Browse Definitions:

pink contract

Contributor(s): Matthew Haughn

A pink contract is an agreement between an Internet service provider (ISP) and a spammer that exempts the spammer from standard policies and allows them to send spam through the ISP.

The term pink contract comes from the canned meat for which unsolicited bulk emails (UBE) are named. Most spam is unsolicited commercial email (UCE): bulk email that is offering the recipient a product or service. Other types of spam include email chain letters, personal campaign mailings, messages with virus-laden attachments, phishing attempts and messages containing virus hoaxes, among other possibilities. The defining characteristics of spam are: It’s sent to huge numbers of recipients, and at least some of those recipients have not agreed to receive it.

Some current regulations, such as Canadian anti-spam legislation (CASL), complicate the spam issue by requiring the express consent of recipients. Under CASL, anyone sending commercial messages to Canadian recipients is required to move from the opt-out to the opt-in model, under which recipients agree to receive the messages.

ISPs usually provide customers with a service-level agreement (SLA) that stipulates the rights and constraints under which the service will be provided. Typically, the customer agrees not to send unsolicited mass emails and the ISP stipulates the consequences of breaking that agreement. Although pink contracts are not made public or advertised -- because they would anger customers who wade through equal parts desired and undesired email -- some ISPs offer them upon request.

Although a pink contract is significantly more expensive than the normal, advertised rates for service, it is worth it to spammers. By definition, spam is sent in enormous volumes, which means that even the tiny percentage of responses that spammers get makes the practice lucrative.

One famous example of a pink contract was reported in 2000, between AT&T and Nevada Hosting.  Spamhaus, an anti-spam organization, exposed a contract between the two companies permitting Nevada Hosting to send spam while under service with AT&T. AT&T confirmed that the contract existed but shortly thereafter removed Nevada Hosting from their service.

This was last updated in August 2014

Continue Reading About pink contract

Start the conversation

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.


File Extensions and File Formats


  • risk map (risk heat map)

    A risk map, also known as a risk heat map, is a data visualization tool for communicating specific risks an organization faces. A...

  • internal audit (IA)

    An internal audit (IA) is an organizational initiative to monitor and analyze its own business operations in order to determine ...

  • pure risk (absolute risk)

    Pure risk, also called absolute risk, is a category of threat that is beyond human control and has only one possible outcome if ...


  • federated identity management (FIM)

    Federated identity management (FIM) is an arrangement that can be made among multiple enterprises to let subscribers use the same...

  • cross-site scripting (XSS)

    Cross-site scripting (XSS) is a type of injection security attack in which an attacker injects data, such as a malicious script, ...

  • firewall

    In computing, a firewall is software or firmware that enforces a set of rules about what data packets will be allowed to enter or...



  • business continuity and disaster recovery (BCDR)

    Business continuity and disaster recovery (BCDR) are closely related practices that describe an organization's preparation for ...

  • business continuity plan (BCP)

    A business continuity plan (BCP) is a document that consists of the critical information an organization needs to continue ...

  • call tree

    A call tree -- sometimes referred to as a phone tree -- is a telecommunications chain for notifying specific individuals of an ...


  • all-flash array (AFA)

    An all-flash array (AFA), also known as a solid-state storage disk system, is an external storage array that uses only flash ...

  • volume manager

    A volume manager is software within an operating system (OS) that controls capacity allocation for storage arrays.

  • external storage device

    An external storage device, also referred to as auxiliary storage and secondary storage, is a device that contains all the ...


  • hybrid hard disk drive (HDD)

    A hybrid hard disk drive is an electromechanical spinning hard disk that contains some amount of NAND Flash memory.