Cold Email in HubSpot: What Its Own Anti-Spam Policy Says You May Send
Whether HubSpot can send cold email is a feature question. What it permits is a contract question, and HubSpot answers it in writing on a page most buyers never open.

HubSpot's Anti-Spam Policy requires express, verifiable consent, prohibits contacting recipients from purchased, rented or enrichment lists in violation of laws or supplier terms, and counts one-to-one commercial mail within its definition of spam. It also reserves the right to request documentation of consent, and asks for complaint rates below 0.1%.
Key takeaways
- HubSpot's Acceptable Use Policy bars spam and binds you to a separate Anti-Spam Policy, which is where the operative definitions and thresholds live.
- The policy names purchased, rented, borrowed and enrichment lists directly, and its consent requirement asks for a documented opt-in rather than a legitimate-interest argument.
- HubSpot reserves the right to review lists, audit compliance and request documentation of consent, so the evidence has to exist in a form you could hand over.
- Even where the contract permits a send, HubSpot leaves through your corporate domain and connected inboxes, which is the reputation your customer correspondence depends on.
Reviewed and updated August 16, 2026
The question people bring to this topic is whether HubSpot can send cold email. It can, mechanically, and that is the least useful thing to know about it. The decidable question is what HubSpot's own contract permits, and HubSpot answers it in writing on a page most buyers never open.
HubSpot's Acceptable Use Policy contains one line at section 2.1 that everything else hangs from: you may not use HubSpot to send spam. Section 2.3 then binds you to a separate HubSpot Anti-Spam Policy, last modified 2 February 2026, and that document is where the word spam gets defined. It is worth reading before designing a prospecting motion around the platform, because the definition is stricter than the one most outbound teams work to.
What HubSpot's Anti-Spam Policy actually prohibits
Three provisions decide the question.
The definition of spam. Section 2.1 lists unsolicited bulk messages sent to recipients who have not provided verifiable, explicit consent, unsolicited commercial messages or one-to-one commercial communications that violate applicable anti-spam laws, and messages sent in violation of applicable data protection regulations. The middle clause is the one that catches people out, because it reaches one-to-one email and not only bulk sends. A sequence of individually addressed messages is not outside the policy on the grounds that each one went to a single person.
The list clause. Section 2.1.1 states that you are strictly prohibited from using the HubSpot Services to directly contact recipients from purchased, rented, borrowed, or other third-party lists, including email append services or enrichment services lists, in violation of applicable laws or third-party terms. Enrichment output is named explicitly, which matters because a great many outbound lists are exactly that.
The consent requirement. Section 3.1 says messages sent through HubSpot Services must go only to recipients who have provided express, verifiable consent, opted in through a clear documented process, and not withdrawn that consent. Section 3.1.1 carves out two exceptions and they are narrow: purely transactional messages relating to an existing transaction or relationship with no marketing content, and internal communications to employees or stakeholders.
Read those together and the policy describes a permission-based sending product. Cold prospecting to strangers sourced from a data vendor sits outside the shape it describes, whatever the tooling makes possible.
One qualifier in the list clause deserves to be read carefully rather than skipped, because it is doing real work. Section 2.1.1 prohibits contacting recipients from those lists in violation of applicable laws or third-party terms, which means the clause inherits whatever your jurisdiction and your data supplier's contract say rather than banning the practice outright everywhere. That is genuinely different from a flat prohibition, and it is also a heavier obligation than it first reads as, because it puts you on the hook for the data vendor's terms as well as the statute. Establishing which laws apply, and what the supplier's contract permits, is homework somebody has to do and write down. It is not a question a support conversation will settle for you.
- Express, verifiable consent, documented through a clear opt-in process
- No direct contact with recipients from purchased, rented or enrichment lists
- One-to-one commercial mail is inside the definition of spam where laws are breached
- Exceptions limited to transactional and internal messages
- Recipients who never asked to hear from you
- Lists built from data vendors and enrichment waterfalls
- Individually addressed messages, sent at programme volume
- Lawful basis argued from legitimate interest or a B2B exemption, not from opt-in
The enforcement half, which is not theoretical

Section 4.1 sets out what HubSpot reserves the right to do. It may monitor sending patterns and content, review user lists and subscription practices, investigate complaints and suspicious activity, request documentation of consent, and audit compliance.
That fourth power is the one to plan around. A programme whose consent evidence is an argument about legitimate interest rather than a stored opt-in record has nothing to hand over when asked. Whether that argument is legally sound in a given jurisdiction is a separate question from whether it satisfies a vendor's contract, and the two answers can differ.
Section 3.6 adds numeric standards that are stricter than the provider thresholds most senders manage to. It requires bounce rates below 5% and spam complaint rates below 0.1%, with engagement consistent with industry standards and regular list hygiene. For comparison, Google's own sender guidelines ask senders of 5,000 or more daily messages to Gmail to keep the spam rate reported in Postmaster Tools below 0.30%. HubSpot's published figure is three times tighter than the mailbox provider's.
Section 3.5 states that HubSpot maintains sending limits including daily limits based on account type and history, hourly rate limits, per-message recipient limits and automatic throttling for accounts showing signs of abuse. So volume is governed by the platform's read of your account rather than by a number you can plan against.
The tooling gates sit on top of all that. HubSpot's own documentation for the sequences tool, last updated 3 August 2026, lists it as available with Sales Hub Professional or Enterprise and Service Hub Professional or Enterprise, with seats required. Reaching the feature is a subscription decision before it is a policy one.
The part that is not about policy at all
Suppose the contract question resolves in your favour, because you are messaging an existing relationship or your counsel is satisfied with the lawful basis where you operate. There is a second constraint underneath, and it does not care about consent.
HubSpot sends from your identity. Connected inboxes are real people's mailboxes on your corporate domain, and marketing email is authenticated against your own sending domain, which section 3.2 of the Anti-Spam Policy requires you to configure properly with SPF, DKIM and DMARC records, valid DNS and authorised sending IPs. That is the same domain carrying your contracts, invoices, renewals, support threads and every live commercial conversation your account executives are having.
Cold volume from that identity puts all of it on one reputation. A bad month in prospecting stops being a prospecting problem and becomes a deliverability problem in correspondence with customers, and the recovery is slow because reputation heals slowly. The separation of sending estates is the single most consequential architectural decision in an outbound programme, and it is undone the moment the prospecting mail leaves through the CRM's connected inboxes. The reasoning in full, along with what a separated estate looks like, is in the cold email infrastructure guide, the authentication half is in SPF, DKIM and DMARC for cold email, and the signal to watch is in Google Postmaster Tools.
- Step 1Corporate domain
Contracts, invoices, renewals, support and live customer threads, sent from named people's mailboxes.
- Step 2CRM connected inboxes
HubSpot sends through those same mailboxes and authenticates against that same domain.
- Step 3Prospecting volume added
Complaints and spam-folder placement from strangers accrue to the identity carrying the customer mail.
- Step 4Separate estate instead
Dedicated prospecting domains and warmed mailboxes, so the two workloads cannot damage each other.
Where HubSpot genuinely belongs in an outbound motion

None of the above is an argument for keeping the CRM out of outbound. It is an argument about which half of the job it does.
The suppression check. Before anybody is contacted, somebody has to answer whether this company is already a customer, already in an open deal, already owned by a colleague, or has already asked not to be contacted. The CRM is the only system that knows, and the join has to happen before the send rather than after the reply. Keeping that answer in a suppression list the sending platform consults is what makes the rest safe.
Routing and ownership. A reply is worth nothing until it reaches the right person with context attached, and that is CRM work.
Reporting on outcomes rather than sends. Meetings, opportunities and revenue live in the CRM. Volume of email sent is an input and belongs nowhere near a leadership dashboard, because a metric that rewards sending more reliably produces more sending.
Deduplication at the boundary. The moment two systems write contacts, you need a rule about which one wins and what counts as the same person. The worked example of that going wrong across a CRM boundary is in Apollo and HubSpot deduplication.
Section 3.4 of the policy is worth reading even if you never send a marketing message from HubSpot, because it is a decent specification for any programme: a clear and conspicuous unsubscribe mechanism, one-click functionality, unsubscribe requests processed within 24 hours, suppression maintained and honoured across all channels, no login required, no fees or conditions. The mechanism itself is covered in one-click unsubscribe, and the wider legal picture in GDPR for B2B outbound.
- Yes: Suppression of customers, open deals and prior contacts lives in the CRM and is checked before the send
- Yes: Prospecting mail leaves from dedicated domains and warmed mailboxes, not connected corporate inboxes
- Yes: Replies route to a named owner with the account context attached
- Yes: Opt-outs propagate from wherever they arrive into every list and every tool
- Yes: Reporting counts meetings and opportunities rather than messages sent
- Depends: Consent evidence exists in a form that could be handed over if a vendor asked for it
- No: Cold lists loaded into the CRM's own sending tools because the feature is available
Where we sit

RevenueFlow does not sell HubSpot, resell it, or take a fee for configuring it, and we do not run our own prospecting through it. We run cold email and LinkedIn outbound on Email Bison and HeyReach, with dedicated sending domains kept separate from the mailboxes our own commercial conversations run through.
Our campaigns send one message per prospect with nothing scheduled behind it. No thread replies and no bumps, because every step after the first reaches only people who already declined to answer, and the reply lift is measured inside a sequence while the reputation cost is paid across the whole domain. That argument in full is in why we run one-message campaigns instead. Meetings are qualified against criteria agreed in writing before launch.
If you want to see what a properly separated programme produces on your own market before rebuilding anything, we will build the first campaign.
HubSpot's Acceptable Use Policy and Anti-Spam Policy provisions, and the sequences subscription requirements, are per HubSpot's own published pages, fetched 16 August 2026. Google's 0.30% Postmaster spam-rate guidance is per Google's published email sender guidelines, fetched the same day. Nothing here is legal advice. Verify current terms with the vendor and with counsel before relying on them.
Frequently asked questions.
Frequently asked questions- Does HubSpot allow cold email?
- Its Anti-Spam Policy requires express, verifiable consent captured through a documented opt-in, with exceptions only for transactional and internal messages. It separately prohibits contacting recipients from purchased, rented or enrichment lists in violation of applicable laws or supplier terms. That describes a permission-based product rather than a prospecting one.
- Do HubSpot sequences count as cold email under the policy?
- The definition of spam in section 2.1 covers unsolicited commercial messages and one-to-one commercial communications that breach applicable anti-spam laws, so individually addressed sequence mail is not exempt by virtue of being one to one. Sequences also require Sales Hub or Service Hub Professional or Enterprise with seats assigned.
- What complaint rate does HubSpot expect?
- Its Anti-Spam Policy asks senders to keep bounce rates below 5% and spam complaint rates below 0.1%, alongside regular list hygiene. That threshold is roughly three times tighter than Google's published guidance, which asks senders of 5,000 or more daily Gmail messages to keep Postmaster spam rates below 0.30%.
- Where should a CRM sit in an outbound programme?
- On the record side rather than the sending side. The CRM owns the suppression check before anyone is contacted, reply routing and ownership, and reporting on meetings rather than sends. Prospecting mail belongs on dedicated domains and warmed mailboxes kept structurally separate from customer correspondence.
About the author.

Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.
Ben Carden · CRO
Connect on LinkedIn →Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
Suppression List: What It Means and Why the Textbook Definition Misleads
A suppression list is the memory of every instruction you have been given about who not to contact. Its value comes entirely from being enforced everywhere.
Yesware Email Tracking: What the Open Notification Actually Proves
Yesware tracks opens, clicks and attachment views from inside Gmail and Outlook. What each event proves, what every tier costs, and why an open is not a trigger.
GDPR for B2B Outbound: What Emailing Contacts in Europe Actually Requires
Territorial scope, the assessment behind a legitimate interest send, the national ePrivacy layer that decides whether you may send, and what the first message carries.
CAN-SPAM Act Compliance for B2B Cold Email: What the Law Requires
The CAN-SPAM Act makes no exception for business-to-business email. Here are the seven requirements, the opt-out clocks, and where liability lands when an agency sends.
CCPA Compliance for Cold Outreach: The B2B Exemption That Lapsed
CCPA's business-to-business exemption went inoperative on 1 January 2023, so a B2B prospect record for a California resident carries full consumer rights.
One-Click Unsubscribe: A Working Definition for People Who Have to Ship It
One-click unsubscribe is two headers and a URL that honours an unauthenticated POST. The headers are trivial; the endpoint is where implementations fail.