A cold email is an unsolicited, one-to-one business message sent to a specific person who has not previously contacted you, asked for information, or opted in. Its purpose is to start a conversation, not to close a sale in one message. It is legal in the United States and, for business recipients, in the EU and UK, provided you identify yourself, give a real postal address, and honour opt-outs.
Published by emailcampaign.ai, which builds cold email sending infrastructure. We have a commercial interest in this subject, so every number below is one a provider publishes or that we can show from our own sending.
Key details
It is one-to-one, not one-to-many. The defining feature is not the word “cold” but the fact that the message is addressed to a named person for a reason specific to them. A message that would read identically to ten thousand people is not a cold email; it is a bulk campaign wearing one.
The goal is a reply, not a sale. The realistic aim is a conversation, a meeting, or a clear no. Asking for a signature in a first message is the most common reason a well-targeted email gets ignored.
No prior relationship exists. The recipient has not subscribed, downloaded anything, or visited your pricing page. That absence is what separates it from every other kind of business email and is why the rules below apply.
It is short. Fifty to a hundred and twenty-five words is the range that gets read. Longer messages are not more persuasive; they are more skippable.
Cold email and spam are not the same thing
The distinction is real and worth stating precisely, because it is the question most people are actually asking.
| Cold email | Spam | |
|---|---|---|
| Recipient | A named person chosen for a stated reason | An address from a bought or scraped list |
| Message | Written for that person or a narrow segment | Identical at volume, personalised only by token |
| Sender identity | Real company, real postal address, real reply-to | Concealed, forged or rotating |
| Opt-out | Present and honoured | Absent, broken, or used to confirm the address is live |
| Volume per mailbox | Single figures to low tens per day | Thousands, from disposable infrastructure |
| Legal position | Lawful under CAN-SPAM, and for B2B under GDPR legitimate interest | Unlawful in most jurisdictions |
The uncomfortable part: a mailbox filter cannot read intent. It infers it from behaviour. Send lawful, relevant, well-written cold email from a brand-new domain at four hundred a day and you will be classified as spam, correctly by the filter’s own logic and wrongly by yours.
The rules, by jurisdiction
United States, CAN-SPAM. Prior consent is not required. You must not use deceptive header information or subject lines, you must disclose that the message is a solicitation, include a valid physical postal address, provide a working opt-out, and honour it within ten business days. Penalties are assessed per message.
EU and UK, GDPR and PECR. Business-to-business cold email is generally permitted on the legitimate interest basis. You must identify yourself, be able to explain how you obtained the address, offer an opt-out in every message, and keep a record of your legitimate interest assessment. Business-to-consumer email generally requires prior consent.
This is a summary, not legal advice. The rules turn on where the recipient is, not where you are.
What actually decides whether it arrives
Compliance keeps you lawful. It does not get you into the inbox. Placement is decided, roughly in this order of weight:
- Domain age and warm-up. A mailbox with no sending history has nothing for a filter to read; a mailbox that sent four hundred messages on its first day has supplied history that is worse than none. Two to three weeks of ramp is the floor.
- Authentication that resolves. SPF, DKIM and DMARC that actually evaluate, not merely exist. Two SPF records on one host is a permanent error. So is an include chain past ten DNS lookups.
- Bounce rate. Above roughly two percent, a provider reads the list as bought or stale.
- Complaint rate. Google publishes the threshold: stay below 0.1 percent, never reach 0.3 percent.
- Content. Fifth of five. This is why rewriting the subject line is the first thing people try and the last thing that helps.
You can check the second one right now: the free SPF, DKIM and DMARC checker counts every record on the host and walks the whole include tree, rather than reading the first record and stopping.
Practices that survive contact with a filter
Eight to ten sends per mailbox per day. Not because a provider stops you there, but because that is where a mailbox stops looking like software.
Verify the list, and treat accept-all separately. A catch-all domain accepts mail for any address, so “valid” from a verifier means the server did not say no, not that a person exists.
One clear ask. A single, low-pressure question outperforms a paragraph of options.
An obvious way out, honoured immediately. This is both the legal requirement and the cheapest defence against the complaint rate that actually costs you the domain.
A separate domain from your real one. Cold outreach is the highest-variance mail you will send. When a domain burns, it should burn alone, and not take your password resets with it.
Questions, answered straight
- Is cold email legal?
- In the United States, yes, under CAN-SPAM: you must not use deceptive headers or subject lines, you must identify the message as a solicitation, include a valid physical postal address, and honour an opt-out within ten business days. In the EU and UK, GDPR and PECR allow business-to-business cold email under legitimate interest, but you must name yourself, explain how you obtained the address, and offer an opt-out in every message. Business-to-consumer cold email in the EU generally requires prior consent.
- What is the difference between cold email and spam?
- Intent and scale. Spam is the same message sent to a bought list at volume with no regard for relevance and often with concealed sender details. A cold email is sent to a named person for a reason you can state in one sentence, from an identified sender, with a working opt-out. Filters cannot read intent, so they infer it from sending behaviour: volume per mailbox, bounce rate, complaint rate and authentication.
- How many cold emails can I send per day?
- Eight to ten per mailbox per day is the figure that holds up over months. That is far below what Google and Microsoft publish as limits, because a published limit describes when the provider stops you, not when it starts distrusting you. Volume comes from more mailboxes, not from busier ones.
- Do I need permission to send a cold email?
- Not in the US for B2B, and not in the EU or UK for B2B under legitimate interest, provided you meet the disclosure and opt-out requirements. You do need consent for B2C in the EU. None of this is legal advice; check your jurisdiction and the recipient's.
- Why do my cold emails go to spam even when they are legal?
- Legality and placement are unrelated. Filters score the sending domain's history, authentication and complaint rate long before they read the message. A perfectly lawful email from a cold, unauthenticated domain still lands in spam.
Published 20 September 2026. Updated 20 September 2026. Written by the team that runs the infrastructure; numbers come from the platform's own provisioning and sending, and from the providers' published documentation at the time of writing.