How to Run a Re-Permission Email Campaign (Safely)

The short answer
Send only to your most-engaged contacts first, from a dedicated subdomain with SPF, DKIM and DMARC set up, in small batches you can stop. Watch your spam-complaint and bounce rates after each batch, and abort if complaints climb toward 0.3%. Then delete everyone who never re-confirms.
How to run a re-permission email campaign safely: email your best segment first, from an isolated subdomain, in small batches you can stop and measure.
On this page
- 01The short answer
- 02What a re-permission campaign is — and when you need one
- 03Before you start: the pre-flight checks
- 04How to run the campaign, step by step
- 05What a re-opt-in email should contain
- 06Platform and inbox-provider differences
- 07How the batched send flows
- 08What to do when it doesn't work
- 09A faster way — and where AI Emaily honestly fits
Learning how to run a re-permission email campaign is really learning how to make your riskiest send safely. You are about to email people who have not heard from you in months or years, and a stale list is the fastest way to a spike in spam complaints, a wave of hard bounces, and a sending reputation that takes weeks to rebuild.
Done carefully, a re-permission campaign trims a dead list down to the people who still want your mail, and protects the deliverability of everyone you email afterward. The core idea is simple: treat it as a controlled experiment, not a single blast. Send to your best contacts first, from a dedicated sending subdomain, in small batches you can stop the moment the numbers turn.
The short answer#
A re-permission (or re-opt-in) campaign asks an old list to confirm they still want your email. Run it in this order: authenticate the sending domain with SPF, DKIM and DMARC; move the send to a dedicated subdomain so a bad reaction cannot damage your primary domain; sort the list by engagement and email your most recently active contacts first; then send in small batches, reading the response to each one before releasing the next.
Set an abort condition before you start. A spam-complaint rate creeping toward 0.3%, or a bounce rate above a few percent, means stop. When the campaign ends, keep only the people who re-confirmed and delete the rest. That deletion is the point: a smaller list that engages beats a large one that gets you filtered.
What a re-permission campaign is — and when you need one#
A re-permission campaign is a deliberate email, sometimes a short series, that asks dormant subscribers to actively confirm they still want to hear from you. Everyone who clicks "yes" stays; everyone who ignores it is removed. It is also called a re-opt-in or reconfirmation campaign.
You need one when you are about to email a list you have not touched in a long time. Is it safe to email a list you haven't used in a year? Not as-is. Addresses decay: people change jobs, abandon inboxes, and forget they ever signed up. Some of those old addresses have since become spam traps — addresses that mailbox providers and blocklist operators use to catch senders mailing stale lists. Hitting a few can be enough to damage your reputation, which is why M3AAWG publishes guidance specifically for senders who have hit one.
- You are restarting a newsletter or product that has been quiet for six months or more.
- You inherited or merged a list and are unsure when or how each contact last engaged.
- Your open and click rates have collapsed while complaints or bounces are rising.
- You are moving to a new sending platform and want to start from a clean, confirmed list.
Consent law is not the same everywhere
Before you start: the pre-flight checks#
Three things must be true before the first email goes out. Skip them and the campaign becomes the very reputation problem it was meant to prevent.
- Authentication is live. SPF, DKIM and DMARC must be set up and passing for the domain you send from. As of 2026, Gmail, Yahoo and Microsoft all require SPF, DKIM and DMARC from senders above roughly 5,000 messages a day, and a re-permission send to an old list often crosses that line.
- You have a dedicated subdomain. Send from something like news.yourdomain.com, not your primary domain. A subdomain carries its own sending reputation, so if the campaign goes badly your main domain's mail — invoices, replies, password resets — keeps landing.
- One-click unsubscribe works. Marketing mail to Gmail, Yahoo and Apple must support one-click unsubscribe (the List-Unsubscribe-Post header defined in RFC 8058) and show a visible unsubscribe link. A re-permission email is marketing mail; it needs both.
- You can measure per batch. Connect Google Postmaster Tools, plus the Yahoo and Microsoft equivalents, before you send. Without them you cannot see your complaint rate, and you are flying blind on the one number that decides whether to keep going.
Your abort condition is a number, not a feeling
How to run the campaign, step by step#
Work through these in order. The sequence is what keeps the risk bounded: your best contacts and smallest batches go first, so early signals to the inbox providers are positive and any problem shows up while it is still small.
- 1
Segment by engagement
Sort the list by last activity. Anyone who opened or clicked in the last few months goes in the first batch. The truly cold addresses — the ones most likely to be traps or complainers — go last, or not at all. Emailing your best segment first builds positive history before the harder addresses arrive.
- 2
Write a clear re-opt-in email
Say who you are, why they are getting this, and give exactly one thing to do: confirm. Remind them where they signed up and roughly when. Make the confirm a single obvious button, and keep a visible one-click unsubscribe alongside it. The structure is laid out in the next section.
- 3
Warm the subdomain first
If the subdomain is new, do not open with your largest batch. Send low volumes to your most engaged contacts over several days so the subdomain builds a sending history before harder addresses arrive. A brand-new subdomain sending thousands of messages on day one looks exactly like a spammer.
- 4
Send in small, stoppable batches
Split each engagement tier into batches small enough that one bad batch cannot wreck the whole send — a few hundred to a few thousand, scaled to your normal volume. Send one, wait, read the numbers, release the next. Batching a re-permission send is what turns a single high-risk blast into a series of low-risk experiments.
- 5
Read the numbers before the next batch
After each batch, check the delivered rate, bounce rate, spam-complaint rate, and how many people re-confirmed. Rising complaints or bounces mean the next, colder tier will be worse — stop, do not push through. Healthy numbers mean you may proceed to the next batch.
- 6
Delete the non-responders
When the campaign closes, keep everyone who re-confirmed and remove everyone who did not — including people who opened but never clicked confirm. This is the hard part and the whole point. The addresses you delete were the ones dragging your deliverability down.
What a re-opt-in email should contain#
The email itself is short and single-purpose. Every extra ask lowers the confirm rate, so cut anything that is not the reminder, the confirm, and the consequence. Here is the structure that reconfirms the most people without tripping filters.
Platform and inbox-provider differences#
Your email service provider handles the sending mechanics, but the rules that decide whether the mail lands come from the inbox providers. The requirements below are the ones that bite a re-permission send hardest, verified against each provider's own guidance as of 2026 — always re-check the live page before you rely on a number.
| Provider / tool | What matters for a re-permission send | Where to verify |
|---|---|---|
| Gmail (Google) | SPF, DKIM and DMARC required above ~5,000 messages/day to personal Gmail; spam-complaint rate below 0.1% and never 0.3%; one-click unsubscribe required for marketing mail. | Gmail Email sender guidelines + Postmaster Tools |
| Yahoo | Parallel requirements to Gmail: authentication, low complaint rates, and one-click unsubscribe for bulk marketing mail. Monitor reputation in the Yahoo sender tools. | Yahoo Sender Hub best practices |
| Microsoft (Outlook.com) | Runs its own regime: SPF, DKIM and DMARC expected above ~5,000/day. Non-compliant bulk mail can be junked or rejected; recommends one-click unsubscribe. | Outlook.com Postmaster / SNDS |
| Your ESP | Enforces its own list-quality and complaint limits, and may suspend an account that mails a stale list. Most ESPs let you throttle sends into batches — the control this whole method depends on. | Your ESP's acceptable-use and deliverability docs |
How the batched send flows#
The picture below is the whole method at a glance: the list is sorted warmest-first, each tier is broken into small batches, and every batch passes through a checkpoint that can stop the campaign before the next one goes out.

A subdomain limits the damage — it does not dodge the rules
What to do when it doesn't work#
A re-permission campaign fails in a handful of predictable ways. Match your symptom to the table, and in almost every case the fix is to stop, narrow the audience, and slow down rather than push more volume through.
| Symptom | Likely cause | What to do |
|---|---|---|
| Spam complaints climb toward 0.3% | You reached a colder tier, or people no longer recognise you | Stop immediately. Do not send the next batch. Tighten the segment to only your most recently engaged contacts and revisit the sender name and subject line. |
| Bounce rate spikes on a batch | That tier holds many dead addresses and probable spam traps | Halt and run the remaining addresses through list validation before any further sending. High bounces on cold tiers are a signal to shrink the list, not to keep going. |
| Confirms are very low but complaints are fine | The email is unclear, or the audience genuinely lapsed | That is a valid result — most of a truly old list will not reconfirm. Accept it and remove the non-responders; a small confirmed list is the goal, not a failure. |
| Mail is landing in spam / promotions | New subdomain with no history, or authentication not aligned | Confirm SPF, DKIM and DMARC pass and align, then warm the subdomain with smaller, warmer batches over several days before increasing volume. |
| Your ESP flags or pauses the account | Complaint or bounce rates crossed the provider's threshold | Do not open a new account to get around it — that follows you. Work with the ESP, prove you are reconfirming and pruning, and resume at lower volume once metrics recover. |
A faster way — and where AI Emaily honestly fits#
A re-permission campaign is a sending job, and AI Emaily does not send it. We are a receiving-side email client, not an email service provider, a mail-merge tool, or a deliverability platform — we do not blast a list, warm a subdomain, or read your Postmaster Tools spam rate. For the send itself, use your ESP; that is the right tool, and this method works with any of them.
Where AI Emaily fits is the wave that comes back. A re-permission send generates real inbound — confirmations, "yes, keep me," the occasional "who are you," unsubscribe-by-reply, and out-of-office — all landing in the mailbox you actually read. AI Emaily triages that inbound, drafts replies in your voice from a context brain you set, and its spam protection flags anything that looks like a phishing reply, with approve-before-send, undo, and a full audit trail. We build AI Emaily, and it comes with a 7-day free trial on the Pro and Autopilot plans. That is the honest scope: we handle the responses, not the campaign.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.