Enforcing
Canada’s Anti-Spam
Legislation (CASL)
Actions carried out by the CRTC between
October 1, 2025 to March 31, 2026
View previous time period
Regulatory highlights
Focus on domain name abuse in Canada
Canadians are targeted and sometimes fall victim to phishing campaigns that rely on deceptive domain names to trick them into thinking they are interacting with trusted organizations such as banks, government agencies, and other popular services (e.g., parcel and food delivery services, parking and highway toll, telecom, technology, media and streaming services). These look-alike domains are easy to buy, which is why domain name registrars can play an important role in identifying and preventing phishing campaigns.
Did you know?
Registrars are in a unique position to know who their customers are, notice suspicious domain requests, and block the registration of domains if they suspect they are likely to be used for the purpose of spam or other unwanted messages.
- The CRTC issued an enforcement advisory outlining that domain name registrars can be held liable under Canada’s Anti-Spam Legislation (CASL) if they facilitate, knowingly or by negligence, the sending of phishing messages.
- Complaints submitted by Canadians through the Spam Reporting Centre (SRC) since 2022 have identified areas where registrars can improve their practices, and the CRTC reminds and educates stakeholders on a regular basis of their obligations to address spam and phishing-related issues.
- The CRTC will continue to monitor this issue and apply appropriate enforcement action against registrars who do not comply.
Enforcement highlights
For businesses - Enhanced Focus on CASL Compliance
The introduction of CASL requirements over 10 years saw CRTC compliance and enforcement activities follow a phased-in approach, beginning with sustained outreach and education, warning letters, and imposing administrative monetary penalties (AMPs) when necessary, recognizing that companies were transitioning under a new piece of legislation at that time.
As CASL is now well-established and widely understood in the Canadian marketplace, there is a heightened expectation of compliance from those who send commercial electronic messages to Canadians. Canadians continue to submit a high volume of complaints to the SRC regarding unwanted spam messages and difficulties unsubscribing, often due to broken links or overly complicated unsubscribe processes.
The CRTC will continue to investigate complaints and intends to take stronger enforcement measures when appropriate, including applying administrative monetary penalties that are proportionate to the severity and extent of the violations (up to $10,000,000 per violation for a business or $1,000,000 for individuals).
Enforcement measures between October 1, 2025 and March 31, 2026
Long description:
- 11 Warning or Information Letters
- 96 Notices to Produce
- 2 Preservation Demands
Complaints filed to the Spam Reporting Centre
Reporting unsolicited commercial electronic messages to the SRC is a key part of how the CRTC gathers intelligence on spam and electronic threats.
The CRTC, the Competition Bureau, and the Office of the Privacy Commissioner of Canada share responsibility for CASL compliance and leverage the SRC database to collect information that supports their respective mandates.
Between October 1, 2025 and March 31, 2026:
- The SRC received 189,908 submissions, averaging 7,304 per week
- Approximately 4,545 complaints were submitted using the SRC's online form , which allows users to report spam and other electronic threats in detail
- The remaining submissions, about 98%, were submitted by email to spam@fightspam.gc.ca
The best way to report spam is to use the SRC online form and upload your spam message.
Long description:
189,908 submissions to the Spam Reporting Centre
Sources of spam reported via the SRC online form
Long description:
- Email: 60%
- Text message (SMS): 34%
- Unspecified: 4%
- Instant message (IM): 1%
Note: Percentages may not add up to 100% due to rounding.
Types of SMS spam reported via the SRC online form
Long description:
- Commercial: 17%
- Other/Unknown: 46%
- Scams (including phishing): 29%
- Political SMS (CASL-exempt): 8%
Reasons why Canadians complain to the SRC
Long description:
Complaint reasons and percentages
- Lack of consent: 93%
- Indentification of sender: 48%
- Deceptive Marketing Practices: 46%
- Other: 23%
- Software and malware: 15%
Note: the percentages add up to more than 100% because people can select multiple reasons.
Top categories of commercial messages reported via the SRC online form
Long description:
- Retail and Online Shopping
- Computer & Tech Services
- Health & Wellness
- Finance & Banking
- Automotive
Top five categories of scam complaints filed via the SRC online form
Unsolicited messages are sometimes used to facilitate fraudulent activity. While the CRTC does not investigate the criminal aspects of scams, such messages are often non-compliant with CASL requirements.
Long description:
- Phishing
- Employment Scams
- Extortion
- Advance Fee
- Gift Card Scams
Outreach
Outreach and engagement activities are essential for educating legitimate businesses about their responsibilities under CASL.
To help the industry and Canadians better understand CASL, the CRTC offers a variety of resources on how to contact Canadians for commercial purposes in a compliant manner. These include:
- The Spam and Malware webpage, which includes CASL frequently asked questions, guidelines, compliance tips and more
- Videos on the CRTC YouTube channel, which provide practical tips on sending commercial electronic messages
Did you know?
In early 2026, the Compliance and Enforcement sector at CRTC met with the Office of the Senior’s Advocate for Newfoundland and Labrador, responsible for overseeing seniors' associations and groups across the province, to discuss disseminating messaging, products, and presentations to these groups.
Did you know?
March is Fraud Prevention Month. During this annual campaign, the CRTC collaborates with government partners on outreach and awareness activities. Consistent messaging is shared across government social media platforms to help educate Canadians about spam and provide practical information on how to protect themselves from fraud and other online threats.
Collaboration with International Partners
The CRTC collaborates with many countries around the globe to fulfill its mandate, to promote international cooperation and address problems relating to spam and unsolicited communication.
Canada
Memorandum of Understanding
- Competition Bureau (CB)
- Office of the Privacy Commissioner (OPC)
- Consumer Protection Authority of British Columbia
Enforcement Collaboration:
- Royal Canadian Mounted Police (RCMP)
United States
Memorandum of Understanding
- Federal Trade Commission (FTC)
- Federal Communications Commission (FCC)
Enforcement Collaboration:
- Federal Bureau of Investigation (FBI)
Ireland
Memorandum of Understanding
- Commission for Communications Reguation (ComReg)
United Kingdom
Memorandum of Understanding
- Information Commissioner’s Office (ICO)
Japan
Memorandum of Understanding
- Ministry of Internal Affairs and Communications
Australia
Memorandum of Understanding
- Australian Communications and Media Authority
- Australia Federal Police (AFP)
Enforcement Collaboration:
- Federal Bureau of Investigation (FBI)
New Zealand
Memorandum of Understanding
- Department of Internal Affairs (DIA)
Maple Disruption
The CRTC, along with 25 partner organizations, participated in Maple Disruption, a Canadian Anti-Fraud Centre and National Cybercrime Coordination Unit (NC3) of the Royal Canadian Mounted Police initiative to disrupt and degrade key enablers that fraudsters rely on, including malicious email addresses, phone numbers, bank accounts, websites, and cryptocurrency accounts. This operation took place from December 8 to 11, 2025, and focused on phishing, bank investigators, and investment scams.
Maple Disruption partners worked together to identify instances of suspected fraud and coordinated over 3,000 disruptive actions against fraud enablers. These included:
- shutting down malicious email accounts
- blocking malicious phone numbers
- taking phishing websites down
- flagging suspicious transactions
- blocklisting criminal cryptocurrency addresses linked to fraud
Partnerships such as these are another tool the CRTC employs to be responsive to activities that negatively affect the day-to-day lives of Canadians.
Useful Resources
Check out recent fraudulent activities reported to the Canadian Anti-Fraud Centre.
Looking for cyber safety tips?
- Date modified: