Last updated: September 22, 2026

Required practices

  • Use recipient data only with a lawful basis and any consent required by the recipient’s location.
  • Identify the responsible sender and use accurate routing information and subject lines.
  • Do not use deceptive claims, impersonation, hidden identity, or misleading destinations.
  • Include a clear, functioning unsubscribe method in marketing messages.
  • Honor opt-outs and applicable suppression records before further sending.
  • Maintain reasonable evidence about data source, permission, and campaign responsibility.

Prohibited email

Campaigns must not distribute phishing, malware, credential-harvesting pages, illegal content, fraudulent offers, harassment, or messages that violate applicable anti-spam, privacy, or consumer-protection requirements. Purchased, scraped, guessed, or otherwise unauthorized recipient data must not be used where prohibited.

Unsubscribe and suppression

An opt-out should be processed promptly and must not require a fee, account login, or unnecessary personal information. Limited suppression data may be retained to prevent the address from being reintroduced into future campaigns.

Enforcement

Links or campaigns may be restricted, suspended, blocked, or investigated when complaints, technical evidence, or policy violations indicate risk. Cooperation may be required to establish the source of recipient data and the identity of the responsible sender.