The Cold Email Campaign Checklist: 20 Checks Before You Send

Table of Contents
Hire an SDR

Major Takeaways: Cold Email Campaign Checklist

Why do most cold email campaigns underperform?
  • Because the failure is almost always upstream of the writing. Unverified data, unauthenticated domains, and a list too broad to personalize will sink good copy, and practitioner threads describing “high opens, zero replies” usually trace back to one of those three.

What has to be true before the first email goes out?
  • Twenty checks, most of them upstream of the copy: authentication passing on every sending domain, mailboxes warmed, the list verified, and a segment tight enough that one message genuinely fits everyone in it.

How much does personalization actually move reply rates?
  • Woodpecker’s analysis of more than 20 million sales emails puts deeply personalized outreach near 17–18% reply rates against roughly 7–9% for basic merge fields. Depth of research is what moves the number; a first-name merge field does nothing.

Is open rate still worth tracking?
  • Only as a direction. Apple Mail Privacy Protection pre-loads tracking pixels and accounts for close to half of recorded opens, which leaves reply rate, positive reply rate, and meetings booked as the numbers that survive scrutiny.

How many follow-ups should a sequence carry?
  • Four to seven touches in total, spaced three to seven days apart, each carrying something the previous message didn’t. Sequences with follow-ups reply at roughly double the rate of one-touch sends, and nearly half of reps never send a second email at all.

Does CAN-SPAM apply to B2B outreach?
  • Yes. The FTC states plainly that the law makes no exception for business-to-business email, and each separate non-compliant message carries a civil penalty of up to $53,088.

When is a campaign ready to scale?
  • When reply rate, positive reply rate, and meetings booked hold steady across two full sequence cycles. Volume added before that point multiplies whatever defect is already there.

When is cold email the wrong channel to build on?
  • When the addressable market is too small for volume to matter, or the contract value too low to absorb the cost of domains, mailboxes, and verification. Both questions are answerable with arithmetic before anyone buys a domain.

Introduction

Most cold email problems announce themselves late. A campaign goes out, the dashboard fills with opens, and three weeks pass before anyone works out that the sending domain was flagged on day four and the replies were never coming. By then the fix is a rebuild rather than an adjustment.

That is why a checklist matters. Best practices explain what a strong campaign should look like. A checklist makes sure the fundamentals are in place before anything is sent: what needs to be verified, what order to handle it in, and what “ready” actually means.

The checklist below is the process our cold email services team works through before a campaign launches, drawn from 17+ years running outbound for 2,000+ B2B brands across 50+ verticals.

It is built for teams that already understand cold email and want to scale outreach without damaging their sending reputation. The order matters as much as the items, so work it top to bottom: the numbers worth measuring only mean something once the setup underneath them is right.

The Cold Email Campaign Checklist Summary 

  1. A cold email campaign checklist runs five stages in order: channel fit, targeting and data, sending infrastructure, message and timing, then compliance and instrumentation. Twenty specific checks sit inside those stages, and all 20 should clear before launch. Working them out of order is the most common cause of a failed launch. 
  2. Before sending, confirm SPF, DKIM, and DMARC pass on every sending domain, hold the list’s bounce rate under 2%, and warm each mailbox for three to four weeks minimum.
  3. Keep the first email under roughly 80 words, with one idea and one ask, personalized on something specific to the account rather than a merge field.
  4. Plan four to seven touches spaced three to seven days apart, each follow-up adding new information rather than repeating the ask.
  5. Measure reply rate, positive reply rate, and meetings booked. Treat open rate as directional only, since privacy features inflate it.
  6. Scale after those numbers hold steady across two full sequence cycles, raising volume no faster than about 25% a week.

What Changed in 2026

  • Microsoft now refuses unauthenticated bulk mail. Since May 2025, domains sending more than 5,000 messages a day to Outlook.com, Hotmail, and Live addresses must pass SPF, DKIM, and DMARC. Non-compliant mail goes to Junk first, then gets refused outright (Microsoft).
  • Google’s spam-rate thresholds function as a gate rather than a guideline. Google asks bulk senders to keep user-reported spam below 0.1% and never let it reach 0.3%, calculates it daily, and restores mitigation eligibility only after seven consecutive days back under the ceiling (Google).
  • Inbox placement improved, unevenly. Validity’s Email Deliverability Benchmark Report, built on trillions of inbox data points, found global placement rose through 2025 to roughly 87%, with Microsoft remaining the hardest provider to reach (Validity).
  • Open rate lost its last claim to precision. Apple Mail Privacy Protection now accounts for close to half of recorded opens, so a rising open rate can reflect nothing but pixel pre-loading (Woodpecker).
  • The per-email penalty ceiling moved. Following the FTC’s January 2025 inflation adjustment, each non-compliant commercial email carries a civil penalty of up to $53,088 (FTC).

Terms Worth Knowing

  • SPF, DKIM, and DMARC are the three DNS records that together prove a message came from a domain authorized to send it and arrived unaltered.
  • Domain warm-up is the practice of raising send volume gradually from a handful of messages a day so mailbox providers build a sending history before real volume arrives.
  • Inbox rotation is the distribution of a campaign’s sends across several mailboxes and domains so no single one carries enough volume to trigger throttling.
  • Inbox placement rate is the share of delivered messages that reach the primary inbox, as distinct from delivery rate, which only confirms a server accepted them.
  • Positive reply rate is the share of recipients who reply with interest, separated out from unsubscribes, referrals, and “wrong person” responses.
  • Spam trap is an address planted by a provider or blocklist operator specifically to catch senders using scraped or unverified data.
  • MQL and SQL mark the two qualification stages after first contact: an MQL has responded and matches the ICP, and an SQL has expressed interest in a next step.

How This Guide Was Built

We reviewed the current provider requirements from Google and Microsoft, the published benchmark data on reply rates and deliverability, and the recurring questions in practitioner communities, then interpreted all of it through Martal’s own experience running cold email inside omnichannel B2B campaigns. Every step below is one a team can work through in order.

The Email Deployment Checklist: All 20 Checks Before Launch 

Each check is elaborated in its own section below. Nothing here is optional, and the order is the order we work in.

Stage 1 — Confirm the channel fits

  1. ☐ Cold email fits your market size and your deal economics.

Stage 2 — Build and verify the list

  1. ☐ Your segment is tight enough that one email fits every account in it.
  2. ☐ The person receiving the email owns the problem you’re naming.
  3. ☐ Every address is verified, with projected bounce rate under 2%.
  4. ☐ Every address is traceable to a legitimate source.

Stage 3 — Stand up the sending infrastructure

  1. ☐ Sending runs on secondary domains, never your primary one.
  2. ☐ SPF, DKIM, and DMARC pass on every sending domain, with DMARC aligned.
  3. ☐ Mailbox count covers your daily target at 20 to 30 sends each.
  4. ☐ Every mailbox has completed three to four weeks of warm-up.
  5. ☐ A seed test confirms primary-inbox placement across Gmail, Outlook, and a corporate domain.

Stage 4 — Write and time the sequence

  1. ☐ The subject line runs 36 to 50 characters and describes what’s inside.
  2. ☐ The first line is about the recipient and demonstrably researched.
  3. ☐ Personalization is deep enough that the email couldn’t go to anyone else.
  4. ☐ The body is under 80 words, carries one idea, and contains no links.
  5. ☐ There is exactly one low-friction ask.
  6. ☐ Four to seven touches are written and scheduled before launch.
  7. ☐ The first send is timed to a trigger event at the account.

Stage 5 — Clear compliance and instrumentation

  1. ☐ Headers, physical address, and opt-out meet CAN-SPAM, and non-US targets are routed to compliant channels.
  2. ☐ The pre-send QA pass is complete, with auto-stop on reply and unsubscribe confirmed.
  3. ☐ Reply, positive-reply, and meeting tracking are live before the first send.

Anything under 18 of 20 means the campaign is likely to underperform for reasons that have nothing to do with the copy, and the fix is cheaper now than after a domain is flagged.

Stage 1: Confirm the Channel Fits

Before any budget goes to domains or data, establish that cold email is the right channel for this business. It is a volume-and-repetition channel, and two variables decide whether that model works for you.

1. Confirm Cold Email Fits Your Market and Deal Economics

Cold email earns its place when your addressable market is large enough that volume matters and your contract value is high enough to absorb the cost of running it properly. That cost is real: secondary domains, several mailboxes, a verification budget, a sending platform, and four to six weeks before the first campaign can legitimately go out.

Users in Reddit and community discussions often ask how to make cold email work without spending on infrastructure first. The honest answer is that you usually can’t, and the arithmetic tells you whether it’s worth it. Two rough gates:

  • Market size. If your total addressable market is a few thousand accounts, cold email is a supporting channel rather than a primary one. There isn’t enough volume for reply-rate averages to produce a predictable number of meetings, and burning through the list with a mediocre first attempt costs you the whole market.
  • Deal economics. If average contract value is low and retention is short, the monthly cost of domains, mailboxes, data, and verification eats the return before the pipeline compounds.

Teams whose priority right now is brand awareness or inbound demand rather than direct sales conversations are usually better served starting elsewhere and adding outbound once there’s a defined ICP to aim at. Where the market is large and the deal size supports it, cold email remains one of the few channels that reaches a named buyer directly and on your schedule. Martal’s managed cold email services exist for exactly the case where the economics work but the internal capacity to run the infrastructure doesn’t.

Clear when: you can state your addressable account count and your average contract value, and both support repeated outreach at volume.

Stage 2: Build and Verify the List

Targeting and data decide most of the outcome, and they come before any infrastructure spend. A verified list aimed at the wrong person performs about as badly as an unverified list aimed at the right one.

2. Define the Segment One Email Can Serve

A usable segment is specific enough that one email can speak to everyone inside it. “Software companies” is a market. “Series A SaaS companies of 50 to 200 employees that just posted a RevOps role” is a segment. Against the first, you write two hundred emails. Against the second, you write one and change three details.

Build it from three layers, with the fourth handled separately in check 3:

  • Firmographics: company size, industry, revenue band, growth stage
  • Geography: which markets you’re targeting, and which you’re excluded from by channel rules
  • Psychographics: the pain the buyer already knows they have, the technology they already run

Narrow segments also make research cheaper. When everyone in a campaign shares a trigger, the same three facts personalize every message, which is what makes niche b2b cold email outreach sustainable at more than a handful of accounts.

Clear when: you could write one email that fits every account in the segment without editing more than three details per recipient.

3. Map the Buyer Who Owns the Problem

Identify who inside the account actually feels the problem, who controls the budget, and whether those are the same person. This layer gets skipped more than any other, and it produces a specific and confusing failure: a well-written email to a plausible-looking title that generates nothing.

Consider a message sent to a CEO about a reporting problem the operations manager owns. Nothing about the copy is wrong. The recipient simply has no reason to act, and no reason to forward it either, because forwarding it would mean explaining why a stranger emailed them about it.

Three questions resolve most of this:

  • Who lives with the consequence? That person replies. The person who merely approves the purchase usually doesn’t.
  • Is the problem owner senior enough to act? If not, you need a second contact at the account and a different message for them.
  • Would this person recognize the problem in your words? Job titles vary enormously between companies. The problem description has to survive that variation.

Where the buying committee is genuinely split, treat it as two segments rather than one, with qualification based on authority and need handled at the reply stage rather than assumed at the list stage.

Clear when: for every title on the list, you can name the consequence that person personally lives with.

4. Verify Every Address Within Days of Sending

Verification comes before segmentation, because a bounce costs more than a bad segment. Woodpecker’s data across 20 million-plus sales emails puts the average cold email bounce rate at 5.1%, with well-maintained lists holding under 2% and the best under 1.5% (Woodpecker). That gap is almost entirely list hygiene.

Work through:

  • Verify every address within a few days of sending. Contact data decays as people change roles, so a list checked last month is already partly stale.
  • Remove role-based addresses (info@, sales@, support@) that damage sender reputation and rarely reach a decision-maker.
  • Re-verify before every significant volume increase, not just at the start of a campaign.
  • Segment after verification, into groups small enough to share one message.

A note on volume and segment size: Woodpecker’s own campaign data shows reply rates falling as list size climbs, with a gap of roughly ten percentage points between campaigns aimed at a couple of hundred prospects and those aimed at a thousand or more. The mechanism isn’t mysterious. Smaller lists are easier to research, so the copy is better and the targeting is tighter.

Clear when: your verification tool projects a bounce rate under 2% on the exact list you’re about to send to.

5. Confirm Every Address Is Traceable to a Legitimate Source

Every address on the list should have a source you could describe out loud. Scraped databases and purchased lists carry spam traps, and a single trap hit can cost you a domain that took six weeks to warm.

A spam trap is an address planted by a mailbox provider or blocklist operator for exactly this purpose. It has never opted into anything and belongs to no real person, so mail arriving at it is proof that the sender is working from harvested data. There is no way to identify one by inspection, which is why provenance is the only defense.

What this looks like in practice:

  • Keep a record of where each segment came from. A named data provider, a verified export from a platform you licensed, or research your own team did are all defensible.
  • Treat “found in a shared spreadsheet” or “bought as a bundle” as disqualifying, however good the addresses look.
  • Drop entire batches rather than individual addresses when provenance is unclear, because trap density tends to cluster by source.
  • Keep suppression permanent. An address that unsubscribed or hard-bounced should never reappear through a later import.

This is also the check that protects you legally. Provenance is what lets you demonstrate a lawful basis for contact if anyone asks, which matters considerably more outside the US.

Clear when: you can name the source of every segment on the list, and no segment came from a scraped or resold database.

Stage 3: Stand Up the Sending Infrastructure

Infrastructure is the stage that takes real calendar time, so start it the day the segment is agreed. Authentication is now a precondition for delivery rather than a best practice, and warm-up cannot be compressed.

6. Move Sending Off Your Primary Domain

Never send cold email from the domain that carries your invoices, contracts, and support replies. Buy close variants of your primary domain, point them at your main site with a redirect, and send everything cold from those.

The reasoning is containment. Cold outreach generates complaints and bounces at rates normal business mail never does, and if a flagged domain is the one your finance team emails from, the cost of a bad campaign stops being a marketing problem. Recovering a burned primary domain can take months, and there is no way to rush it.

Set up:

  • Two to three secondary domains minimum, so a single flag doesn’t stop the program.
  • Redirects to your real site, so a prospect who types the domain into a browser lands somewhere legitimate rather than on a parked page.
  • Complete profile information on every mailbox: real name, real photo, real job title. Providers read incomplete profiles as a spam signal.
  • Separate domains per offer or market if you’re running more than one motion, so performance and reputation stay diagnosable.

Clear when: no cold email in the campaign will send from your primary domain, and every secondary domain resolves to your real site.

7. Authenticate With SPF, DKIM, and DMARC

All three records must pass on every sending domain, with DMARC aligned to at least one of the other two. Microsoft began requiring exactly this for domains sending more than 5,000 messages a day to its consumer addresses, first routing non-compliant mail to Junk and then refusing it with a 550 5.7.515 error (Microsoft). Google and Yahoo set the same expectations a year earlier.

Configure in week one, before anything sends:

  • SPF record. Lists the servers authorized to send for your domain.
  • DKIM signing. Verifies the message wasn’t altered in transit.
  • DMARC policy. Tells providers what to do when SPF or DKIM fails. Needs at least p=none, aligned with one of the other two.
  • One-click unsubscribe. Now expected on commercial mail by every major provider.

Configure in the first two to three weeks:

  • Reverse DNS (PTR). Resolves the sending IP back to its hostname.
  • Inbox rotation. Spreads volume so no single mailbox carries enough to get throttled.

Most cold email platforms handle rotation, warm-up scheduling, and per-mailbox caps natively, which is the main practical reason to run outbound through one rather than a standard marketing tool. What no platform does is fix a domain that was never authenticated. Check the DNS records first, then configure the tool.

Clear when: an authentication checker returns a pass on SPF, DKIM, and DMARC for every sending domain, with alignment confirmed.

8. Size Your Mailboxes Against Your Daily Volume

Work backward from your daily send target, capping each mailbox well below what it can technically handle. A common working model is two to three mailboxes per secondary domain, each capped in the range of 20 to 30 sends a day, which puts a 300-send-per-day campaign somewhere around four to six domains.

This is the arithmetic most guides skip, and most community threads ask about. Two rules hold across nearly every practitioner account:

  1. Cap per mailbox, not per domain. Providers throttle at the mailbox level, so distributing 200 sends across eight mailboxes reads very differently from 200 out of one.
  2. Add capacity before you need it. New domains need weeks of warm-up, so a domain bought the week you want to scale is a domain you can’t use.

Clear when: your daily target divided by your per-mailbox cap equals a number of mailboxes you actually have warmed and ready.

9. Warm Every Mailbox for Three to Four Weeks

Plan on three to four weeks minimum per new mailbox, and treat six as normal if you’re building several at once. Community reports have been consistent on this point for two years, and they run longer than most published guidance: start at five to ten sends a day, climb gradually, and keep the ramp steady rather than stepped.

Two things break a warm-up. Jumping volume sharply at the end of the schedule undoes the history you just built, and warming a mailbox while sending real campaigns from it mixes two very different engagement patterns. Plan the final week of warm-up to overlap with your intended starting volume, so the transition is invisible to providers.

Clear when: every mailbox in the rotation has a completed warm-up schedule and is sitting at your intended starting volume.

10. Confirm Placement With a Seed Test

Send the real first email to a set of your own addresses across different providers, then check where each copy landed. Delivery reports tell you a server accepted the message. Only a seed test tells you whether a human will see it.

Cover at minimum:

  • Gmail, both a consumer address and a Google Workspace one, since they filter differently.
  • Outlook.com and a Microsoft 365 tenant. Microsoft remains the hardest provider to reach and the most likely to route a technically valid message to Junk.
  • One corporate domain running a third-party security gateway, which is what a lot of your real prospects sit behind.

Read the result as a go or no-go rather than a score. Primary-inbox placement across all three means launch. Anything landing in Junk or Promotions means stop and diagnose, because the campaign is already failing and you haven’t spent the list yet. Check authentication first, then the message body for links and heavy HTML, then the domain’s age and warm-up history.

Run this again after any change to sending domains, authentication, or template structure. Placement is not a property you establish once.

Clear when: a seed test lands in the primary inbox on Gmail, Microsoft, and one corporate domain.

Stage 4: Write and Time the Sequence

Copy matters once the message reaches an inbox, and then it matters a great deal. What teams get wrong is the order they work in. A well-written email to a verified, tightly segmented list on an authenticated domain is the highest-return asset in outbound. The same email to unverified addresses from an unwarmed mailbox produces nothing measurable.

11. Write a Subject Line That Earns the Open

Aim for something short, specific, and honest about what’s inside. Woodpecker’s data puts the strongest response rates on subject lines of roughly 36 to 50 characters, which is also about what a mobile client displays before truncating.

What to do:

  • Reference something concrete: a role they’re hiring for, a market they just entered, a system they run.
  • Keep it plain. Sentence case reads like a colleague; title case reads like a campaign.
  • Avoid the phrases that now signal automation. “Quick question” and “thought this might help” were effective for years and are now pattern-matched by readers and filters alike.
  • Test three to five variants per campaign, and judge them on replies rather than opens.

The last point matters more than it used to. A subject line that lifts opens while depressing replies has usually promised something the email doesn’t deliver, and that mismatch is what damages a domain. A strong cold email subject line says what is actually inside the email, in fewer words than the reader expected.

Clear when: the subject line is under 50 characters and a colleague reading it could correctly guess the email’s contents.

12. Open With a Reason to Keep Reading

The first sentence should be about the recipient and demonstrably researched. A workable pattern names a specific observation, then connects it to a consequence they’d recognize: “You’ve posted three RevOps roles since January, which usually means reporting is being rebuilt by hand somewhere.”

What weakens an opening:

  • Flattery. “Love what you’re building” reads as a template because it is one.
  • Your own introduction. Nobody has agreed to care who you are yet.
  • Surface-level merge data. Company name and city prove nothing about research.

A strong cold email introduction earns the next two sentences, which is all it needs to do.

Clear when: the first sentence would be wrong if pasted into an email to any other account on the list.

13. Personalize Deep Enough That the Email Fits One Account

Personalize until the email couldn’t have been sent to anyone else. Woodpecker’s dataset puts deeply personalized outreach at roughly 17–18% reply rates against 7–9% for basic or absent personalization, close to double, driven entirely by the depth of research behind each message.

The 2026 complication is that AI has made shallow personalization cheap and abundant. Inboxes are full of messages that reference a company’s blog post without saying anything about it, and buyers have learned to spot the pattern. Three custom details drawn from something genuinely public and specific will outperform a paragraph of generated context. Effective cold email personalization is a research practice with a writing step at the end.

Keep it to information the recipient would expect a stranger to find. A funding round, a job posting, a product launch, or a conference talk all read as diligence. Details about their personal life read as surveillance.

Clear when: removing the personalized details would leave a sentence that no longer makes sense.

14. Make the Body Do One Job

Get to the point inside two or three sentences, and keep the whole message under roughly 80 words. Busy buyers read the first line and the last one, so structure accordingly:

  • One idea per email. A message arguing three things argues none of them.
  • Short paragraphs, plenty of white space, no images in the first touch.
  • Concrete proof over adjectives. A named outcome with a number beats any superlative.
  • No links in the first email. They suppress deliverability and give a hesitant reader something to click instead of reply.

A reusable cold email template helps with structure and hurts with substance, so treat one as a skeleton for the argument rather than a script. Templates that circulate widely get pattern-matched by filters and readers at roughly the same speed.

Clear when: the email is under 80 words, argues one thing, and contains no links or images.

15. Ask for One Low-Friction Next Step

One ask, phrased so that agreeing costs almost nothing. In most B2B contexts, a short exploratory conversation converts better than a demo request, because a demo implies evaluation and a conversation implies curiosity.

Formats that work:

  • “Worth a short conversation?”
  • “Would 15 minutes on Tuesday or Wednesday work?”
  • “Want me to send the two-line version?”

Formats that don’t: multi-step asks, calendar links in the first touch, and anything requiring the recipient to make three decisions before replying.

Clear when: the email contains exactly one question and replying to it takes one sentence.

16. Build the Follow-Up Sequence Before You Launch

Write and schedule every touch before the first email sends. Plan four to seven across two to four weeks. Woodpecker’s data shows sequences carrying follow-ups reply at 8.3% against 4.1% for one-touch sends, and that 48% of reps never send a second email, which means roughly half of outbound teams are leaving the larger half of their replies uncollected.

A five-touch shape that works across most B2B segments:

  • Email 1, day 1. Names the problem and why you’re writing to them specifically. Carries the trigger or observation.
  • Email 2, day 3 or 4. A short nudge that adds one new data point.
  • Email 3, day 7 or 8. Proof: a comparable outcome, a resource, something they can evaluate without a meeting.
  • Email 4, day 11 to 13. A new angle on a different problem the same buyer has.
  • Email 5, day 18 to 20. Closes the loop with a clean exit and an open door.

Two disciplines make this work. Vary the intervals, because identical spacing reads as automation. And give every touch new information: “just checking in” is the worst-performing follow-up phrasing in current data, because it announces that nothing has been added. A cold email follow-up that carries a fresh fact is a second attempt. One that repeats the ask is a reminder that you want something.

Past four follow-ups, complaint and unsubscribe risk rises faster than reply rate, which is where the community’s “two or three and stop” advice and the “five to seven” orthodoxy actually reconcile. Longer sequences work for high-value enterprise accounts with long buying cycles. Shorter ones are right for smaller deals, where a fifth email costs more in reputation than the reply is worth.

Clear when: every touch is written, scheduled, and adds information the previous one didn’t.

17. Time the First Send Around a Trigger Event

Send when something has just changed at the account. Mid-week mornings in the recipient’s timezone are a reasonable default, with Tuesday through Thursday outperforming Monday and Friday across most datasets, but treat that as a starting position and stop optimizing it after the first test, because the returns flatten fast. Avoid weekends and public holidays outright: a message landing Saturday gets read Monday alongside everything else, by which point the trigger that justified it has gone cold.

Trigger timing is where the leverage sits. A message that lands within a few days of a funding round, a leadership change, a new office, or a relevant job posting arrives when the problem is already on someone’s desk. Intent-based prospecting has doubled campaign conversion rates in Martal’s own programs compared with static-list outreach, which is why trigger definition now happens during segment work rather than after launch.

Practical version: define three to five triggers your buyer can’t ignore, monitor for them, and route matching accounts into a faster, tighter sequence than your baseline list.

Clear when: you can name the trigger behind the send, and it happened within the last few weeks.

Stage 5: Clear Compliance and Instrumentation

The last stage is the one teams postpone, and postponing it is what makes the first fortnight of data unusable. Both checks here take under an hour.

18. Meet CAN-SPAM, GDPR, and CASL Requirements

For US recipients, cold email is permitted without prior consent, subject to specific obligations. The FTC is explicit that CAN-SPAM makes no exception for business-to-business email, and that each separate violating message carries a civil penalty of up to $53,088 (FTC). The requirements are short:

  • Accurate “From,” “Reply-To,” and routing information
  • A subject line that reflects the content
  • Clear disclosure that the message is an advertisement
  • A valid physical postal address
  • A working opt-out honored within 10 business days

Canada works differently. Under CASL, a commercial electronic message requires prior consent (express or implied), identification information, and an unsubscribe mechanism, with the burden of proving consent falling on the sender (CRTC). The EU and UK apply their own consent and legitimate-interest tests under GDPR.

The practical consequence for anyone selling across borders: cold email is a US-market channel, and reaching EU, UK, or Canadian buyers means leading with phone and LinkedIn instead. Martal builds campaigns that way by default, routing each target market to the channels that are compliant there, which keeps a single program running across North America and Europe without a separate legal review per country. We state our position and move on: GDPR compliant, SOC II certified, CAN-SPAM compliant, and CASL-aware for Canadian targets.

Clear when: every email carries a physical address and a working opt-out, and no non-US contact is scheduled to receive cold email.

19. Run the Pre-Send QA Pass

Run a fixed check on every campaign before it goes out. This takes ten minutes and catches the errors that are unrecoverable once sent:

  • Send yourself the full sequence with real merge data and read it on a phone.
  • Confirm no merge field can render empty or wrong. “Hi,” ends a conversation immediately.
  • Turn off open tracking. The pixel injects HTML that filters dislike, and the data it returns is unreliable anyway. If your team insists on tracking, at least route it through a custom tracking domain on your own CNAME instead of the platform’s shared one, which carries every other sender’s reputation alongside yours.
  • Send plain text, or as close to it as the platform allows.
  • Score the draft in a spam-checking tool before launch. Mail-Tester and GlockApps both flag the authentication gaps, trigger words, and formatting problems that a seed test alone won’t surface.
  • Confirm the sequence auto-stops on reply and on unsubscribe. Following up on somebody who already answered is the fastest way to turn a warm reply cold, and continuing to mail an unsubscribe is a compliance failure rather than an oversight.
  • Check the unsubscribe mechanism actually works, from a live send.

Clear when: you have read the full sequence on a phone, the spam score is clean, and auto-stop is confirmed on both reply and unsubscribe.

20. Turn On Reply and Meeting Tracking Before the First Send

Instrument the campaign before it launches, because the first fortnight is the data you most want and the only window you cannot recreate. Three things need to be recording from the first send: replies, replies sorted by sentiment, and meetings booked.

Set up:

  • Reply capture by sequence step, so you can see which touch starts conversations rather than only that some do.
  • A sentiment split separating genuine interest from unsubscribes, referrals, and “wrong person” responses. Without it, a 9% reply rate can look identical to a 3% one.
  • Meeting attribution back to the campaign and segment, so a booked meeting is traceable to the list that produced it.
  • UTM parameters on any link that appears deeper in the sequence, so the meetings the campaign produces are traceable in whatever CRM your team already runs. Untagged cold email lands in “direct” traffic and gets credited to nobody, which is how a channel that works quietly loses its funding.

One clarification worth making internally: prospects engaged is a volume figure, not a result. Report prospects reached, MQLs, SQLs, and booked meetings as separate stages so the conversion between them stays visible.

Clear when: you could answer “how many positive replies did step two produce” on day three of the campaign.

After Launch: Reading the Numbers and Scaling

The 20 checks get a campaign safely out the door. What follows is the ongoing work, and none of it is a pre-send gate.

Protect Your Sender Reputation

Watch three numbers, and treat the first as a hard ceiling. Google asks bulk senders to hold user-reported spam below 0.1% and never reach 0.3%, calculates it daily, and restores mitigation eligibility only after seven consecutive days back under the threshold (Google).

  • Spam complaint rate: target under 0.1%. At 0.3%, you are already in enforcement.
  • Bounce rate: under 2%. Above that, list quality is actively damaging reputation.
  • Engagement: measured on replies, since providers weigh real interaction and an open can be machine-generated.

Placement itself has improved industry-wide. Validity’s Email Deliverability Benchmark Report, drawn from trillions of inbox data points, found global inbox placement rose through 2025 to roughly 87%, with Microsoft still the toughest provider to reach (Validity). The practical reading: even a well-run program should expect a meaningful share of messages never to be seen, and a Microsoft-heavy list needs more infrastructure headroom than a Gmail-heavy one.

The line between cold email vs. spam is drawn by these numbers rather than by intent. A relevant message to a researched buyer with a working opt-out generates almost no complaints. A generic one to a scraped list generates enough to trip a threshold, whatever the sender meant by it.

Measure Reply Rate and Meetings Booked

Track reply rate, positive reply rate, and meetings booked. Those three describe whether a campaign is working. Open rate no longer does: Apple Mail Privacy Protection pre-loads tracking pixels and accounts for close to half of all recorded opens, which makes a rising open rate compatible with a campaign that nobody has read.

The six numbers worth a weekly look, with the range to aim for and what each one actually tells you:

  • Reply rate. 5% and up is solid, 10% and up is strong. Tells you whether the message and the list match.
  • Positive reply rate. Roughly 1–2% of sends. Tells you whether those replies are interest or friction.
  • Meetings booked. Roughly 0.5–2% of sends. Tells you whether the CTA converts the interest you earned.
  • Bounce rate. Under 2%. Tells you about list quality, and nothing else moves faster when data goes stale.
  • Spam complaints. Under 0.1%. Tells you how much reputation risk you’re carrying.
  • Cost per booked meeting. Should fall over time. Tells you whether the program is compounding or just running.

For fuller benchmark context on any of these, our b2b cold email statistics page tracks the underlying numbers as they move.

Cost per booked meeting is the metric that survives contact with a CFO. Calculate it as total program spend divided by meetings booked, including data, domains, tooling, and time, then track its direction rather than its absolute value. The right cold email metrics for a $200,000 contract look nothing like the right ones for a $6,000 one.

Test One Variable at a Time

Test one variable at a time, on segments large enough to mean something. A hundred recipients per variant is a workable floor for reply-rate comparison; below that you’re reading noise.

Sequence the tests by leverage: targeting first, then the opening line, then the subject line, then the CTA, then send timing. That order surprises teams who expect subject lines to lead, but the ceiling on a subject-line test is how many people open. Targeting sets the ceiling on how many of them had a reason to reply.

Sequence Email With Calls and LinkedIn

Cold email works better inside a coordinated sequence than on its own. After the second or third email, a LinkedIn touch on the same account gives a hesitant buyer a lower-commitment way to respond, and a call gives them a faster one. The coordination is the point: the channels reference the same context and follow one order, rather than three teams contacting the same person about three things.

Martal runs cold emailing, cold calling, and LinkedIn lead generation as one sequenced motion inside tiered packages for this reason. It also prevents a common waste in outbound programs, where an account that would have answered the phone gets written off after four unanswered emails. Running the channels together this way shortens the sales cycle, because a buyer who stalls in one channel can keep moving in another.

Honor Opt-Outs and Retire Dead Addresses

Beyond the statutes, a few habits protect the asset you’re building:

  • Honor opt-outs immediately rather than within the legal window.
  • Suppress across every campaign, not just the one that generated the request.
  • Keep research to information the recipient would expect a stranger to find.
  • Retire an address after a sequence completes without engagement. Re-approaching the same person quarterly turns a neutral contact into a complaint.

Scale Only After the Numbers Hold

Scale when reply rate, positive reply rate, and meetings booked have held steady across two full sequence cycles. One strong week is variance. Then move in increments:

  • Raise volume by no more than about 25% a week
  • Add domains before you need the capacity, so warm-up is finished when you do
  • Watch bounce and complaint rates daily through the ramp, weekly afterward
  • Re-verify the list before each significant volume increase

If reply rate falls as volume rises, the constraint is segment quality: you’ve exhausted the accounts that fit and started emailing ones that don’t. That looks like a scale problem and behaves like a targeting one, so adding domains and mailboxes will not move it.

Decide Between Building In-House and Outsourcing

Building in-house gives you control and costs you time. A functioning cold email operation needs someone who owns deliverability, someone who owns data, and someone who writes, plus four to six weeks of infrastructure work before the first campaign. Working with a cold email lead generation agency trades some control for a running start, since the domains, warm-up, verification, and platform already exist.

The pilot is what makes the decision cheap. Complete EDI, an EDI solutions provider in South Carolina, tested outbound with Martal using a single fractional Sales Executive across a three-month pilot targeting operations and IT leaders in manufacturing, logistics, and healthcare. The first two SQLs landed in week two, and the pilot closed with 14 SQLs before the engagement expanded. What made that work at small scale was the prioritization rather than the volume: one rep working a precisely defined segment, with qualification based on authority and need before anything reached the client’s calendar.

Either route can work. The question worth answering first is whether your constraint is expertise, capacity, or speed, because those point in different directions.

Common Pitfalls and How to Avoid Them

Stop Treating Volume as a Strategy

Sending 10,000 generic emails reliably produces worse results than 500 researched ones, and it costs you the domain as well. The correction is structural rather than motivational: build segments small enough to research, cap campaign size at what you can personalize, and measure replies per hundred sent rather than replies in total.

Users in Reddit and community discussions often ask how to keep volume high without personalizing each message. Most of the workable answers are the same idea from different angles: personalize the segment rather than the individual. When every account in a campaign shares a trigger, three sentences of shared context do the work of individual research.

Never Stop After One Email

Roughly half of outbound reps never send a second message, which means the follow-up sequence is the cheapest available improvement for most teams. Build the sequence before launching the campaign, and make every touch a scheduled part of it rather than a decision someone has to remember to make.

Well-built cold email sequences read as a conversation progressing rather than a series of requests. The test is whether each message would make sense if the recipient had never seen the previous one, while still adding something to it.

Diagnose the Right Problem First

When replies stop, three very different failures look identical from the outside. Separate them before changing anything:

  • High bounces and few opens point at data or authentication. Check verification first, then SPF, DKIM, DMARC, then domain reputation.
  • Opens look normal, but nobody replies points at targeting or message. Check ICP fit and buyer mapping before you touch the opening line.
  • Only one email ever went out is not a performance problem at all. Check whether a sequence was built.

An unusually high open rate with no replies usually points at the first row rather than the second, since filter pre-fetching inflates opens on exactly the domains where placement is worst. Check bounce rate first. It’s the fastest signal on the page, and effective cold email campaigns are usually the ones where somebody checked it weekly.

Conclusion: Work the Sequence in Order

Cold email still reaches buyers who ignore every other channel, and it still fails for the same reasons it failed two years ago, with less margin for error now that authentication is enforced, and open rate has stopped being informative. The order is what a checklist protects: confirm the channel fits, define a segment tight enough to write to, verify the data, authenticate and warm the infrastructure, then write. Measure replies and meetings rather than opens, and scale only once those numbers hold.

If your team has the segment and the message but not the domains, the warm-up time, or the deliverability expertise to run it properly, that’s the gap our cold email programs are built to close inside an omnichannel motion across email, phone, and LinkedIn. Book a consultation, and we’ll walk through what your current setup would need before launch.

FAQs: Cold Email Campaign Checklist

Rachana Pallikaraki
Rachana Pallikaraki
Marketing Specialist at Martal Group