emailmarketing.net

M3AAWG Position on Cold Email (Nov 2025)

The industry-consensus stance — deceptive delivery of unsolicited "cold email" is an abusive practice; full definition, deceptive-tactic list, detection indicators, and the non-transferability of consent.

Reference4 min read

Who it is for ESP operators, Senders, Compliance teams

Applies to senders on any platform

If a customer argues that its cold outreach is sales, not spam, the industry's answer is clear: sending unsolicited email with deceptive delivery methods is abuse. The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG), whose members include the major mailbox providers, set out that position in a one-page statement.

The statement is M3AAWG Position on Cold Email, November 2025, Version 1.0 (M3AAWG-154; reference URL m3aawg.org/M3AAWGPositionOnColdEmail). It is the industry's explicit position on "cold outreach", and it focuses on deceptive practices used to deploy cold-email communications that mimic or appear to be one-to-one communications, but in reality are considered spam.

Definition

In email marketing terms, a "Cold Email" is an unsolicited email from otherwise legitimate, identifiable senders that tries to create a business relationship, a sale, a business opportunity, or other professional benefit from a recipient who has no prior relationship, connection, or consent with the sender or business.

Note that the senders are described as "otherwise legitimate, identifiable". The position is not about criminal spam operations. What defines cold email is the absence of any prior relationship, connection or consent.

Deceptive tactics the position targets

To look personally related to the recipient and appear to be one-to-one messages, cold emails sent in bulk often use:

  • Authentication (SPF, DKIM and DMARC, technically compliant but used as camouflage)
  • Opt-out links
  • Personalization (first name, job title, company name, and so on)
  • Other content generated by AI

Misleading delivery methods, used to avoid detection by spam filters:

  • Sending at random intervals
  • Lookalike domains, which resemble legitimate domains but are actually unrelated (M3AAWG's example: paypal-security.com for paypal.com)
  • Multiple sending accounts

The practice of using or facilitating deceptive delivery methods to mask Cold Emailing is in direct violation of core M3AAWG values.

Detection indicators

The reputation metrics that indicate a sender is sending cold email include, but are not limited to:

Indicator Where to read more
Detection in spam traps Spam Traps · Trap Incident Response
Blocklisting Blocklists & Spamhaus
High numbers of hard bounces for unknown users DSNs
High complaint rates Complaint Feedback Loops

Particularly egregious practices

Any attempt to do the following "are particularly egregious and are not acceptable in any manner":

  • Get around limits on mail volume
  • Avoid spam filters
  • Hide sending domains
  • Simulate subscriber engagement artificially (for example, with tools that fake warm-up or engagement)
  • Use other tools or services that exploit loopholes at mailbox providers or cloud platforms

M3AAWG's position is that the specific form of consent received to market to an individual is not transferable between marketing channels. Its example: consent to be contacted or marketed to by telephone does not give the business consent to contact that person by cold email.

The position

M3AAWG's position is that using deceptive and misleading delivery methods to send unsolicited email (including Cold Email) is an abusive practice.

M3AAWG's Sender Best Common Practices (Version 4.0, August 2026, section 4.5) summarizes this position in one paragraph, and its wording is broader than the position paper. The summary says M3AAWG views cold email itself as abusive, without the qualifier about deceptive or misleading delivery methods. It then refers readers to the Position on Cold Email for the full details. If you read both, the position paper is the document the summary points to.

What this means for an ESP

  • Cold email may be legal in some jurisdictions (for example, under the opt-out regime of CAN-SPAM; see CAN-SPAM). But the industry body that includes the major mailbox providers classifies cold email delivered deceptively as abuse, not marketing. Being legal does not make mail deliverable or acceptable.
  • The list of detection indicators also works as a checklist for vetting and monitoring. Trap hits, blocklistings, bounces for unknown users and complaints, together on one customer's stream, are the fingerprint of cold email.
  • Customers who rotate domains, use lookalike domains, run farms of mailbox accounts, randomize their sending schedule or use services that simulate engagement ("warm-up" services) fall under the "particularly egregious" clause.
  • The position is in addition to and inclusive of all other M3AAWG best practice guidance. It builds explicitly on the M3AAWG Position on Selling Email Address Lists (m3aawg.org/SellingEmailLists) and the M3AAWG Position on Email Appending (m3aawg.org/AppendingPosition). Selling lists and appending email addresses were already condemned, and this position applies the same stance to the way cold outreach is delivered.