The sender requirements everyone is anxious about do not formally apply to business to business email. Read the pages themselves and they say so.
The threshold that triggers the stricter regime at one major provider is, in its own words, “close to 5,000 messages or more to personal Gmail accounts within a 24-hour period”. Another frames its whole requirements page around delivery to its own consumer domains. A third scopes its high volume rules to its consumer service explicitly. If your list is corporate domains, none of the three regimes binds you.
That is not permission to be sloppy, and the rest of this piece explains why. But it does mean the compliance panic sold alongside most outreach tooling is aimed at a rule you are not subject to, while the things that actually decide whether a campaign works get two paragraphs and a template.
This page walks the campaign in the order it is built: what your mailbox will let you send, where the list can legally come from, what verification cannot do, what the evidence on writing actually supports, and what is still measurable now that open rates are not.
What your mailbox will actually let you send
The two dominant suites cap different things, which is why comparing their numbers directly produces nonsense.
One counts messages sent. The other counts recipients reached, over a rolling window rather than a calendar day. A four-message sequence to 1,000 contacts is 4,000 messages on one platform and up to 4,000 recipient events on the other, and the ceilings you hit are not in the same place.
Three details that catch people out.
Trial limits do not lift when you upgrade. One provider states that sending limits rise only once the domain “has cumulatively paid at least $100 USD”, and that it “can take up to 75 days after meeting this payment threshold”. A new domain spun up for outreach is on trial limits for longer than most campaign calendars.
The second provider tells you not to do this. Its own documentation says the service “isn’t suited to accommodate bulk-mailing scenarios” and directs customers who need to send legitimate bulk commercial email to third party providers. When the vendor says you are outside its use case, that is not a limit to route around.
Two rules that get attributed to the wrong provider. The widely repeated obligation to process unsubscribe requests within two days is not on the first provider’s current guidelines or FAQ; it belongs to the second consumer provider. And the numeric 5,000 threshold belongs to the first; the second publishes no number at all. Both errors circulate in the same vendor blog posts, usually together.
Where a US B2B list can legally come from
This is where most campaigns rest on a belief that does not survive checking. We checked.
We queried one state’s open business dataset live. It returns 35 columns: entity name and identifier, status, type, formation date, principal and mailing postal addresses, and the registered agent’s name and postal address. The fields labelled “mailing” are postal. There is no email column.
The federal contractor registry is the one worth getting right, because it is the one most often invoked. Point of contact email addresses do exist in its schema. They sit in the restricted tier, which the agency’s own data dictionary reserves to holders of “a Federal System Account with the ‘Read FOUO’ permission”. The public tier returns the contact’s name and postal address. Anyone telling you they pull verified emails from it is either inferring an address from a name pattern or describing something else.
The statistical business register is not merely restricted but confidential by statute, with penalties running to imprisonment. And the annual return filed by tax exempt organisations, often suggested as a nonprofit prospecting source, collects postal address, telephone, website and named officers, and has no email field anywhere on the form.
So the honest description of a compliant US B2B list is this: public registries give you identity, firmographics and targeting. The address itself always comes from somewhere else, and “somewhere else” is what you must be able to account for when asked.
What address verification cannot do
Verification works by opening a connection to the recipient’s mail exchanger, naming the recipient, reading the reply code and hanging up before any message body is sent. It has two blind spots, and both sit in the protocol rather than in the tool you buy.
Catch-all domains. A server configured to accept all mail for its domain answers favourably to every address, real or invented. The standard itself anticipates this: it defines a dedicated reply code for the case where “an address appears to be valid but cannot reasonably be verified in real time”, specifically where the server answering you is a mail exchanger fronting some other system with no local knowledge of the mailbox. Catch-all configurations are common at exactly the small and mid-sized companies B2B campaigns target.
Greylisting. A separate standard describes the technique: temporarily reject mail from an unrecognised sender and require a retry, on the reasoning that a real mail server retries and a robot does not. During that first rejection a perfectly valid address is indistinguishable from a nonexistent one.
There is a third point, less often made, that should affect how you run verification at all. A probe that connects, names a recipient and disconnects before sending is behaviourally identical to a directory harvest attack. Running it at volume from your sending address is a good way to have that address flagged by the very domains you intend to mail.
So a good verification tool is not one that returns a clean binary. It is one that reports three states instead of two, and a high share of “unknown” is not a defect in the tool, it is information about your list.
Bounce thresholds are contracts, not measurements
This deserves saying plainly because it is sold as science. No standards body, regulator or neutral authority publishes a maximum bounce rate. Every figure in circulation is a sending platform setting the terms of its own service.
The clearest illustration comes from the most transparent provider in the market, which is why it is worth using.
One provider publishes a 5 per cent ceiling on one page and a 2 per cent ceiling on another. It also states that the rate is not computed over a fixed period, but over a representative volume that “is different for each user and changes as the user’s sending patterns change”, and answers a direct question about whether customers can calculate the figure themselves with a flat no.
Treat these numbers for what they are: suspension triggers, published so you can avoid tripping them. They are not findings, and they do not transfer between providers.
What the evidence on writing actually says
Here is the part everyone talks about and almost nobody has evidence for.
There is exactly one peer-reviewed field experiment on email personalisation worth citing. It ran with three companies across millions of recipients and measured a single intervention: adding the recipient’s first name to the subject line. Opening probability rose by 20 per cent, sales leads by 31 per cent, and unsubscribes fell by 17 per cent.
Those relative figures are the ones that circulate. The levels are not, and they change the meaning entirely.
The lead rate moved from 0.39 per cent to 0.51 per cent. That is the famous “31 per cent more leads”: twelve hundredths of a percentage point. And the context is consumer marketing to the companies’ own lists, not cold outreach to strangers. The giveaway is that unsubscribe rate is a measured outcome, and you can only unsubscribe from a list you are already on.
We searched hard for an independent peer-reviewed measurement of personalisation in cold B2B outreach. There is none. Every larger figure traces to a company selling personalisation features, with no published method and no inspectable control group.
The practical reading is not that personalisation fails. It is that the choice is about volume, not quality. Real personalisation, a sentence that could not have been written to another company, does not automate and forces a short list. Variable insertion automates and scales, and its most reliable effect is negative when a merge field fails visibly in the middle of a sentence. Wanting both at once is the contradiction at the centre of most campaigns.
Open rates broke in 2013, not 2021
The privacy feature usually blamed for the death of open tracking arrived in 2021. The real break came eight years earlier.
One provider announced in December 2013 that it would stop serving images from their original hosts and serve them “through Google’s own secure proxy servers”. From that day the pixel request came from infrastructure rather than from a reader: no recipient address, no device, no location, and caching that makes repeat opens unreliable. That provider states on its sender guidelines, in its own words, that it does not track open rates and cannot verify the accuracy of open rates reported by third parties.
The later mail privacy feature added a second layer, and one detail is almost universally misreported. It is not on by default. The vendor’s own support pages describe it as something the user turns on, and the phrase “by default” on its legal page refers to how the feature behaves once active, not to whether it is active. Whichever way a given recipient went, you cannot tell from your own data which group they are in.
That is the real problem. Not that opens are inflated, but that the contamination rate is unobservable, so there is no correction factor. Drop the metric rather than adjust it.
Clicks survive, with two caveats worth knowing. Enterprise security gateways rewrite and inspect inbound links, and the dominant one documents that URLs without an established reputation “are detonated asynchronously in the background”. A new tracking domain has no reputation by definition, so it gets fetched, and your tool records that fetch as a click. The same documentation warns that wrapping links with another service beforehand “might prevent Safe Links from processing links”, which is a poor position to be in with a security product. Note who has this deployed: it is a business product, so it is precisely your B2B recipients.
And the organisation that maintains the main domain blocklist publishes a dedicated return code for “abused spammed redirector domain”. Shared tracking domains are listable as a unit, which means your click links carry the aggregate behaviour of your tool’s worst customer. A tracking subdomain on a domain you control is the fix.
Where the campaign leaks on the way to a deal
Two failure modes are documented by the vendors themselves, and both are quiet.
Merging is irreversible and opt-out attaches to the address. One major CRM states flatly that “it’s not possible to unmerge records”, and that an opt-out import does not create a contact at all but marks the address as ineligible. Opt-out therefore lives against the address rather than the person. A routine enrichment job that “corrects” an address can resurrect someone who opted out, with no warning and no audit trail.
Attribution cannot reach a deal closed offline. The analytics protocol identifies a user by an identifier that a browser generated, and a call or a meeting produces none. Even when you capture that identifier at a web interaction and store it, the platform documents a 48-hour window for joining later events, and warns that events arriving after it may not be processed as expected “particularly for purposes like conversion attribution”. A B2B cycle is weeks to quarters. The window expires by one to two orders of magnitude.
This is not a tagging problem with a tagging solution. Source attribution belongs in the CRM, entered by a person at the point of conversation. Tracking parameters still tell you which email produced a visit. They cannot tell you which email produced revenue.
What to do with this
Start with the list, because it is the only step where an error cannot be recovered. Write down where every address came from and when. If you cannot answer that for a segment, do not mail it.
Compute your daily load before you build a sequence: contacts multiplied by messages, divided by working days and by the number of mailboxes. If the answer approaches the ceilings above, cut the list rather than stretching the calendar. Approaching a bulk sender threshold on a B2B campaign is itself the signal that targeting was skipped.
Take open rate out of your reporting entirely, and replace it with four things a server observed: delivery, hard bounces, complaints and replies. Count refusals as replies, because a refusal proves the message arrived and was read.
Then put one question at the start of every discovery call: how did you come across us. Recorded at the meeting rather than modelled afterwards, it produces the only attribution that survives a long sales cycle.
The related pieces are what US law actually allows in cold email and the real cost of social selling.