Scams Prevention Framework

Branding & Strategy

Also: SPF · Scams Prevention Framework Act

What it isAustralian anti-scam law
Who it hits firstBanks, telcos, platforms
Marketing angleHow you contact customers
Enforced byACCC and sector regulators

Quick definition

The Scams Prevention Framework (SPF) is an Australian law that forces designated industries to prevent, detect, disrupt and respond to scams targeting their customers. It sets legal obligations for banks, telcos and digital platforms first, with other sectors expected to follow as the framework expands.

How it varies across Australia

Preparedness varies sharply across Australian sectors. Banks and telcos are furthest along because they were designated first. Mid-market businesses in adjacent regulated categories are largely unprepared, which is where the compliance risk sits highest as the framework widens.

See brand and compliance readiness across Australian industries

What it actually means

Most marketers first read the Scams Prevention Framework and assume it's someone else's problem. Legal team, fraud team, not the brand people. That's the wrong read.

Scammers work by impersonating trusted brands. They copy your emails, spoof your sender name, mimic your call-to-action buttons and clone your landing pages. The framework makes the businesses being impersonated partly responsible for protecting customers from that impersonation. That drags marketing into scope.

The obvious pressure point is how you contact customers. If your genuine marketing emails contain urgent language, unexpected links and requests to log in, you've trained your audience to click exactly the things a scammer relies on. Consistent sender identity, predictable domains and clean email authentication stop being nice-to-haves. They become part of your legal defence and your brand trust story at the same time.

This sits alongside the ACMA spam rules and Privacy Act obligations you already manage. The framework doesn't replace those. It adds a duty to actively design communications that are harder to impersonate and easier for customers to verify.

Scammers impersonate trusted brands. The framework quietly makes your brand's contact behaviour a legal matter, not just a marketing one.

How it shows up

The framework shows up in the details of every customer touchpoint. The sender domain on your marketing emails. Whether SPF, DKIM and DMARC authentication are configured so scammers can't spoof your address. The consistency of your call-to-action language across channels. Whether customers have a documented way to verify a message really came from you.

It also shows up in your incident response. Designated businesses need documented processes for reporting scams, disrupting them and compensating customers where obligations are breached. For marketing teams the practical test is simple: could a customer tell your genuine message apart from a convincing fake, and have you made that easy?

The Australian context

This is Australian legislation with no direct global equivalent, so overseas playbooks don't help. The framework applies economy-wide in principle but designates specific sectors in stages. Banks, telecommunications providers and digital platforms carrying ads and social media are the first regulated sectors. The ACCC coordinates the overarching framework while sector regulators like APRA, ASIC and ACMA enforce within their patches.

For marketers in or adjacent to these sectors, the near-term work is defensive. Lock down email authentication so your domain can't be spoofed. Standardise sender identity across every campaign. Strip the fake-urgency patterns from your copy that scammers exploit. Document how customers verify genuine communications. Businesses expecting future designation should start now rather than wait for the regulator to knock.

Where people get this wrong

Treating it as a legal problem with no marketing involvement.The framework targets brand impersonation, which means your email design, sender identity and call-to-action patterns are directly in scope.
Assuming only banks and telcos need to care.Those sectors were designated first, not exclusively. The framework is built to expand, and adjacent regulated businesses are the least prepared.
Using fake urgency and unexpected login links in genuine campaigns.Copy that mimics scam tactics trains customers to click the exact things fraudsters rely on, which undermines both compliance and brand trust.

Related terms

Common questions

Does the Scams Prevention Framework apply to my business?

Directly, only if your sector has been designated. Banks, telcos and digital platforms are first. If you operate in or adjacent to those sectors, plan for it. The framework is designed to widen over time, so waiting for formal designation is a risky default.

What does an anti-scam law have to do with marketing?

Scammers impersonate trusted brands using fake emails, spoofed senders and cloned landing pages. The framework makes impersonated businesses partly responsible for protecting customers. That puts your sender identity, email authentication and call-to-action design squarely in scope for marketing teams.

How is this different from the ACMA spam rules?

The spam rules govern consent and unsubscribe for the messages you send. The framework adds a duty to make your communications harder to impersonate and easier to verify. They stack rather than replace. You need to satisfy both at once.

What should marketing do first to prepare?

Lock down email authentication so your domain cannot be spoofed. Standardise sender identity across every campaign. Remove fake-urgency patterns and unexpected login links from your copy. Give customers a clear, documented way to confirm a message genuinely came from you.

Debrief

Get the next one

No spam. No fluff. Just the next article, straight to your inbox.

Keep exploring

About New Rebellion

New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.

How we think →