AI for Sales Teams: Prospecting, Conversations and PipelineOutreach at scale, done right · Lesson 6 of 16

Deliverability and compliance: CAN-SPAM, GDPR, PECR and beyond

Article · 8 min · 7 min lecture

Video lecture

Deliverability and compliance: CAN-SPAM, GDPR, PECR and beyond

14 chapters · about 7 min · full transcript

Coming soon

Chapter 1 of 14

Deliverability and compliance

  • The technical gate
  • The legal gate
  • A compliant checklist
  • Practical guidance, not legal advice

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Two gates between you and the buyer

Every cold email must pass two gates. The technical gate: mailbox providers decide whether your email reaches the inbox, the spam folder or nowhere. The legal gate: laws decide whether you may send it at all, and how. AI increases volume and speed, which makes both gates more important, not less. This lesson is practical guidance, not legal advice; check the rules for your jurisdictions and take advice for your situation.

Deliverability essentials

Since 2024, major mailbox providers have tightened requirements for senders. Google and Yahoo introduced bulk-sender requirements in 2024, and Microsoft followed for Outlook consumer domains in 2025. For bulk senders (Google defines this around 5,000 messages a day to its users) they include:

  • Authentication: SPF and DKIM set up, with a DMARC policy published and aligned with your From domain.
  • Easy unsubscribe: one-click unsubscribe (via List-Unsubscribe headers) for marketing messages, processed promptly.
  • Low spam complaint rates: Google advises keeping user-reported spam rates low (below 0.1%) and never reaching 0.3%.
  • Valid forward and reverse DNS, TLS for transmission, and correctly formatted messages.

Even below bulk thresholds, follow these practices; they are how mailbox providers judge reputation.

Operational practices for sales teams:

  • Send cold outreach from a dedicated subdomain or secondary domain, properly authenticated, to protect your main domain's reputation.
  • Warm up new domains and mailboxes gradually; keep daily volumes per mailbox modest.
  • Verify addresses before sending; high bounce rates damage reputation.
  • Monitor Google Postmaster Tools and your providers' feedback; watch bounces, complaints and blocklists.
  • Avoid link shorteners, heavy images, attachments and spammy wording in cold emails.
DNS checklist (illustrative records; your email provider gives the exact values)
SPF   : example-sales.com TXT "v=spf1 include:<your-provider> -all"
DKIM  : selector._domainkey.example-sales.com TXT "<public key from provider>"
DMARC : _dmarc.example-sales.com TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
        (start with p=none to monitor, then move to quarantine/reject once aligned)

United States: CAN-SPAM Act. Applies to commercial email, including B2B, with no exception for business-to-business. Requirements include: accurate header information, non-deceptive subject lines, identifying the message as an ad where applicable, a valid physical postal address, a clear way to opt out, honouring opt-outs within 10 business days, and responsibility for vendors sending on your behalf. Penalties are significant and assessed per email (the FTC adjusts the maximum annually). US law is opt-out based; some states add rules.

United Kingdom: PECR plus UK GDPR. PECR distinguishes corporate subscribers (companies, LLPs, government bodies) from individual subscribers (individuals, sole traders, some partnerships). You may send B2B marketing emails to corporate subscribers without prior consent, but you must identify yourself and provide a valid way to opt out; for individual subscribers (including sole traders), you generally need consent or the "soft opt-in" for existing customers. UK GDPR still applies to the personal data involved: lawful basis (often legitimate interests, with an assessment), transparency (tell people where you got their data), minimisation and rights. The Data (Use and Access) Act 2025 raised maximum PECR fines to the UK GDPR level (up to £17.5 million or 4% of global turnover).

European Union: GDPR plus national ePrivacy rules. GDPR applies as above. Rules for unsolicited B2B email differ by member state: some permit B2B email under conditions, while others (for example Germany) are much stricter and often require prior consent. Check each target country.

Gulf and Pakistan. Saudi Arabia's Personal Data Protection Law (enforced since September 2024) and the UAE's federal data protection law regulate processing of personal data, including for marketing, with requirements on lawful basis or consent, transparency and cross-border transfers; telecom and marketing regulators may impose additional rules on unsolicited messages. Pakistan's data protection framework has been evolving; check current status and sector rules. When in doubt, favour consent, transparency and easy opt-out.

A compliant outbound checklist

[ ] Lawful basis documented (e.g., legitimate interests assessment for B2B outreach)
[ ] Data source recorded for each contact; privacy notice link in first email
[ ] Sender identity clear; physical address (US); honest subject lines
[ ] One-click unsubscribe / clear opt-out; honoured fast; global suppression list across tools
[ ] Sole traders / individual subscribers treated under consent rules (UK/EU)
[ ] Country rules checked for EU targets (e.g., stricter B2B rules in some states)
[ ] Vendors (including AI SDR tools) contractually bound and monitored
[ ] SPF, DKIM, DMARC aligned; complaint and bounce rates monitored

Worked example: a Dubai SaaS company expanding to the UK and EU

A Dubai SaaS firm launched outbound into the UK and Germany. It set up an authenticated subdomain, warmed mailboxes over several weeks, added a short transparency line and privacy link to first emails, and recorded data sources. For the UK, it targeted corporate addresses and excluded sole traders; for Germany, legal advice led it to rely on events, content and LinkedIn engagement to earn consent rather than cold email. Complaint rates stayed low and no regulator complaints arose.

Pitfalls

  • Sending cold outreach from the main corporate domain.
  • Assuming "B2B is exempt" everywhere.
  • Separate unsubscribe lists in each tool, so opted-out people keep receiving messages.

How to measure success

Inbox placement tests, bounce and complaint rates, unsubscribe handling time, DMARC alignment rate, and zero regulatory complaints.

Key takeaways

  • Cold email must pass a technical gate (authentication, reputation, complaints) and a legal gate (consent, transparency, opt-out).
  • Authenticate with SPF, DKIM and DMARC, use one-click unsubscribe, keep complaint rates low, warm up and use a dedicated sending domain.
  • CAN-SPAM covers B2B email; UK PECR allows B2B email to corporate subscribers with identification and opt-out; GDPR applies to the data.
  • Rules differ across EU states, KSA, UAE and Pakistan; keep a global suppression list and bind vendors, including AI SDR tools.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Under CAN-SPAM, is B2B commercial email exempt?
  2. In the UK, you want to email a sole trader you've never dealt with. What generally applies?
  3. Which setup best protects your main domain's reputation for cold outreach?

Put it into practice

Audit your outbound setup against the DNS and compliance checklists, fix the top three gaps, and set up a single suppression list shared across all sending tools.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.