Unwanted messages, and why they penalise everyone
Spam needs no introduction. It fills mailboxes, it is met with irritation or suspicion, and it is the reason aggressive filtering exists at all. Its real cost falls on legitimate senders: every unwanted message makes mailbox providers more sceptical of the next one, and honest campaigns pay for it in deliverability.
The distinction that matters is not tone or volume. It is permission. A newsletter someone asked for and a bulk message they never invited are different things in law as well as in the recipient's inbox.
Where the word came from
The term borrows from Spiced Ham, the tinned meat sold under the SPAM brand — by way of a Monty Python sketch in which the word is repeated until nothing else can be heard. That is a fair description of the phenomenon.
Most spam is advertising, but the same technique carries appeals disguised as charity requests, messages with a political purpose, and outright financial fraud. What characterises it technically is a concealed or falsified sender and addresses obtained without permission — which is why replying or unsubscribing usually achieves nothing.
Phishing is a different problem
Phishing goes a step further than unsolicited advertising. The sender impersonates an organisation the recipient already trusts — a bank, a public administration, a familiar supplier — in order to harvest credentials or payment details. The goal is not attention but deception, and the legal consequences sit in criminal law rather than in marketing regulation.
For legitimate senders, the practical defence is authentication. Publishing SPF, DKIM and DMARC records makes it substantially harder for anyone to send convincing mail in your name, and mailbox providers increasingly treat their absence as a signal in itself.
What the law says
Across Europe, the rule descends from the ePrivacy Directive of 2002: commercial email to an individual requires prior consent, the sender must be identifiable, and every message must offer a free and simple way to stop receiving them. Member states implement it in their own instruments, which is why the detail differs from one country to the next even though the principle does not.
The GDPR then sits on top, governing the personal data behind the list — how it was collected, how long it is kept, and the recipient's absolute right to object to direct marketing. Outside Europe the drafting differs but the direction is the same: Switzerland treats unsolicited commercial email as unfair competition, and Canada requires consent, identification and a working unsubscribe under CASL.
The consistent thread is that none of these regimes asks whether your message was interesting. They ask whether the person agreed to receive it, whether they can tell who sent it, and whether they can make it stop.
See also:
- Comply to French law with your email marketing campaigns
- Professional emailing tightly controlled by Swiss law
- Ensure compliance with Belgian law during professional email campaigns
- Conduct professional email campaigns in accordance with Canadian law