The sender requirements everyone is anxious about do not formally apply to business to business email. Read the pages themselves and they say so.

The threshold that triggers the stricter regime at one major provider is, in its own words, “close to 5,000 messages or more to personal Gmail accounts within a 24-hour period”. Another frames its whole requirements page around delivery to its own consumer domains. A third scopes its high volume rules to its consumer service explicitly. If your list is corporate domains, none of the three regimes binds you.

That is not permission to be sloppy, and the rest of this piece explains why. But it does mean the compliance panic sold alongside most outreach tooling is aimed at a rule you are not subject to, while the things that actually decide whether a campaign works get two paragraphs and a template.

This page walks the campaign in the order it is built: what your mailbox will let you send, where the list can legally come from, what verification cannot do, what the evidence on writing actually supports, and what is still measurable now that open rates are not.

What your mailbox will actually let you send

The two dominant suites cap different things, which is why comparing their numbers directly produces nonsense.

One counts messages sent. The other counts recipients reached, over a rolling window rather than a calendar day. A four-message sequence to 1,000 contacts is 4,000 messages on one platform and up to 4,000 recipient events on the other, and the ceilings you hit are not in the same place.

Published sending ceilings of the two dominant business email suitesTable comparing the published sending ceilings of the two dominant business email suites as documented on their own support pages in September two thousand twenty six. The first provider counts messages sent per user per day, with a ceiling of two thousand messages on a paid account and five hundred on a trial account, a maximum of two thousand recipients per message of which at most five hundred may be external, a separate ceiling of three thousand external recipients per day, and no published per minute rate. On exceeding a limit the user receives an error and cannot send new messages for up to twenty four hours while continuing to receive mail and use other services. The same provider states that trial limits do not lift on upgrade alone, increasing only once the domain has cumulatively paid at least one hundred dollars, a process that can take up to seventy five days. The second provider counts recipients reached over a rolling twenty four hour window, with a ceiling of ten thousand recipients per day identical across all business plans, a per message recipient limit configurable up to one thousand, a rate limit of thirty messages per minute above which messages are queued and carried over rather than blocked, and a tenant wide external recipient ceiling that scales with licence count and is capped at five thousand per day on a trial tenant. The documentation of the second provider states that the service is not suited to accommodate bulk mailing scenarios and recommends third party providers specialising in such services.What the mailbox lets outFigures published by the providers themselves, read in September 2026.What is cappedFirst providerSecond providerUnit countedMessages sent per dayRecipients over rolling 24 hPer user ceiling2,000, or 500 on trial10,000, all business plansPer message2,000, of which 500 externalConfigurable up to 1,000RateNot published30 messages per minuteOn exceedingSending blocked up to 24 hQueued and carried overThe second provider’s own documentation: the service “isn’t suited to accommodate bulk-mailing scenarios”.
Two providers, two units of account. One caps messages leaving, the other caps recipients reached over a rolling 24 hours.

Three details that catch people out.

Trial limits do not lift when you upgrade. One provider states that sending limits rise only once the domain “has cumulatively paid at least $100 USD”, and that it “can take up to 75 days after meeting this payment threshold”. A new domain spun up for outreach is on trial limits for longer than most campaign calendars.

The second provider tells you not to do this. Its own documentation says the service “isn’t suited to accommodate bulk-mailing scenarios” and directs customers who need to send legitimate bulk commercial email to third party providers. When the vendor says you are outside its use case, that is not a limit to route around.

Two rules that get attributed to the wrong provider. The widely repeated obligation to process unsubscribe requests within two days is not on the first provider’s current guidelines or FAQ; it belongs to the second consumer provider. And the numeric 5,000 threshold belongs to the first; the second publishes no number at all. Both errors circulate in the same vendor blog posts, usually together.

Where a US B2B list can legally come from

This is where most campaigns rest on a belief that does not survive checking. We checked.

What United States public business registries containTable describing what four categories of United States public business data actually expose, each verified by querying the source or reading its published data dictionary rather than by assumption. State secretary of state business registries expose entity name, status, entity type, formation date, principal and mailing postal addresses and the registered agent name and postal address; a live query of one state open data endpoint returned thirty five columns and no email field of any kind. The federal contractor registry exposes in its public tier the entity name, unique identifier, registration details, physical and mailing addresses, business types, procurement classification codes and point of contact names and addresses, while point of contact email addresses, telephone and fax numbers sit in a restricted tier requiring a federal system account with read permission and an associated key, which a commercial marketer cannot obtain. The federal statistical business register is confidential by statute, may not be used for any purpose other than the statistical purposes for which it was supplied, may not be published in a form allowing an individual establishment to be identified, and carries criminal penalties including imprisonment. The annual information return filed by tax exempt organisations collects the organisation name, postal address, employer identification number, telephone number, the name and address of the principal officer and the website address, and contains no email field anywhere on the form. The table concludes that a compliant list joins public firmographic identity to contact data sourced elsewhere, and that any claim to extract email addresses from these registries is either pattern inference or misrepresentation.Four public sources, zero email addressesSourceWhat it givesEmail?State business registryEntity name, status, type, formation date,postal addresses, registered agentNo, 35 fieldsFederal contractor registryIdentity, addresses, business types, codes,contact names and postal addressesRestrictedfederal accountStatistical business registerNothing identifiable. Confidential by statute,criminal penalties for disclosureNeverNonprofit annual returnName, postal address, telephone, website,named principal officerNo field
Four public sources, none of which exposes an email address. Firmographics are public. Contact data is not.

We queried one state’s open business dataset live. It returns 35 columns: entity name and identifier, status, type, formation date, principal and mailing postal addresses, and the registered agent’s name and postal address. The fields labelled “mailing” are postal. There is no email column.

The federal contractor registry is the one worth getting right, because it is the one most often invoked. Point of contact email addresses do exist in its schema. They sit in the restricted tier, which the agency’s own data dictionary reserves to holders of “a Federal System Account with the ‘Read FOUO’ permission”. The public tier returns the contact’s name and postal address. Anyone telling you they pull verified emails from it is either inferring an address from a name pattern or describing something else.

The statistical business register is not merely restricted but confidential by statute, with penalties running to imprisonment. And the annual return filed by tax exempt organisations, often suggested as a nonprofit prospecting source, collects postal address, telephone, website and named officers, and has no email field anywhere on the form.

So the honest description of a compliant US B2B list is this: public registries give you identity, firmographics and targeting. The address itself always comes from somewhere else, and “somewhere else” is what you must be able to account for when asked.

What address verification cannot do

Verification works by opening a connection to the recipient’s mail exchanger, naming the recipient, reading the reply code and hanging up before any message body is sent. It has two blind spots, and both sit in the protocol rather than in the tool you buy.

Catch-all domains. A server configured to accept all mail for its domain answers favourably to every address, real or invented. The standard itself anticipates this: it defines a dedicated reply code for the case where “an address appears to be valid but cannot reasonably be verified in real time”, specifically where the server answering you is a mail exchanger fronting some other system with no local knowledge of the mailbox. Catch-all configurations are common at exactly the small and mid-sized companies B2B campaigns target.

Greylisting. A separate standard describes the technique: temporarily reject mail from an unrecognised sender and require a retry, on the reasoning that a real mail server retries and a robot does not. During that first rejection a perfectly valid address is indistinguishable from a nonexistent one.

There is a third point, less often made, that should affect how you run verification at all. A probe that connects, names a recipient and disconnects before sending is behaviourally identical to a directory harvest attack. Running it at volume from your sending address is a good way to have that address flagged by the very domains you intend to mail.

So a good verification tool is not one that returns a clean binary. It is one that reports three states instead of two, and a high share of “unknown” is not a defect in the tool, it is information about your list.

Bounce thresholds are contracts, not measurements

This deserves saying plainly because it is sold as science. No standards body, regulator or neutral authority publishes a maximum bounce rate. Every figure in circulation is a sending platform setting the terms of its own service.

The clearest illustration comes from the most transparent provider in the market, which is why it is worth using.

Published bounce and complaint thresholds from one sending platformTable setting out the bounce and complaint thresholds published by a single large sending platform on its own documentation pages, and the internal inconsistency between them. On its reputation dashboard page the platform states that a bounce rate of five per cent or greater places the account automatically under review, and that a bounce rate of ten per cent or greater may cause the platform to pause the account ability to send further email. On its enforcement frequently asked questions page, the same platform recommends maintaining a bounce rate below two per cent, a different figure from the five per cent ceiling given on the other page. For complaints, a rate of one tenth of one per cent or greater places the account under review, and a rate of five tenths of one per cent or greater may cause sending to be paused. Critically, the platform states that it does not calculate the bounce rate over a fixed period of time because different senders send at different rates, and that it instead uses a representative volume that differs for each user and changes as sending patterns change. Asked directly whether a customer can calculate their own bounce rate from the console or the sending statistics interface, the platform answers no. The table concludes that these figures are account suspension triggers set unilaterally by a provider and published so that customers can avoid tripping them, that they are not measured findings about deliverability, and that they are not portable between providers.Thresholds set by a vendor, not by a standardSignalUnder reviewSending may be pausedBounce rate5 % or greater10 % or greaterComplaint rate0.1 % or greater0.5 % or greaterThe same provider, another page“maintain a bounce rate below 2%”Two recommended ceilings, one product.Can you compute it yourself?No.The denominator is a “representative volume” it does not disclose.
Published thresholds from a single provider, on two of its own pages. The ceilings disagree, and the denominator is undisclosed by design.

One provider publishes a 5 per cent ceiling on one page and a 2 per cent ceiling on another. It also states that the rate is not computed over a fixed period, but over a representative volume that “is different for each user and changes as the user’s sending patterns change”, and answers a direct question about whether customers can calculate the figure themselves with a flat no.

Treat these numbers for what they are: suspension triggers, published so you can avoid tripping them. They are not findings, and they do not transfer between providers.

What the evidence on writing actually says

Here is the part everyone talks about and almost nobody has evidence for.

There is exactly one peer-reviewed field experiment on email personalisation worth citing. It ran with three companies across millions of recipients and measured a single intervention: adding the recipient’s first name to the subject line. Opening probability rose by 20 per cent, sales leads by 31 per cent, and unsubscribes fell by 17 per cent.

Those relative figures are the ones that circulate. The levels are not, and they change the meaning entirely.

What the personalisation experiment measuredTwo column comparison of what the single peer reviewed field experiment on email personalisation actually measured against how it is generally cited. The left column sets out the measured results: adding the recipient first name to the subject line raised the probability of opening from nine point zero five per cent to ten point eight per cent, a twenty per cent relative increase; raised sales leads from thirty nine hundredths of a per cent to fifty one hundredths of a per cent, a thirty one per cent relative increase but an absolute movement of only twelve hundredths of a percentage point; and reduced unsubscribes from one point two per cent to one per cent, a seventeen per cent relative reduction. The right column sets out the context that is usually dropped when the study is cited: the experiment was conducted in consumer marketing and not business to business; it was run on the companies own existing mailing lists rather than on cold contacts, as demonstrated by the fact that unsubscribe rate was a measured outcome, which is only possible for recipients already on a list; the intervention was a first name in a subject line and nothing more, the papers own thesis being that this content is non informative and adds nothing about the product or the company, with the proposed mechanism being increased attention to the rest of the message. The figure concludes that no independent peer reviewed measurement of personalisation in cold business to business outreach exists, and that every larger figure in circulation comes from a vendor selling personalisation features.What was measured, and what was notMeasuredRandomised field experiment, peer reviewed.Opens: 9.05 % to 10.80 %a 20 % relative riseLeads: 0.39 % to 0.51 %the famous “31 % more leads”Unsubscribes: 1.2 % to 1.0 %The intervention: a first name in a subject line.Not measuredDropped whenever the study is quoted.Anything business to businessAnything cold. These were thecompanies’ own lists.Any research beyond a first nameAny effect on repliesNo independent study of cold B2B exists.
A real and well-designed result. The 31 per cent lift in leads is an absolute movement of twelve hundredths of a percentage point.

The lead rate moved from 0.39 per cent to 0.51 per cent. That is the famous “31 per cent more leads”: twelve hundredths of a percentage point. And the context is consumer marketing to the companies’ own lists, not cold outreach to strangers. The giveaway is that unsubscribe rate is a measured outcome, and you can only unsubscribe from a list you are already on.

We searched hard for an independent peer-reviewed measurement of personalisation in cold B2B outreach. There is none. Every larger figure traces to a company selling personalisation features, with no published method and no inspectable control group.

The practical reading is not that personalisation fails. It is that the choice is about volume, not quality. Real personalisation, a sentence that could not have been written to another company, does not automate and forces a short list. Variable insertion automates and scales, and its most reliable effect is negative when a merge field fails visibly in the middle of a sentence. Wanting both at once is the contradiction at the centre of most campaigns.

Open rates broke in 2013, not 2021

The privacy feature usually blamed for the death of open tracking arrived in 2021. The real break came eight years earlier.

One provider announced in December 2013 that it would stop serving images from their original hosts and serve them “through Google’s own secure proxy servers”. From that day the pixel request came from infrastructure rather than from a reader: no recipient address, no device, no location, and caching that makes repeat opens unreliable. That provider states on its sender guidelines, in its own words, that it does not track open rates and cannot verify the accuracy of open rates reported by third parties.

The later mail privacy feature added a second layer, and one detail is almost universally misreported. It is not on by default. The vendor’s own support pages describe it as something the user turns on, and the phrase “by default” on its legal page refers to how the feature behaves once active, not to whether it is active. Whichever way a given recipient went, you cannot tell from your own data which group they are in.

That is the real problem. Not that opens are inflated, but that the contamination rate is unobservable, so there is no correction factor. Drop the metric rather than adjust it.

What remains measurable in a cold email campaignTwo column comparison of the signals that remain reliably measurable in a business to business cold email campaign against those that no longer are. The left column lists four signals observed by a mail server rather than reported by a recipient device. Delivery and rejection at the protocol level, including hard bounces, soft bounces, deferrals and error codes, are transactional and server observed. The spam complaint rate is reported through the sending reputation tools of the mailbox providers, though one provider computes it only on mail delivered to the inbox. Replies of any kind, including refusals, are the only unambiguous positive signal in cold outreach and the one that maps to revenue. Domain and address reputation is reported through provider postmaster tools. The right column lists three signals that no longer support a decision. The open rate has been structurally compromised since December two thousand thirteen, when one provider began routing all images through its own proxy servers, and that provider states that it does not track open rates and cannot verify those reported by third parties; a later mail privacy feature on another platform added further noise, and because the share of recipients affected is unobservable there is no correction factor. Click counts are inflated by enterprise security gateways, whose documentation states that links without an established reputation are detonated asynchronously in the background, a fetch that outreach tools record as a click. Offline attribution fails because the analytics protocol identifies a user by an identifier generated in a browser and imposes a forty eight hour window for joining later events, while a business to business sales cycle runs for weeks to quarters.What a server saw, and what a browser was meant to reportStill measurableObserved server side, not device side.Delivery and rejection codesHard bounces, the quality of the listComplaint rate, the only sanctionReplies, refusals includedA refusal proves the message arrivedand was read.No longer decidableContamination rate unobservable.Opens, broken since December 2013image proxying, then mail privacyClicks, inflated by security gatewaysunknown links are detonated in advanceOffline attribution, 48 hour windowagainst a sales cycle of weeks or quarters.
Four signals a server observed, and three a browser was supposed to report. Only the first group survives contact with modern mail clients.

Clicks survive, with two caveats worth knowing. Enterprise security gateways rewrite and inspect inbound links, and the dominant one documents that URLs without an established reputation “are detonated asynchronously in the background”. A new tracking domain has no reputation by definition, so it gets fetched, and your tool records that fetch as a click. The same documentation warns that wrapping links with another service beforehand “might prevent Safe Links from processing links”, which is a poor position to be in with a security product. Note who has this deployed: it is a business product, so it is precisely your B2B recipients.

And the organisation that maintains the main domain blocklist publishes a dedicated return code for “abused spammed redirector domain”. Shared tracking domains are listable as a unit, which means your click links carry the aggregate behaviour of your tool’s worst customer. A tracking subdomain on a domain you control is the fix.

Where the campaign leaks on the way to a deal

Two failure modes are documented by the vendors themselves, and both are quiet.

Merging is irreversible and opt-out attaches to the address. One major CRM states flatly that “it’s not possible to unmerge records”, and that an opt-out import does not create a contact at all but marks the address as ineligible. Opt-out therefore lives against the address rather than the person. A routine enrichment job that “corrects” an address can resurrect someone who opted out, with no warning and no audit trail.

Attribution cannot reach a deal closed offline. The analytics protocol identifies a user by an identifier that a browser generated, and a call or a meeting produces none. Even when you capture that identifier at a web interaction and store it, the platform documents a 48-hour window for joining later events, and warns that events arriving after it may not be processed as expected “particularly for purposes like conversion attribution”. A B2B cycle is weeks to quarters. The window expires by one to two orders of magnitude.

This is not a tagging problem with a tagging solution. Source attribution belongs in the CRM, entered by a person at the point of conversation. Tracking parameters still tell you which email produced a visit. They cannot tell you which email produced revenue.

What to do with this

Start with the list, because it is the only step where an error cannot be recovered. Write down where every address came from and when. If you cannot answer that for a segment, do not mail it.

Compute your daily load before you build a sequence: contacts multiplied by messages, divided by working days and by the number of mailboxes. If the answer approaches the ceilings above, cut the list rather than stretching the calendar. Approaching a bulk sender threshold on a B2B campaign is itself the signal that targeting was skipped.

Take open rate out of your reporting entirely, and replace it with four things a server observed: delivery, hard bounces, complaints and replies. Count refusals as replies, because a refusal proves the message arrived and was read.

Then put one question at the start of every discovery call: how did you come across us. Recorded at the meeting rather than modelled afterwards, it produces the only attribution that survives a long sales cycle.

The related pieces are what US law actually allows in cold email and the real cost of social selling.