What CAN-SPAM requires#
CAN-SPAM requires accurate headers, a physical address, and honoring opt-outs within 10 business days.
What email account takeover is#
Account takeover (ATO) is unauthorized access to a legitimate mailbox, typically via phished credentials, password reuse, or OAuth consent phishing.
Why it matters#
A taken-over mailbox bypasses every authentication control and becomes a launchpad for BEC and internal phishing.
How email account takeover supports CAN-SPAM compliance#
Regulators and recipients need to identify who sent a message and trust that opt-out mechanisms work. Email account takeover contributes by a taken-over mailbox bypasses every authentication control and becomes a launchpad for BEC and internal phishing.
Implementation steps#
- Enforce phishing-resistant MFA (FIDO2 keys or passkeys) for admins and finance.
- Review third-party OAuth grants monthly and restrict user consent.
- Alert on impossible-travel logins and mass downloads.
- Have a documented response: revoke sessions, reset, audit rules and forwards, notify affected parties.
Frequently asked questions#
What are signs of a compromised email account?
Unknown sent items, new forwarding rules, missing mail, login alerts from unfamiliar locations, and contacts reporting odd messages.