Cold Email Strategy

    Cold Email in HubSpot: What Its Own Anti-Spam Policy Says You May Send

    Whether HubSpot can send cold email is a feature question. What it permits is a contract question, and HubSpot answers it in writing on a page most buyers never open.

    Editorial illustration for Cold Email in HubSpot
    August 18, 2026Updated August 16, 20267 min read
    Share:
    The short answer

    HubSpot's Anti-Spam Policy requires express, verifiable consent, prohibits contacting recipients from purchased, rented or enrichment lists in violation of laws or supplier terms, and counts one-to-one commercial mail within its definition of spam. It also reserves the right to request documentation of consent, and asks for complaint rates below 0.1%.

    Key takeaways

    • HubSpot's Acceptable Use Policy bars spam and binds you to a separate Anti-Spam Policy, which is where the operative definitions and thresholds live.
    • The policy names purchased, rented, borrowed and enrichment lists directly, and its consent requirement asks for a documented opt-in rather than a legitimate-interest argument.
    • HubSpot reserves the right to review lists, audit compliance and request documentation of consent, so the evidence has to exist in a form you could hand over.
    • Even where the contract permits a send, HubSpot leaves through your corporate domain and connected inboxes, which is the reputation your customer correspondence depends on.

    Reviewed and updated August 16, 2026

    The question people bring to this topic is whether HubSpot can send cold email. It can, mechanically, and that is the least useful thing to know about it. The decidable question is what HubSpot's own contract permits, and HubSpot answers it in writing on a page most buyers never open.

    HubSpot's Acceptable Use Policy contains one line at section 2.1 that everything else hangs from: you may not use HubSpot to send spam. Section 2.3 then binds you to a separate HubSpot Anti-Spam Policy, last modified 2 February 2026, and that document is where the word spam gets defined. It is worth reading before designing a prospecting motion around the platform, because the definition is stricter than the one most outbound teams work to.

    What HubSpot's Anti-Spam Policy actually prohibits

    Three provisions decide the question.

    The definition of spam. Section 2.1 lists unsolicited bulk messages sent to recipients who have not provided verifiable, explicit consent, unsolicited commercial messages or one-to-one commercial communications that violate applicable anti-spam laws, and messages sent in violation of applicable data protection regulations. The middle clause is the one that catches people out, because it reaches one-to-one email and not only bulk sends. A sequence of individually addressed messages is not outside the policy on the grounds that each one went to a single person.

    The list clause. Section 2.1.1 states that you are strictly prohibited from using the HubSpot Services to directly contact recipients from purchased, rented, borrowed, or other third-party lists, including email append services or enrichment services lists, in violation of applicable laws or third-party terms. Enrichment output is named explicitly, which matters because a great many outbound lists are exactly that.

    The consent requirement. Section 3.1 says messages sent through HubSpot Services must go only to recipients who have provided express, verifiable consent, opted in through a clear documented process, and not withdrawn that consent. Section 3.1.1 carves out two exceptions and they are narrow: purely transactional messages relating to an existing transaction or relationship with no marketing content, and internal communications to employees or stakeholders.

    Read those together and the policy describes a permission-based sending product. Cold prospecting to strangers sourced from a data vendor sits outside the shape it describes, whatever the tooling makes possible.

    One qualifier in the list clause deserves to be read carefully rather than skipped, because it is doing real work. Section 2.1.1 prohibits contacting recipients from those lists in violation of applicable laws or third-party terms, which means the clause inherits whatever your jurisdiction and your data supplier's contract say rather than banning the practice outright everywhere. That is genuinely different from a flat prohibition, and it is also a heavier obligation than it first reads as, because it puts you on the hook for the data vendor's terms as well as the statute. Establishing which laws apply, and what the supplier's contract permits, is homework somebody has to do and write down. It is not a question a support conversation will settle for you.

    What the policy describesSections 2.1, 2.1.1 and 3.1
    • Express, verifiable consent, documented through a clear opt-in process
    • No direct contact with recipients from purchased, rented or enrichment lists
    • One-to-one commercial mail is inside the definition of spam where laws are breached
    • Exceptions limited to transactional and internal messages
    What cold outbound isThe honest description
    • Recipients who never asked to hear from you
    • Lists built from data vendors and enrichment waterfalls
    • Individually addressed messages, sent at programme volume
    • Lawful basis argued from legitimate interest or a B2B exemption, not from opt-in
    What HubSpot's published Anti-Spam Policy asks of a sender, set against what a cold outbound programme typically looks like. Both columns are descriptions rather than recommendations.

    The enforcement half, which is not theoretical

    Section illustration: The enforcement half, which is not theoretical

    Section 4.1 sets out what HubSpot reserves the right to do. It may monitor sending patterns and content, review user lists and subscription practices, investigate complaints and suspicious activity, request documentation of consent, and audit compliance.

    That fourth power is the one to plan around. A programme whose consent evidence is an argument about legitimate interest rather than a stored opt-in record has nothing to hand over when asked. Whether that argument is legally sound in a given jurisdiction is a separate question from whether it satisfies a vendor's contract, and the two answers can differ.

    Section 3.6 adds numeric standards that are stricter than the provider thresholds most senders manage to. It requires bounce rates below 5% and spam complaint rates below 0.1%, with engagement consistent with industry standards and regular list hygiene. For comparison, Google's own sender guidelines ask senders of 5,000 or more daily messages to Gmail to keep the spam rate reported in Postmaster Tools below 0.30%. HubSpot's published figure is three times tighter than the mailbox provider's.

    Section 3.5 states that HubSpot maintains sending limits including daily limits based on account type and history, hourly rate limits, per-message recipient limits and automatic throttling for accounts showing signs of abuse. So volume is governed by the platform's read of your account rather than by a number you can plan against.

    The tooling gates sit on top of all that. HubSpot's own documentation for the sequences tool, last updated 3 August 2026, lists it as available with Sales Hub Professional or Enterprise and Service Hub Professional or Enterprise, with seats required. Reaching the feature is a subscription decision before it is a policy one.

    The part that is not about policy at all

    Suppose the contract question resolves in your favour, because you are messaging an existing relationship or your counsel is satisfied with the lawful basis where you operate. There is a second constraint underneath, and it does not care about consent.

    HubSpot sends from your identity. Connected inboxes are real people's mailboxes on your corporate domain, and marketing email is authenticated against your own sending domain, which section 3.2 of the Anti-Spam Policy requires you to configure properly with SPF, DKIM and DMARC records, valid DNS and authorised sending IPs. That is the same domain carrying your contracts, invoices, renewals, support threads and every live commercial conversation your account executives are having.

    Cold volume from that identity puts all of it on one reputation. A bad month in prospecting stops being a prospecting problem and becomes a deliverability problem in correspondence with customers, and the recovery is slow because reputation heals slowly. The separation of sending estates is the single most consequential architectural decision in an outbound programme, and it is undone the moment the prospecting mail leaves through the CRM's connected inboxes. The reasoning in full, along with what a separated estate looks like, is in the cold email infrastructure guide, the authentication half is in SPF, DKIM and DMARC for cold email, and the signal to watch is in Google Postmaster Tools.

    1. Step 1Corporate domain

      Contracts, invoices, renewals, support and live customer threads, sent from named people's mailboxes.

    2. Step 2CRM connected inboxes

      HubSpot sends through those same mailboxes and authenticates against that same domain.

    3. Step 3Prospecting volume added

      Complaints and spam-folder placement from strangers accrue to the identity carrying the customer mail.

    4. Step 4Separate estate instead

      Dedicated prospecting domains and warmed mailboxes, so the two workloads cannot damage each other.

    Two sending estates and the reputation each one carries. The separation is what keeps a bad prospecting week away from customer correspondence.

    Where HubSpot genuinely belongs in an outbound motion

    Section illustration: Where HubSpot genuinely belongs in an outbound motion

    None of the above is an argument for keeping the CRM out of outbound. It is an argument about which half of the job it does.

    The suppression check. Before anybody is contacted, somebody has to answer whether this company is already a customer, already in an open deal, already owned by a colleague, or has already asked not to be contacted. The CRM is the only system that knows, and the join has to happen before the send rather than after the reply. Keeping that answer in a suppression list the sending platform consults is what makes the rest safe.

    Routing and ownership. A reply is worth nothing until it reaches the right person with context attached, and that is CRM work.

    Reporting on outcomes rather than sends. Meetings, opportunities and revenue live in the CRM. Volume of email sent is an input and belongs nowhere near a leadership dashboard, because a metric that rewards sending more reliably produces more sending.

    Deduplication at the boundary. The moment two systems write contacts, you need a rule about which one wins and what counts as the same person. The worked example of that going wrong across a CRM boundary is in Apollo and HubSpot deduplication.

    Section 3.4 of the policy is worth reading even if you never send a marketing message from HubSpot, because it is a decent specification for any programme: a clear and conspicuous unsubscribe mechanism, one-click functionality, unsubscribe requests processed within 24 hours, suppression maintained and honoured across all channels, no login required, no fees or conditions. The mechanism itself is covered in one-click unsubscribe, and the wider legal picture in GDPR for B2B outbound.

    Which system owns which job
    • Yes: Suppression of customers, open deals and prior contacts lives in the CRM and is checked before the send
    • Yes: Prospecting mail leaves from dedicated domains and warmed mailboxes, not connected corporate inboxes
    • Yes: Replies route to a named owner with the account context attached
    • Yes: Opt-outs propagate from wherever they arrive into every list and every tool
    • Yes: Reporting counts meetings and opportunities rather than messages sent
    • Depends: Consent evidence exists in a form that could be handed over if a vendor asked for it
    • No: Cold lists loaded into the CRM's own sending tools because the feature is available
    Splitting an outbound programme between a CRM and a sending estate, with each line placed where the system that owns it actually sits.

    Where we sit

    Section illustration: Where we sit

    RevenueFlow does not sell HubSpot, resell it, or take a fee for configuring it, and we do not run our own prospecting through it. We run cold email and LinkedIn outbound on Email Bison and HeyReach, with dedicated sending domains kept separate from the mailboxes our own commercial conversations run through.

    Our campaigns send one message per prospect with nothing scheduled behind it. No thread replies and no bumps, because every step after the first reaches only people who already declined to answer, and the reply lift is measured inside a sequence while the reputation cost is paid across the whole domain. That argument in full is in why we run one-message campaigns instead. Meetings are qualified against criteria agreed in writing before launch.

    If you want to see what a properly separated programme produces on your own market before rebuilding anything, we will build the first campaign.

    HubSpot's Acceptable Use Policy and Anti-Spam Policy provisions, and the sequences subscription requirements, are per HubSpot's own published pages, fetched 16 August 2026. Google's 0.30% Postmaster spam-rate guidance is per Google's published email sender guidelines, fetched the same day. Nothing here is legal advice. Verify current terms with the vendor and with counsel before relying on them.

    Questions

    Frequently asked questions.

    Frequently asked questions
    Does HubSpot allow cold email?
    Its Anti-Spam Policy requires express, verifiable consent captured through a documented opt-in, with exceptions only for transactional and internal messages. It separately prohibits contacting recipients from purchased, rented or enrichment lists in violation of applicable laws or supplier terms. That describes a permission-based product rather than a prospecting one.
    Do HubSpot sequences count as cold email under the policy?
    The definition of spam in section 2.1 covers unsolicited commercial messages and one-to-one commercial communications that breach applicable anti-spam laws, so individually addressed sequence mail is not exempt by virtue of being one to one. Sequences also require Sales Hub or Service Hub Professional or Enterprise with seats assigned.
    What complaint rate does HubSpot expect?
    Its Anti-Spam Policy asks senders to keep bounce rates below 5% and spam complaint rates below 0.1%, alongside regular list hygiene. That threshold is roughly three times tighter than Google's published guidance, which asks senders of 5,000 or more daily Gmail messages to keep Postmaster spam rates below 0.30%.
    Where should a CRM sit in an outbound programme?
    On the record side rather than the sending side. The CRM owns the suppression check before anyone is contacted, reply routing and ownership, and reporting on meetings rather than sends. Prospecting mail belongs on dedicated domains and warmed mailboxes kept structurally separate from customer correspondence.
    HubSpotCold EmailComplianceDeliverabilityCRM
    Byline

    About the author.

    Ben Carden

    Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.

    Ben Carden · CRO

    Connect on LinkedIn →
    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.

    Cold Email Strategy

    Suppression List: What It Means and Why the Textbook Definition Misleads

    A suppression list is the memory of every instruction you have been given about who not to contact. Its value comes entirely from being enforced everywhere.

    7 min readRead →
    Cold Email Strategy

    Yesware Email Tracking: What the Open Notification Actually Proves

    Yesware tracks opens, clicks and attachment views from inside Gmail and Outlook. What each event proves, what every tier costs, and why an open is not a trigger.

    7 min readRead →
    Cold Email Strategy

    GDPR for B2B Outbound: What Emailing Contacts in Europe Actually Requires

    Territorial scope, the assessment behind a legitimate interest send, the national ePrivacy layer that decides whether you may send, and what the first message carries.

    11 min readRead →
    Cold Email Strategy

    CAN-SPAM Act Compliance for B2B Cold Email: What the Law Requires

    The CAN-SPAM Act makes no exception for business-to-business email. Here are the seven requirements, the opt-out clocks, and where liability lands when an agency sends.

    11 min readRead →
    Cold Email Strategy

    CCPA Compliance for Cold Outreach: The B2B Exemption That Lapsed

    CCPA's business-to-business exemption went inoperative on 1 January 2023, so a B2B prospect record for a California resident carries full consumer rights.

    11 min readRead →
    Cold Email Strategy

    One-Click Unsubscribe: A Working Definition for People Who Have to Ship It

    One-click unsubscribe is two headers and a URL that honours an unauthenticated POST. The headers are trivial; the endpoint is where implementations fail.

    7 min readRead →