Australian SMS & MMS Marketing Compliance: The Working Guide

August 5, 2026
Illustration warning about breaking ACMA spam rules

If you send marketing SMS or MMS in Australia, three obligations under the Spam Act 2003 apply to every single message: you must have consent, you must identify your business, and you must provide a working unsubscribe. Since 1 July 2026 a fourth applies in practice: if you send from an alphanumeric sender name, it must be registered on the ACMA's SMS Sender ID Register or your messages will be labelled "Unverified" — or blocked. Australian businesses have paid more than $15 million in spam and telemarketing penalties in the last 18 months, and SMS is squarely in the ACMA's enforcement priorities. This guide covers what compliance actually requires in operational terms — with the current penalty record, so the cost of getting it wrong isn't abstract.

Last reviewed and fact-checked: 5 August 2026. This is practical guidance, not legal advice; for edge cases, talk to your lawyer.

The three obligations, in operational terms

The Spam Act 2003 governs "commercial electronic messages" — any commercial message sent to an electronic address. That is email, SMS, MMS, and instant messaging (WhatsApp messages were part of Tabcorp's $4 million penalty), and the statute's "or similar account" wording means the prudent operating assumption is that push and in-app messages are in scope too. The channels that are not Spam Act territory: voice calls and faxes, which sit under the separate Do Not Call Register and telemarketing rules. One law, one consent posture, every addressable channel — this guide focuses on SMS and MMS mechanics, but your consent records and opt-out propagation must span all of them, because the ACMA's penalties do.

Whether a message is commercial depends on its content and purpose, not what you call it: a "service message" that promotes an offer is a marketing message, and mislabelling marketing as service traffic is a stated ACMA enforcement priority.

1. Consent — express or inferred, and you carry the burden of proof

Express consent is an affirmative opt-in: a ticked box (not pre-ticked), a completed sign-up, a keyword reply. Inferred consent comes from an existing customer relationship where the person would reasonably expect your messages.

Inferred consent is where most programs get hurt, because teams read it wider than the ACMA does. Before relying on it, every send should pass three questions:

  1. Would this recipient expect this message, because of a real, recent dealing with us — and is this message a reasonable extension of that relationship?
  2. Does the message identify us and deal with our actual business?
  3. Can the recipient opt out instantly and never hear from us again?

If any answer is no, you need express consent. Two more operational rules: consent must be provable (store when, where and how each number opted in — your platform or CRM should hold this per contact, not in a spreadsheet), and consent to one thing is not consent to everything (a receipt-delivery opt-in is not a marketing opt-in — this distinction is exactly what several recent penalties were about).

2. Identification — every message, no exceptions

Every message must clearly identify the sender and how to contact them. In 160 SMS characters that means your brand name in the message body, every time — not only in the sender ID. For MMS, put the brand in both the visual and the text component; the image may not load on every handset.

3. Unsubscribe — functional, free, and honoured within five business days

The unsubscribe must be present in every message, must work for at least 30 days after the send, must not cost more than a standard message, must not require a login or account, and opt-outs must take effect within five business days. "STOP to opt out" replies are the SMS norm — but the mechanics behind them are where audits fail:

  • The reply path must actually work. Sending from a number the recipient cannot reply to (a common side effect of unregistered alphanumeric sender IDs) can render your unsubscribe non-functional. Telstra paid $626,040 in October 2024 for marketing SMS lacking a functional unsubscribe — this is not a small-operator problem.
  • Suppression must propagate everywhere. If your e-commerce platform, CRM and messaging platform each hold their own lists, one opt-out must reach all of them within the five-day window. This is an integration problem before it is a policy problem — solve it at the API and webhook layer, not with manual exports.

The Sender ID Register: the 2026 change

As of 1 July 2026, the ACMA's SMS Sender ID Register is mandatory for alphanumeric sender IDs (sending as "BRAND" instead of a phone number). Unregistered alphanumeric IDs are labelled "Unverified" on delivery — or blocked by carriers outright. Registration runs through participating telcos and messaging providers and typically takes about two weeks, so it cannot be left to campaign week.

The register exists because alphanumeric IDs were trivially spoofable — scammers sent as "AusPost" and banks for years. We argued against unregistered alpha headers long before the register existed, for exactly this reason, plus one the register doesn't fix: recipients still can't reply to an alphanumeric ID. No reply path means no "STOP", no two-way conversation, and a harder case that your unsubscribe is functional. A dedicated registered number builds the same brand recognition in the handset — via contact cards and consistent sending — while keeping the reply path open.

Decision rule: if two-way matters (it should), send from a dedicated number and put your brand in the message body and vCard. If you must use an alphanumeric ID for one-way traffic, it has to be on the register — no exceptions since July 2026.

How registration actually works (and no, it's not too late)

If you missed the July deadline, your messages show as "Unverified" today — but registration is open and takes roughly two weeks end to end. You don't register directly with the ACMA yourself; registration runs through a registered telco or messaging provider. MobileDigital is a registered telco actively participating in the register, and the process looks like this:

  1. You nominate the sender ID you want to use with your messaging provider (in our case, MobileDigital).
  2. Your provider registers your business — your ABN and entity details — with the ACMA through the register portal, and nominates the contact authorised to verify business ownership. In practice this is a role address like legal@yourentity.com.au, not an individual's inbox.
  3. The ACMA contacts that nominated party directly to confirm ownership. This is the step that catches teams out: the nominated contact must hold an ACMA account linked to that same email address, log in, and confirm that the business claims ownership of the sender ID and authorises its use. If legal@ is an unmonitored alias with no ACMA account, the verification stalls right here.
  4. On verification, your provider is notified and the sender ID stops being labelled "Unverified". Done.

The practical prep before you start: know which entity and ABN owns the brand you send under, and make sure the nominated ownership contact is monitored and has (or can create) an ACMA account. Those two items are the difference between a two-week registration and a six-week one.

What enforcement actually costs: the penalty record

The pattern across recent ACMA enforcement is consistent: consent failures and broken unsubscribes, mostly caught after consumer complaints. Verified from ACMA enforcement actions, most recent first:

WhenWhoPenaltyWhat went wrong
Jun 2025Betfair$871,000Email/SMS marketing without consent or functional unsubscribe
Apr 2025Tabcorp$4,000,000SMS/WhatsApp marketing without sender identification, consent, or unsubscribe
Nov 2024PointsBet$500,000Marketing without consent or unsubscribe
Oct 2024Telstra$626,040Marketing SMS lacking a functional unsubscribe
Aug 2024Commonwealth Bank$7,500,000170 million marketing messages without consent or unsubscribe
Apr 2024Pizza Hut$2,500,00010+ million marketing messages without consent or unsubscribe
Feb 2024Luxottica$1,500,000Marketing without consent or functional unsubscribe
Jan 2024Outdoor Supacentre$302,00083,000 marketing SMS without customer consent

Three things to read out of that table. First, SMS specifically — Tabcorp, Telstra, Outdoor Supacentre — this is not an email-only regime. Second, repeat scrutiny: an ACMA investigation typically brings a multi-year compliance program, not just the headline figure. Third, the failures are boring: nobody was fined for an exotic edge case; they were fined for sending without consent and for unsubscribes that didn't work.

MMS: same law, two extra failure modes

Everything above applies identically to MMS (the richer channel we'd argue you should be using). Two additions:

  1. Identification lives in two layers. Brand the visual and the text component. If the image fails to load, the text alone must still identify you and carry the opt-out.
  2. Frequency expectations are lower. MMS reads as higher-touch; the same cadence that is tolerable for SMS erodes the "reasonable expectation" basis of inferred consent faster. A common working pattern: MMS quarterly for brand-building, SMS for the in-between touches.

The pre-send checklist

Run every campaign against this before it leaves the platform:

  1. Consent source on file for every number in the audience (type, date, origin)
  2. Audience excludes every opt-out from all systems, synced within 5 business days
  3. Sender: dedicated number, or registered sender ID (registered before campaign week)
  4. Brand name in the message body (and in the MMS visual)
  5. Working opt-out in every message; reply path tested end-to-end this campaign
  6. Opt-out remains functional 30+ days after send
  7. Message content matches what the recipient consented to
  8. Send window is daytime, recipient's timezone
  9. Not disguising marketing as a service/transactional message
  10. Evidence trail: audience definition, consent basis and message archived

FAQ

Is inferred consent enough for SMS marketing in Australia? Only when the recipient has a genuine existing relationship with you and would reasonably expect the message. It is the most commonly over-stretched basis in ACMA enforcement — when in doubt, get express consent.

Which channels does the Spam Act cover? Email, SMS, MMS and instant messaging — Tabcorp's $4 million penalty in April 2025 covered SMS and WhatsApp messages — and push/in-app messaging should be treated as in scope. Voice calls and faxes are regulated separately (Do Not Call Register and telemarketing rules), not under the Spam Act.

What happens if I send from an unregistered alphanumeric sender ID? Since 1 July 2026, messages from unregistered alphanumeric sender IDs are labelled "Unverified" or blocked by Australian carriers. Registration through your telco or messaging provider takes roughly two weeks.

Is it too late to register a sender ID? No. The register remains open — your messages simply show as "Unverified" until registration completes. Through a registered participating telco such as MobileDigital, the process typically takes about two weeks.

Who actually registers my sender ID — me or my provider? Your provider. A registered telco or messaging provider lodges your business (ABN and entity details) with the ACMA and nominates your ownership-verification contact. The ACMA then contacts that nominee, who must log in with an ACMA account linked to that email address and confirm the business owns and authorises the sender ID. Once verified, your provider is notified and the Unverified label is removed.

How fast must an opt-out take effect? Within five business days, across every system that can message that person. The unsubscribe mechanism itself must keep working for at least 30 days after the message was sent.

Can I charge for or gate the unsubscribe? No. Opting out must cost no more than a standard message and must not require logging in to an account.

What's the realistic penalty exposure? Recent ACMA penalties for consent and unsubscribe failures range from roughly $300,000 to $7.5 million, and enforcement usually adds a supervised compliance program. Australian businesses have paid over $15 million in spam and telemarketing penalties in the last 18 months.


MobileDigital's intouch platform manages consent records, opt-out synchronisation and dedicated-number sending as platform features. This page is reviewed against ACMA guidance and enforcement actions; it is general information, not legal advice.