BestPrac.Org

Stop Spam : Best Practice in Email
Spam Prevention and Eradication


Principles of Best Practice -
Mailing List & Autoresponder Hosting Services:

Summary:

Outsourced or Third-Party solutions for email list management, including ezines, newsletters, autoresponders and such like, are known to be vulnerable to abuse by spammers.

Sensible policies and diligent enforcement by mailing list and autoresponder hosting services can ensure that this potential avenue of exploitation of email servers and compromization of network security by spammers is minimized.

Ref # Principle or Proposed Principle
LHS001  List Hosting Services should ensure that all lists hosted only accept new subscriber listings where the subscribers have been added to the mailing list via either:
  • A confirmed-opt-in (sometimes referred to as 'double-opt-in') process; or
  • A paid subscription

LHS002  List Hosting Services should ensure that all lists hosted have, use and publicise in all mailings a clear and easy-to-use unsubscription procedure.
LHS003  Before accepting a new client with a pre-existing mailing list, the List Hosting Service should make all possible enquiries and conduct a thorough "due diligence" to ensure that that the existing list being transfered has been acquired via either:
  • Confirmed-opt-in (sometimes referred to as 'double-opt-in') processes; or
  • Paid subscription processes,
And that the subscribed recipients have, at all times, been provided with a clear and easy-to-use unsubscription procedure which has been publicised in all prior mailings.
LHS004  List Hosting Services should ensure that their Terms of Service / Acceptable Use Policy include a strong antispam clause, prohibiting the ending of unsolicited email, whether directly from the service being hosted, or from any other source where reference is made to the mailing list or the any website used to promote the list,with violation resulting in immediate account termination of all accounts associated with the offender without further warning, and the imposition of a "cleanup" fee. (For the sake of example and recommendation only - $US2,500-00 .)
LHS005  List Hosting Services should maintain an adequately and competently staffed abuse desk on a 24 hour, 365 day per year basis. The contact details for the abuse desk should be readily and easily accessible on the website of the List Hosting Service, and also listed with the Network Abuse Clearinghouse at http://abuse.net
LHS006  In the event of a clear cut violation of Terms of Service / Acceptable Use Policy, the List Hosting Service should terminate all accounts associated with the offender, within two (2) hours of an evidence-based abuse report being received.

In the event of a prima facie violation (such as where a list is implicated, though the possibility that it has been maliciously implicated exists), appropriate investigations should be conducted, completed and acted upon within 24 hours. In the event that a violation is proven, the List Hosting Service should terminate all accounts associated with the offender immediately.
LHS007  List Hosting Services must also stipulate in their Terms of Service that clients are obliged to comply with all relevant Federal, State or Other anti-spam laws and Statutes applicable in the jurisdiction of both the Server itself as well as that of the publisher.
LHS008 
LHS009 
LHS010 
LHS011 
LHS012