Consent and deliverability: why your automation may not be arriving
Delivery rate and inbox placement are not the same measurement, and most platforms only report the first. Mail accepted by the receiving server and filed into spam counts as delivered in your dashboard. That gap is where automation programmes fail invisibly, and the main determinant of which side of it you land on is whether the people receiving your mail asked for it, which turns consent from a legal formality into the mechanism that decides whether the system works.
Why does consent decide deliverability?
Because mailbox providers have no view of your legal basis and every view of recipient behaviour. They watch whether people open, reply, move messages out of spam, delete unread, or mark as spam, and they build a reputation for your sending domain from those signals. Mail people did not ask for produces the behaviour that reputation systems punish, regardless of whether sending it was lawful.
This is why a technically compliant purchased list still destroys a sending domain. The recipients did not choose you, so the complaint and delete rates run high from the first send, and the reputation damage extends to your ordinary business mail if it shares the domain.
The practical consequence is that consent quality, not just consent existence, is an operational input. A list built from people who ticked a box to get a download behaves differently from one built from people who asked for your newsletter, and the two should not be treated as one audience.
What does the law actually require?
It varies by jurisdiction and by whether you are writing to an individual or an organisation, which is why blanket answers are usually wrong. Under UK and EU rules, marketing email to individuals generally requires consent, with a narrow exception known as the soft opt-in. Mail to corporate addresses at organisations is treated more permissively in the UK, though the data protection obligations still apply.
The soft opt-in is wider than most summaries of it. Under PECR regulation 22(3) it applies where you obtained the address in the course of the sale or negotiations for the sale of a product or service, so a completed purchase is not required and someone who only negotiated qualifies. The similarity test attaches to the products or services you are now marketing, not to whatever the person bought, and the opt-out has to be offered when the address is collected and in every message since. From 5 February 2026 the Data (Use and Access) Act 2025 added a charitable purpose version of the same exemption, which lets registered charities email existing supporters on the same conditions with no sale involved. The same commencement raised PECR penalties to UK GDPR levels, up to 17.5 million GBP or 4 per cent of global turnover.
Elsewhere the model differs fundamentally. Some jurisdictions permit sending until someone opts out, provided the message identifies you and the opt-out works. Others require express consent that you must be able to evidence, with meaningful penalties attached.
The United States is the first of those, and its rules are more specific than a general duty not to deceive. CAN-SPAM requires a valid physical postal address in every commercial message, from and subject lines that are not misleading, identification of the message as an advertisement where the recipient did not ask for it, and opt-outs honoured within 10 business days. Penalties reach 53,088 USD per email, and they attach per message rather than per campaign.
What all of them share is the requirement to identify yourself, to make withdrawal easy, and to act on it promptly. If you record what someone consented to, when, and by what action, you are in a defensible position in most regimes and you also have the data needed to segment by consent quality.
The table below separates statute from mailbox provider policy, because the checklist most senders work from is the second one. SPF, DKIM, DMARC, the RFC 8058 one-click unsubscribe header and a complaint rate below 0.3 per cent are policy: Google and Yahoo imposed them on senders of 5,000 or more messages a day from February 2024, and Microsoft Outlook followed on 5 May 2025. No UK, EU or US statute requires any of them. They decide whether your mail arrives, the statutory items decide whether you are fined, and satisfying one set says nothing about the other.
| Requirement | Imposed by | What it means | Where it commonly fails |
|---|---|---|---|
| Consent or a soft opt-in | Law: PECR, ePrivacy Directive | A lawful basis for each individual you write to, evidenced | A single unsegmented list holding consent of several different qualities |
| Physical postal address | Law: CAN-SPAM | A valid postal address for the sender in every commercial message | Templates built for a UK audience and reused for a US send |
| Honest from and subject lines | Law: CAN-SPAM | Headers that identify the sender and describe the message accurately | Subject lines written as a fake reply or a false notification |
| Opt-out within 10 business days | Law: CAN-SPAM | Requests honoured inside a fixed statutory window | Opt-out held in one system and not synced to the sender |
| SPF | Provider policy | Lists which servers may send for your domain | Records that exceed the lookup limit after adding several tools |
| DKIM | Provider policy | Cryptographically signs your mail | Signing on the platform domain rather than your own |
| DMARC | Provider policy | Tells receivers what to do when checks fail, and where to report | Published as monitoring only and never reviewed again |
| One-click unsubscribe header | Provider policy | Lets the mail client remove someone without visiting a page | Present in the footer link only, not the message header |
| Complaint rate below 0.3 per cent | Provider policy | Few recipients marking messages as spam | Re-engaging a long dormant list in one large send |
What breaks inbox placement most often?
Sending to a dormant list after a long gap. The addresses that no longer exist bounce, the people who forgot you complain, and both spikes arrive in the same send, which is precisely the pattern reputation systems are built to catch. Volume increases sharply from a domain with no recent history have a similar effect.
Sharing a sending domain between bulk marketing and individual business mail is the second. When the marketing reputation degrades, invoices and sales replies degrade with it, and by the time anyone notices, the cause is several weeks old. Sending marketing mail from a subdomain keeps the reputations separate.
Third is authentication configured once and never revisited. Adding a new tool that sends on your behalf commonly breaks an existing record, and nothing warns you. The mail simply starts failing checks and the effect appears gradually across providers.
How do you check whether your mail is arriving?
Do not use your dashboard's delivery rate, which only says the receiving server accepted the message. Instead run a seed test: hold real accounts across the major providers, include them in a normal send, and look at where the message lands in each. Doing this on every significant campaign builds a history that shows a decline before customers do.
Second, read your DMARC reports. They tell you which sources are sending as your domain and which are failing authentication, which is the only way to find a forgotten tool or a misconfigured integration before it damages you.
Third, segment your engagement data by mailbox provider. If open and click rates for one provider drop sharply while the others hold, the problem is placement at that provider rather than content, and those two have completely different fixes.
What should a sunset policy look like?
A defined rule that moves people who have not engaged for a set period into a reduced-frequency track, and then stops sending to them entirely. The period should relate to your buying cycle rather than a number copied from an article, but the existence of the rule matters more than its precise value.
Removing people feels like destroying an asset and is closer to removing a liability. Unengaged addresses depress every engagement metric, raise complaint and bounce rates, and include the recycled addresses that providers use as spam traps. A smaller list that people read outperforms a large one that people ignore, and it does so on the same content.
Give the sunset a last message that states plainly what is about to happen and offers a way to stay. Some people take it, and those who do are worth more than the segment you removed.
Who should own consent state in your systems?
One system, exclusively, with every other reading from it. Consent held in both the CRM and the sending platform will eventually disagree, and the direction of the failure matters: someone who opted out in one system and remains subscribed in the other will keep receiving mail, which is the version with legal consequences.
Record the basis alongside the state. The date, the action taken, the wording shown at the time, and the source. Without those, a subject access request or a regulator's question is answered with a shrug, and you also cannot separate high quality consent from low quality consent when segmenting.
Then test it. Unsubscribe from your own mail with a test record, and check every connected system an hour later to confirm the state propagated. Most teams have never run that test, and a meaningful number discover that it does not work.
Common questions
- What is the difference between delivery rate and inbox placement?
- Delivery rate counts messages the receiving server accepted, which includes everything filed straight into spam. Inbox placement is whether the message reached the inbox where someone might read it. Marketing platforms report the first and cannot see the second, which is why automation programmes fail invisibly. Seed accounts across the major providers, included in normal sends, are the practical way to measure placement.
- Why does buying an email list damage deliverability?
- Because mailbox providers judge you on recipient behaviour, not on your legal basis. People who did not choose to hear from you delete, ignore and mark as spam at high rates from the first send, which builds a poor reputation for your sending domain. If that domain also carries invoices and sales replies, those suffer too, and the damage takes far longer to repair than it took to cause.
- What email authentication does a sender need?
- SPF to list which servers may send for your domain, DKIM to sign the mail cryptographically, and DMARC to tell receivers what to do when those checks fail and where to send reports. Google and Yahoo have required all three from senders of 5,000 or more messages a day since February 2024, and Microsoft Outlook since 5 May 2025, along with a one-click unsubscribe header. None of that is law, it is mailbox provider policy, and the statutory rules sit alongside it: the CAN-SPAM postal address, honest headers and opt-outs honoured within 10 business days. Adding a new sending tool commonly breaks an existing record with no warning.
- Should you delete unengaged email subscribers?
- Yes, on a defined schedule. Unengaged addresses depress engagement metrics, raise bounce and complaint rates, and include recycled addresses that providers use as spam traps. A sunset policy should move non-engagers to reduced frequency and then stop sending, with a final message stating plainly what is about to happen. A smaller list that people read outperforms a large ignored one on identical content.
- Where should consent be stored when you run several systems?
- In one system, with all others reading from it and none writing. When two systems hold consent independently they will eventually disagree, and the damaging direction is the one where someone has opted out in the CRM but remains subscribed in the sending platform. Store the basis alongside the state: the date, the action, the wording shown, and the source. Then test propagation with a real unsubscribe.
- Should marketing email be sent from your main domain?
- Better from a subdomain. Bulk marketing and individual business mail build sending reputation together when they share a domain, so a poorly received campaign can affect whether invoices and sales replies reach an inbox. A separate subdomain keeps the reputations independent, which matters most at exactly the moment something goes wrong with a campaign.