Cold Email Without Burning Your Domain
Permission first, then the practical guide — list, research, message, follow-up, and the sending setup where cold email fails.
Cold email is the one channel where the mistake is invisible until it is permanent.
Nothing bounces back saying "you have damaged your domain reputation". You just get a slow decline in every email your company sends.
So it needs its own rules, not one line in a B2B lead generation plan. We start with permission, because most pages skip to templates.
Is cold email legal? The honest answer
It is banned nowhere and a free pass nowhere. The answer changes with where the recipient sits. This is general information, not legal advice — have counsel review your programme before you scale it.
| Market | Instrument | What it means |
|---|---|---|
| India | DPDP Act, 2023; Rules notified 14 November 2025 | Consent-based, with a narrow carve-out for data the person published themselves. |
| EU / UK | ePrivacy Directive 2002/58/EC, Article 13, with GDPR | Article 13(1) requires prior consent for marketing by electronic mail. The strictest of the three. |
| United States | CAN-SPAM Act (FTC guide, August 2023) | Opt-out, not opt-in. No consent needed, but honest headers, a postal address and a working opt-out are mandatory. |
B2B is not exempt in Europe: Article 13(5) tells member states to protect "the legitimate interests of subscribers other than natural persons with regard to unsolicited communications". And legality is a separate test from reputation — lawful mail still gets blocked by Gmail, which sets its own standards.
The list decides everything, and a bought list destroys your sending domain
The fastest way to destroy a sending domain is to buy a list and mail it. Not over months — over one or two sends.
- Hard bounces cluster. Dead addresses and typo domains fire at once — the signature of a list you did not build.
- Spam traps are planted in these lists deliberately. Mailing one proves you never collected the address.
- Complaints come from strangers, and people who have never heard of you report spam fastest.
- The damage attaches to the domain, not the campaign — stopping the sends does not undo it.
We name no list-building or email-finding tools here, and will not help you assemble addresses someone has not chosen to make reachable. Build the list by hand: company sites, your own CRM, people you have met.
Opted-in email is a different discipline — that is our guide to email marketing. This page is about writing to someone who did not ask to hear from you.
Research that makes one email worth sending
Cold email works when the recipient can tell from the first line that you know something specific about their situation. Before a name goes on the list, answer four questions in a sentence each.
- Who is this person and what do they own? Their job, not their job title. A buyer persona gets you the segment; account research gets you the individual.
- What changed recently? A new market, a new site, a hiring push, a launch — a reason this email arrives now.
- What is visibly not working? Something you can see from outside. Speculation dressed as diagnosis reads as a pitch.
- What is the smallest useful thing you can say? One observation they could act on even if they never reply.
The relevance test: could this email have gone to 500 people unchanged?
Read the draft and ask exactly that. If every word could go to five hundred other companies unedited, it will perform exactly like that.
Personalisation tokens do not pass — a first name is the field every bulk tool fills. What passes is a sentence only true of this account.
| Fails the test | Passes the test |
|---|---|
| "Noticed some SEO opportunities on your website." | "Your Pune range doesn't rank for its own model names — the titles are generic." |
| "As a leading company, you care about growth." | "You've opened two cities this quarter; neither has a location page." |
The structure of a cold email that earns a reply
Short, specific, one ask. Anything serving none of those three comes out. A working cold email is five moves and under 120 words. Keep subject lines plain rather than clever — clever reads as marketing.
1 Why you, why now One line that proves you looked. 2 Relevance bridge Tie it to a problem they may already feel. 3 What you do One line. Concrete, not a capability list. 4 One ask A single easy yes. "Worth a look?" 5 An exit One line telling them how to make it stop.
Delete three things before sending: your company's history, the second ask, and every adjective in the sentence describing what you do. That sentence is a plain claim — a value proposition compressed to one line.
Keep the exit genuine. A real opt-out is a legal requirement in the United States and the cheapest way to stop a spam report.
Follow-up discipline: how many is too many
Every follow-up raises complaint risk and lowers your odds of a reply. No sourced figure exists for an optimal count and we will not invent one. One email and two follow-ups over ten to fourteen days is a defensible ceiling.
- Each follow-up must add something. "Just bumping this" says only that you want something.
- Stop on any signal — a reply, an unsubscribe, an out-of-office naming someone else.
- Never restart a dead sequence. The same opener months later trains a human to mark you as spam.
The honest read on "breakup" emails: they do produce replies, and most are a polite no. That is useful — it cleans the list. Do not read it as interest, and do not use the format if the scarcity is false.
Sending infrastructure is where cold email actually fails
A reply-rate problem is usually a deliverability problem in disguise: nobody replies because nobody reads, because the mail sits in spam. Four decisions carry most of the outcome.
- Use a separate sending domain. A close variant you own, kept only for outreach, so reputation damage lands somewhere that does not carry your invoices.
- Warm it first. A new domain sending cold volume on day one looks like a throwaway; build up over weeks.
- Keep volume low per mailbox. Google Workspace itself caps a user at 2,000 messages and 2,000 external recipients a day, 500 external recipients per message, and blocks sending for up to 24 hours once a limit is hit (Gmail sending limits in Google Workspace, Google Workspace Admin Help; no last-updated date shown, read 1 October 2026). Cold outreach belongs in the tens per day.
- Authenticate properly. SPF, DKIM and DMARC on the sending domain are the floor, not an optimisation — the mechanics are in our guide to email deliverability.
The Google and Yahoo sender rules
This is the part most cold email articles have not updated. Google announced its bulk-sender requirements on 3 October 2023 for senders of "more than 5,000 messages to Gmail addresses in one day", enforced from February 2024 (blog.google, 3 October 2023). Yahoo says its enforcement began the same month.
| Requirement | Google (Gmail) | Yahoo |
|---|---|---|
| Applies to | Over 5,000 messages a day to Gmail addresses, counted per primary domain | Bulk senders; no threshold published |
| Authentication | Strong authentication of outgoing mail | SPF and DKIM, plus DMARC at least p=none, aligned to SPF or DKIM |
| One-click unsubscribe | Required for commercial mail, processed within two days | List-unsubscribe supporting one-click (RFC 8058 POST recommended), within two days |
| Spam rate | Below 0.1% in Postmaster Tools; 0.3%+ costs mitigation eligibility | Below 0.3%, measured on inbox-delivered mail |
Sources: "Email sender guidelines FAQ", Gmail Help; "Sender Best Practices", senders.yahooinc.com. Neither shows a last-updated date; both read 1 October 2026.
A 0.1% spam rate is roughly one complaint per thousand delivered messages — the real argument for small, researched volumes over scale.
Measurement that is not vanity
Measure cold email on reply rate and, above all, positive reply rate — the share of delivered emails producing a reply sales would want. Everything else is a diagnostic.
Open rate is unreliable now. Apple's Mail Privacy Protection routes remote content through relays and is designed to stop senders learning "when and how many times you opened their email" (Apple, "Mail Privacy Protection & Privacy", 12 December 2025). Opens inflate where proxies pre-fetch images and vanish where images are blocked. Never report it as performance.
| Metric | Use it for | Trust |
|---|---|---|
| Positive reply rate | Keep, change or stop the programme | High — a human typed it |
| Reply rate | Whether the message lands and is read | High |
| Bounce rate | List quality; rising bounces mean stop | High |
| Spam complaint rate | Standing against Gmail and Yahoo thresholds | High — can end the channel |
| Open rate | Rough direction, never a target | Low — proxies distort it both ways |
A realistic response is lower than any vendor case study showed you, and we will not quote a benchmark we cannot trace to a primary source. Judge month one against your own pipeline, not an average.
India, the DPDP Act, and what changes when you send abroad
India's framework is consent-first. Section 6(1) of the Digital Personal Data Protection Act, 2023 requires consent that is "free, specific, informed, unconditional and unambiguous with a clear affirmative action", and Section 5(1) requires a notice stating the purpose first (Act 22 of 2023, assented 11 August 2023; India Code, read 1 October 2026).
The nuance sits in Section 3: the Act does not apply to "personal data that is made or caused to be made publicly available by the Data Principal to whom such personal data relates". An address someone published themselves sits differently from one a vendor compiled — a narrow carve-out, not a licence, and worth nothing for a purchased file.
Section 3(b) extends the Act to processing outside India connected to offering goods or services to people in India. The Rules were notified on 14 November 2025 with a phased eighteen-month window (Press Information Bureau, 17 November 2025). The detail is in our DPDP Act guide for marketers.
- Into the EU or UK? Article 13(1) of the ePrivacy Directive 2002/58/EC (12 July 2002) allows marketing by electronic mail only to "subscribers who have given their prior consent".
- Into the United States? CAN-SPAM is opt-out: accurate headers, a matching subject line, a valid physical postal address, opt-outs honoured within 10 business days, penalties up to $53,088 per email (FTC compliance guide, August 2023, edited January 2024).
- Anywhere? Keep a suppression list that survives tool changes, and record where every address came from. If you cannot say, do not mail it.
Again: general information, not legal advice.
Where to go from here
Cold email is a small-batch channel most people run as a bulk one. In order: fifty researched accounts by hand, a separate sending domain warmed properly, one message per account that passes the relevance test, sequences capped at three, positive replies as the only report.
Then ask whether it is the right channel at all. For many Indian businesses, search demand and paid media produce more qualified conversations, and for software companies outbound works best stacked on inbound — see B2B SaaS lead generation. Organic takes three to six months, so plan both timelines together.
Frequently asked questions
Is cold email legal in India?
It is not banned, but it is governed. The Digital Personal Data Protection Act, 2023 requires consent that is free, specific, informed, unconditional and unambiguous, with a narrow exclusion for data the person published themselves. A purchased list fails that standard. General information, not legal advice.
Should I send cold email from my main company domain?
No. Use a separate sending domain you own, kept only for outreach, and warm it slowly before any sequence starts. Reputation damage attaches to the domain, and that must not be the domain sending your invoices.
How many follow-ups should a cold sequence have?
One initial email and two follow-ups over ten to fourteen days is a defensible ceiling. No trustworthy sourced figure exists for an optimal count. Each follow-up raises spam-complaint risk, so each must add a new observation.
Why is my cold email reply rate so low?
Usually because the mail is not being read. A reply-rate problem is most often a deliverability problem in disguise: an unwarmed domain, missing authentication, too much volume per mailbox, or dead addresses. Check inboxing first.
Can I still use open rate to judge cold email?
Only as a rough direction, never as a target. Apple's Mail Privacy Protection is designed to stop senders learning when and how many times a message was opened, and proxies distort it both ways. Measure positive reply rate instead.
Pipeline without the reputation risk
We build B2B demand programmes where outreach, search and paid work together — with the sending setup done right before the first email goes out.
Related guides
Make Digital Hangover a preferred source
One tap tells Google to show more of our SEO and marketing coverage in your Top Stories.
