Cold Email in HubSpot: What Its Anti-Spam Policy Says
Whether HubSpot can send cold email is a feature question. What it permits is a contract question, and HubSpot answers it in writing on a page most buyers never open.

HubSpot can send cold email mechanically, but its Anti-Spam Policy requires express, verifiable, documented consent, prohibits contacting purchased, rented or enrichment lists where laws or third-party terms forbid it, and caps spam complaints at 0.1% and bounces at 5%. Cold prospecting sits outside what the policy describes.
Key takeaways
- HubSpot's Acceptable Use Policy forbids spam, and its Anti-Spam Policy defines it to include one-to-one commercial mail that breaks anti-spam law.
- Section 2.1.1 prohibits contacting purchased, rented, borrowed or enrichment lists in violation of applicable laws or third-party terms.
- HubSpot requires bounce rates below 5% and spam complaints below 0.1%, three times tighter than Google's 0.3% ceiling.
- Use HubSpot for suppression, routing and reporting, and send prospecting mail from a separate estate of dedicated domains.
Reviewed and updated September 21, 2026
The question people bring to this topic is whether HubSpot can send cold email. It can, mechanically, and that is the least useful thing to know about it. The decidable question is what HubSpot's own contract permits, and HubSpot answers it in writing on a page most buyers never open.
HubSpot's Acceptable Use Policy contains one line at section 2.1 that everything else hangs from: you may not use HubSpot to send spam. Section 2.3 then binds you to a separate HubSpot Anti-Spam Policy, last modified 2 February 2026, and that document is where the word spam gets defined. It is worth reading before designing a prospecting motion around the platform, because the definition is stricter than the one most outbound teams work to.
HubSpot and cold email: what the Anti-Spam Policy prohibits
Three provisions decide the question.
The definition of spam. Section 2.1 lists unsolicited bulk messages sent to recipients who have not provided verifiable, explicit consent, unsolicited commercial messages or one-to-one commercial communications that violate applicable anti-spam laws, and messages sent in violation of applicable data protection regulations. The middle clause is the one that catches people out, because it reaches one-to-one email and not only bulk sends. A sequence of individually addressed messages is not outside the policy on the grounds that each one went to a single person.
The list clause. Section 2.1.1 states that you are strictly prohibited from using the HubSpot Services to directly contact recipients from purchased, rented, borrowed, or other third-party lists, including email append services or enrichment services lists, in violation of applicable laws or third-party terms. Enrichment output is named explicitly, which matters because a great many outbound lists are exactly that.
The consent requirement. Section 3.1 says messages sent through HubSpot Services must go only to recipients who have provided express, verifiable consent, opted in through a clear documented process, and not withdrawn that consent. Section 3.1.1 carves out two exceptions and they are narrow: purely transactional messages relating to an existing transaction or relationship with no marketing content, and internal communications to employees or stakeholders.
Read those together and the policy describes a permission-based sending product. Cold prospecting to strangers sourced from a data vendor sits outside the shape it describes, whatever the tooling makes possible.
One qualifier in the list clause deserves to be read carefully rather than skipped, because it is doing real work. Section 2.1.1 prohibits contacting recipients from those lists in violation of applicable laws or third-party terms, which means the clause inherits whatever your jurisdiction and your data supplier's contract say rather than banning the practice outright everywhere. That is genuinely different from a flat prohibition, and it is also a heavier obligation than it first reads as, because it puts you on the hook for the data vendor's terms as well as the statute. Establishing which laws apply, and what the supplier's contract permits, is homework somebody has to do and write down. It is not a question a support conversation will settle for you.
| Line | The policy (2.1, 2.1.1, 3.1) | Cold outbound |
|---|---|---|
| Recipients | Express, verifiable, documented opt-in | People who never asked to hear from you |
| Lists | No purchased, rented or enrichment lists where laws or terms forbid | Built from data vendors and enrichment waterfalls |
| One-to-one mail | Inside the definition of spam where it breaks the law | Individually addressed, at programme volume |
| Exceptions | Transactional and internal messages only | Lawful basis argued from legitimate interest or a B2B exemption |
The enforcement half, which is not theoretical

Section 4.1 sets out what HubSpot reserves the right to do. It may monitor sending patterns and content, review user lists and subscription practices, investigate complaints and suspicious activity, request documentation of consent, and audit compliance.
That fourth power is the one to plan around. A programme whose consent evidence is an argument about legitimate interest rather than a stored opt-in record has nothing to hand over when asked. Whether that argument is legally sound in a given jurisdiction is a separate question from whether it satisfies a vendor's contract, and the two answers can differ.
Section 3.6 adds numeric standards that are stricter than the provider thresholds most senders manage to. It requires bounce rates below 5% and spam complaint rates below 0.1%, with engagement consistent with industry standards and regular list hygiene. For comparison, Google's own sender guidelines require every sender to Gmail to keep the spam rate reported in Postmaster Tools below 0.3%. HubSpot's published figure is three times tighter than the mailbox provider's.
Section 3.5 states that HubSpot maintains sending limits including daily limits based on account type and history, hourly rate limits, per-message recipient limits and automatic throttling for accounts showing signs of abuse. So volume is governed by the platform's read of your account rather than by a number you can plan against.
The tooling gates sit on top of all that. HubSpot's own documentation for the sequences tool lists it as available with Sales Hub Professional or Enterprise and Service Hub Professional or Enterprise, with seats required. Reaching the feature is a subscription decision before it is a policy one.
The part that is not about policy at all
Suppose the contract question resolves in your favour, because you are messaging an existing relationship or your counsel is satisfied with the lawful basis where you operate. There is a second constraint underneath, and it does not care about consent.
HubSpot sends from your identity. Connected inboxes are real people's mailboxes on your corporate domain, and marketing email is authenticated against your own sending domain, which section 3.2 of the Anti-Spam Policy requires you to configure properly with SPF, DKIM and DMARC records, valid DNS and authorised sending IPs. That is the same domain carrying your contracts, invoices, renewals, support threads and every live commercial conversation your account executives are having.
Reputation also attaches to the domains inside a message, and a blocklist that reads message links explains why the listed name often belongs to somebody else.
Cold volume from that identity puts all of it on one reputation. A bad month in prospecting stops being a prospecting problem and becomes a deliverability problem in correspondence with customers, and the recovery is slow because reputation heals slowly. The separation of sending estates is the single most consequential architectural decision in an outbound programme, and it is undone the moment the prospecting mail leaves through the CRM's connected inboxes. The reasoning in full, along with what a separated estate looks like, is in the cold email infrastructure guide, the authentication half is in SPF, DKIM and DMARC for cold email, and the signal to watch is in Google Postmaster Tools.
Where HubSpot genuinely belongs in an outbound motion

None of the above is an argument for keeping the CRM out of outbound. It is an argument about which half of the job it does.
The suppression check. Before anybody is contacted, somebody has to answer whether this company is already a customer, already in an open deal, already owned by a colleague, or has already asked not to be contacted. The CRM is the only system that knows, and the join has to happen before the send rather than after the reply. Keeping that answer in a suppression list the sending platform consults is what makes the rest safe.
Routing and ownership. A reply is worth nothing until it reaches the right person with context attached, and that is CRM work.
Reporting on outcomes rather than sends. Meetings, opportunities and revenue live in the CRM. Volume of email sent is an input and belongs nowhere near a leadership dashboard, because a metric that rewards sending more reliably produces more sending.
Deduplication at the boundary. The moment two systems write contacts, you need a rule about which one wins and what counts as the same person. The worked example of that going wrong across a CRM boundary is in Apollo and HubSpot deduplication.
Section 3.4 of the policy is worth reading even if you never send a marketing message from HubSpot, because it is a decent specification for any programme: a clear and conspicuous unsubscribe mechanism, one-click functionality, unsubscribe requests processed within 24 hours, suppression maintained and honoured across all channels, no login required, no fees or conditions. The mechanism itself is covered in one-click unsubscribe, and the wider legal picture in GDPR for B2B outbound.
The CRM owns
- Suppression of customers, open deals and prior contacts, checked before the send
- Routing replies to a named owner with context
- Reporting meetings and opportunities, not sends
- Opt-outs, propagated to every list and tool
The sending estate owns
- Prospecting mail from dedicated domains
- Warmed mailboxes, never corporate inboxes
- Consent or lawful-basis evidence you could hand over if asked
Where we sit

RevenueFlow does not sell HubSpot, resell it, or take a fee for configuring it, and we do not run our own prospecting through it. We run cold email and LinkedIn outbound on Email Bison and HeyReach, with dedicated sending domains kept separate from the mailboxes our own commercial conversations run through.
Our campaigns send one message per prospect with nothing scheduled behind it. No thread replies and no bumps, because every step after the first reaches only people who already declined to answer, and the reply lift is measured inside a sequence while the reputation cost is paid across the whole domain. That argument in full is in why we run one-message campaigns instead. Meetings are qualified against criteria agreed in writing before launch.
If you want to see what a properly separated programme produces on your own market before rebuilding anything, we will build the first campaign.
HubSpot's Acceptable Use Policy and Anti-Spam Policy provisions, and the sequences subscription requirements, are per HubSpot's own published pages. Google's spam-rate guidance is per Google's published email sender guidelines. Dated snapshots of both are retained. Nothing here is legal advice. Verify current terms with the vendor and with counsel before relying on them.
Frequently asked questions.
Frequently asked questions- Can you send cold emails from HubSpot?
- Mechanically yes, contractually mostly no. HubSpot's Anti-Spam Policy requires recipients to have given express, verifiable consent through a documented opt-in, with narrow exceptions for transactional and internal messages. Cold prospecting to strangers sourced from a data vendor sits outside what the policy describes.
- Does HubSpot allow purchased email lists?
- Section 2.1.1 of HubSpot's Anti-Spam Policy strictly prohibits using HubSpot to contact recipients from purchased, rented, borrowed or other third-party lists, including email append and enrichment lists, in violation of applicable laws or third-party terms. That puts the laws you operate under and your data supplier's contract in scope.
- What spam complaint rate does HubSpot allow?
- Section 3.6 of HubSpot's Anti-Spam Policy requires spam complaint rates below 0.1% and bounce rates below 5%, alongside engagement consistent with industry standards and regular list hygiene. Google's sender guidelines set the Postmaster Tools ceiling at 0.3%, so HubSpot's figure is three times tighter.
- Which HubSpot plans include sequences?
- HubSpot's knowledge base lists the sequences tool with Sales Hub Professional or Enterprise and Service Hub Professional or Enterprise, and an assigned Sales or Service seat is required. Whether sending a given sequence is permitted is then a question for the Anti-Spam Policy, not the subscription.
About the author.

Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.
Ben Carden · CRO
Connect on LinkedIn →Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
SMTP Reply Codes: What Each Class Instructs
The digits are a verdict and the text is the reason. Separating an address failure from a policy refusal before reacting is what decides whether the fix works.
No-Reply Email Address: What It Costs a Sender
A no-reply address is defensible on a receipt and indefensible on a cold message, because the reply is the entire product of a first contact.
Email Tracking Software: Six Tools, Priced and Capped
Streak, Mailsuite, Right Inbox, Mixmax, Yesware and HubSpot compared on free-tier caps and published prices, plus what an open event still proves.
Transactional Email: The Class That Needs Its Own Domain
A transactional email is triggered by the recipient's own action and expected by them. The reason it needs separating from marketing and cold mail is reputation.
SURBL Blacklist: What It Lists and How to Get Removed
SURBL tests the domains inside your message rather than your sending IP. Which of its six lists fired, what the bitmask means, and the fix that works.
SPF Flattening: The Definition, and What It Trades Away
SPF flattening swaps include statements for the addresses they resolve to, to stay under the ten-lookup ceiling. What it fixes, and what it quietly costs.