M3AAWG Position on Cold Email (Nov 2025)
The industry-consensus stance — deceptive delivery of unsolicited "cold email" is an abusive practice; full definition, deceptive-tactic list, detection indicators, and the non-transferability of consent.
Reference4 min read
Who it is for ESP operators, Senders, Compliance teams
Applies to senders on any platform
ContentsOn this page — 8 sections
If a customer argues that its cold outreach is sales, not spam, the industry's answer is clear: sending unsolicited email with deceptive delivery methods is abuse. The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG), whose members include the major mailbox providers, set out that position in a one-page statement.
The statement is M3AAWG Position on Cold Email, November 2025, Version 1.0 (M3AAWG-154; reference URL m3aawg.org/M3AAWGPositionOnColdEmail). It is the industry's explicit position on "cold outreach", and it focuses on deceptive practices used to deploy cold-email communications that mimic or appear to be one-to-one communications, but in reality are considered spam.
Definition
In email marketing terms, a "Cold Email" is an unsolicited email from otherwise legitimate, identifiable senders that tries to create a business relationship, a sale, a business opportunity, or other professional benefit from a recipient who has no prior relationship, connection, or consent with the sender or business.
Note that the senders are described as "otherwise legitimate, identifiable". The position is not about criminal spam operations. What defines cold email is the absence of any prior relationship, connection or consent.
Deceptive tactics the position targets
To look personally related to the recipient and appear to be one-to-one messages, cold emails sent in bulk often use:
- Authentication (SPF, DKIM and DMARC, technically compliant but used as camouflage)
- Opt-out links
- Personalization (first name, job title, company name, and so on)
- Other content generated by AI
Misleading delivery methods, used to avoid detection by spam filters:
- Sending at random intervals
- Lookalike domains, which resemble legitimate domains but are actually unrelated (M3AAWG's example:
paypal-security.comforpaypal.com) - Multiple sending accounts
The practice of using or facilitating deceptive delivery methods to mask Cold Emailing is in direct violation of core M3AAWG values.
Detection indicators
The reputation metrics that indicate a sender is sending cold email include, but are not limited to:
| Indicator | Where to read more |
|---|---|
| Detection in spam traps | Spam Traps · Trap Incident Response |
| Blocklisting | Blocklists & Spamhaus |
| High numbers of hard bounces for unknown users | DSNs |
| High complaint rates | Complaint Feedback Loops |
Particularly egregious practices
Any attempt to do the following "are particularly egregious and are not acceptable in any manner":
- Get around limits on mail volume
- Avoid spam filters
- Hide sending domains
- Simulate subscriber engagement artificially (for example, with tools that fake warm-up or engagement)
- Use other tools or services that exploit loopholes at mailbox providers or cloud platforms
Consent cannot be transferred between channels
M3AAWG's position is that the specific form of consent received to market to an individual is not transferable between marketing channels. Its example: consent to be contacted or marketed to by telephone does not give the business consent to contact that person by cold email.
The position
M3AAWG's position is that using deceptive and misleading delivery methods to send unsolicited email (including Cold Email) is an abusive practice.
M3AAWG's Sender Best Common Practices (Version 4.0, August 2026, section 4.5) summarizes this position in one paragraph, and its wording is broader than the position paper. The summary says M3AAWG views cold email itself as abusive, without the qualifier about deceptive or misleading delivery methods. It then refers readers to the Position on Cold Email for the full details. If you read both, the position paper is the document the summary points to.
What this means for an ESP
- Cold email may be legal in some jurisdictions (for example, under the opt-out regime of CAN-SPAM; see CAN-SPAM). But the industry body that includes the major mailbox providers classifies cold email delivered deceptively as abuse, not marketing. Being legal does not make mail deliverable or acceptable.
- The list of detection indicators also works as a checklist for vetting and monitoring. Trap hits, blocklistings, bounces for unknown users and complaints, together on one customer's stream, are the fingerprint of cold email.
- Customers who rotate domains, use lookalike domains, run farms of mailbox accounts, randomize their sending schedule or use services that simulate engagement ("warm-up" services) fall under the "particularly egregious" clause.
- The position is in addition to and inclusive of all other M3AAWG best practice guidance. It builds explicitly on the M3AAWG Position on Selling Email Address Lists (m3aawg.org/SellingEmailLists) and the M3AAWG Position on Email Appending (m3aawg.org/AppendingPosition). Selling lists and appending email addresses were already condemned, and this position applies the same stance to the way cold outreach is delivered.
Related articles
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
- Deliverability Glossary
- Email Abuse Taxonomy
- DNS Blocklists and the Spamhaus Zones
- Spamhaus Listings Deep Dive — SBL, CSS, PBL, DBL Policy and Delisting