Compliance · Field Guide
The legal rules differ sharply by jurisdiction and are less restrictive than most people assume. The technical rules apply everywhere, are enforced automatically, and will stop you long before a regulator does.
Two things are true about cold email that people rarely hold simultaneously. The first is that it is legal in more places and circumstances than the internet’s collective anxiety suggests. The second is that legality is largely beside the point, because the constraint that actually stops most cold outreach isn’t a regulator — it’s Gmail, deciding automatically, within about a day.
I’ll cover both, in that order, and be clear about which is which. But I want to put a caveat at the top rather than the bottom: I am not a lawyer, this is not legal advice, and email law varies by jurisdiction, by recipient type, and by what you’re actually sending. If you’re building a business on cold outreach into regulated markets, pay someone qualified to look at your specific programme. What follows is a working practitioner’s map of the terrain, which is a different thing from advice on your situation.
The United States: CAN-SPAM Opt-out, and more permissive than expected
CAN-SPAM is an opt-out regime. You do not need permission before sending a commercial email to someone in the US. That surprises people who have absorbed European assumptions, and it’s the single most important jurisdictional difference in the field.
What the law requires is straightforward:
No deceptive headers. From, To, Reply-To and routing information must be accurate. The sender must be genuinely identifiable.
No misleading subject lines. The subject must reflect the content.
Identify the message as an advertisement, in some reasonable way, if that’s what it is.
Include a valid physical postal address. A real one. A registered agent address or a PO box obtained through the postal service is acceptable; an invented one is not.
Provide a clear opt-out mechanism, and honour requests within ten business days. The opt-out must remain functional for at least thirty days after sending, and you cannot charge for it or require anything beyond an email address and a preference.
Monitor what others do on your behalf. Hiring an agency does not transfer liability. Both the company whose product is promoted and the company sending can be held responsible.
Penalties are assessed per individual email, which is the mechanism that turns a sloppy campaign into a serious number very quickly. The per-message figure has been adjusted for inflation over the years, so check the current amount rather than trusting a figure in an old article — but the structure is what matters: it multiplies by volume.
The EU and UK: GDPR and ePrivacy More restrictive, more nuanced than “banned”
The common belief is that GDPR prohibits cold email in Europe. It doesn’t, quite — but the path is narrow and the details matter.
Two separate instruments apply. GDPR governs processing personal data, including a business contact’s name and work email address. ePrivacy — implemented nationally, as PECR in the UK — governs unsolicited electronic marketing specifically.
Under GDPR you need a lawful basis to process the data. For B2B outreach, the usual candidate is legitimate interest, which requires you to conduct and document a balancing test: your interest in contacting them, weighed against their rights and reasonable expectations. The test is genuinely meant to be performed, in writing, before you send. A relevant, targeted message to a decision-maker whose role makes your product obviously pertinent sits far more comfortably in legitimate interest than a scraped list blasted to everyone at a company.
Under ePrivacy, the crucial distinction is individual versus corporate subscriber. Marketing to individuals — personal addresses, and in most interpretations sole traders and some partnerships — requires prior consent. Marketing to corporate subscribers — a named person at an incorporated company — is generally permitted without prior consent in the UK and several member states, subject to the GDPR obligations still applying.
National implementations differ meaningfully. Germany is considerably stricter than the UK. Italy, France and Spain each have their own positions. “Compliant in Europe” is not a single thing, and anyone telling you otherwise is simplifying to sell you something.
What you must do regardless: identify yourself clearly, provide an opt-out in every message, honour it immediately, tell people where you obtained their data if asked, and be able to fulfil access and erasure requests. That last obligation is the one most cold-outreach operations cannot actually meet, because they don’t know where their list came from.
Canada: CASL The strictest of the major regimes
Canada’s Anti-Spam Legislation is opt-in and is the harshest of the three in both requirements and penalties.
You need consent before sending commercial electronic messages — either express, meaning they actively agreed, or implied, which arises from specific defined relationships: an existing business relationship within the preceding two years, an enquiry within six months, or a conspicuously published business address where the message relates to that person’s role and they haven’t indicated they don’t want messages.
That last category is the narrow path most legitimate B2B outreach into Canada uses. It’s narrower than people assume: the address must be published by that person, without a statement declining unsolicited messages, and your message must genuinely relate to their professional role.
Every message needs sender identification, contact details valid for sixty days, and a working unsubscribe honoured within ten business days. Penalties run to substantial figures per violation, and enforcement has been real.
The Comparison
| Jurisdiction | Model | B2B cold email | Opt-out window | Key requirement |
|---|---|---|---|---|
| United States | Opt-out | Permitted | 10 business days | Physical address; accurate headers |
| United Kingdom | Mixed | Corporate subscribers generally permitted | Immediately | Documented legitimate interest assessment |
| EU (varies) | Mixed to opt-in | Varies sharply by member state | Immediately | Lawful basis; data provenance |
| Canada | Opt-in | Narrow implied-consent path only | 10 business days | Consent, express or implied |
| Australia | Opt-in | Inferred consent from published address | 5 business days | Consent; sender identification |
The Constraint That Actually Stops You Technical, automatic, immediate
Here’s the part that matters more than everything above, for most people, most of the time.
Regulators are slow and act on complaints. Mailbox providers are instant and act on statistics. Since the bulk sender requirements took effect — Google and Yahoo from February 2024, Microsoft from May 2025 — the enforcement that will actually stop your campaign happens automatically within about twenty-four hours of your first bad send.
The thresholds are unforgiving. Spam complaint rates must stay below 0.3%, with Google recommending below 0.1%. On a send of a thousand cold emails, three complaints breaches the recommended level. Cold email, by its nature, generates complaints at rates that make this arithmetic brutal.
And the consequence has hardened. Google escalated in November 2025 from temporary rate-limiting failures to permanent rejections. Non-compliant mail doesn’t go to spam — it bounces, and the recipient never knows it existed.
“The regulator might write to you in eighteen months. Gmail decides tomorrow, automatically, and doesn’t tell you.”
What this means practically:
Never send cold email from your primary domain. This is the single most important operational rule in the field. Burn a secondary domain, not the one your invoices and customer support come from. Domain reputation damage is slow to repair and affects everything you send.
Authenticate properly on the sending domain. SPF, DKIM and DMARC, with alignment. Non-negotiable, and it’s the bare minimum rather than an advantage.
Warm up before volume. A new domain sending hundreds of cold emails on day one is the clearest possible spam signal. Weeks of gradual ramp, not days.
Verify addresses before sending. High bounce rates are a reputation signal independent of complaints. A list with 15% invalid addresses will damage you regardless of how good the message is.
Keep volumes low per domain per day. The 5,000-per-day bulk sender threshold classifies you permanently once crossed — and for cold outreach specifically, meaningful volume should be distributed rather than concentrated. Most serious operators run well below that per sending identity.
Monitor Google Postmaster Tools. It’s free and it’s the only view you get of what Google thinks of your domain. If your complaint rate is climbing, you want to know before you’re blocked rather than after.
The Practice That Solves Both Problems Relevance
There’s a convergence worth noticing. The legal frameworks and the technical ones reward the same behaviour, from opposite directions.
The GDPR legitimate interest test is essentially asking: would this person reasonably expect and not object to this message? The spam complaint threshold is measuring, empirically, whether they objected. Those are the same question, asked before and after the fact.
Which means the practical route through both is identical: send fewer, better-targeted, genuinely relevant messages to people for whom the message makes obvious sense. A hundred researched emails to people whose role makes your product plainly pertinent will generate almost no complaints, sit comfortably inside legitimate interest, and convert better than ten thousand blasted messages. The compliance-friendly approach and the effective approach are the same approach.
This is not a moral point. It’s an operational one. The spray-and-pray model has been made non-viable by automated enforcement, independently of whether any regulator ever notices.
The Sending Infrastructure, Specifically How practitioners actually set this up
The technical section above says “use a separate domain.” Here’s what that means in practice, because the details are where campaigns succeed or die.
Buy a lookalike domain, not a subdomain. A subdomain of your primary domain shares reputation signals with the parent in ways that can bleed back. Register something adjacent — your brand with a different TLD, or a hyphenated variant — and point it at the same site so it doesn’t look abandoned.
Set up the domain properly before sending anything. A live website at that address, an MX record so it can receive mail, SPF, DKIM, DMARC, and a real reply address that a human monitors. A sending domain with no website and no inbound mail is a recognisable pattern.
Warm up over four to six weeks. Start at a handful of messages a day and increase gradually. The temptation to compress this is strong and the failure is unrecoverable — a domain that gets flagged during warm-up is generally cheaper to replace than to rehabilitate.
Keep per-mailbox volume low. Serious operators run modest daily volumes per sending identity and scale by adding identities rather than by increasing throughput on one. This is partly reputation management and partly that low volume forces the targeting discipline that makes cold outreach work at all.
Verify every address before sending. Bounce rate is a reputation signal independent of complaints, and cold lists decay fast — people change jobs constantly. A list assembled six months ago and never re-verified will bounce at a rate that damages you on its own.
Monitor from day one. Google Postmaster Tools for Gmail visibility, plus your own bounce and reply tracking. The signal you’re watching for is a trend, and by the time a problem is obvious in your reply rate it has usually been visible in complaint data for a fortnight.
What Actually Gets People in Trouble Patterns, not paragraphs of statute
In practice, enforcement and complaints cluster around a small number of behaviours, and none of them are ambiguous edge cases.
Continuing after an opt-out. The single most reliable way to convert an annoyed recipient into a complainant. Suppression must be global across every campaign and every sending domain you operate, not scoped to the campaign they replied to. Most failures here are technical rather than malicious — two tools with separate suppression lists — which is no defence.
Impersonation and false familiarity. Subject lines implying a prior conversation, fake “re:” prefixes, invented mutual connections, sender names designed to look like a colleague. This is deceptive-header territory in the US, and it’s the behaviour that generates the sharpest complaint response everywhere.
Volume without relevance. The pattern that triggers automated enforcement fastest, and it’s self-inflicted. Complaint rates scale with irrelevance, and the threshold is low enough that a poorly-targeted campaign can breach it on its first send.
Scraped consumer addresses. Personal addresses rather than role-based business ones move you out of the corporate-subscriber exemptions in the UK and EU entirely, and into territory where you needed consent you don’t have.
Being unable to answer basic questions. Where did you get my data, who are you, how do I stop this. An operation that can’t answer these promptly and honestly is one that will eventually meet a regulator who asks them formally.
The Minimum Checklist
Before you send anything: know where every address came from and be able to say so. Use a separate sending domain. Configure SPF, DKIM and DMARC on it. Warm it up over weeks. Verify the list.
In every message: real sender name and identifiable organisation. Accurate subject. Physical address. Working opt-out. If in the EU or UK, be prepared to state your lawful basis.
After sending: honour opt-outs immediately regardless of what the law’s minimum window allows — the ten-business-day permission is legal, and using it fully will earn you complaints. Suppress permanently across all campaigns, not just the one. Monitor complaint rates daily. Stop immediately if they climb.
Never: hide the opt-out, use a fake sender identity, continue after an opt-out, buy a list you can’t trace, or use the same domain as your customer-facing mail.
Regulatory summaries are simplified overviews of complex law and vary by national implementation, recipient type and message content; penalty amounts are periodically adjusted and should be verified against current official sources. This article is not legal advice. Sender requirements verified against Google, Yahoo and Microsoft published guidelines. This article contains no affiliate links.