How to be cool with Cold Emails

Rui Serra By Rui Serra • June 23, 2026

Cold email are unsolicited outreach sent to people who have no prior relationship or consent—usually to pitch a product, partnership, or opportunity. Well, the key message is simple: most cold email, especially at scale, behaves like spam—even if it looks personalized or “legit.” Don't let it pass more than once or twice!

I was recently asked, as someone working in an email security company, what should be done about the constant stream of “legitimate” cold emails—real businesses reaching out for sales or partnerships.

It’s a fair question: These are not obvious scams. Likely from legitimate businesses, often well-written, friendly, and sometimes even personalized. But from the recipient’s perspective, they’re still a burden:

  • replying politely takes time,
  • ignoring them often leads to more follow-ups,
  • and in some cases, the tone is so familiar that it can be misleading—almost as if it’s coming from someone you already know - 

My answer was simple: this isn’t just a nuisance—it’s a known, global problem, and there’s a clear position on it.

As members of M3AAWG (the Messaging, Malware and Mobile Anti-Abuse Working Group), widely considered the de facto authority on email ecosystem best practices, we align with their principles:

 

The principles

Consent matters most
You shouldn’t email someone unless they explicitly agreed to it—and consent from another channel (like phone) doesn’t carry over to email. [m3aawg.org]

Deceptive tactics are a hard no
Fake personalization, rotating domains, or trying to bypass filters is considered abusive behavior. [m3aawg.org]

Cold email = reputation risk
These campaigns often lead to complaints, bounces, and blocklisting, ultimately damaging sender reputation. [m3aawg.org]

Best practice: opt-in only
M3AAWG consistently recommends building lists through explicit opt-in, not scraping or buying contacts. [marketscreener.com]

 

How should senders behave?

M3AAWG isn’t saying “never email someone first.”

They’re saying: don’t industrialize unsolicited outreach—or try to disguise it as something it’s not.

If you care about long-term deliverability and trust, the safe path is:

  • build opt-in audiences
  • be transparent. What is the purpose of the email, how did you get the contact. 
  • avoid anything that looks like you’re gaming the system

And we might add: 

  • One email is OK. If it's unanswered, apologize in a second email and leave that contact alone!

So, what should recipients do?

The reality is: not all cold emails are equal. Occasionally, one might even be relevant! If it's not, than our practical suggestion is what we call the “rule of persistence”:

  • First email: tolerate it.
    If it’s clearly written and honest (e.g., openly saying how they got your contact), you can ignore it—or send a quick “not interested.” After all, it’s just a business trying to do business.
  • Second email: evaluate tone and intent.
    If the approach is respectful and transparent, you might still let it pass.
    If it leans on fake familiarity (“Hi <First name>, I love your work… we’re a perfect fit…”), it’s already crossing into questionable territory.
  • Third email: treat it as spam.
    At this point, persistence turns into abuse—and should be handled accordingly (filters, reporting, blocking).


References

Recent Posts

Subscribe to Email Updates
Get instant notifications of new posts

Posts by Topic