Map the audience and responsibilities
List the recipient countries, organisation types and contact sources, and record the purpose of each message. A new promotional invitation needs to be considered separately from information for someone who has already registered. A complimentary invitation can still carry marketing obligations.
We recommend naming an organiser contact and a campaign owner, then assigning responsibility for approving the data and messages in each market. Record who controls the mailbox, who can access contact records and how suppliers receive their instructions. Someone also needs responsibility for objections. Get a specific review where the applicable rules are unclear.
Confirm the UK, US and European requirements separately
The UK's ICO distinguishes corporate subscribers from sole traders and some partnerships when explaining business email marketing. Its guidance also makes clear that UK GDPR can apply to named business contacts and that objections must be respected. A publicly listed business address is not, by itself, a complete permission assessment. See the ICO's business-to-business guidance, which is currently flagged as under review.
For US commercial email, the FTC's CAN-SPAM compliance guide covers accurate sender information, non-deceptive subjects, advertising identification, a valid postal address and an effective opt-out. It specifies honouring opt-outs within 10 business days. Hiring a supplier does not remove the advertiser's potential responsibility. The message's primary purpose matters when assessing which provisions apply.
For EU audiences, the European Commission explains that third-party contact data needs an appropriate basis for use and that email marketing must also comply with ePrivacy rules. Its third-party marketing-data guidance is a starting point. Check the relevant national requirements for the specific campaign. For other destinations, obtain the corresponding local assessment rather than transferring a UK or US assumption.
Check authentication with the actual sending service
Google's sender guidelines for personal Gmail accounts require SPF or DKIM for all senders and add SPF, DKIM, DMARC and other requirements for bulk senders. Relevant bulk marketing messages also need one-click unsubscribe and a visible unsubscribe link. These requirements have a defined scope; review the complete guidance against the campaign's sending pattern.
For the setup check, we recommend listing every authorised sender and confirming the domain configuration with the provider. Inspect the authentication results on test messages. Then test what the recipient sees and can do: the From address, reply route, links and unsubscribe mechanism. Domain purchase and DNS records are only part of that check.
Make suppression work across the whole campaign
Keep a controlled record of people who should receive no further marketing. Test a removal request sent as a direct reply as well as the unsubscribe mechanism. Check that fresh list imports preserve the exclusion and that another team member can take over without losing it.
We recommend checking suppression before every send and assigning someone to process requests. Keep enough of an audit record to prevent accidental recontact. Agree how the team will review bounced addresses, role changes and complaints. Personal contact records must stay out of public reports and shared website assets.
Ramp sending according to evidence
Google recommends gradual volume increases, monitoring delivery responses and avoiding sudden bursts; it also advises against purchased lists and messages to people who have not subscribed. These provider expectations sit alongside legal requirements. Review both in the Gmail sender guidance before choosing a sending approach.
Agree a modest first batch, the checks required before expanding and the conditions that will pause sending. Investigate authentication errors, repeated delivery failures and complaints. Adding more mailboxes does not resolve those causes. Monitor any warm-up schedule as an operational plan. It cannot establish permission to contact someone or guarantee inbox placement.
Keep a clear launch record
Before launch, record the approved audience scope and sender tests, together with the current exclusion process, reply owner and reporting definitions. Review that record if the country mix, provider or message purpose changes. The organiser should be able to see what is ready and which decisions remain open.
Editorial and source note
By Summitrix editorial team. Draft for founder review. Official guidance accessed 26 September 2026 and may change. Process recommendations are identified separately from sourced requirements. Confirm the requirements for the actual campaign and jurisdictions before sending.
Sources and further reading
- ICO business-to-business marketing guidance
- FTC CAN-SPAM compliance guide
- European Commission third-party marketing-data guidance
- Google personal Gmail sender guidelines
Sources checked 26 September 2026. Guidance can change. This article combines cited source information with Summitrix’s proposed working approach.