In November 2025, M3AAWG published a position on cold email. The body brings together mailbox operators, internet service providers and anti-abuse professionals: these are the people who decide whether your messages get in.
The document has been read in two opposite ways, both wrong. Some saw a ban on cold email, others a mere reminder of good manners.
It says something more precise, and more uncomfortable.
The definition adopted
The document begins by defining its object, and the definition deserves quoting in full:
“An unsolicited email from otherwise legitimate, identifiable senders that tries to create a business relationship, a sale, a business opportunity, or other professional benefit from a recipient who has no prior relationship, connection, or consent with the sender or business.”
Note “otherwise legitimate, identifiable senders”. M3AAWG is not talking about fraudsters. It is talking about real, identifiable companies writing to people who do not know them.
That is B2B prospecting as it is practised, described without hostility and without indulgence.
What is called abusive
The central sentence is this: “using deceptive and misleading delivery methods to send unsolicited email (including Cold Email) is an abusive practice.”
It is not the sending that is targeted, it is the deceptive delivery method. And the document spells out what it means by that.
First, the disguise: “Cold Emails sent in bulk often use authentication, opt-out links, and personalization […] to make them look uniquely related to the recipient and appear as one-to-one communications.” Authentication and the unsubscribe link, presented everywhere as marks of seriousness, are here described as elements of disguise when they serve to pass a bulk send off as individual correspondence.
Then, circumvention, and the wording leaves no margin: “Any attempts to bypass mail volume limits, avoid spam filters, mask sending domains […] are not acceptable in any manner.”
Finally, transferred consent: “the specific form of consent received to market to an individual is not transferable between multiple marketing channels.” A business card exchanged at a trade show is not consent to receive a six-message sequence.
What the market sells, and what appears on that list
Take the standard toolkit sold today as modern outbound prospecting.
Buying ten secondary domains so as not to expose the main one: that is masking sending domains.
Spreading sends across thirty warmed mailboxes to stay under thresholds: that is bypassing volume limits.
Inserting a variable mentioning the recipient’s latest blog post so the message looks handwritten: that is passing a bulk send off as an individual communication.
Those three practices are taught, tooled and invoiced. They appear by name in the list of what the operators’ own body declares unacceptable, in any circumstances.
M3AAWG also condemns, in its sender best common practices updated on 27 August 2026, email appending: “Email appending is a direct violation of core M3AAWG values”, on the grounds that the address holder “has neither explicitly provided the address nor given consent to receive messages”.
What this document does not say
It does not say that a flawless cold email would be acceptable. It files cold email under unsolicited mail and never once praises it.
So we are not going to turn a condemnation of methods into an authorisation of the practice. An identified send, from your own domain, at declared volume, with an exit that works, escapes the listed grievances. It remains unsolicited mail in that body’s eyes.
Which leaves you with two sets of norms, and they do not coincide.
European law permits professional prospecting on the basis of legitimate interest, when the subject of the approach relates to the recipient’s profession. Your send may therefore be perfectly lawful.
Mailbox operators do not judge lawfulness. They judge behaviour, and they penalise it immediately, with no procedure and no appeal.
Being in order with your data protection authority and blocked by Gmail is a perfectly coherent situation. Many companies discover it while looking for a lawyer when they needed a systems administrator.
The dividing line, in practice
It does not run between cold email and everything else. It runs between what hides and what owns up.
A sending domain that is yours, the one you put on your invoices. A volume that is not trying to slip under a threshold. An exact identification of the sender, without detour. An exit that works first time and is honoured immediately. And an approach for which you can say, recipient by recipient, why it concerns them.
That is Sestaro’s position on sending: messages go out from your server, with your credentials, under your domain, and the resulting reputation is yours. It is the exact opposite of the disposable domain strategy, and it means owning what you send.
That line costs volume. It is also the only one that does not depend on a filter’s inattention.
What to do tomorrow morning
List the domains your company sends prospecting from. If there is more than one or two, ask why, and listen to the answer: it almost always contains the word “reputation” or the word “threshold”.
Then look at your outbound sequences and count the elements whose only function is to make a message look individual. Each one is a bet that the filter will not see what the operators’ own body has already described.
And ask the question that settles it: if the recipient found out exactly how this message reached them, would your method look honest to them? That is, word for word, the test M3AAWG applies.
Sources
- M3AAWG (November 2025). M3AAWG Position on Cold Email, Version 1.0
- M3AAWG (27 August 2026). M3AAWG Sender Best Common Practices, Version 4.0
- M3AAWG (updated January 2019). M3AAWG Position on Email Appending
- CNIL (updated 10 June 2026). La prospection commerciale par courrier électronique, SMS-MMS et automate d’appel
- Spamhaus. Marketing email FAQ
LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.
