Scams Prevention Framework
Branding & StrategyAlso: SPF · Scams Prevention Framework Act
Quick definition
The Scams Prevention Framework (SPF) is an Australian law that forces designated industries to prevent, detect, disrupt and respond to scams targeting their customers. It sets legal obligations for banks, telcos and digital platforms first, with other sectors expected to follow as the framework expands.
How it varies across Australia
Preparedness varies sharply across Australian sectors. Banks and telcos are furthest along because they were designated first. Mid-market businesses in adjacent regulated categories are largely unprepared, which is where the compliance risk sits highest as the framework widens.
See brand and compliance readiness across Australian industries →What it actually means
Most marketers first read the Scams Prevention Framework and assume it's someone else's problem. Legal team, fraud team, not the brand people. That's the wrong read.
Scammers work by impersonating trusted brands. They copy your emails, spoof your sender name, mimic your call-to-action buttons and clone your landing pages. The framework makes the businesses being impersonated partly responsible for protecting customers from that impersonation. That drags marketing into scope.
The obvious pressure point is how you contact customers. If your genuine marketing emails contain urgent language, unexpected links and requests to log in, you've trained your audience to click exactly the things a scammer relies on. Consistent sender identity, predictable domains and clean email authentication stop being nice-to-haves. They become part of your legal defence and your brand trust story at the same time.
This sits alongside the ACMA spam rules and Privacy Act obligations you already manage. The framework doesn't replace those. It adds a duty to actively design communications that are harder to impersonate and easier for customers to verify.
Scammers impersonate trusted brands. The framework quietly makes your brand's contact behaviour a legal matter, not just a marketing one.
How it shows up
The framework shows up in the details of every customer touchpoint. The sender domain on your marketing emails. Whether SPF, DKIM and DMARC authentication are configured so scammers can't spoof your address. The consistency of your call-to-action language across channels. Whether customers have a documented way to verify a message really came from you.
It also shows up in your incident response. Designated businesses need documented processes for reporting scams, disrupting them and compensating customers where obligations are breached. For marketing teams the practical test is simple: could a customer tell your genuine message apart from a convincing fake, and have you made that easy?
The Australian context
This is Australian legislation with no direct global equivalent, so overseas playbooks don't help. The framework applies economy-wide in principle but designates specific sectors in stages. Banks, telecommunications providers and digital platforms carrying ads and social media are the first regulated sectors. The ACCC coordinates the overarching framework while sector regulators like APRA, ASIC and ACMA enforce within their patches.
For marketers in or adjacent to these sectors, the near-term work is defensive. Lock down email authentication so your domain can't be spoofed. Standardise sender identity across every campaign. Strip the fake-urgency patterns from your copy that scammers exploit. Document how customers verify genuine communications. Businesses expecting future designation should start now rather than wait for the regulator to knock.
Where people get this wrong
Related terms
Common questions
Does the Scams Prevention Framework apply to my business?
Directly, only if your sector has been designated. Banks, telcos and digital platforms are first. If you operate in or adjacent to those sectors, plan for it. The framework is designed to widen over time, so waiting for formal designation is a risky default.
What does an anti-scam law have to do with marketing?
Scammers impersonate trusted brands using fake emails, spoofed senders and cloned landing pages. The framework makes impersonated businesses partly responsible for protecting customers. That puts your sender identity, email authentication and call-to-action design squarely in scope for marketing teams.
How is this different from the ACMA spam rules?
The spam rules govern consent and unsubscribe for the messages you send. The framework adds a duty to make your communications harder to impersonate and easier to verify. They stack rather than replace. You need to satisfy both at once.
What should marketing do first to prepare?
Lock down email authentication so your domain cannot be spoofed. Standardise sender identity across every campaign. Remove fake-urgency patterns and unexpected login links from your copy. Give customers a clear, documented way to confirm a message genuinely came from you.
Debrief
Get the next one
No spam. No fluff. Just the next article, straight to your inbox.
Keep exploring
About New Rebellion
New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.
How we think →