Conspicuously Published Address Rule in the Australian Spam Act
Understand the conspicuously published address rule in the Australian Spam Act. Ensure compliance and avoid penalties with accurate email validation and.
What is the conspicuously published address rule under the Australian Spam Act?
You send a marketing email to someone in Australia. It lands in their inbox. Then, minutes later, you get an automated reply: “Your message was blocked for violating the Australian Spam Act.”
Here’s the catch: you hadn’t sent it to the wrong person. You’d followed the rules. You had consent. But you missed one detail—your email address wasn’t clearly visible on your website. That’s the “conspicuously published address” rule in action.
Under the Australian Spam Act 2003, if you're sending commercial emails to Australian recipients, you must publish your email address in a visible, prominent, and clearly identifiable way on your public website or platform. It’s not enough to tuck it into a legal footer buried under a “Terms of Use” link. The address must be easy to spot—no obscure, hidden, or pixelated versions.
This rule is part of the “inferred consent” framework. It means that if you’ve made your email address publicly available in a conspicuous way, you can assume the recipient agrees to receive your marketing messages. But if it’s not conspicuous, you’ve lost that assumption—and with it, legal protection.
Key takeaways
- Under the Australian Spam Act 2003, your email address must be conspicuously published on a public website to send marketing emails to Australian recipients.
- “Conspicuously” means it must be visible, prominent, and clearly identifiable—no hidden or obscure placements.
- Failure to meet this requirement voids inferred consent, making your email campaign potentially illegal, even if you have opt-in lists.
How does conspicuously published address rule affect email list validation?
You must only email people whose addresses are conspicuously published on your website or public materials to claim inferred consent under Australia’s Spam Act. If your list contains emails not visibly published, you risk violating the law, especially if recipients didn’t opt in. Email list validation can detect these non-published addresses, helping you avoid compliance issues before sending.
Why visibility matters in Australian email compliance
Under the Spam Act 2003, consent can be inferred only if an email address was clearly and publicly available. That means it must be displayed in a way that’s easy for a reasonable person to find—like in a public contact page, footer, or newsletter signup form. If an address wasn’t published this way, you can’t assume consent, even if you obtained it from a third party.
Let’s say you bought a list of marketing emails from a broker. Even if those emails were valid, if they weren’t visibly published online, you’re not legally allowed to send to them without explicit opt-in. Sending to such addresses could trigger enforcement actions from the Australian Communications and Media Authority (ACMA), including penalties or formal warnings.
How verification catches compliance risks early
Email list validation acts as a pre-send compliance check. It identifies whether an address was likely published on your site by analyzing patterns, domain ownership, and public visibility signals. For example, if an email is from a domain you own but appears nowhere on your website, it’s flagged as suspicious—likely not publicly published.
Our tool uses this logic to surface high-risk addresses before you send. You can then filter out non-published addresses, reduce spam complaints, and avoid legal exposure. This is especially important if you're running campaigns based on third-party lists, scraped data, or outdated sources.
Validating your list doesn’t just improve deliverability—it also ensures you’re not operating on the wrong side of the law. The Australian Privacy Principles (APP) and the Spam Act reinforce that transparency and consent go hand-in-hand. As noted by the European Data Protection Board, “Consent must be freely given, specific, and informed”—principles that mirror the expectations in Australia.
Use this as a safeguard: run a bulk verification to clean your list before any campaign. It’s not just about bouncing emails—it’s about ensuring every recipient is someone who could reasonably expect to hear from you. Start cleaning your list today and reduce compliance risk at scale.
Why is inferred consent tied to conspicuously published addresses?
Inferred consent under the Australian Spam Act only applies when an email address is publicly visible and clearly presented—meaning you can’t assume permission just because you found an address online. The law insists on visibility because only then can a recipient reasonably be expected to know their address is being used. Without clear exposure, a sender has no justified claim to consent, preventing spam from hidden data harvesting or scraped lists.
The logic behind public visibility
Let’s be clear: if an email address isn’t conspicuously published, its use for marketing purposes breaks the principle of informed consent. The Australian Communications and Media Authority (ACMA) emphasizes that consent must be “informed and specific”—and you can’t inform someone if you don’t let them see the address in the first place.
Think of it like this: if you list your email on a company website’s “Contact” page, with a visible form or a mailto link, you’ve made a public signal you’re open to outreach. But if someone sniffs it from an unlisted database, a dark web dump, or a script-scraped webpage, you haven’t signaled agreement. That’s where inferred consent fails.
Why this stops abuse
By tying consent to conspicuously published addresses, the law blocks bulk data harvesting without the recipient’s knowledge. This prevents companies from buying or scraping emails from obscure sources and calling them “valid” simply because they exist. The threshold ensures that only addresses openly shared in a public context may be used for marketing without explicit opt-in.
It’s not about access—it’s about expectation. If an email isn’t placed where a person might reasonably think it’s open to contact, sending them marketing messages is not just annoying; it’s legally questionable. This aligns with global standards, including the EU’s GDPR, which likewise treat privacy differently when data is harvested from non-public sources.
For marketers, this means verifying every email address isn’t enough—you need to ensure it was published in a way that makes consent plausible. That’s why tools like bulk email list cleaning matter: they help identify addresses that, while technically valid, were never meant for marketing use.
Even if an address passes syntax and delivery checks, its legitimacy as a consent signal depends on context. You can’t verify consent; you can only validate visibility. If you’re unsure whether an address was conspicuously published, treat it as a non-consensual lead.
ACMA’s guidelines on the Spam Act reinforce that “conspicuously published” means clearly visible and accessible—no hidden links, obfuscated scripts, or embedded images hiding the email. If you wouldn’t know the address was public by just browsing the page, it doesn’t qualify.
What counts as a conspicuously published email address?
You’re allowed to send marketing emails to an Australian contact if their email is visibly published on your website—no hidden form, no obfuscated text, no tricky formatting. It must be easy to find in a header, footer, or contact page, and standard substitutions like 'at' or 'dot' are acceptable. The Australian Spam Act doesn’t require a specific layout, only that it’s clearly visible and accessible.
What makes an email address conspicuous?
- Displayed in a website header, footer, or a standalone contact page—no buried in navigation menus.
- Clearly formatted, not hidden behind a “click to reveal” button or obscured by dense text.
- Written in standard readable format:
[email protected], or using common substitutions likeinfo at example dot com—especially if that’s how the platform handles it (e.g., social media, forums). - Not disguised with image text, JavaScript, or CSS tricks that prevent easy copying.
- Not part of a form requiring a user to input data before seeing it.
When is it NOT conspicuous?
- Emails in a “contact us” form where users must submit their details first.
- Hidden within JavaScript or CSS-generated content unless it’s instantly visible to browsers.
- Replaced with placeholder text like “[email protected]” without a link or visible actual address.
- Displayed as a PNG or SVG image of an email address (unscannable by bots and hard to copy).
- Presented via a mailto: link hidden behind non-obvious buttons or icons.
Let’s be clear: this rule isn’t about aesthetics—it’s about user intent. If the email is there so you can reach someone, it doesn’t matter if it’s shown as [email protected] or support at example dot com, as long as it’s unambiguous and easy to find. The Australian Communications and Media Authority (ACMA) consistently interprets this requirement to favor transparency over technical perfection.
Even if your email looks “normal” to you, you’re still on thin ice if it’s only accessible after clicking through several layers. If someone has to navigate your site for more than a couple of clicks to find it, it doesn’t count. Keep things simple, consistent, and visible.
That said, just because an address is published doesn’t mean it’s valid. An old, misspelled, or non-functional email can still lead to complaints, bounces, and blacklisting. Use a service like bulk email list cleaning to verify the actual deliverability of any address you plan to reach. Validating your list ensures you don’t accidentally violate the Spam Act’s spirit, even when you’ve technically met the “conspicuous” standard.
How to verify whether an email address qualifies under the conspicuously published rule?
You can verify if an email qualifies under the conspicuously published address rule in Australia’s Spam Act by checking whether it’s openly displayed on a public website in a fixed, consistent location—like a contact page or footer—and appears the same across multiple pages or is directly linked. If it’s not prominently placed or appears only in dynamic or hidden sections, it likely doesn’t meet the standard.
Step-by-step verification process
- Locate the email on the official website—it must be published in a fixed, identifiable location, such as a static contact page or footer. The email should be visible without requiring navigation through forms, scripts, or dynamic content.
- Check for consistency across pages—the email should appear in the same form and position on several pages (e.g., homepage, contact page, and privacy policy). If it appears only in one place or changes format, it’s not reliably conspicuous.
- Confirm the domain matches public records—ensure the email’s domain is tied to the website’s public presence. Use tools like MxToolbox or RFC 5322 to validate domain authenticity and email format standards.
- Look for public exposure patterns—some domains publish emails in ways that are intentionally visible (e.g., “[email protected]” in a fixed header). Avoid addresses that are generated dynamically (e.g., via JavaScript or hidden forms).
- Use verification tools for deeper analysis—services like email list validation can scan for signs of public exposure, including domain-level visibility and consistent placement patterns across pages.
How tools help automate this validation
Manually checking every email against the conspicuously published rule is slow and error-prone. That’s where tools come in. Real-time email verification services can analyze domain exposure by checking public web presence, detect if an address appears consistently across sites, and flag those that appear only in dynamic or hidden locations.
For example, the bulk verification feature checks large lists for compliance by identifying emails that are likely not publicly displayed. The real-time API can be integrated into forms or workflows to ensure only conspicuously published addresses are captured. The email finder helps locate contact points that were already published—giving you visibility into what’s already out in the open.
What happens if you use an email not conspicuously published?
If you send marketing emails to addresses not conspicuously published under the Australian Spam Act, you risk breaching the law, triggering enforcement actions by the ACMA, and facing fines of up to $1.1 million per breach. Even if you believe you have consent, sending to non-conspicuous addresses can lead to deliverability issues, as email providers may flag or block your messages as spam.
ACMA enforcement and financial risk
ACMA takes violations of the Spam Act seriously. Sending unsolicited commercial emails to addresses not conspicuously published can be treated as a breach, especially if the recipient didn’t explicitly opt in. The maximum penalty is $1.1 million for a single violation, which applies to both individuals and corporations. While ACMA typically focuses on repeated or large-scale abuses, even a single instance without a clear basis in inferred consent can trigger an investigation.
Under the Spam Act, "conspicuously published" means the email address must be visible and easy to find—like in a company’s public contact page, not hidden in footers, behind forms, or buried in a PDF. If you’re using an email found in a directory, scraped from a site, or harvested via a bot, it’s likely not conspicuously published. That’s a red flag for compliance.
Deliverability and long-term reputation
Even if ACMA doesn’t act, your emails may still fail to reach inboxes. Major providers like Gmail, Outlook, and Apple Mail use filters to detect patterns of non-consensual outreach. Sending to conspicuously published emails only reduces risk across the board.
Using an email not conspicuously published increases the chance your messages get tagged as spam or blocked entirely. This hurts deliverability and damages your sender reputation. Over time, even one problematic send can trigger rate limiting, IP throttling, or domain blacklisting.
Let’s be clear: if you’re not 100% sure an email address was conspicuously published, it isn’t. That’s where Email List Validation helps: by checking for validity, catch-all status, and role accounts, and flagging risks before you send. You can verify thousands of addresses in minutes to avoid compliance issues and improve inbox placement.
If you're building or maintaining a list, use bulk email list cleaning to screen for non-conspicuous, invalid, or risky addresses. For real-time checks, integrate our API into your signup workflow. You can also test inbox placement at scale with inbox-placement testing, ensuring your messages land in the inbox, not the spam folder.
For more, see the ACMA’s guidance on the Spam Act and the RFC 8098, which outlines best practices for sending and verifying email content and authenticity.
How does email list validation help with the conspicuously published rule?
Validating your email list helps ensure you're only sending to addresses that are technically real and likely to be publicly available. It flags role addresses, disposable domains, and catch-all accounts—common sources of non-conspicuously published email data—thereby reducing your risk of violating the Australian Spam Act’s conspicuously published address rule. You can’t reliably claim an address is publicly available if it’s a generic or temporary one.
What the rule actually means for your list
The Australian Spam Act doesn’t require you to publish a full mailing list online. But it does mean that if you send marketing emails, the addresses you use must have been "conspicuously published" — meaning they were made visible to the public in a way that reasonably suggests they’re open for contact. Addresses like info@, sales@, or temporary ones from disposable domains don’t meet this standard. Even if you obtained them legally, sending to them still risks non-compliance.
That’s where validation comes in. A true email validation service doesn’t just check syntax or domain existence. It digs deeper—checking for known disposable domains (like mailinator.com), role accounts (e.g., support@ or service@), and catch-all setups that accept all messages regardless of the local part. These are red flags for compliance. The Australian Communications and Media Authority (ACMA) has indicated that relying on such addresses as publicly available can undermine your compliance defense.
How validation reduces compliance risk
By filtering out role accounts and disposable domains before you send, you’re left with a list of addresses that are more likely to have been openly advertised. For example, an email like [email protected] is far more defensible than [email protected], especially if the latter is not listed on any public-facing page.
Our email verification API and bulk cleaning tools help you do this at scale. They identify and flag problematic addresses before they ever hit your campaign. You can then decide whether to include them or remove them.
For teams using platforms like Mailchimp, HubSpot, or Klaviyo, integrating our email verification integrations means that bad addresses never even get into your ESP’s system, reducing bounce rates and protecting your sender reputation. It's a technical safeguard against legal exposure.
When it comes to the conspicuously published address rule, your best defense isn’t a legal disclaimer — it’s a clean, validated list. And that starts with tools that know the difference between an address that’s publicly available and one that’s just sitting in a form or scraper database.
Why bulk validation is essential for compliance at scale
You can’t manually check tens of thousands of email addresses for conspicuous publication under the Australian Spam Act—automated bulk validation is the only practical way to ensure your list meets technical and regulatory standards. It scans every address at scale, identifying those that are invalid, high-risk, or likely to trigger spam filters, reducing your exposure to enforcement actions and deliverability penalties.
The impracticality of manual checks
Let’s be honest—manually reviewing each email to see if it’s conspicuously published is impossible when you’re managing a list of 50,000+ leads. The Australian Spam Act requires you to avoid sending marketing emails to addresses that are published in a way that makes them easily available to spammers. But even if you had the time, you’d still miss subtle issues like catch-all domains, disposable mailboxes, or role-based addresses that don’t belong to real users.
How bulk verification enforces compliance
Instead, bulk validation tools like Email List Validation scan your entire list in minutes, flagging addresses that fail basic checks. It checks for valid syntax, active mail servers, and policy compliance—like whether an email is a known disposable address or part of a catch-all system. You’re not just cleaning your list; you’re reducing compliance risk from the ground up.
With 98.9% accuracy, our system identifies invalid or high-risk addresses before they send, helping you avoid bounces and reputation damage. This isn’t guesswork. It’s based on real-time checks against SMTP servers, MX records, and known patterns of abuse—validated through industry-standard practices like those defined in RFC 5321 and RFC 5322.
For example, if an email includes a role account like admin@ or sales@ across hundreds of entries, the system marks these as risky. You’re not sending to ghost accounts or spam traps—just people who are actually receiving mail.
With integrations for Mailchimp, HubSpot, Klaviyo, and SendGrid, you can automate this step directly in your workflow. Use the bulk verification tool before every campaign, or build real-time validation into your signup flow via the API. The result? Fewer bounces, higher inbox placement, and lower risk of penalties.
Real-time API verification for safe, compliant outreach
Integrate real-time email verification into your signup or CRM workflows to block invalid, non-public, or risky addresses before they enter your list—preventing bounces, spam complaints, and violations of the conspicuous published address rule under Australia’s Spam Act. This ensures every email you send is both deliverable and compliant.
Stop non-public addresses before they cause trouble
Under the Australian Spam Act, you must make your contact details conspicuously published if you're sending marketing emails. That means you can’t send to addresses that aren’t publicly listed or that don’t belong to a real person. Real-time API verification checks whether an email address is valid, deliverable, and not flagged as a role account or disposable address—helping you avoid sending to non-public or fake addresses that could trigger compliance issues.
Let’s say someone signs up with a support@ or admin@ address. These often point to role accounts, which are not personal or publicly accessible. Without verification, you risk violating the conspicuously published address rule. A real-time check catches these early—keeping your list clean and your outreach safe.
Verify, deliver, comply—all in one flow
When you add email verification to your signup or CRM workflows, you validate each address at the point of entry. This isn’t just about catching typos or full-time junk. It checks for actual presence, inbox availability, and alignment with known compliance standards—including the Australian Spam Act’s expectations for public contact points.
For example, we use standard protocols like SMTP and MX checks to confirm whether an inbox exists and will accept mail. We also detect catch-all domains, greylisted servers, and disposable domains—common sources of bounce and compliance risk. These checks run in under a second, so you don’t slow down user onboarding.
With real-time verification, you reduce bounce rates, avoid spam traps, and maintain a healthy sender reputation—all of which matter when proving compliance under the Spam Act. You’re not just reducing waste; you’re building an email list where every address has a chance of being real and public.
You can test deliverability with inbox placement tools like inbox-placement testing and ensure your outreach lands in the inbox, while maintaining compliance through tools like the real-time verification API. For deeper list cleaning, use bulk verification or email finder to recover valid addresses from existing lists.
How to maintain a compliant email list over time
Outdated or improperly published email addresses violate the conspicuously published address rule in the Australian Spam Act. Regularly cleaning your database with bulk verification tools removes invalid, disposable, or non-existent addresses before they trigger complaints or bounces.
Verify before you send
Use real-time verification and inbox placement testing to validate deliverability and ensure your messages reach inboxes, not spam folders. These tools detect issues like catch-all domains, greylisting, and role-based accounts that can undermine compliance.
Trace every address back to a visible source
Only include addresses that were publicly and visibly shared—such as on a website form or in a contact page. Audit your list sources periodically to confirm each address has a verifiable, opt-in origin.
Keep reading
- Email marketing compliance: GDPR, CAN-SPAM, consent and unsubscribes (complete guide)
- Best Ways to Validate Cleaning Vendors’ Email Privacy Compliance in 2026
- Secure Email Verification with Two-Person Sign-Off for Large Audience Distribution
- Reduce Unsubscribe Rates in Freshsales with Email Verification
- Compliance-Aware Email Verification for List Retention Success
Ready to put this into practice? Email List Validation verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
Does the conspicuously published address rule apply to all emails sent in Australia?
Yes, it applies to all commercial electronic messages sent to Australian recipients, regardless of sender location.
Can a phone number serve as proof of consent instead of a published email?
No. The Spam Act specifies that a published email address is required to claim inferred consent. Phone numbers do not substitute for this.
What if an email is published, but not clearly visible?
If the address is hidden behind layers of navigation or styled non-uniformly, it may not qualify as conspicuously published under the Act.
Do newsletters sent to subscribers need to meet the conspicuously published rule?
Only if they are sent to new or non-consenting recipients. Subscribers who opted in don’t require public publication for consent.
How does Email List Validation help with Australian compliance?
It identifies invalid, role, and disposable addresses, reducing the risk of using non-conspicuously published emails in campaigns.
Are there any tools that test for conspicuously published email compliance?
No dedicated tools exist to analyze website visibility, but email list validation identifies invalid or risky addresses that may not meet the rule.
Can I use a scraped email if it’s publicly available?
No. Scraper-provided emails do not qualify for inferred consent unless the address was visibly published in a way consistent with the Act.
What’s the risk of using a non-public email after 2026?
The risk remains consistent across years; regulations don’t expire. ACMA enforcement continues to prioritize compliance with the Spam Act.
Does ACMA provide examples of conspicuously published addresses?
ACMA does not publish specific examples, but guidance emphasizes visibility, permanence, and ease of location on public websites.
How often should I validate my email list for compliance?
At least quarterly, or after major list growth, to maintain hygiene and reduce the risk of sending non-compliant messages.