May 20, 2004

CAN-SPAM law: Little impact so far

Amount of spam may be rising, not dropping, since the law went into effect

WASHINGTON - The chairman of a U.S. Senate committee called for more federal enforcement of a new antispam law amid reports Thursday that the amount of spam sent to U.S. consumers may be rising, not dropping, since the law went into effect in January.

Senator John McCain, chairman of the Senate Commerce, Science and Transportation Committee, questioned why the U.S. Federal Trade Commission (FTC) hasn't focused on the companies using spammers to advertise their products while that agency attempts to enforce the Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act.

The FTC and federal law enforcement officials brought CAN-SPAM and other charges against two alleged spamming companies in late-April, but McCain urged the FTC and the Federal Bureau of Investigation (FBI) to step up their enforcement efforts against spammers, including child pornography spammers, during a hearing on the effectiveness of CAN-SPAM.

"If the FTC can't find the spammers, it should do the next best thing: go after the businesses that knowingly hire spammers to promote their goods and services," said McCain, an Arizona Republican. "At a minimum, the FTC could put thousands of businesses -- many of them online pornography retailers -- on notice that using anonymous spam is an illegal means of driving consumer traffic to their Web sites."

But bulk e-mailers trying to comply with the law -- by using their own IP (Internet Protocol) addresses instead of forging headers, and by including their company names and postal addresses in the text of the e-mail -- are being punished by ISPs (Internet service providers) like America Online Inc. (AOL), said Ronald Scelson, president of MicroEvolutions.com, a bulk e-mail company based in Montgomery, Texas. Scelson's company has stopped using common spamming techniques in order to comply with CAN-SPAM, but AOL and other ISPs are still blocking his company's e-mail, Scelson said.

Scelson told the committee he could go back to using forged headers and defeat most spam filters. "Does the government want us to mail legal or not?" Scelson asked. "As long as we're doing it the right way and we're going to get blocked, interfered with and shut down, people are going to go around it."

While senators called for more enforcement of CAN-SPAM, representatives of the FTC and FBI said their agencies are working hard to combat spam. The FTC has more than 50 staffers working on CAN-SPAM enforcement, said FTC Chairman Timothy Muris. The FTC is still working on some rules related to CAN-SPAM, and Muris promised that the agency will deliver a plan for a national do-not-e-mail registry by CAN-SPAM's June 16 deadline. He noted that an FTC rule requiring sexually explicit e-mails to be labeled just went into effect this week.

"We've already begun searching for enforcement targets," Muris said of the sexually explicit rule.

Representatives of spam-filtering service Postini Inc. and the Consumers Union told the committee that the amount of unsolicited commercial e-mail continues to rise after CAN-SPAM became law. Postini, which processes about 1.3 billion e-mails a week, has seen the percentage of spam in that e-mail processed increase from 78 percent to 83 percent since CAN-SPAM went into effect.

Subscribe to the Security Central Newsletter

The one-stop resource center for IT professionals.

White Paper

CA Security Management Solutions

A comprehensive security management solution can help you streamline, as well as grow, your current or evolving business. In this way, a strategic security approach can help you increase your competitiveness in these challenging market conditions.

Download now! »

White paper

Beyond Compliance: The Significant Benefits of Log Management

Find out how you can effectively collect, normalize and archive enterprise-wide, security-related data that is invaluable for security investigation and compliance reporting.

Download now! »

Webcast

Integrated Identity Compliance: Enabling Cost-Effective Role-Based Compliance

This session focuses on the intersection of role management and identity compliance, and addresses the importance of identity compliance in enterprise governance and the challenges that organizations may face in achieving it.

View now! »
©1994-2009 Infoworld, Inc.