Compliance
What the Cold Email Agent helps with (opt-out handling, DNC, authentication) and what you're responsible for under CAN-SPAM, GDPR, and other cold email rules.
Cold email is legal in most of the world, but there are rules. This page explains which rules apply to you, what the Cold Email Agent does automatically to keep you on the right side of them, and what's left for you to handle.
This page is not legal advice
The information here is a practical summary. If you're sending cold email for regulated industries (finance, healthcare), sending to high-stakes jurisdictions, or you're unsure whether a specific campaign is compliant, talk to a lawyer who knows the jurisdiction. The platform handles a lot of the mechanics, but responsibility for who you contact and what you say sits with you.
The three laws that matter most
CAN-SPAM (United States)
Covers commercial email sent to people in the US. The rules are relatively practical:
- Every email must clearly identify the sender (you or your company).
- The email must include a physical mailing address.
- It must include a working unsubscribe option.
- You must honour unsubscribes promptly (typically within 10 business days).
- The subject line must not be deceptive.
CAN-SPAM does not require opt-in consent before a first email. Cold outreach is allowed.
GDPR (European Union and UK)
Covers personal data about people in the EU or UK — and an email address counts as personal data. The rules are stricter than CAN-SPAM:
- You need a lawful basis to contact the person. For B2B cold outreach, that basis is usually legitimate interest — meaning you've genuinely considered whether your email is relevant to them and isn't intrusive.
- You must be able to answer a data-subject request: "what information do you hold about me, and delete it if I ask."
- You must honour unsubscribes immediately and not re-contact.
- Sending to purchased lists is very risky under GDPR. Lists you assembled yourself, with care, are safer.
CASL (Canada)
Stricter than CAN-SPAM. Cold email to Canadian recipients generally requires express or implied consent.
Check specifically if you're sending into Canada.
What the Cold Email Agent does for you
The platform handles the mechanical parts of compliance so you don't have to hand-roll them.
Opt-out and DNC handling
- AI SDR can detect opt-out language such as "unsubscribe", "remove me", or "stop emailing" in replies.
- Use Add to DNC in the AI SDR Inbox, or Settings → Cold Email Blocklist, to block future outreach to an address.
- When the outreach provider sends an unsubscribe event, the lead can move to Unsubscribed and the address is blocked from future outreach.
- You still need to include any required opt-out wording in your copy or signature for the jurisdictions you target.
Sender identification
- The "from" name on each email is the actual human or business name from your sending inbox, not a generic one.
- Replies go to a real inbox you control.
Domain authentication
- SPF, DKIM, and DMARC records are automatically configured on domains you buy through the platform. These authenticate your sending identity to receiving email providers. See Domain provisioning for what the platform manages behind the scenes.
Bounce handling
- Hard bounces are automatically flagged and prevent further sends to that address.
- High bounce rates trigger bounce protection, which pauses the campaign so you can investigate before damaging your sender reputation.
Reply detection
- Replies that look like removal requests can be detected by the AI SDR and should be added to DNC if they need human review.
- Out-of-office replies are detected and don't count as engagement.
What this covers (and what it doesn't)
These mechanics cover most of CAN-SPAM's requirements and the technical side of GDPR. They do not prove you had a lawful basis to contact the recipient in the first place — that's still your responsibility.
What's still your responsibility
Content to verify with legal if you handle regulated industries or sensitive markets
These points below reflect common good practice. They're not a substitute for legal review when you're contacting specific regulated audiences.
Your physical mailing address
CAN-SPAM requires every commercial email to include one. It doesn't need to be a fancy office — a PO Box is fine. Make sure it's set correctly on your sending inbox or in your email signature.
A lawful basis for contacting EU/UK recipients
For B2B outreach under GDPR's legitimate interest basis, you generally need to:
- Contact people whose role is genuinely relevant to what you're offering (CFOs for a finance product, not random personal addresses).
- Use business email addresses, not personal ones.
- Be prepared to justify — in writing — why you thought the email was relevant.
Keeping a short note about why a target list was built (your reasoning, your sources) is good practice.
Your list sources
- List you built yourself from public sources (LinkedIn, company websites, conferences) — generally fine for B2B.
- List built by the Cold Email Agent's lead finder — built from public business contact data. Compliant in most jurisdictions but not a replacement for your judgement about fit.
- Purchased lists from third-party vendors — high risk under GDPR. Often bad for deliverability too. We don't recommend them.
What you say in the email
Nothing in the platform reviews your copy for legal compliance. Avoid:
- Deceptive subject lines.
- False claims about who you are or what you do.
- Content that could reasonably be read as harassment.
Responding to data-subject requests (GDPR)
If someone replies asking what data you hold on them or asks for deletion, you need to answer promptly (typically 30 days). The Cold Email Agent can show you which campaigns contain a given lead — search the Leads tab — and you can remove them. For more formal requests, consult your data protection officer or legal counsel.
For procurement / vendor reviews
If a client or prospective client asks for compliance documentation before purchasing — which happens often, especially with enterprise buyers — reach out to support for the current compliance summary package. That typically includes:
- A statement of data-handling practices.
- Sub-processor list.
- GDPR compliance posture.
- SOC 2 or other certifications (where applicable).
You'll know you're in a healthy compliance posture when…
- Every campaign's bounce rate is below 3%.
- You haven't received any unsubscribe complaints in a while.
- Your sender reputation / health scores stay in the green.
- You can point to a reason for any target list you've built.
If something's not right
A recipient is threatening legal action
- Stop contacting them immediately. Add their email address or domain to DNC / the Cold Email Blocklist, and remove the lead from any active follow-up workflow.
- Document what happened: when you contacted them, what you sent, where their email came from.
- Consult legal counsel before responding formally.
My campaign is paused for high bounce rate
This is often a signal of a list quality issue that can compound into a compliance problem. See bounce protection and Deliverability troubleshooting. Fix the list before sending more.
Someone in Europe replied asking me to delete their data
Honour the request promptly. Add them to DNC or the Cold Email Blocklist, remove them from active outreach, and reply confirming deletion where appropriate. If they're asking about data beyond what the campaign sent (e.g. what we hold on them as a company), escalate to whoever handles data protection for your team.
Related
- Lead lifecycle — how unsubscribes flow through the system
- Domain provisioning — SPF/DKIM/DMARC for authenticated sending
- Deliverability — the technical context
- Deliverability FAQ → CAN-SPAM compliance — specific question on CAN-SPAM handling
- Deliverability FAQ → GDPR language for proposals — boilerplate you can paste into proposal docs