Resources›Blog›Cold outreach in 2026: the compliance checklist that keeps you out of spam
Cold outreach in 2026: the compliance checklist that keeps you out of spam
Since the bulk sender rules tightened, unauthenticated mail is rejected outright - and it takes your invoices with it. SPF/DKIM/DMARC, one-click unsubscribe, the 0.3% complaint ceiling, legal basis, suppression lists and warm-up.
AI92 Team7 min read
Cold outreach has quietly become a technical discipline. For years the failure mode was being ignored; now the failure mode is never arriving at all. Since Google and Yahoo tightened their bulk sender requirements, a domain that sends unauthenticated mail or attracts complaints does not land in spam - it gets rejected outright, and it takes the rest of your email with it, including invoices and password resets.
This is the checklist to clear before the first send, and the reasoning behind each item.
Authenticate the domain. All three records.
SPF, DKIM and DMARC are no longer optional. SPF lists who may send for your domain, DKIM signs each message so it cannot be tampered with, DMARC tells receivers what to do when the first two fail and gives you reports.
The common half-measure is SPF and DKIM without DMARC, or DMARC published at p=none and forgotten. p=none is a monitoring mode - useful for two weeks while you read the reports, not a destination. Move to quarantine and then reject once the reports are clean.
One-click unsubscribe, in the headers
A visible unsubscribe link at the bottom is not enough. Bulk senders must include the List-Unsubscribe header with one-click support, so the recipient's mail client can offer an unsubscribe button that works without them opening anything. Honour it within two days.
This feels like handing people the exit. It is - and that is the point. The alternative is that an irritated recipient marks you as spam instead, which is far more expensive.
Keep complaints under 0.3%
That threshold is the one that quietly kills sender reputation. Three complaints per thousand delivered is the ceiling; you want to be well under it. Complaints come overwhelmingly from two places: lists the recipient does not recognise, and frequency. Both are fixable before you send, and neither is fixable afterwards.
Know which legal basis you are actually using
In the EU, B2B cold email is generally handled under legitimate interest rather than consent - but legitimate interest is a test you must be able to show your work on, not a magic phrase. In practice that means: the message is relevant to the person's professional role, you say plainly where you got their details, and you make objecting trivial. Consumers are a different matter entirely, and in several countries require prior consent.
In the US, CAN-SPAM is more permissive but still requires a real postal address, no deceptive subject lines, and honouring opt-outs promptly. If you are sending across markets, build to the strictest rule you touch rather than maintaining several standards.
Maintain a suppression list, and respect it forever
Every unsubscribe, bounce and complaint goes onto a do-not-contact list that survives campaigns, tools and staff changes. The most common way good senders get into trouble is not malice - it is a new list, imported to a new tool, that quietly re-contacts people who opted out two years ago.
Contact quality beats contact quantity
Scraped lists are the fastest route to a burned domain: they are full of stale addresses and spam traps, and a hard bounce rate above roughly 2% is read as a sender who does not know who they are writing to. Verified, current contacts cost more per record and are dramatically cheaper per reply.
Related, and often ignored: do not email markets you cannot serve. Sending into a country where you have no coverage generates complaints, no revenue, and occasionally a regulatory question.
Warm up, then hold a steady rhythm
A domain that has never sent volume and suddenly sends thousands looks exactly like a compromised account. Start small, grow gradually over several weeks, and keep volume steady rather than spiky.
The short version
- SPF, DKIM, DMARC published and DMARC moved past
p=none List-Unsubscribewith one-click, honoured within two days- Complaint rate under 0.3%, bounces under ~2%
- A defensible legal basis, stated plainly in the message
- A permanent suppression list
- Verified contacts, scoped to markets you actually serve
- Gradual warm-up, steady volume
Where this sits in AI92
Outreach in AI92 is built to clear this list by default rather than leaving it to whoever configures the campaign. Sending domains are authenticated, one-click unsubscribe is present on every message, opt-outs and bounces go to a suppression list that campaigns cannot override, prospects are verified rather than scraped, and targeting is scoped to the countries a business actually serves. Messages sit in your approval queue before they go out unless you deliberately switch a workflow to auto-send.
None of that makes outreach a guarantee. It makes it survivable - which, for a channel where one bad month can take your whole domain down with it, is the part worth engineering.
See it work on your business - the 48-hour trial needs nothing but a business email.
Start Free Trial