Cold Email vs Spam in 2026: The New Rules of Deliverability & Compliance
Major Takeaways: Cold Email vs Spam
Consent and scale, not tone or effort. The definition blocklist operators use is unsolicited bulk email, so a polished, personalized message still counts as spam if it went to a list that never agreed to receive it.
Twice over. Gmail began issuing temporary and permanent rejections for non-compliant bulk traffic in November 2025, and Microsoft started refusing unauthenticated bulk mail to Outlook addresses in May 2025.
In the United States, yes. CAN-SPAM permits commercial email without prior consent, and the Federal Trade Commission states that the law makes no exception for business-to-business mail, so every requirement applies to B2B outreach.
In November 2025, M3AAWG, whose members include Google, Microsoft, Apple and Yahoo, published a position naming deceptive delivery as abusive: lookalike domains, extra sending accounts used to dodge volume limits, and artificially simulated engagement.
Your spam complaint rate. Google sets 0.1% as the working target and 0.3% as the ceiling, and crossing it costs you access to mitigation until you hold below 0.3% for seven consecutive days.
Because relevance is judged by the recipient, not the sender. In Hunter’s survey of decision-makers alongside an analysis of 11 million cold emails, 71% said they ignore cold email because it does not address a problem they actually have.
Just under half of all email. Kaspersky’s telemetry put spam at 44.99% of global email traffic in 2025, which is the volume every legitimate sender is now filtered against.
Bad data. Purchased and scraped lists carry spam traps and dead addresses, and the resulting bounces and complaints damage domain reputation faster than any subject line can repair it.
Introduction
Most B2B teams discover they crossed from outreach into spam only after the damage lands. Reply rates flatten, a sending domain quietly stops delivering, and nobody can name the message that caused it.
Cold email remains one of the most direct routes into a buying committee, which is why the boundary matters commercially and not only ethically. Having run outbound for 2,000+ B2B brands over 16+ years, we see the same pattern repeat: programs rarely fail on copy. They fail on consent, data quality, and sending infrastructure.
Two shifts moved the ground under everyone in 2026. Mailbox providers went from quietly filtering non-compliant senders to rejecting them outright, and the organizations that maintain the blocklists published formal positions treating most modern cold outreach as spam. Neither change makes cold email illegal. Both change what a program has to look like to survive.
The line sits in three different places depending on who is judging: regulators, mailbox providers, and recipients. Each applies a different test, and a sustainable program has to pass all three.
Cold Email vs Spam: The Short Answer
- Cold email and spam are separated by consent and bulk, not by tone or effort, because the industry-standard definition of spam is unsolicited bulk email, which turns on permission rather than content (Spamhaus).
- Cold email is legal in the United States under CAN-SPAM without prior opt-in, provided the message carries accurate headers, a valid physical address, and a working opt-out that you honor within 10 business days (Federal Trade Commission).
- Legality does not guarantee delivery, because Gmail, Yahoo, Outlook and Apple apply their own thresholds, and a user-reported spam rate at or above 0.3% damages inbox placement regardless of compliance (Google).
- A cold email crosses into spam operationally when it is sent in bulk to unverified recipients, masks its origin behind lookalike domains or extra sending accounts, or relies on faked engagement to pass filters (M3AAWG).
- The practical dividing line is data quality and relevance, since 71% of decision-makers say they ignore cold email because it does not address a problem they have (Hunter).
What Changed Going Into 2026
November 2025: Gmail ended the grace period. Google’s sender guidelines confirm that enforcement ramped up on non-compliant bulk traffic, with messages facing temporary rate limiting and permanent rejections instead of quiet filtering. The requirements have not changed since February 2024. The consequences have (Google).
May 5, 2025: Microsoft moved from junking to rejecting. Domains sending more than 5,000 messages a day to Outlook.com, Hotmail.com and Live.com addresses must pass SPF, DKIM and DMARC, or the message is refused outright with a 550 5.7.515 access-denied error (Microsoft).
November 2025: the anti-abuse industry took a formal position. M3AAWG published its Position on Cold Email, naming deceptive delivery methods as abusive and stating that consent given for one channel does not transfer to another (M3AAWG).
June 2025: Spamhaus published its definition. The blocklist operator set out its view that cold emailing as currently practiced is spam under the unsolicited-bulk-email standard, and said it will assess bulk cold outreach hitting its spamtraps as a candidate for listing (Spamhaus).
2025 volume context: spam averaged 44.99% of all global email traffic, so every legitimate sender is being judged against a background of roughly one junk message for every real one (Kaspersky).
Terms Worth Knowing
- Unsolicited bulk email (UBE) is the industry-standard definition of spam: mail sent without verifiable permission, as part of a batch of substantively identical messages.
- Sender reputation is the score mailbox providers assign a domain and IP based on authentication, complaint rates, bounces, and recipient engagement.
- Spam complaint rate is the share of delivered messages that recipients manually report as spam.
- One-click unsubscribe is an opt-out carried in the message headers under RFC 8058, rather than only as a link in the body.
- Spam trap is an address maintained by a provider or blocklist that should never legitimately receive mail, so hitting one signals a scraped or stale list.
- Lookalike domain is a domain registered to resemble a legitimate one while being unrelated to it.
- Blocklist is a maintained list of domains and IP addresses that receiving mail servers consult before accepting a connection.
- Implied consent is permission inferred from an existing business relationship or a conspicuously published business address rather than from an explicit opt-in.
What’s the Difference Between Cold Email and Spam?
Cold email is targeted business outreach sent to a specific person for a defensible reason. Spam is unsolicited mail sent in bulk with substantively identical content and no permission. The separation is consent and scale, not polish. A carefully written, personalized message sent to five thousand scraped addresses is still spam under the definition mailbox providers apply.
That definition has an operational consequence. Teams running cold email outreach services at any real volume cannot fix the problem in the copy layer, because everything being judged sits upstream of the copy: who is on the list, how they got there, and whether the sending setup is honest about who stands behind it. Managed cold email campaigns that hold up over several years treat those three as one system rather than three separate checkboxes.
Here is how the two compare across the dimensions that filters and recipients actually weigh:
- Intent and targeting. Cold email: a specific business reason, aimed at a named person or role. Spam: volume-first sending where the recipient’s identity is beside the point.
- Value to the recipient. Cold email: addresses a problem the recipient plausibly has. Spam: promotes the sender’s offer with no reference to the reader’s situation.
- Personalization. Cold email: built from real details such as a company’s tech stack, funding round, hiring pattern, or recent announcement. Spam: merge tags, broken fields, or generated variation that changes the wording without changing the relevance.
- Sender identity. Cold email: a real person at a real company, sending from a domain that plainly belongs to that company. Spam: obscured or spoofed headers, throwaway domains, free webmail accounts.
- Consent and opt-out. Cold email: a working opt-out honored quickly, plus a defensible legal basis in the recipient’s jurisdiction. Spam: no opt-out, or one that quietly fails.
- Infrastructure. Cold email: authenticated domain, gradual volume ramp, monitored reputation. Spam: unauthenticated senders, sudden blasts, rotating domains.
- Reputation outcome. Cold email: complaint rates comfortably under 0.1% and stable inbox placement. Spam: complaints, bounces, and blocklisting.
When does a cold email become spam?
A cold email becomes spam when it is sent in bulk without permission, offers nothing relevant to the person receiving it, hides where it came from, or provides no working way to opt out. Any one of those is enough on its own. Bulk blasts to unverified lists, misleading subject lines, and ignored unsubscribe requests all push a message across the line, whatever the sender intended.
Intent counts for less than most senders assume, because the judgment is made by two parties who cannot see it. Filters see sending patterns. Recipients see whether the message speaks to something real. Hunter’s research is blunt on that second point: across a survey of decision-makers paired with an analysis of 11 million cold emails, 71% said they do not reply to cold email because it fails to address a relevant problem. Relevance is not a nicety layered on top of a campaign. It is the thing being measured.
Cold Email vs Direct Email Marketing vs Transactional Email
Three kinds of business email get confused with each other, and the difference decides which rules apply to you. Cold email goes to someone with no prior relationship. Direct email marketing, sometimes called direct e-mailing, goes in bulk to a list that opted in. Transactional email is triggered by something the recipient already did.
Spamhaus’s own definition is more precise than its headline suggests, and the precision is useful here. Spam requires two conditions at once: a message must be both unsolicited and bulk. Unsolicited mail that is not bulk, such as a first-contact enquiry or a sales enquiry, is described as normal email. Bulk mail that is solicited, such as a subscriber newsletter, is also normal email. Only the overlap qualifies.
That gives you two axes rather than one label:
- Direct email marketing is bulk but solicited. Recipients opted in, the content is substantively identical across the list, and an unsubscribe is mandatory. CAN-SPAM treats it as commercial email, so the full requirement set applies: honest headers, a physical address, a working opt-out. Consent is what keeps it off the spam side of the line.
- Transactional email is neither. A password reset, an order confirmation, a booking change: each is triggered by an action the recipient took, and each is unique to them. The FTC classes these as transactional-or-relationship messages, exempt from most CAN-SPAM requirements though still bound to truthful routing information. Borderline cases turn on the primary-purpose test, so a receipt with a promotion stapled to the top counts as a commercial message rather than a transactional one.
- Cold email is unsolicited by definition, and its position on the bulk axis is a choice. A genuinely individual message, researched and written for one person, is unsolicited but not bulk, which is the space Spamhaus itself describes as normal email. The same message templated and pushed to five thousand addresses is both.
That last point is the practical one, and it is the strongest available answer to the argument that all cold outreach is spam. Consent is fixed. Cold email is unsolicited, and no amount of care changes that. Bulk is the variable a sender actually controls. A program that keeps volume genuinely low and messages genuinely distinct operates inside a category the anti-spam community treats as legitimate. A program sending identical content at scale has moved into the other one, whatever it calls itself.
Is Cold Email Spam? What Spamhaus and M3AAWG Actually Say
Under the definition used by the organizations that maintain email blocklists, most cold email is spam. Spamhaus put this in writing in June 2025, arguing that cold emailing as it is practiced today meets the unsolicited-bulk-email standard, where “unsolicited” means no verifiable permission and “bulk” means the message is one of a batch of substantively identical sends. By that standard, consent decides the question and content does not.
This is uncomfortable reading for anyone running outbound, and it is worth taking seriously rather than arguing around. Spamhaus is not a commentator. It maintains lists that receiving mail servers consult before deciding whether to accept a connection at all.
Three tests, three different answers
The reason the cold email debate stays unresolved is that people arguing about it are usually applying different tests without saying so.
- The legal test asks whether a message satisfies the rules of the recipient’s jurisdiction. In the United States, CAN-SPAM answers yes to cold email without prior consent, provided the specific requirements are met.
- The deliverability test asks whether mailbox providers will accept the mail. Google, Microsoft, Yahoo and Apple set authentication requirements and complaint thresholds as private companies. They are under no obligation to deliver anything, and their thresholds are not written by legislators.
- The acceptability test asks whether the anti-abuse community treats the sending pattern as legitimate. Spamhaus and M3AAWG answer that one, and their answer determines whether a domain ends up on a list that other servers check.
A program can pass the first test cleanly and fail the other two. In practice, that is the most common failure mode we see in outbound: a team invests in legal review, confirms it is CAN-SPAM compliant, and then loses a domain anyway because the sending pattern looked like evasion.
What M3AAWG named as abusive in November 2025
M3AAWG is the industry body whose membership includes the largest mailbox providers on the planet. Its Position on Cold Email is narrower than the Spamhaus piece and, for that reason, more useful to a compliant sender: it targets deception rather than outreach itself.
The practices it names as violating M3AAWG’s values are specific:
- Lookalike domains, meaning domains registered to resemble a legitimate one while being unrelated to it
- Multiple sending accounts used to bypass mail volume limits
- Artificially simulating subscriber engagement to train filters
- Tools and services that exploit loopholes in mailbox providers or cloud platforms
- Masking sending domains to avoid spam filter detection
The document also settles a question that came up constantly in outbound teams: consent is not transferable between channels. Permission to call someone is not permission to email them.
Two of those practices sat inside mainstream cold email playbooks as recently as last year. Cousin domains and engagement-simulating warm-up networks were widely recommended, including in earlier versions of this guide. They are now named liabilities, and the correction matters more than the embarrassment.
Where that leaves compliant B2B senders
The line that both organizations draw is around deception and scale, which leaves genuine room for outreach that does neither. That means narrow lists rather than broad ones, transparent sending identity, real engagement instead of manufactured engagement, and a volume that a human sender could plausibly stand behind.
It also argues for narrower targeting than most teams start with. Niche B2B cold email outreach, aimed at a defined segment where the problem being raised is specific and verifiable, sits comfortably on the safe side of the line. Broad market sweeps do not, and no amount of generated variation changes that.
What Sales Teams and Email Admins Actually Argue About
The cold email debate runs hot in practitioner communities, and most of the heat comes from two groups applying different tests without noticing. Sales teams ask whether the outreach is useful. Deliverability admins ask whether the recipient agreed to it. Both are reasonable questions. They are not the same question.
Four arguments recur across outbound and email marketing communities on Reddit, LinkedIn, Quora and industry forums:
“Does the value I provide make it not spam?” The most common defense, usually phrased as some version of it depends on the value you are giving people. The counter from the deliverability side is blunt: you cannot know what a stranger values by looking at their email address, and the standard definition turns on consent rather than on the sender’s own assessment of usefulness. For deliverability purposes the second view wins, because the measurement is the complaint rate and the recipient does the measuring.
“Is this a copy problem or an infrastructure problem?” Sales threads argue about subject lines. Email admins point at DNS records. The evidence favors the admins. Rewriting a subject line will not repair a missing DMARC record or a 6% bounce rate, and the working order is authentication first, list quality second, copy third.
“How many domains can I run?” Domain rotation math circulated for years, with rules of thumb for how many domains a given daily volume requires. That advice aged badly. Running extra domains and sending accounts specifically to spread volume past provider limits is exactly what M3AAWG names as deceptive, which turns the old math into a liability.
“Is buying a list automatically spam?” Someone raises it in every thread, and someone else reports getting burned. A maintained, verified B2B database and a scraped CSV are genuinely different products with different bounce profiles. What gets missed is that neither creates consent. Data quality and permission are separate questions, and better data only answers the first.
Underneath all four sits the same question, usually asked as some version of how do we run cold outreach at scale without being treated as spammers. The honest answer is that scale is the part causing the problem. Everything else on the list follows from it.
The 2026 Deliverability Landscape: What Mailbox Providers Now Enforce
Email deliverability is now decided by a combination of authentication, engagement history, and complaint rates, and providers enforce all three automatically. The pressure behind that enforcement is sheer volume: spam made up 44.99% of global email traffic in 2025, according to Kaspersky’s telemetry, so filters are calibrated for a world where roughly every second message is unwanted. Content still matters, but it matters last. A message with excellent copy from an unauthenticated domain will not reach an inbox to be judged on its copy.
Authentication became a rejection condition
SPF, DKIM and DMARC moved from best practice to gatekeeping. Google’s email sender guidelines confirm that starting in November 2025, Gmail ramped up enforcement against non-compliant traffic, with disruptions including both temporary and permanent rejections. The underlying requirements have been in place since February 2024. What changed is that the grace period ended.
Microsoft moved in the same direction earlier. Microsoft’s requirements for high-volume senders took effect on May 5, 2025, and Outlook now rejects rather than junks messages from domains sending more than 5,000 emails per day to Outlook.com, Hotmail.com and Live.com addresses without passing all three authentication checks. Rejected mail returns a 550 5.7.515 access-denied response, which is unambiguous but arrives too late to help.
Both providers apply the same thresholds to mail sent through a third-party platform, because authentication is tied to your domain rather than to the sending service. Outsourcing the send does not outsource the DNS records.
Engagement signals set your sender reputation
Modern filters weigh how recipients behave far more heavily than what a message says. Opens, replies, deletions without reading, and manual spam reports all feed a reputation score attached to your domain.
The complaint rate is the metric with a hard number attached. Google’s guidance sets 0.1% as the level a stable sender should hold and 0.3% as the point where deliverability breaks, and a sender who crosses 0.3% loses access to mitigation support until the rate stays below that line for seven consecutive days. At 0.1%, that is one complaint per thousand delivered messages. It is a smaller margin than most teams plan for.
Low engagement carries its own penalty. Sending repeatedly to people who never open or reply tells providers the mail is unwanted, even when nobody reports it.
Volume and sending patterns
How much you send, and how evenly, is read as a signal in itself. Sending several thousand messages from a domain with no history is the clearest possible flag, which is why gradual volume ramping is standard rather than optional. Community consensus among practitioners has been pushing warm-up periods longer, toward four to six weeks rather than the ten days that circulated a few years ago.
Predictable machine-like patterns also read poorly. Identical volumes at identical times, day after day, look automated because they are. Varying send windows and daily volumes within sensible limits reads more like a person working through a list.
Domain strategy after the lookalike crackdown
Protecting your primary corporate domain is still sound, but the method has changed. The approach that was widely recommended, registering a separate domain that resembles your company’s real one, is exactly what M3AAWG now names as deceptive. Registering yourcompany-outreach.com to send mail on behalf of yourcompany.com fits that description whether or not you intended deception.
The defensible version is a subdomain of the domain you already own, such as sales.yourcompany.com, where the relationship is transparent to anyone inspecting the headers. Ownership is verifiable, reputation is contained, and nothing about the setup is trying to look like something it is not.
What is no longer defensible is domain rotation as a strategy: spinning up new domains, burning them, and moving on. Providers correlate this, and both M3AAWG and Spamhaus name it directly. Building reputation on one domain you can actually maintain is now the cheaper path.
Monitoring is the other half of this. Google Postmaster Tools shows your domain reputation as Gmail sees it, and blocklist checks catch listings before they compound. A dedicated platform like Warmy warms the sending domain and monitors sender reputation continuously across major mailbox providers, so reputation drops get caught before they translate into a campaign-wide deliverability hit.
Omnichannel outreach changes inbox perception
Combining email with LinkedIn touches and calls does not directly affect filtering, but it changes how a message is received, and reception feeds back into complaint rates. A prospect who has seen a connection request or taken a call is far less likely to treat the follow-up email as an intrusion.
This is the logic behind running cold email inside a sequenced omnichannel motion rather than as a standalone channel. Our campaigns coordinate email with cold calling and LinkedIn outreach so that no single channel carries the entire burden of introduction, which keeps per-channel volume low enough to stay well inside provider thresholds.
What are the biggest deliverability risks for cold email campaigns?
The failures that damage sender reputation are consistent and mostly preventable:
- Sending from a new or unauthenticated domain
- Using purchased, scraped, or unverified lists
- Bounce rates above 2% or complaint rates approaching 0.3%
- Ignoring or slow-walking opt-out requests
- Design-heavy templates, excessive links, or obvious sales language
- Rotating domains or extra sending accounts to work around volume limits
Any one of these will cost you inbox placement. Two or three together will cost you the domain.
Cold Email Compliance: Laws and Regulations You Must Know
Cold email is governed by different rules in every major market, and the differences are large enough that a single global campaign template will break the law somewhere. The United States permits cold outreach without consent. Canada effectively requires it. The EU and UK sit between the two, with a narrower allowance for business-to-business contact.
Is cold emailing legal?
Yes, in many countries, provided it is done properly. In the United States, cold email is permitted under CAN-SPAM as long as the message identifies the sender accurately, includes a physical address and a functioning opt-out, and does not mislead. Canada and most EU member states require consent or a documented legitimate interest, which makes pure cold prospecting considerably harder.
United States: the CAN-SPAM Act
Cold email is legal in the US without prior opt-in, and the rules are short enough to work through in an afternoon. The FTC’s compliance guide sets out the requirements, and it closes one loophole senders often assume exists: the law makes no exception for business-to-business email.
What the Act requires:
- Accurate header information. Your From, To, Reply-To and routing details must identify the real sender.
- Honest subject lines. The subject must reflect the content. Writing “Re: our conversation” to someone you have never spoken to is a violation, not a tactic.
- Identification as an advertisement. The message must disclose clearly that it is a commercial solicitation.
- A valid physical postal address. A street address, registered PO box, or a private mailbox registered with a commercial mail receiving agency.
- A working opt-out. It must function for at least 30 days after the send, cost nothing, and require no more than a reply or a single web page visit.
- Opt-outs honored within 10 business days. After that, you cannot email them, and you cannot sell or transfer their address.
- Responsibility for third parties. Hiring an agency or platform to send does not transfer liability. Both parties can be held responsible.
Penalties are assessed per message rather than per campaign, at up to $53,088 per non-compliant email under the FTC’s inflation adjustment effective January 17, 2025. Enforcement is real rather than theoretical, and the practical exposure sits well below the theoretical maximum, but the per-email structure gives regulators considerable leverage in any settlement.
European Union and the UK: GDPR and ePrivacy
In Europe, two frameworks apply at once, and passing one does not satisfy the other.
GDPR governs how you obtain, store and use personal data, and a work email address qualifies as personal data because it identifies an individual. You need a lawful basis to process it, and for outreach that basis is normally consent or legitimate interest. Legitimate interest is available for B2B contact in many member states, but it is a documented justification rather than a label: you have to be able to explain why the message is relevant to the person’s job and why receiving it would not surprise them. GDPR also gives individuals the right to ask how you obtained their data and to object to further processing.
The ePrivacy Directive, implemented as PECR in the UK and equivalent laws elsewhere, governs electronic communications specifically. It generally requires opt-in consent for unsolicited email to individuals, while many countries carve out a softer position for corporate addresses. The UK’s PECR, for example, permits B2B cold email to company addresses without prior consent, provided the message is relevant to the recipient’s role and carries an opt-out.
Penalties sit in the tier structure of GDPR Article 83, where the upper band reaches €20 million or 4% of global annual turnover, whichever is higher. Marketing-specific enforcement typically lands far lower, in the tens or hundreds of thousands, but the exposure is structural rather than nominal.
The practical approach for EU and UK targets is narrow, defensible, role-relevant B2B outreach with an opt-out in every message and a suppression list that is actually maintained.
Canada: CASL
Canada’s Anti-Spam Legislation is the strictest of the three regimes, and it inverts the American default. CASL requires consent, express or implied, before you send commercial email to a Canadian recipient.
Express consent means the person actively agreed. Implied consent covers a narrower set of situations: an existing business relationship, or a business address published conspicuously without a statement refusing unsolicited mail, where your message relates to the person’s role. Cold prospecting into a purchased Canadian list falls outside both.
CASL also requires clear sender identification and an unsubscribe mechanism honored within 10 business days, and it is worth keeping records of when and how consent was obtained. As law firm Borden Ladner Gervais sets out in its review of CASL enforcement, penalties reach up to $1 million CAD per violation for individuals and $10 million for organizations, and the Canadian regulator has issued multi-million dollar penalties in practice.
Because of this, many teams reach Canadian prospects through calls and LinkedIn outreach first and reserve email for contacts who have engaged. That constraint shapes campaign design more than it limits it. Working with Berger-Levrault, a France-based HR and ERP software provider entering North America, we built outbound sequences into both the US and Canada using email, calls and LinkedIn in combination, with channel mix varying by jurisdiction. The program delivered over 85 MQLs a month and 12 sales-ready leads, five of which produced tangible traction and two of which were significant enough on their own to justify the full campaign investment.
How do you obtain permission or “implied consent” for cold emailing?
Implied consent generally exists where you have a prior business relationship, or where the contact’s email was published publicly for business purposes without a notice refusing unsolicited mail, and your message genuinely relates to their role. Express consent means the recipient opted in directly, usually through a form or a documented agreement. Where a jurisdiction requires consent and you cannot demonstrate either, the safer route is a different channel.
Other regions
Most other markets lean toward opt-in. Australia’s Spam Act requires consent with no general B2B exception, and New Zealand and much of Asia-Pacific take similar positions. When you are sending internationally, applying the strictest common standard across all campaigns is simpler than maintaining separate rulesets: identify yourself, include an opt-out in every message, and make sure the content is defensibly relevant to the recipient’s job.
This section is general information rather than legal advice. Consult a qualified professional for compliance decisions in your markets.
What Key Best Practices Help a Cold Email Avoid Spam Filters?
Reaching the inbox in 2026 comes down to five things in order: authenticated infrastructure, clean data, genuine relevance, controlled sending, and fast opt-out handling. Copy sits fourth on that list, which surprises most teams. Working through them as a cold email campaign checklist before launch prevents more damage than any amount of optimization afterward.
1. Build sending infrastructure that tells the truth
Set the technical foundation before the first campaign, and set it up so that anyone inspecting it sees exactly what is happening.
- Use a subdomain of your real domain. Send from something like sales.yourcompany.com rather than a separately registered lookalike. Reputation stays contained, and the relationship to your business is verifiable.
- Implement SPF, DKIM and DMARC properly. SPF lists which servers may send for your domain, DKIM signs messages so tampering is detectable, and DMARC tells receivers how to handle mail that fails. Publish DMARC at a minimum policy of p=none and make sure alignment passes. Watch the ten-lookup limit on SPF records, which fails silently when exceeded.
- Ramp volume gradually. Start at 20 to 50 messages a day and increase steadily over four to six weeks, watching bounce and complaint rates as you go. Avoid warm-up services that simulate opens and replies. M3AAWG names artificial engagement simulation as particularly egregious, and it is the kind of signal providers have become good at detecting.
- Choose a sending platform built for outreach. A dedicated cold email platform handles custom tracking domains, feedback loops and per-mailbox limits properly, where a standard mailbox will hit sending caps and internal filters.
- Monitor reputation continuously. Google Postmaster Tools shows how Gmail scores your domain, and regular blocklist checks catch problems early. If you are listed, stop sending and resolve it before resuming.
2. Write content that reads like a one-to-one message
Content will not rescue a broken setup, but it will break a working one. The goal is a message a professional would plausibly send to another professional.
- Personalize on substance. Inserting a first name is not personalization. Effective cold email personalization references something specific and verifiable: a technology in their stack, a role they are hiring for, an expansion they announced, a problem typical of their segment. The message should make clear why you contacted this person rather than a thousand others.
- Write an honest subject line. A cold email subject line that overstates or misleads will earn opens and complaints in roughly equal measure. Straightforward and specific outperforms clever, and it keeps you inside CAN-SPAM’s requirement that subjects reflect content.
- Open with context, not with yourself. A strong cold email introduction establishes relevance in the first sentence. Company boilerplate belongs lower down, if at all.
- Keep the format plain. Mostly plain text with minimal formatting outperforms a designed cold email template for this use case. Heavy HTML, image-heavy layouts and large attachments all raise filter scrutiny and read as marketing rather than correspondence.
- Watch the tone and the punctuation. Excessive exclamation marks, capitals, and inflated claims still trip content scoring. More importantly, they read as sales collateral to a human.
- Limit links. One or two at most, ideally on a custom tracking domain. Providers and blocklists check the reputation of domains you link to, so a single poorly rated URL can sink an otherwise clean message.
- Sign properly and include the opt-out. A full signature with name, title, company and physical address satisfies the legal requirement and reassures the reader. The opt-out feels awkward in a one-to-one style message and remains worth including: it gives an irritated recipient a gentler exit than the spam button.
How much personalization turns a cold email into something not spam?
At minimum, the message needs the recipient’s name, their company, and content that connects to their actual role. Effective personalization goes further, referencing their industry, a specific responsibility, or a recent business event. Shallow mail merges do not clear the bar, because the test is whether the recipient can tell the message was written for their situation rather than assembled for a list.
3. Control timing, cadence, and segmentation
Sending behavior is as visible to providers as content, and it is easier to get wrong.
- Send at human pace. Spread messages across the day rather than firing them in a block. Eight to twelve an hour looks like a person working. A hundred at once does not.
- Lengthen the gaps between touches. Four to seven days between messages is a reasonable floor. Cold email follow-up should give each message room to land, and the total sequence should scale with deal size: two to four touches for small businesses, three to six for mid-market, more for enterprise where buying cycles are long.
- Add something each time. A follow-up that only asks whether the last one arrived generates complaints. Each touch in your email cadence should carry a new angle, a new proof point, or a sharper question.
- Sunset unresponsive contacts. If someone has not opened or replied after several attempts, remove them from the sequence. Continuing to send to people who never engage damages reputation with no upside.
- Cap contacts per company. Emailing five people at the same small business in the same week invites internal comparison and spam reports. One active contact at a small company, two or three at mid-market, is a sensible ceiling.
- Track the right numbers. Watch bounce rate, complaint rate, reply rate and positive reply rate rather than opens, which are unreliable and increasingly inflated by security scanners. The cold email metrics that predict deliverability problems are bounces and complaints, and both move before placement collapses.
4. Protect list quality
Good deliverability starts with who you email, and this is where most damage originates.
- Build lists rather than buying them blind. Scraped and bulk-purchased lead lists carry spam traps, role addresses and dead accounts. If you use a data provider, use one that verifies and refreshes.
- Verify before every send. Run the list through a verification tool and keep projected bounce under 2%. Regular email list cleaning removes typos, departures and dead domains before they become bounces.
- Use intent to narrow, not to expand. Buying signals such as hiring activity, funding, technology adoption and content consumption should reduce the size of your list rather than justify a larger one. We build outbound prospecting around intent data for exactly this reason: a smaller list of contacts with a live reason to care outperforms a larger one on every metric that matters.
- Avoid role-based addresses. Generic mailboxes such as info@ and sales@ are more likely to be monitored or repurposed as traps.
- Segment by problem, not by industry alone. A CFO and a VP of Sales at the same company have different problems, and a message that addresses neither specifically will be read as a broadcast. Effective lead segmentation groups contacts by the problem you are addressing.
- Keep data fresh. Contacts who have not engaged in six to twelve months should be revalidated before further outreach.
Across wildly different industries, deal sizes and buying cycles, the pattern is consistent: teams that cut list size and raise verification standards see complaint rates fall and reply rates rise at the same time. It is the least glamorous fix available and reliably the most effective one.
5. Honor opt-outs immediately
Respecting opt-outs is both a legal requirement and a deliverability advantage.
- Make unsubscribing easy. A visible one-click opt-out costs you a contact. A hidden one costs you a spam complaint, and the complaint is far more expensive.
- Process removals fast. CAN-SPAM allows 10 business days. Same-day is achievable and avoids the accidental resend that reliably triggers a report.
- Treat negative replies as opt-outs. “Not interested” and “please stop” mean the same thing as clicking unsubscribe. Acknowledge and remove.
- Monitor feedback loops. Major providers report spam complaints back to senders who register for them. Watch the data and act on patterns rather than individual reports.
- Answer replies promptly. Real conversations improve sender reputation. A prospect who replies and hears nothing is more likely to report the next message.
6. What to do if your domain is already in the spam folder
Stop sending first. Continuing to send while placement is poor deepens the reputation problem rather than testing it.
Then work through the diagnosis in order. Check whether the domain appears on any major blocklist and follow the delisting process where it does. Verify that SPF, DKIM and DMARC still pass, since records break quietly when infrastructure changes. Review the last thirty days of bounce and complaint data to identify which campaign or list segment caused the shift. Purge and reverify the list before resuming.
Recovery is slower than damage. Restart at low volume with your most engaged segment, rebuild positive signals for several weeks, and expect the full recovery to take longer than the ramp that caused the problem. In severe cases, where a domain has been burned rather than dented, moving to a fresh subdomain and rebuilding from scratch is more realistic than rehabilitation.
Is Your Cold Email Program on the Right Side of the Line?
You can settle this for your own program in about ten minutes. Each signal below carries a threshold that mailbox providers, regulators, or blocklist operators actually apply, so the answers are checkable rather than debatable.
- Consent basis — Can you state, for any given recipient, why you are permitted to contact them in their jurisdiction? A documented answer, not a general policy. If you cannot produce one for a Canadian or German contact, that segment should not be receiving email.
- Spam complaint rate — Below 0.1%. At 0.3% Google withdraws mitigation support and placement degrades sharply. The single most decisive number on this list.
- Bounce rate — Below 2%. Above 5%, stop sending and reverify the list before anything else goes out.
- List provenance — Can you trace where each address came from? Treat anything untraceable as scraped until proven otherwise.
- Sending identity — Does the sending domain visibly belong to your company? A subdomain of your real domain passes. A separately registered domain that merely resembles it fails.
- Account and domain count — How many are in rotation, and why? If the honest answer is “to get past volume limits,” that is the practice M3AAWG names as abusive.
- Engagement authenticity — Is every open and reply on your account from a human? Warm-up services that simulate engagement fail this outright.
- Message distinctness — Could this exact message go to anyone else on the list without editing? If yes, it is bulk by the standard definition, whatever the merge tags suggest.
- Sequence exit — Is there a defined point at which an unresponsive contact stops receiving mail? Sequences without an exit generate complaints indefinitely.
- Opt-out latency — How long from request to removal? CAN-SPAM allows 10 business days. Anything over 48 hours is a risk you do not need to carry.
How to read the result. Failing on complaint rate, bounce rate, or opt-out latency is urgent, because all three are costing you deliverability right now. Failing on consent basis or sending identity is structural and takes longer to correct. Failing on message distinctness or account count means the program rests on assumptions that stopped being safe in 2025, and it will keep failing until the design changes rather than the copy.
Conclusion
The distinction between cold email and spam has stopped being a matter of opinion. Regulators define it one way, mailbox providers enforce it another, and the anti-abuse community has now put its own definition in writing. A program that passes only the legal test will still lose its domain.
What survives is narrow, honest, and slower than most teams expect: verified data, transparent sending identity, relevance the recipient can recognize, and volume a person could stand behind. That is a harder standard than the 2023 playbook demanded, and it is a more durable one.
If you would rather not rebuild that infrastructure in-house, this is the work we do. Martal Group is ranked #1 in Lead Generation on Clutch, and our teams handle targeting, deliverability, compliance and sequenced omnichannel outreach as one program. Book a consultation to talk through your setup.
FAQs: Cold Email vs Spam
Is cold emailing illegal or considered spam?
Cold emailing is legal in the United States and many other countries when it follows the applicable rules, which generally means accurate sender identification, a clear opt-out, and content relevant to the recipient. Whether it is considered spam is a separate question with a different answer: blocklist operators such as Spamhaus classify unsolicited bulk email as spam regardless of legality. Legal and deliverable are two different tests, and a compliant message can still be filtered.
Why do my cold emails go to spam when the copy is fine?
Because copy is rarely the cause. Deliverability is decided first by authentication, then by list quality, then by engagement and complaint history, and only then by content. A missing DMARC record, a bounce rate above 2%, or a sudden volume increase will send well-written mail to the spam folder. Check your DNS records and your bounce data before rewriting a subject line.
What are the rules of the CAN-SPAM Act for cold emails?
Commercial emails must carry truthful header information and subject lines, disclose that the message is an advertisement, include a valid physical postal address, and provide a working opt-out that stays functional for at least 30 days. Opt-out requests must be honored within 10 business days. The rules apply to business-to-business email with no exception, and hiring a vendor to send does not transfer liability.
Do I need permission (opt-in) to send B2B cold emails?
In the United States, no. In Canada, CASL requires express or implied consent before you send. In the EU and UK, you need a lawful basis under GDPR, usually consent or a documented legitimate interest, and several member states require opt-in for anything beyond narrow B2B contact. Include an opt-out everywhere, and keep the message relevant to the recipient’s professional role.
Is cold email spam if I bought the list?
Purchased lists sit on the wrong side of the line almost by definition, because the recipients never granted permission and the addresses are usually unverified. The practical risk is immediate: bought lists carry spam traps and dead accounts, and hitting either damages sender reputation quickly. If you use a data provider, choose one that verifies and refreshes, and run your own verification pass before sending.
How many domains can I send from without looking like a spammer?
Sending from a fleet of domains to spread volume is now specifically named as deceptive by M3AAWG, alongside using multiple accounts to bypass sending limits. The defensible pattern is one primary sending domain or a small number of transparent subdomains of a domain you own, with volume kept low enough that you do not need to spread it. Domain rotation as a strategy is what the current guidance is aimed at.
Should I include an unsubscribe link in a one-to-one cold email?
Yes. It is required in many jurisdictions, and it reduces spam complaints even where it is not, because it gives an uninterested recipient a low-friction way out. A recipient who cannot find an opt-out and keeps receiving messages will use the spam button instead, which is far more damaging than losing a contact.
How many follow-ups are appropriate in a cold email sequence?
Three to five messages in a cold email sequence, spaced across two to four weeks, is a safe range for most B2B contexts, with longer sequences justified for enterprise deals with long buying cycles. Every message should add something new rather than repeat the previous one. Stop when engagement is absent: continuing past that point produces complaints without producing replies.