Marketing automation guide

Consent and deliverability: why your automation may not be arriving

Delivery rate and inbox placement are not the same measurement, and most platforms only report the first. Mail accepted by the receiving server and filed into spam counts as delivered in your dashboard. That gap is where automation programmes fail invisibly, and the main determinant of which side of it you land on is whether the people receiving your mail asked for it, which turns consent from a legal formality into the mechanism that decides whether the system works.

Why does consent decide deliverability?

Because mailbox providers have no view of your legal basis and every view of recipient behaviour. They watch whether people open, reply, move messages out of spam, delete unread, or mark as spam, and they build a reputation for your sending domain from those signals. Mail people did not ask for produces the behaviour that reputation systems punish, regardless of whether sending it was lawful.

This is why a technically compliant purchased list still destroys a sending domain. The recipients did not choose you, so the complaint and delete rates run high from the first send, and the reputation damage extends to your ordinary business mail if it shares the domain.

The practical consequence is that consent quality, not just consent existence, is an operational input. A list built from people who ticked a box to get a download behaves differently from one built from people who asked for your newsletter, and the two should not be treated as one audience.

What does the law actually require?

It varies by jurisdiction and by whether you are writing to an individual or an organisation, which is why blanket answers are usually wrong. Under UK and EU rules, marketing email to individuals generally requires consent, with a narrow exception known as the soft opt-in. Mail to corporate addresses at organisations is treated more permissively in the UK, though the data protection obligations still apply.

The soft opt-in is wider than most summaries of it. Under PECR regulation 22(3) it applies where you obtained the address in the course of the sale or negotiations for the sale of a product or service, so a completed purchase is not required and someone who only negotiated qualifies. The similarity test attaches to the products or services you are now marketing, not to whatever the person bought, and the opt-out has to be offered when the address is collected and in every message since. From 5 February 2026 the Data (Use and Access) Act 2025 added a charitable purpose version of the same exemption, which lets registered charities email existing supporters on the same conditions with no sale involved. The same commencement raised PECR penalties to UK GDPR levels, up to 17.5 million GBP or 4 per cent of global turnover.

Elsewhere the model differs fundamentally. Some jurisdictions permit sending until someone opts out, provided the message identifies you and the opt-out works. Others require express consent that you must be able to evidence, with meaningful penalties attached.

The United States is the first of those, and its rules are more specific than a general duty not to deceive. CAN-SPAM requires a valid physical postal address in every commercial message, from and subject lines that are not misleading, identification of the message as an advertisement where the recipient did not ask for it, and opt-outs honoured within 10 business days. Penalties reach 53,088 USD per email, and they attach per message rather than per campaign.

What all of them share is the requirement to identify yourself, to make withdrawal easy, and to act on it promptly. If you record what someone consented to, when, and by what action, you are in a defensible position in most regimes and you also have the data needed to segment by consent quality.

The table below separates statute from mailbox provider policy, because the checklist most senders work from is the second one. SPF, DKIM, DMARC, the RFC 8058 one-click unsubscribe header and a complaint rate below 0.3 per cent are policy: Google and Yahoo imposed them on senders of 5,000 or more messages a day from February 2024, and Microsoft Outlook followed on 5 May 2025. No UK, EU or US statute requires any of them. They decide whether your mail arrives, the statutory items decide whether you are fined, and satisfying one set says nothing about the other.

RequirementImposed byWhat it meansWhere it commonly fails
Consent or a soft opt-inLaw: PECR, ePrivacy DirectiveA lawful basis for each individual you write to, evidencedA single unsegmented list holding consent of several different qualities
Physical postal addressLaw: CAN-SPAMA valid postal address for the sender in every commercial messageTemplates built for a UK audience and reused for a US send
Honest from and subject linesLaw: CAN-SPAMHeaders that identify the sender and describe the message accuratelySubject lines written as a fake reply or a false notification
Opt-out within 10 business daysLaw: CAN-SPAMRequests honoured inside a fixed statutory windowOpt-out held in one system and not synced to the sender
SPFProvider policyLists which servers may send for your domainRecords that exceed the lookup limit after adding several tools
DKIMProvider policyCryptographically signs your mailSigning on the platform domain rather than your own
DMARCProvider policyTells receivers what to do when checks fail, and where to reportPublished as monitoring only and never reviewed again
One-click unsubscribe headerProvider policyLets the mail client remove someone without visiting a pagePresent in the footer link only, not the message header
Complaint rate below 0.3 per centProvider policyFew recipients marking messages as spamRe-engaging a long dormant list in one large send

What breaks inbox placement most often?

Sending to a dormant list after a long gap. The addresses that no longer exist bounce, the people who forgot you complain, and both spikes arrive in the same send, which is precisely the pattern reputation systems are built to catch. Volume increases sharply from a domain with no recent history have a similar effect.

Sharing a sending domain between bulk marketing and individual business mail is the second. When the marketing reputation degrades, invoices and sales replies degrade with it, and by the time anyone notices, the cause is several weeks old. Sending marketing mail from a subdomain keeps the reputations separate.

Third is authentication configured once and never revisited. Adding a new tool that sends on your behalf commonly breaks an existing record, and nothing warns you. The mail simply starts failing checks and the effect appears gradually across providers.

How do you check whether your mail is arriving?

Do not use your dashboard's delivery rate, which only says the receiving server accepted the message. Instead run a seed test: hold real accounts across the major providers, include them in a normal send, and look at where the message lands in each. Doing this on every significant campaign builds a history that shows a decline before customers do.

Second, read your DMARC reports. They tell you which sources are sending as your domain and which are failing authentication, which is the only way to find a forgotten tool or a misconfigured integration before it damages you.

Third, segment your engagement data by mailbox provider. If open and click rates for one provider drop sharply while the others hold, the problem is placement at that provider rather than content, and those two have completely different fixes.

What should a sunset policy look like?

A defined rule that moves people who have not engaged for a set period into a reduced-frequency track, and then stops sending to them entirely. The period should relate to your buying cycle rather than a number copied from an article, but the existence of the rule matters more than its precise value.

Removing people feels like destroying an asset and is closer to removing a liability. Unengaged addresses depress every engagement metric, raise complaint and bounce rates, and include the recycled addresses that providers use as spam traps. A smaller list that people read outperforms a large one that people ignore, and it does so on the same content.

Give the sunset a last message that states plainly what is about to happen and offers a way to stay. Some people take it, and those who do are worth more than the segment you removed.

Who should own consent state in your systems?

One system, exclusively, with every other reading from it. Consent held in both the CRM and the sending platform will eventually disagree, and the direction of the failure matters: someone who opted out in one system and remains subscribed in the other will keep receiving mail, which is the version with legal consequences.

Record the basis alongside the state. The date, the action taken, the wording shown at the time, and the source. Without those, a subject access request or a regulator's question is answered with a shrug, and you also cannot separate high quality consent from low quality consent when segmenting.

Then test it. Unsubscribe from your own mail with a test record, and check every connected system an hour later to confirm the state propagated. Most teams have never run that test, and a meaningful number discover that it does not work.

Common questions

What is the difference between delivery rate and inbox placement?
Delivery rate counts messages the receiving server accepted, which includes everything filed straight into spam. Inbox placement is whether the message reached the inbox where someone might read it. Marketing platforms report the first and cannot see the second, which is why automation programmes fail invisibly. Seed accounts across the major providers, included in normal sends, are the practical way to measure placement.
Why does buying an email list damage deliverability?
Because mailbox providers judge you on recipient behaviour, not on your legal basis. People who did not choose to hear from you delete, ignore and mark as spam at high rates from the first send, which builds a poor reputation for your sending domain. If that domain also carries invoices and sales replies, those suffer too, and the damage takes far longer to repair than it took to cause.
What email authentication does a sender need?
SPF to list which servers may send for your domain, DKIM to sign the mail cryptographically, and DMARC to tell receivers what to do when those checks fail and where to send reports. Google and Yahoo have required all three from senders of 5,000 or more messages a day since February 2024, and Microsoft Outlook since 5 May 2025, along with a one-click unsubscribe header. None of that is law, it is mailbox provider policy, and the statutory rules sit alongside it: the CAN-SPAM postal address, honest headers and opt-outs honoured within 10 business days. Adding a new sending tool commonly breaks an existing record with no warning.
Should you delete unengaged email subscribers?
Yes, on a defined schedule. Unengaged addresses depress engagement metrics, raise bounce and complaint rates, and include recycled addresses that providers use as spam traps. A sunset policy should move non-engagers to reduced frequency and then stop sending, with a final message stating plainly what is about to happen. A smaller list that people read outperforms a large ignored one on identical content.
Where should consent be stored when you run several systems?
In one system, with all others reading from it and none writing. When two systems hold consent independently they will eventually disagree, and the damaging direction is the one where someone has opted out in the CRM but remains subscribed in the sending platform. Store the basis alongside the state: the date, the action, the wording shown, and the source. Then test propagation with a real unsubscribe.
Should marketing email be sent from your main domain?
Better from a subdomain. Bulk marketing and individual business mail build sending reputation together when they share a domain, so a poorly received campaign can affect whether invoices and sales replies reach an inbox. A separate subdomain keeps the reputations independent, which matters most at exactly the moment something goes wrong with a campaign.

More on Marketing automation

Let’s create something out of this world together.

Have a project in mind? Contact us for expert design and development solutions. Let’s discuss how we can help grow your business.

Azaadi Offer

Claim a free security assessment

Until 31 August we're covering the cost of a full vulnerability assessment and penetration test. Mention it in your message and we'll scope it with you.

  • Web application testing, authenticated and unauthenticated
  • Mobile application testing across iOS and Android
  • External network and infrastructure assessment
  • Manual exploitation by engineers, not scanner output

Testing and the report are free. Fixing what we find is quoted separately, with no obligation to accept.

Read the full offer

Tell us what you are trying to build and we will tell you plainly whether we are the right people for it. Book a call with an expert to work through the detail, or ask for a fixed quote if the scope is already clear. No obligation either way.

Four fields is all we need to get started.

Fastnexa Logo

© 2026 fastnexa. All rights reserved.