All articles

The FTC's rule against fake reviews: what it actually requires from a directory that hosts advertiser reviews

8 min read

A different kind of complaint than the one operators are used to

Most of what an operator learns about review risk comes from an angry advertiser threatening to sue over a bad rating. That is a real problem, and what actually protects a platform when a reviewer's claim gets challenged is a question worth knowing cold, because Section 230 and defamation law decide who is on the hook for what a client wrote. But that is a private dispute between two people, with the platform caught in the middle.

There is a second, newer front that has nothing to do with any individual review, and it comes from a regulator rather than an advertiser's lawyer. On December 22, 2025, the Federal Trade Commission sent warning letters to ten companies over possible violations of its Rule on the Use of Consumer Reviews and Testimonials, a regulation that took effect on October 21, 2024, and that authorizes the agency to seek civil penalties of up to $53,088 per violation. Nobody has to sue anybody for this one. The rule gives the FTC itself standing to act, and as of late 2025 it started using it.

The rule, codified at 16 CFR Part 465, does not target adult businesses specifically, and it does not care what industry a site operates in. It applies to any business in the United States that solicits, hosts, or uses consumer reviews, which covers a classifieds directory as squarely as it covers a retailer. What it actually regulates is not what a client says about a provider. It is what the platform itself does with reviews: whether it writes or buys them, how it structures incentives to get them, whether staff post them without saying who they are, and how it responds when someone wants a bad one gone. That is a different set of questions than the defamation ones, and it needs its own written answers.

What the rule actually forbids

The regulation groups prohibited conduct into six categories, and most of them describe things an operator would never do on purpose, but are worth ruling out explicitly rather than assuming. The first bans creating, buying, selling, or otherwise disseminating a review or testimonial that misrepresents who wrote it or what experience they actually had, including a review generated by AI and passed off as a client's words. A directory that never writes reviews for anyone is already clear of this one, and the rule includes an explicit exemption for platforms that do nothing more than host what clients submit, covered in the next section.

The second category prohibits paying or otherwise compensating someone for a review on the condition, stated or implied, that it expresses a particular sentiment. Offering a small credit for leaving any review is fine. Offering it for a five-star review, or phrasing the offer in a way that implies the review needs to be positive, such as asking clients to share how much they loved a booking in exchange for a reward, is not. The distinction is narrow but the rule is specific about it: a business can reward participation, not the verdict.

The third covers insider reviews. An officer or manager who asks a relative, an employee, or a contractor to write a review without disclosing that relationship, or a business that circulates a testimonial from a staff member without that disclosure once it knew or should have known who wrote it, is in violation. A single mass email to every past client asking for a review is exempt even if some of those clients happen to work for the business, since nothing about a generalized request singles out insiders. The fourth prohibits running a site or seal that appears independent while the business actually controls it, which sits close to a separate case worth knowing: the FTC's own action over a listings platform that printed "verified" without doing the verification. The fifth and sixth cover suppressing genuine negative reviews and buying fake social media followers or engagement, both addressed further below.

The hosting exemption, and where it stops covering you

For a directory whose review feature is exactly what it looks like, a place for clients to rate the providers they booked, the rule's most relevant provision is the one that protects it by default. Section 465.2(d) exempts a business that is merely hosting reviews submitted by consumers, and the FTC's own guidance confirms that exemption holds even if the platform prompts people to leave a review or aggregates their ratings into a star average. A directory that did not write, buy, or solicit any specific review is not liable under this rule just because one of the reviews sitting on its site turns out to be fake, the same way a retailer is not liable for a fake review of a product it did not manufacture.

That protection has a limit worth taking seriously rather than assuming away. It disappears the moment a platform knew, or should have known, that a review was not genuine, and the FTC's own guidance spells out what "should have known" looks like in practice: reviews that appear implausibly fast after a booking, an unusual spike in volume within a short window, or reviews that reference a provider other than the one they were posted under. None of those require an investigation to notice, only attention, which is a reason the team already reading every listing before it goes live is worth handing this checklist to as well, the same team already covered when it comes to staffing the review of new listings.

The other detail worth knowing before assuming it away: handing review moderation to an outside vendor does not transfer this exposure off the platform's books. The rule attaches to the business hosting the reviews, not to whichever contractor happens to be reading them that week, so a vendor contract is an operational choice, not a liability shield.

Handling a provider's complaint without becoming the problem

An advertiser upset about a negative review is the most common trigger for a mistake under this rule, because the instinct to just make the complaint go away is exactly the instinct Section 465.7 targets. The rule prohibits using an unfounded or groundless legal threat, a physical threat, intimidation, or a knowingly false public accusation against a reviewer to get a negative review removed or changed. None of that requires bad intent to trigger; a support script that leans on a client with vague talk of legal consequences to get them to delete an honest complaint fits the definition even if nobody involved thought of it as intimidation.

What the rule does not prohibit is worth knowing just as well, because overcorrecting into silence is its own mistake. A platform can respond publicly to a negative review, reach out to a client privately to try to resolve the underlying issue, and decline to publish reviews that are about the wrong business or that fail a policy applied the same way to positive and negative reviews alike. Sorting reviews with the best ones on top by default is not suppression under this section either, according to the FTC's own guidance on the point. It is a separate question, and one worth watching, whether burying negative reviews behind a design choice that makes them hard to find could count as a deceptive practice under the FTC Act more broadly, even where this specific rule does not reach it, so a sort order that makes it functionally impossible to find a one-star review is not a settled safe harbor just because it clears this one section.

The useful distinction to keep in mind between this rule and the defamation question covered above is who is doing the complaining. A defamation threat comes from the provider and puts the platform in the position of judging a factual dispute between two people. A Section 465.7 violation is something the platform does to a reviewer on a provider's behalf, and it is the FTC, not the provider, who gets to decide it happened.

What to put in writing this week

None of this requires legal counsel on retainer to get right, but it does require a short written policy that exists before the first complaint arrives rather than one improvised under pressure. Write down the criteria a review has to fail to get pulled, in terms that apply identically whether the review is glowing or scathing, so nobody on the team is deciding case by case whether an advertiser's complaint is worth honoring. State plainly that no compensation, credit, or perk is ever offered in exchange for a positive review, only for leaving one, and remove any script or email template that implies otherwise even subtly.

Add a one-line disclosure rule for any review or testimonial that comes from a staff member, an owner's relative, or a contractor, and make sure whoever handles customer support knows never to threaten a client with legal consequences to get a review down without an actual lawyer having reviewed the claim first. If review moderation is outsourced, put the same rules in the vendor contract rather than assuming the contractor already follows them.

None of this comes with a private lawsuit attached. There is no individual right to sue over a violation of this specific rule, which means the incentive to get it right is regulatory rather than the kind of everyday legal threat operators are used to filtering out. But a regulator that sent ten warning letters in December 2025, with civil penalties of up to $53,088 per violation sitting behind them, is not a theoretical risk to file away for later. It is worth the one afternoon it takes to write the policy down before it becomes the FTC's question rather than an internal one.

Try the DEMO

Escort directory software, ready to go