· OwnDesk · Cold email in the UK · 8 min read
Is B2B cold email legal in the UK? What the rules say
Yes, to companies and LLPs, if you say who you are and give a way to opt out. Sole traders need consent. What PECR, UK GDPR, Gmail and Outlook require.
If you’re a UK founder, financial adviser or wealth manager emailing prospects you’ve never spoken to, these are the rules that apply. It’s what PECR, UK GDPR, the ICO and the big mailbox providers say, not legal advice.
Are cold emails legal in the UK?
Yes, for business-to-business email to companies. PECR’s consent rule for marketing email covers individual subscribers, not corporate ones, so you can email staff at limited companies, LLPs and Scottish partnerships without prior consent. You must still say who you are, give a valid opt-out address, and follow UK GDPR when you’re emailing a named person.
The detail sits in two regulations. Regulation 22 of PECR bans unsolicited marketing email without consent, but only to “individual subscribers”. Regulation 23 covers every marketing email, company or not. You can’t disguise who it’s from, and you must give a valid address where people can ask you to stop.
The ICO’s business-to-business marketing guidance adds three points:
- You should honour a company’s opt-out and keep a “do not email” list, even though PECR doesn’t spell that out for companies.
- If you can’t tell whether an address belongs to a company or an individual subscriber, treat it as an individual.
- If your open-tracking pixels read or store information on the reader’s device, PECR’s cookie rules apply to every subscriber, companies included.
The ICO says its PECR guidance is under review because of the Data (Use and Access) Act 2025. Check the live pages before you plan a campaign.
Is it legal in the UK to send cold emails to self-employed people?
Only if they’ve agreed to it, or the “soft opt-in” applies. PECR treats sole traders and ordinary partnerships outside Scotland as individuals, the same as consumers. The soft opt-in only covers people who bought, or talked about buying, something similar from you and were offered an opt-out.
The ICO’s electronic mail marketing guidance sets out the soft opt-in. All four conditions must be true:
- You got their details during a sale, or negotiations for a sale.
- You’re marketing your own similar products or services.
- You gave them a clear chance to opt out when you collected the details.
- You give them that chance again in every message.
A bought or scraped list fails the first condition, because the details didn’t come from a sale or a sales conversation with you.
The hard part is telling a sole trader from a company. A one-person advice firm could be either, and its website may not say. You can search Companies House for free. If the firm isn’t registered as a company or LLP, or you can’t tell, the ICO says to treat the address as an individual’s. Its own example treats a personal address, used instead of a work one, as an individual subscriber too.
Is cold emailing businesses still allowed under GDPR, as long as I give them a way to opt out?
Usually yes, but the opt-out is only part of it. A work email that names a person is personal data, so you need a lawful basis. The ICO says legitimate interests is likely to fit emails to business contacts, but only if you pass its three-part test: purpose, necessity and balance.
Since the Data (Use and Access) Act 2025, Article 6(11) of the UK GDPR names direct marketing as processing that “may” be a legitimate interest. The ICO’s legitimate interests guidance stresses that it isn’t automatic. For business contacts, it says you may find the balancing test straightforward, because people expect contact in a work setting.
What the ICO and the UK GDPR expect in practice:
- Write the test down. The ICO calls this a legitimate interests assessment (LIA). The law doesn’t require one, but the ICO says “you should do one anyway” and offers a sample template.
- Tell people who you are and where you got their details. Under Article 14, when you use the data to contact someone, this must happen by your first message at the latest.
- Tell them they can object, in that first message, “separately from any other information” (Article 21(4)).
- When someone objects, stop. The right to object to direct marketing is absolute. The ICO suggests adding them to a suppression list rather than deleting them, so you can screen future lists against it.
Is it against the law to send emails without an unsubscribe link?
The law asks for a way to opt out, not a link as such. PECR regulation 23 bans marketing email with no valid address for stop requests, and UK GDPR says your first email to a named person must mention their right to object. Gmail and Yahoo separately require one-click unsubscribe from bulk senders.
For sole traders on the soft opt-in, regulation 22(3) asks for more: a simple, free way to refuse in every message.
The mailbox providers are where “link” becomes literal. Google’s sender guidelines say anyone sending 5,000 or more messages a day to Gmail accounts must support one-click unsubscribe on marketing messages. They must also show a visible unsubscribe link in the body. Google’s sender FAQ recommends acting on unsubscribes within 48 hours. Yahoo asks bulk senders for the same one-click header and to honour unsubscribes within 2 days.
Google’s rules are written for personal accounts ending in @gmail.com or @googlemail.com. A firm that runs its email on Google Workspace isn’t one. Even so, Google says one-click unsubscribe helps you keep a low spam rate, and a high spam rate hurts delivery of everything you send.
How many outbound emails can you send per day without being banned?
There’s no legal number. The hard caps come from your provider: Google Workspace allows 2,000 messages a day per user, or 500 on a trial, and Microsoft 365 allows 10,000 recipients a day per mailbox. Instantly, a cold email tool, recommends far less: 30 campaign emails per inbox per day.
The provider caps are in Google’s Workspace sending limits and Microsoft’s Exchange Online limits. Instantly’s figure is on its account limits page, and we cover the tool in our Instantly review. The mailbox providers also set reputation rules:
- Google treats you as a bulk sender once you send close to 5,000 messages in 24 hours to personal Gmail accounts. The label is permanent, and mail from your subdomains counts towards your main domain.
- Google asks you to keep the spam rate shown in Postmaster Tools below 0.1% and never let it reach 0.3%. Yahoo’s limit is also 0.3%.
- Microsoft requires domains sending over 5,000 emails a day to Outlook.com, Hotmail and Live addresses to pass SPF, DKIM and DMARC checks.
- Microsoft also says Microsoft 365 customers who need to send bulk commercial email should use a specialist provider.
Google’s advice on building volume is plain. Start low, send at a steady rate, avoid sudden spikes, and cut back if bounces or deferrals rise.
One line in Google’s guidelines is worth reading twice. It says: “Don’t send messages to people who didn’t sign up to get messages from you.” Cold email does exactly that, so every campaign carries some risk of spam reports. A small daily count per inbox, a tight list and an easy way out all cut the number of people who press “spam”.
Should you send cold emails from your own domain or a separate domain?
Use a separate domain. Yahoo’s sender guidance says each IP and DKIM domain has its own reputation, that unsolicited commercial email can damage it, and that bulk mail should be kept apart from your everyday mail. A second domain keeps spam reports away from the address your clients, invoices and replies depend on.
A subdomain gives you less separation at Gmail. Google counts mail from subdomains towards the main domain’s 5,000-a-day bulk sender total.
How long to warm up a new domain, and how to set it up:
- Instantly’s warm-up guidance says to warm a new inbox for at least 2 weeks before it sends campaigns, or 3 weeks for its AirMail inboxes.
- Its setup guide suggests no more than 3 to 5 inboxes per domain.
- Set up SPF, DKIM and DMARC on the new domain first. Google requires SPF or DKIM from every sender, and all three from bulk senders.
- Keep it recognisably yours. PECR bans disguising who an email is from, and Google says display names and sender details should identify the sender accurately. Pick a domain people can connect to your firm, and name the firm in the email.
Sources
- PECR regulation 22: use of electronic mail for direct marketing
- PECR regulation 23: concealed identity or address
- ICO: business-to-business marketing
- ICO: electronic mail marketing
- ICO: when can we rely on legitimate interests?
- ICO: how do we apply legitimate interests in practice?
- UK GDPR Article 6, Article 14 and Article 21
- GOV.UK: get information about a company
- Google: email sender guidelines and sender guidelines FAQ
- Google: Gmail sending limits in Google Workspace
- Yahoo: sender best practices
- Microsoft: Outlook’s requirements for high-volume senders
- Microsoft: Exchange Online limits
- Instantly: account and campaign limits, how warm-up works and cold email strategy
Want cold email run alongside LinkedIn outreach sent by hand? See our lead generation service.
- cold email
- PECR
- UK GDPR
- deliverability