective, confidential and easy-to-use system for handling complaints
9 Disclose the addresses of existing consumers to third-party affiliates or within a family of companies only if they are used consistently with the purpose of collection, an easy opt-out exists, or consent was given. Be transparent about brand relationships

Technical tips for electronic marketers (Annex III):

  • All servers (inbound, outbound, websites) should have reverse DNS (PTR) entries. Forward and reverse lookups should match, and sending machines should identify themselves with that name in HELO or EHLO.
  • Publish SPF records, domain-key records (the predecessor of DKIM), or both for senders and for third-party sites associated with a mailing, and keep them current.
  • Give outbound mail servers IP addresses distinct from the site's other servers.
  • Keep WHOIS records accurate and complete.
  • Keep role accounts (postmaster@, abuse@) working and actively monitored for all sender domains, including sites referenced in the content.

Bounce handling (Annex III):

Bounce type Rule
Hard (5xx): no such user, or mailbox unavailable Promptly suppress the address across all lists once refusals reach 3 or more in 14 days. If a 5xx indicates spam blocking rather than a bad address, the address may be reactivated once the block is removed.
Soft (4xx): transient failure Remove the address when refusals exceed 5 in consecutive campaigns from a single list, or 5 in aggregate across several lists within 10 days.

For modern, provider-specific handling, compare Enhanced Status Codes, List Hygiene & Sunset Policies and Suppression-List Architecture.

Elements IV–VIII (brief)

  • IV Technical measures: no single tool is enough. Layering at origination, on the backbone, at the gateway and at the recipient greatly reduces spam. Current practice is covered under authentication, transport security and filtering.
  • V Education and awareness: governments run public campaigns. ISPs use their customer channels (website, portal, SMS, newsletters) to explain how to avoid spam, which filters exist, how to report abuse, and the abuse-desk contact. "The education of recipients is as important as the education of senders."
  • VI Co-operative partnerships: anti-spam strategy should be developed in partnership between the public and private sectors. ISPs and enforcement authorities should stay in contact to report spam cases and share network data.
  • VII Spam metrics: measure in order to evaluate national strategies. The Task Force welcomed and encouraged MAAWG's Email Metrics Program.
  • VIII Global co-operation (Outreach): make the Toolkit and best practices available to non-OECD economies, and promote anti-spam activity abroad through bilateral and multilateral arrangements. A companion site (historically www.oecd-antispam.org) hosted updated information on national spam laws and the list of national enforcement contact points.

Why this still matters for running an ESP

Turn to the Toolkit when a question is about jurisdiction or crosses borders rather than being technical: which legislative model a target country follows, how enforcement authorities co-operate across borders, what an ISP's acceptable use policy and abuse obligations look like in policy terms, and how best practices for senders and marketers were written down before M3AAWG formalised them. For day-to-day deliverability, the specific provider requirements and authentication standards govern. The OECD framework governs the legal and inter-agency layer around them.