The first control happens before copywriting
A defensible cold email setup is not a clever template. It is a chain of decisions that can be explained later: why this person, why this professional topic, under which rule, from which data source, with which sender identity and how the person can object.
This article is an operational checklist, not legal advice. Electronic prospecting rules vary by country, recipient type, message purpose and existing relationship. Identify the applicable jurisdiction and obtain qualified legal advice when the facts are uncertain.
Step 1: identify the rule that actually applies
Do not assume that "B2B" means unrestricted email.
In the United States, the FTC says CAN-SPAM applies to commercial email and has no business-to-business exception. Its guide requires accurate header information, non-deceptive subjects, a valid postal address, an opt-out mechanism and timely handling of opt-outs, among other controls (FTC compliance guide).
In France, the CNIL describes a specific B2B regime when the solicitation relates to the person's professional activity and the person can oppose it easily. The CNIL page also distinguishes prospecting from transactional communication by purpose, not only by wording (CNIL electronic communications rules).
These are different frameworks. A founder selling across borders must not combine the most convenient sentence from each one. Record the recipient's location, the sender's establishment, the data source and the message purpose, then determine the governing requirements with appropriate counsel.
Step 2: prove professional relevance
Write one sentence that connects the recipient's actual role or company situation to the problem. The evidence may be a public company announcement, a documented responsibility or an existing professional interaction.
A title alone is weak evidence. Do not infer budget, authority, urgency, health, politics or other sensitive traits from public data. If the contact reason cannot be explained without speculation, do not send.
Keep the source and review date beside the prospect record. Public availability does not remove data-protection duties, but traceability helps the team review relevance and respond to rights requests.
Step 3: make the sender unambiguous
Use the real sender name, company and domain. Do not imitate a reply, a forwarded message or an internal notification. The subject should describe the real purpose of the message.
The FTC requires accurate From, To and Reply-To information and prohibits deceptive subjects for covered commercial email (FTC compliance guide). Google also asks senders to keep headers and content accurate and not misleading (Gmail sender guidelines).
The message should answer four questions without forcing the reader to investigate:
- Who is writing?
- Why this professional is being contacted?
- What is being proposed or asked?
- How can future contact stop?
Step 4: authenticate the domain
Legal compliance does not guarantee delivery. Configure and verify the sending domain before a campaign.
Google requires all senders to personal Gmail accounts to use SPF or DKIM, and sets additional requirements for senders above its bulk threshold, including SPF, DKIM, DMARC alignment and one-click unsubscribe for relevant messages (Gmail sender guidelines). The same page warns against sudden volume increases and misleading sender identity.
Use the domain provider's instructions. Send a controlled technical test, inspect authentication results and correct failures before contacting prospects. Do not compensate for failed authentication with a new domain and the same behaviour.
Step 5: design opposition before the first send
The opt-out path must be visible, simple and operational. Decide where objections are stored, which systems read them and who verifies that future actions are blocked.
An unsubscribe link is not enough if a separate sales tool can still send a follow-up. Apply the block across manual sends, sequences, monitoring, enrichment and regenerated drafts.
Ember's prospect-rights framework states that known objections, opt-outs and do-not-contact entries block active actions, follow-ups, monitoring, digests and paid enrichment (prospect data and rights). The user remains responsible for the targets, channels and purpose of the mission.
Step 6: write for one evidence-based reason
A first message can stay short:
Context: the verified fact that made the account relevant.
Reason: the professional problem connected to that fact.
Question: one low-friction way to confirm or reject the hypothesis.
Identity and rights: the sender details and required opposition information.
Do not add invented familiarity, fake urgency or a claim that the recipient is "perfect" for the offer. If the evidence only supports a question, write a question.
Step 7: run a manually reviewed pilot
Start with a set small enough for one person to review every recipient, source, message and rights status. The purpose is to find process defects before scale, not to prove a universal conversion rate.
For each record, require a pass on:
- applicable rule reviewed;
- professional relevance documented;
- data source and review date recorded;
- sender identity and subject accurate;
- authentication verified;
- required address and opposition path present;
- no previous objection or do-not-contact block;
- message reviewed by a person.
After sending, inspect bounces, negative feedback, objections, replies and any mismatch between the intended and actual audience. A serious rights or identity failure stops the pilot. It is not a reason to rewrite the subject and continue.
Where Lead Intelligence fits
Lead Intelligence can help prioritise accounts from the ICP, offer and available signals, and suggest a next action (official product page). It must not turn a public signal into consent or erase the jurisdiction review.
Use it after the organisation has defined the legal and operational controls. Keep the source, rationale and human decision visible. Apply known objections before generating, copying or sending any action.
Connect this setup to the defensible qualification framework so relevance is tested before copy is written.
Stop rules
Do not send when any of these points is unresolved:
- jurisdiction or recipient type is unknown;
- the team cannot state the applicable rule;
- the professional relevance relies on an inference;
- the data source is missing;
- sender identity or subject is misleading;
- domain authentication fails;
- opt-out processing is not tested;
- a previous objection may not propagate to every tool.
Limits and sources
This checklist does not decide the lawful basis for a specific campaign and does not cover every national rule, sector restriction or employment context. Consult counsel for the actual facts. Technical sender requirements also change, so verify current provider documentation before launch.
Sources reviewed on August 3, 2026: FTC CAN-SPAM guide, CNIL rules for electronic communications, Google email sender guidelines and Ember prospect data and rights.
Sources
FAQ
Does B2B cold email have no legal restrictions?
No. Rules depend on jurisdiction, recipient type, purpose and relationship. The FTC states that CAN-SPAM has no B2B exception, while the CNIL describes a bounded professional-prospecting regime in France.
What should be checked before writing the message?
Document jurisdiction, applicable rule, professional relevance, data source, existing objections and the person responsible for the decision.
What technical controls matter for a first pilot?
Verify the real sender identity and domain authentication. Google requires SPF or DKIM for all senders to personal Gmail accounts and adds requirements for bulk senders.
Can Lead Intelligence decide whether an email is lawful?
No. It can help research and prioritise accounts. The user remains responsible for jurisdiction, legal basis, relevance, rights handling and the final send.