Skip to content

Cold Email Laws New Zealand: A .nz Address Is Enough

Almost every cold email guide tells you New Zealand's spam law only reaches New Zealand senders. That is the wrong section, and it is why people put .nz addresses back into their sequencer with a clear conscience.

Here is the plain answer. The Unsolicited Electronic Messages Act 2007 tests the message, not the sender. Under section 4(2)(f), an electronic address ending in ".nz" gives a message a New Zealand link on its own, and sections 9, 10 and 11 apply to any message that has one. A US agency emailing a .co.nz address from a US mailbox on US infrastructure is inside the Act.

The Act does not ask where you are. It asks whether the message has a New Zealand link.

The mistake: reading section 8 as the jurisdiction clause

Section 8 is titled "Application of Act outside New Zealand", so it reads like the section that decides whether the Act reaches you. It says the Act "extends to the engaging in conduct outside New Zealand by a relevant person", and defines that as a New Zealand resident individual or an organisation that carries on business or activities in New Zealand.

On its own that reads like a clean exit: no New Zealand residence, no New Zealand business, not caught. The heading invites that reading, and most guides take it.

But sections 9, 10 and 11 never mention section 8. Each is drafted the same way: a person must not send a commercial electronic message "that has a New Zealand link". The test lives in the message. Section 8 adds conduct based reach on top of the prohibitions. It does not narrow them.

X

The section 8 read

"I am not a resident and I do not carry on business in New Zealand, so the Act does not apply to me."

The section 9 read

"Does this message have a New Zealand link. If yes, sections 9, 10 and 11 apply to me wherever I am sitting."

Section 4(2) lists six limbs. The link exists if one or more applies, and four have nothing to do with where you are:

  • the computer, server, or device used to access the message is located in New Zealand, under 4(2)(c)
  • the recipient is an individual physically present in New Zealand when the message is accessed, or an organisation that carries on business or activities in New Zealand when it is accessed, under 4(2)(d)
  • the address ends in ".nz", or the number begins with an international access code directly followed by "64", under 4(2)(f)
  • and if the address does not exist, you ask whether the message would reasonably likely have been accessed on a device located in New Zealand, under 4(2)(e)

Read that twice. A bounce still counts. Cold email lists bounce constantly, and the Act closes that door deliberately.

The drafting confirms it. The sender limb, 4(2)(b)(ii), asks where an organisation's "central management and control" sits, a high bar. The recipient limb, 4(2)(d)(ii), asks only whether the organisation "carries on business or activities in New Zealand". The Act reaches further on the recipient side, on purpose.

6
limbs in section 4(2), any one creates the link
5
working days before consent is deemed withdrawn
NZ$500,000
maximum penalty for an organisation, section 45(4)

The usual comeback is that a published business address solves it. Partly true, and only if you clear all three parts of one test.

Section 4(1) deems consent given when the address "has been conspicuously published by a person in a business or official capacity", when the publication does not carry a statement that the address holder does not want unsolicited messages there, and when the message you send "is relevant to the business, role, functions, or duties of the person in a business or official capacity".

Three consequences, and I have watched all three catch people out:

  • Published by the person. An address in a data vendor export was not published by the holder in a business capacity. That is a purchased record, not deemed consent.
  • One line kills it. A short note beside the address saying no unsolicited email removes deemed consent completely.
  • Relevance is per person, not per company. Sending one offer to every address at a firm fails the third limb for most of that list.

Then section 9(3) puts the burden on you: "A person who contends that a recipient consented to receiving a commercial electronic message has the onus of proof in relation to that matter." You prove consent, not the other way round.

Address published by the holder in a business capacity
No opt out statement beside it
Message relevant to that person's role
Deemed consent

The unsubscribe rule most sequencers quietly break

Section 11 is where cold email stacks fail without anyone noticing. The unsubscribe facility has to be clear and conspicuous, free for the recipient to use, reasonably likely to stay functional for at least 30 days after the message is sent, and it must let the recipient "respond to the sender using the same method of communication that was used to send the principal message".

Same method. If you sent an email, a reply has to reach someone. I have built cold email infrastructure for hundreds of businesses, and unmonitored sending mailboxes are close to universal: the sequencer routes every unsubscribe through a click on a tracking domain, and nobody reads the replies. Under section 11(1)(c) that is the gap.

Section 9(2) then sets the clock. Once a recipient uses that facility, consent is deemed withdrawn from the day that is 5 working days after the day it was used. Not the 10 calendar days people carry over from CAN-SPAM, and the clock only starts if the facility satisfied section 11 to begin with.

Four moves to make on your sequencer this week

1

Segment .nz by the address string

Filter on the suffix of the email address, not on a country field. Section 4(2)(f) operates on the string, and your enrichment data guesses country. The string does not guess.

2

Make reply to unsubscribe work, and read the inbox

Section 11(1)(c) wants the same channel back. At mailbox scale that is an infrastructure job rather than a copy change, and it is the fix we build most often inside cold email infrastructure engagements.

3

Store why each .nz contact is on the list

Save the URL the address was published on and the date you captured it, in a field next to the contact. Section 9(3) makes that record your only defence.

4

Re-check relevance per person

If your offer does not match that individual's role, deemed consent does not cover them, whatever the company does. Cut them or change the offer.

The part that should worry agencies

If you run campaigns for clients, section 15 is pointed at you. It says a person must not aid, abet, counsel, or procure a breach of sections 9 to 11, must not induce one, must not be "in any way, directly or indirectly, knowingly concerned in, or party to" one, and must not conspire to effect one.

The client presses send. The agency built the list, wrote the sequence and ran the infrastructure. Section 15 is broad enough to reach that arrangement. Section 45 caps penalties at NZ$200,000 for an individual and NZ$500,000 for an organisation, and directs the court to weigh how many messages went out and to how many addresses.

The bottom line

New Zealand's Act is short and clear once you read the right section. It does not ask where you are sitting. It asks whether the message has a New Zealand link, and a .nz address answers that by itself. Treat .nz contacts as their own compliance segment, with their own consent evidence and their own working reply path.

Australia's Spam Act 2003 is the acknowledged model, cited section by section in the New Zealand text, so a compliant Australian programme gets you most of the way. Our guide to Australian cold email law covers that side.

This is a reading of the statute, not legal advice. If real money rides on it, have a New Zealand lawyer review your programme.

Frequently Asked Questions

Yes, if the message has a New Zealand link. Sections 9, 10 and 11 of the Unsolicited Electronic Messages Act 2007 prohibit sending a commercial electronic message that has a New Zealand link, and section 4(2) defines that link by reference to the message and the recipient, not the sender's location. Section 8, titled Application of Act outside New Zealand, is an additional conduct based extension for New Zealand residents and New Zealand businesses. It does not limit sections 9 to 11.

Yes. Section 4(2)(f) states that a message has a New Zealand link if it is sent to an electronic address that ends with ".nz", or to a number beginning with an international access code directly followed by "64". Only one of the six limbs in section 4(2) needs to apply, so the address suffix is sufficient by itself.

Only if all three parts of the deemed consent test in section 4(1) are met. The address must have been conspicuously published by that person in a business or official capacity, the publication must not carry a statement that the holder does not want unsolicited messages, and your message must be relevant to that person's business, role, functions or duties. Section 9(3) also places the onus of proving consent on the sender, so keep the source URL and capture date on record.

Section 9(2) deems consent withdrawn from the day that is 5 working days after the day the recipient used the unsubscribe facility. That is shorter than the 10 calendar days many senders assume from CAN-SPAM. The clock only starts if the facility met section 11, which requires it to be free, clear, functional for at least 30 days, and usable by the same method of communication that delivered the message.

Not sure your cold email stack would survive a New Zealand link

I have built cold email infrastructure for hundreds of businesses. Book a 30 minute call and we will look at your sending setup, your consent records and your unsubscribe path together.

Book a 30-Minute Call

Or email [email protected].