Answers
Is cold email legal in Australia? Yes, with conditions.
Sending an unsolicited commercial email to an Australian business is legal, provided you meet the conditions in the Spam Act 2003. You need consent, which for B2B can often be inferred rather than express, you must accurately identify yourself, and you must include a working unsubscribe. Australia has no CAN-SPAM, and advice written for the United States does not apply here. This page explains the rules and is general information, not legal advice.
- 14 days free
- No credit card
- Unlimited users

Start here
The three things the Spam Act requires.
Every commercial electronic message sent to an Australian address has to satisfy all three. Meeting two of the three does not satisfy the Act.
The three rules
1. Consent
You need the recipient’s consent before you send. It can be express, where they agreed, or inferred, where the circumstances allow it. Inferred consent is the part that makes most legitimate B2B outreach possible, and it is narrower than people assume.
2. Identify yourself
The message must accurately name you or your business and include correct contact details. The Act requires those details to stay accurate for at least 30 days after you send, so a temporary address or a burner domain fails this test.
3. A working unsubscribe
Every message needs a clear, functional way to opt out. It must be free, it must keep working for at least 30 days after sending, and you must action requests within five working days. Signal sends from your own inbox, so the unsubscribe mechanism is yours to include.
The detail
Inferred consent is where B2B outreach lives or dies.
Consent
When you can infer consent from a published address
Schedule 2 of the Spam Act sets out when consent may be inferred from the publication of an electronic address. Two conditions have to hold at the same time, and most cold email that gets a company into trouble fails the second one.
The address must be conspicuously published, meaning genuinely put out for the public or a section of the public to use. And the message you send must be relevant to the work-related functions, duties or role of the person whose address it is.
- A role address on a company contact page, emailed about something that role handles: the situation the exception is designed for
- The same address emailed about something unrelated to that role: unlikely to fall inside the exception
- An address published beside a notice saying unsolicited commercial email is not wanted: not available, no matter how relevant your message is
- A personal address, or one guessed from a naming pattern rather than published: not conspicuously published
The relevance test does the real work
This is the condition that separates legitimate outreach from a scraped list. Emailing an operations manager about operations software is relevant to their role. Emailing the same person about an unrelated offer is not, even though the address was sitting on a public page. Relevance is judged against the recipient’s job, not against how well you targeted the company, so a well-researched email to the wrong function still fails it.
Guessed addresses are not published addresses
Working out that a company uses firstname.lastname and generating an address from a staff list is not publication. Nobody put that address out for the public to use, so there is nothing to infer consent from. This matters because it is exactly what a large part of the outbound tooling market does by default, and the fact that a tool verified an address says nothing about whether it was ever published.
Australian law, not American law
The United States CAN-SPAM Act permits unsolicited commercial email and requires you to honour opt-outs after the fact. Australia runs the opposite way round: consent comes first. A great deal of the cold email advice online assumes the American position, and following it in Australia risks putting you outside the Act from the first send.
What it costs to get wrong
ACMA enforces this, and the amounts are not nominal.
Penalties published by ACMA on its infringement notices register. These are real enforcement actions against businesses operating in Australia, not hypotheticals.
Recent enforcement
Commonwealth Bank, $7.5 million
August 2024. ACMA found more than 170 million marketing emails lacking a functional unsubscribe, and 34.8 million messages sent to people who had not consented or had withdrawn consent.
Tabcorp, $4 million
April 2025. A second penalty followed in July 2026, covering marketing messages sent to people who had already unsubscribed. Repeat breaches attract higher penalties under the Act.
Latitude Finance, $3.96 million
January 2026. Other penalties between 2024 and 2026 include Pizza Hut at $2.5 million, Luxottica at $1.5 million, Betfair at $871,000 and Lululemon at $702,000.
In practice
A short checklist before you send.
None of this is a substitute for advice on your own situation, but it covers the mistakes that turn up most often.
Before you press send
Check where the address came from
Published on a company page is a different thing from generated by a pattern or bought in a list. Only the first supports inferred consent.
Check the message fits the role
Write to what that person’s job involves. If you cannot say why the message is relevant to their duties, the inferred consent exception is unlikely to be available.
Put real details in the footer
Your business name and working contact details, accurate for at least 30 days. Sending from your own domain and inbox makes this straightforward.
Make unsubscribe easy and honour it
Free, clear, working for 30 days, actioned within five working days. Keep a record of who opted out so a later campaign does not email them again.
Sources
Where this comes from.
ACMA, avoid sending spam. Spam Act 2003 (Cth), including Schedule 2 on inferred consent. ACMA infringement notices register. For the Privacy Act points: Privacy Act 1988 (Cth) and the Privacy and Other Legislation Amendment Act 2024. All checked 19 September 2026.
This page is general information about Australian law and is not legal advice. Empiraa is a software company, not a law firm. Your obligations depend on your own circumstances, and you should get advice that considers them before relying on anything here.
Questions
Common questions about Australian cold email rules.
Is cold email legal in Australia?
Yes, provided you comply with the Spam Act 2003. You need consent, which for business-to-business email can often be inferred from a conspicuously published work address, you must accurately identify your business and keep those contact details accurate for at least 30 days, and you must include a working unsubscribe that you honour within five working days. Cold email that fails any one of those three conditions is in breach, even if the other two are met.
Can I email a business address I found on a company website?
Often yes, under the inferred consent provisions in Schedule 2 of the Spam Act, but two conditions must both hold. The address has to be conspicuously published, meaning genuinely made available for people to use, and your message has to be relevant to the work-related functions, duties or role of the person whose address it is. If the address is published alongside a statement that unsolicited commercial messages are not wanted, you cannot rely on inferred consent at all.
Does CAN-SPAM apply in Australia?
No. CAN-SPAM is United States legislation and has no application to messages sent to Australian addresses. The two regimes work in opposite directions on the central question: CAN-SPAM broadly permits unsolicited commercial email and requires you to honour opt-outs afterwards, while the Australian Spam Act requires consent before you send. Following American guidance in Australia is one of the most common ways businesses end up in breach.
Can I email an address I guessed from a naming pattern?
Working out a company’s email format and generating an address is not publication, so there is no published address from which to infer consent. Verifying that the address exists does not change this, because the question the Act asks is whether the address was conspicuously published, not whether it is deliverable.
What are the penalties for breaching the Spam Act?
The Act sets maximum penalties in penalty units, with higher maximums for repeat offenders and for multiple contraventions on the same day. What matters in practice is what ACMA actually issues, and recent infringement notices have been substantial: $7.5 million to the Commonwealth Bank in August 2024, $4 million to Tabcorp in April 2025, and $3.96 million to Latitude Finance in January 2026.
Does the Privacy Act affect B2B cold email in Australia?
It can, depending on your business. The Privacy Act 1988 generally exempts businesses with annual turnover of $3 million or less, and the 2024 reform package did not remove that exemption, though several categories of business are carved out of it regardless of turnover. The Spam Act has no equivalent size exemption, so its obligations apply to you whatever your turnover. If you are handling personal information at scale, get advice on your own position rather than relying on the exemption.
Does using Empiraa Signal make my cold email compliant?
No, and no tool can. Compliance depends on where your list came from, whether your message is relevant to the recipient’s role, what your footer says and how you handle opt-outs. Signal sends from your own inbox and domain, so your normal business identification travels with the message, and sequences stop automatically when someone replies. The consent basis for your list and the unsubscribe mechanism in your emails remain your responsibility.
Question not answered here? Ask ANI and get a straight answer.
Outbound that sends from your own inbox.
Sequences that stop the moment someone replies. 14 days free, no credit card.
