Amazon · AWS Acceptable Use Policy

Prohibition on Spam and Unsolicited Communications

Medium severity
Share 𝕏 Share in Share 🔒 PDF

What it is

You cannot use AWS to send spam, bulk unsolicited emails, or run denial-of-service attacks — and you cannot help others do these things through AWS infrastructure.

Consumer impact (what this means for users)

Businesses that use AWS for email marketing must ensure their campaigns include working unsubscribe mechanisms, accurate sender information, and physical mailing addresses as required by CAN-SPAM, or they risk both account termination and FTC enforcement action.

Cross-platform context

See how other platforms handle Prohibition on Spam and Unsolicited Communications and similar clauses.

Compare across platforms →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

This provision aligns with federal CAN-SPAM obligations and means businesses using AWS Simple Email Service (SES) or EC2 for email campaigns must maintain full compliance with opt-out mechanisms, sender identification, and content requirements.

View original clause language
You may not use the Services to transmit, distribute, or deliver unsolicited bulk email (spam), commercial email, or other messages in violation of applicable laws, including the CAN-SPAM Act; to operate mail bombing or denial-of-service attacks; or to facilitate any of the above.

Institutional analysis (Compliance & legal intelligence)

1) REGULATORY FRAMEWORK: This provision directly implements the CAN-SPAM Act (15 U.S.C. § 7701 et seq.), which requires commercial email to include opt-out mechanisms, accurate headers, and physical postal addresses. GDPR Article 6 and Recital 47 govern consent requirements for email marketing to EU data subjects, and the ePrivacy Directive (2002/58/EC) requires prior opt-in consent for electronic marketing in most EU member states. CASL (Canada's Anti-Spam Legislation) applies to messages sent to Canadian recipients. Primary enforcement authorities are the FTC (CAN-SPAM), FCC (robocall/robotext), and EU national DPAs (GDPR/ePrivacy). 2)

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    The FTC is the primary enforcement authority for the CAN-SPAM Act and has jurisdiction over unsolicited commercial email violations involving AWS infrastructure.
    File a complaint →

Provision details

Document information
Document
AWS Acceptable Use Policy
Entity
Amazon
Document last updated
April 29, 2026
Tracking information
First tracked
April 27, 2026
Last verified
April 27, 2026
Record ID
CA-P-003250
Document ID
CA-D-00028
Evidence Provenance
Source URL
Wayback Machine
SHA-256
35a0e34b7136e83dd0dca01e14dd192b01d7012211f2617232fe3d1a27218091
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Amazon | Document: AWS Acceptable Use Policy | Record: CA-P-003250
Captured: 2026-04-27 10:50:37 UTC | SHA-256: 35a0e34b7136e83d…
URL: https://conductatlas.com/platform/amazon/aws-acceptable-use-policy/prohibition-on-spam-and-unsolicited-communications/
Accessed: May 2, 2026
Classification
Severity
Medium
Categories

Other provisions in this document