1. Regulatory focus
In Decision 2026-140, effective June 18, 2026, the CRTC moved beyond a narrower botnet blocklist model and allowed Canadian carriers to use any approved network-level blocking method, provided it meets the principles of necessity, accuracy, and consumer privacy. The framework expressly covers malware, phishing, and related cyber threats, requires a carrier process for false-positive and over-blocking complaints with resolution within five business days, and mandates a dedicated “cyber security blocking” disclosure on carrier websites describing the blocking approach, third-party support including providers located outside Canada, and relevant privacy information.
2. Business impact
For aggregators, brands, and notification programs that rely on shortened links or redirected domains, the compliance risk is no longer limited to content being tagged as spam. Delivery can now be affected by infrastructure-level indicators of compromise, domain reputation, vendor practices, and how quickly blocking complaints are resolved. The CRTC’s latest CASL enforcement update also shows why this matters operationally: between October 1, 2025 and March 31, 2026, the Spam Reporting Centre received 189,908 submissions, and SMS represented 34% of reports filed through the online form. That makes phishing-style text traffic a live enforcement concern, especially where brands depend on third-party sending, external anti-fraud tooling, or offshore support providers.
3. Operating recommendations
For traffic terminating in Canada, teams should expand message governance into an infrastructure compliance package: inventory sending domains, landing pages, link-shortening services, sender-to-brand mappings, anti-fraud vendors, and any processing nodes outside Canada. On the remediation side, prepare evidence that can be assembled within five business days, including timestamps for blocked traffic, message purpose, redirect destinations, IOC review logs, and responsibility boundaries across carriers and vendors. Also treat blocking-derived data carefully: do not repurpose it for profiling, remarketing, or scoring models unless you can point to a separate lawful basis, consent path, or other explicit authorization.