The History of Email Marketing: From Usenet Spam to the AI Era | AI Email Tools
History

The History of Email Marketing: From Usenet Spam to the AI Era

Updated July 202610 min readBy Scott Holmes

On April 12, 1994, a Perl script written by a programmer known only as "Jason" posted an ad for green card lottery filing services to more than 5,500 Usenet newsgroups. Laurence Canter and Martha Siegel, the Phoenix immigration lawyers who'd paid for it, skipped the cross-posting Usenet etiquette required — one message, visible in every group a reader subscribed to. They had it posted separately into each group instead, so it turned up again and again no matter where you looked. Their internet provider, Internet Direct, crashed under the complaint volume within two days and pulled the account. Canter later put the campaign's take at somewhere between $100,000 and $200,000. He was disbarred in Tennessee three years afterward, for reasons that had nothing to do with email, though the timing didn't hurt the story any.

Usenet already had a word for what they'd done, and it predated the incident by about a year. In April 1993, a poster named Richard Depew made a script error that duplicated roughly 200 messages into a single newsgroup. Regulars mocked the mess by comparing it to the Monty Python sketch where a table of Vikings drowns out a diner's order by chanting the word "spam" until it's the only word left in the scene. The name attached itself to the phenomenon before it attached to Canter and Siegel specifically. Their campaign is what carried it out of Usenet and into the vocabulary of everyone else.

Spam itself is older than Usenet, though. Sixteen years before the Green Card posting, on May 3, 1978, a Digital Equipment Corporation marketer named Gary Thuerk sent an invitation to a DECSYSTEM-20 product demo to roughly 400 addresses on ARPANET — close to the network's entire West Coast user base at the time. ARPANET's administrators were furious. One of them tracked Thuerk down and got him to promise he wouldn't do it again. He kept that promise. He didn't need to break it: DEC credited the single message with about $13 million in sales. That's the tension that has followed email marketing through every decade since — the tactic works, roughly in proportion to how much the people receiving it resent it, and that arithmetic has never stayed settled long enough for either side to win outright.

Before anyone regulated it, the internet policed itself

Government didn't touch commercial email for another twenty-five years. In the meantime, spam became a real business. Sanford Wallace started Cyber Promotions in 1995 and, on his own account, built it into the country's largest source of unsolicited email — forging return addresses and routing mail through other providers' servers to dodge the filters that were just starting to exist. Concentric Network sued him in 1996 and won a consent decree. CompuServe went further the following year, arguing in federal court that spam flooding its mail servers was trespass — not against physical property, but against the computing capacity its subscribers were paying to use. In CompuServe Inc. v. Cyber Promotions (S.D. Ohio, 1997), the judge agreed, applying a doctrine built for someone driving a truck onto your lawn to a company routing bulk mail through your servers, and issued a permanent injunction plus about $65,000 in fees. Wallace was out of the spam business by April 1998. An unrelated Facebook spam scheme put him in federal prison in 2016.

The technical fix beat the legal one to market by a year. In 1996, engineers Paul Vixie and Dave Rand built the Realtime Blackhole List under something called the Mail Abuse Prevention System — a shared, constantly updated registry of known spam sources that participating mail servers could check against and reject automatically. It was blunt, and it caught plenty of legitimate senders in its net along with the spammers. But it was the first working version of the reputation-based filtering every major inbox provider still runs today, decades and several architectures later. CAUCE, the Coalition Against Unsolicited Commercial Email, formed the same year Wallace's case was working through the courts and spent the rest of the decade lobbying Congress for a federal law — one that, when it finally showed up, much of CAUCE's own membership ended up disowning.

The tools built to look nothing like Cyber Promotions

While Wallace was making spam infamous, a quieter set of companies was trying to build the opposite: email marketing a legitimate small business could run without turning into him. Randy Parker founded Roving Software in 1995 and renamed it Constant Contact in 2004, aiming the product at businesses with a real customer list and zero interest in scripting mass Usenet posts. Mailchimp's start is stranger. It began in Atlanta in 2001 as a side project inside the Rocket Science Group, a web design agency Ben Chestnut and Dan Kurzius ran for large corporate clients, built as a cheaper alternative to the bloated enterprise email software of the era for the small businesses their agency work didn't otherwise serve. Neither of them set out to build what would become, two decades on, a $12 billion acquisition target for Intuit. The side project outgrew the agency it started in.

By the mid-2000s the category had split again. HubSpot, founded in 2006 by Brian Halligan and Dharmesh Shah out of MIT, gave the approach a name — inbound marketing — built on the idea that a list should be earned through content and consent rather than acquired and blasted. Automation platforms multiplied through the rest of the decade, layering segmentation, behavioral triggers, and drip sequences onto what had started, twenty years earlier, as one Perl script and a distribution list.

The law shows up late, and picks a side

Congress passed the CAN-SPAM Act in December 2003; President Bush signed it December 16, and it took effect that following January. It's remembered less fondly than its acronym suggests. The law is opt-out, not opt-in — it doesn't require permission before the first email, only that senders honor an unsubscribe request within ten business days, use accurate headers, and list a real postal address. Anti-spam advocates were calling it the "You-Can-Spam Act" before the ink dried, on the argument that it handed every marketer in the country one free, fully legal shot at any inbox. Compliance backed up the complaint: researchers found under 1% of spam met the law's requirements in 2004, and 0.27% two years later. It also overrode the tougher state laws several legislatures had already passed, and it gave individual recipients no right to sue — enforcement was left to the FTC and the ISPs, neither of which treated most senders as a priority target.

Other jurisdictions made the opposite bet. Canada's Anti-Spam Legislation, in force since July 1, 2014, requires opt-in consent before commercial email goes out at all, backed by real financial penalties. The EU's GDPR, effective May 2018, went further, treating an email address as personal data and consent as something that has to be freely given, specific, and revocable, with fines that scale off global revenue rather than a fixed dollar figure. Three regimes, three different answers to the same problem Canter and Siegel created in 1994 — and a single mailing list built today can be fully compliant in one of those jurisdictions and flatly illegal in another, depending only on where its recipients happen to live.

The through-line: every legal and technical fix in this history reacted to something that already worked commercially. Thuerk's ad, the Green Card posting, Cyber Promotions — none of them failed on their own terms. They got shut down, sued, or legislated against after the fact, never priced out of working in the first place.

Where the tension lands today

Cold email, the direct descendant of what Thuerk did to those 400 ARPANET addresses, runs on the same math it always has: it costs the sender very little, and the aggregate reaction ranges from indifference to real anger depending almost entirely on how well it's targeted and how honestly it's written. What's changed is the infrastructure around it. Thuerk had no reputation system to worry about, and Wallace could still forge headers and route around a handful of filters. A domain sending cold email today gets scored continuously by Gmail and Microsoft on delivery behavior, complaint rates, and authentication records, in something close to real time. AI has entered the fight on both sides of it — generating personalized volume no 1994 Usenet script could have matched, and getting steadily better at flagging the output of exactly that kind of automation. Neither side has won. It's the same argument Thuerk's ARPANET colleagues were having with him in 1978, running on faster infrastructure with sharper lawyers on both sides of the table.

The Green Card ad is still online, preserved in Usenet archives by the same community that tried to cancel it in real time. Read now, it looks exactly like what it was: cheap to send, impossible to ignore, and immediately, permanently resented. Nothing built in the fifty years since has changed that trade. Only who's allowed to make it, and what happens to them if they get caught.

Timeline, for reference

YearEvent
1978Gary Thuerk sends the first known unsolicited commercial email over ARPANET
1993Richard Depew's Usenet posting error gives "spam" its modern meaning
1994Canter & Siegel's Green Card posting makes "spam" a household term
1995Cyber Promotions and Roving Software (later Constant Contact) both founded
1996MAPS/RBL reputation-based filtering launches; CAUCE forms
1997CompuServe v. Cyber Promotions establishes spam as legal trespass
2001Mailchimp begins as a side project inside an Atlanta design agency
2003/04CAN-SPAM Act signed, takes effect — opt-out, federally preemptive
2006HubSpot founded, popularizes "inbound marketing"
2014Canada's CASL takes effect — opt-in, real penalties
2018EU GDPR takes effect — consent-first, extraterritorial
2021Intuit acquires Mailchimp for roughly $12 billion

Common Questions

It's the first known unsolicited commercial email, sent over ARPANET in 1978, sixteen years before the Usenet incident most people associate with the word "spam." The 1994 Canter & Siegel posting is a different milestone — it's what took "spam" from a Usenet in-joke to a term the general public understood, not the first instance of the thing itself.
Canter later estimated the campaign brought in $100,000 to $200,000. Their follow-on attempt to sell the same tactic to other clients as a consulting service didn't take off, and Canter was disbarred in Tennessee in 1997 over unrelated conduct.
No. CAN-SPAM in the US is opt-out — it permits unsolicited commercial email as long as senders honor unsubscribe requests, use accurate headers, and identify themselves. CASL in Canada and GDPR in the EU require opt-in consent instead, which is why the same message can be compliant for one recipient and illegal for another, depending on where they live. See our CASL compliance guide for the Canadian rules specifically.

Related guides

→ Cold Email Deliverability: The Complete 2026 Guide → Cold Email Laws in Canada: CASL Compliance Guide → How to Build a Cold Email Agency From Scratch (2026) → Best Cold Email Software 2026: Full Tier List & Comparison

Sources

Written by

Scott Holmes

Cold email infrastructure specialist. Founder of Pinnacle Tech Projects.