As a professional in the email security industry, I was recently asked about how to handle the constant influx of “legitimate” cold emails – those from real businesses seeking sales or partnerships.
While these emails may not be obvious scams and may even be well-written and personalized, they can still be a burden for recipients:
- Taking the time to reply politely
- Ignoring them often leads to more follow-ups
- Some emails may seem so familiar that they can be misleading, giving the impression that they are from someone you know
My response to this issue is straightforward: it is not just a minor annoyance – it is a recognized global problem with a clear stance.
As a member of M3AAWG, the leading authority on email ecosystem best practices, we align with their core principles:
The principles
Consent is paramount: Emails should only be sent to individuals who have explicitly agreed to receive them, and consent from other channels does not carry over to email.
Avoid deceptive tactics: Using fake personalization, rotating domains, or attempting to bypass filters is considered abusive behavior.
Cold email equals reputation risk: Unsolicited email campaigns can result in complaints, bounces, and being blocklisted, damaging the sender’s reputation.
Best practice is opt-in only: M3AAWG advocates for building email lists through explicit opt-in methods rather than scraping or purchasing contacts.
How senders should behave
M3AAWG does not advocate for a complete ban on cold emailing but advises against industrializing unsolicited outreach or disguising it as something else.
To maintain long-term deliverability and trust, senders should:
- Build opt-in audiences
- Be transparent about the purpose of the email and how the contact information was obtained
- Avoid any tactics that may appear manipulative
Additionally, recipients should consider the “rule of persistence” when dealing with cold emails:
- First email: Assess the email’s honesty and clarity. If it is respectful, you can choose to ignore it or politely decline.
- Second email: Evaluate the tone and intent. A respectful and transparent approach may be tolerated, but any hint of false familiarity should raise red flags.
- Third email: Treat persistent emails as spam and take appropriate action such as filtering, reporting, or blocking.
References
