Skip to content
Koltrix

Cold email that follows the rules: consent, opt-out, identity

Cold outreach is legal in many places if you identify yourself, offer a real opt-out and honor it. A founder-friendly checklist, plus where the rules differ.

Koltrix Team4 min read
Pile of paper envelopes on a table
Photo by Joanna Kosinska on Unsplash
On this page(9 sections)
  1. Three things every cold email needs
  2. Sender identity
  3. Consent: it depends where the recipient is
  4. Opt-out that actually works
  5. What mailbox providers add on top of the law
  6. What to avoid
  7. A short pre-send checklist
  8. How this looks from the receiving side
  9. Key takeaways

Early-stage founders send cold email because it works. It is also the fastest way to land a new domain in the spam folder or to make a stranger angry enough to complain.

The good news is that the practices that keep you inside the rules are the same ones that keep you in the inbox. This is a plain-language guide to them. It is general information, not legal advice, and the rules change, so check with a lawyer before you run outreach at scale or into countries you have not researched.

Three things every cold email needs

Almost every set of rules, and every mailbox provider's filter, comes back to three questions.

  1. Who is this from? The sender should be a real person or company the recipient could look up, with a working address.
  2. Why am I getting it? There should be an honest reason, such as a role or a problem you can name, not a trick.
  3. How do I make it stop? There should be a clear, working way to opt out, and you must honor it.

If you can answer all three in the email itself, you have most of what matters.

Sender identity

  • Send from a domain you own, authenticated with SPF, DKIM and DMARC. Anything else looks like impersonation to a filter and to a person.
  • Use a real name in the From line and a real reply address. A noreply address on a cold email invites complaints, because the only way to object is the spam button. See the case against noreply addresses.
  • Put your company name and a physical mailing address in the footer. In the United States the CAN-SPAM Act asks commercial senders for a valid postal address.
  • Keep subject lines honest. A subject that implies an existing conversation ("Re: our call") when there was none is deceptive, and some laws say so explicitly.

This is where the rules genuinely differ, and where a founder most needs a lawyer.

  • United States (CAN-SPAM): at the time of writing, cold commercial email is allowed without prior consent, as long as you identify yourself, do not mislead, include an address and give an opt-out that you honor promptly. The law covers business email as well as consumer email.
  • Canada (CASL): consent is the starting point. There are limited forms of implied consent, for example when an address was conspicuously published and the message is relevant to the person's role, but you should not assume it.
  • European Union and UK: the answer depends on the country and on who the recipient is. Rules for messages to individuals are generally stricter than for messages to a company's role-based or corporate addresses, and data-protection law also applies to how you collected the address.
  • Elsewhere: many countries have their own anti-spam laws. If you target a country, look up its rules first.

A safe working habit: record where each address came from and why you believed it was appropriate to email it. If someone asks, you can answer.

Opt-out that actually works

An unsubscribe link that does nothing is worse than none.

  • Put a plain-text way out in every message, such as a link or a simple "reply 'no thanks' and I will not contact you again". Do not make people log in or pay.
  • Honor requests quickly. CAN-SPAM allows up to ten business days; do it the same day if you can.
  • Keep a suppression list of everyone who opted out, bounced or complained, and check it before every send. Importing a new list should never undo old opt-outs.
  • If you send in volume, add the List-Unsubscribe headers so mailbox providers can show their own unsubscribe button. See one-click unsubscribe, RFC 8058.

What mailbox providers add on top of the law

Gmail and Yahoo set their own rules for bulk senders. They expect authentication, easy unsubscribe for promotional mail, and a low spam-complaint rate. At the time of writing, Google's published guidance asks senders to keep their spam rate below 0.1% and never reach 0.3%. Read the current numbers in our summary of the Gmail and Yahoo requirements.

In practice this means the way you send matters as much as the legal minimum:

  • Use a separate sending subdomain so outreach reputation does not touch the domain your customers' receipts come from.
  • Warm up the domain with small volumes before you scale.
  • Send a few messages at a time, to people for whom the email is plausibly relevant.
  • Stop sending to anyone who has not engaged after a couple of attempts.

What to avoid

  • Bought or scraped lists. The addresses are often invalid or traps, the people never agreed to anything, and the risk to your domain is high.
  • Hidden or fake senders. Rotating sender names to dodge filters is both deceptive and easy to detect.
  • Open-tracking as a success metric. Replies, meetings and complaints are the numbers that matter.
  • Long attachments and link shorteners in a first message. They look like phishing.
  • Ignoring replies. People who answer "not interested" are doing you a favour. Record it and move on.

A short pre-send checklist

  • Sender domain authenticated, DMARC in place, sending from a subdomain
  • Real name, real reply address, company name and postal address in the footer
  • A specific, honest reason this person is receiving it
  • A working opt-out, and a suppression list checked before every send
  • A record of where each address came from
  • Volume small enough to watch the first results by hand

How this looks from the receiving side

If you want to see how a team inbox sorts outreach like yours, read how teams triage cold pitches. Writing a message you would be willing to receive is the best test of all.

Key takeaways

  • Identify yourself, be honest about why you are writing, and offer an opt-out you honor.
  • Consent rules vary by country: the US is permissive with conditions, Canada and much of Europe are stricter. Get advice for your markets.
  • Keep a suppression list and check it every time.
  • Authentication, a separate subdomain and low volume protect your deliverability as much as they protect you legally.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn