Blog/ Deliverability & authentication

How to Run a Re-Permission Email Campaign (Safely)

Nafiul HasanNafiul Hasan· 12 min read
Illustration for how to run a re-permission email campaign safely: an old email list sorted by engagement and sent to reconfirm in small, stoppable batches from an isolated subdomain

The short answer

Send only to your most-engaged contacts first, from a dedicated subdomain with SPF, DKIM and DMARC set up, in small batches you can stop. Watch your spam-complaint and bounce rates after each batch, and abort if complaints climb toward 0.3%. Then delete everyone who never re-confirms.

How to run a re-permission email campaign safely: email your best segment first, from an isolated subdomain, in small batches you can stop and measure.

On this page
  1. 01The short answer
  2. 02What a re-permission campaign is — and when you need one
  3. 03Before you start: the pre-flight checks
  4. 04How to run the campaign, step by step
  5. 05What a re-opt-in email should contain
  6. 06Platform and inbox-provider differences
  7. 07How the batched send flows
  8. 08What to do when it doesn't work
  9. 09A faster way — and where AI Emaily honestly fits

Learning how to run a re-permission email campaign is really learning how to make your riskiest send safely. You are about to email people who have not heard from you in months or years, and a stale list is the fastest way to a spike in spam complaints, a wave of hard bounces, and a sending reputation that takes weeks to rebuild.

Done carefully, a re-permission campaign trims a dead list down to the people who still want your mail, and protects the deliverability of everyone you email afterward. The core idea is simple: treat it as a controlled experiment, not a single blast. Send to your best contacts first, from a dedicated sending subdomain, in small batches you can stop the moment the numbers turn.

The short answer#

A re-permission (or re-opt-in) campaign asks an old list to confirm they still want your email. Run it in this order: authenticate the sending domain with SPF, DKIM and DMARC; move the send to a dedicated subdomain so a bad reaction cannot damage your primary domain; sort the list by engagement and email your most recently active contacts first; then send in small batches, reading the response to each one before releasing the next.

Set an abort condition before you start. A spam-complaint rate creeping toward 0.3%, or a bounce rate above a few percent, means stop. When the campaign ends, keep only the people who re-confirmed and delete the rest. That deletion is the point: a smaller list that engages beats a large one that gets you filtered.

What a re-permission campaign is — and when you need one#

A re-permission campaign is a deliberate email, sometimes a short series, that asks dormant subscribers to actively confirm they still want to hear from you. Everyone who clicks "yes" stays; everyone who ignores it is removed. It is also called a re-opt-in or reconfirmation campaign.

You need one when you are about to email a list you have not touched in a long time. Is it safe to email a list you haven't used in a year? Not as-is. Addresses decay: people change jobs, abandon inboxes, and forget they ever signed up. Some of those old addresses have since become spam traps — addresses that mailbox providers and blocklist operators use to catch senders mailing stale lists. Hitting a few can be enough to damage your reputation, which is why M3AAWG publishes guidance specifically for senders who have hit one.

  • You are restarting a newsletter or product that has been quiet for six months or more.
  • You inherited or merged a list and are unsure when or how each contact last engaged.
  • Your open and click rates have collapsed while complaints or bounces are rising.
  • You are moving to a new sending platform and want to start from a clean, confirmed list.

Consent law is not the same everywhere

In the US, the CAN-SPAM Act works on an opt-out basis: commercial mail needs truthful headers, a non-deceptive subject line, a valid physical postal address, and a working opt-out you honour within 10 business days. The EU and UK work the other way — GDPR and PECR require opt-in consent before you send at all, so a re-permission email to people who never consented can itself be a violation. Confirm which regime covers your recipients before you send.

Before you start: the pre-flight checks#

Three things must be true before the first email goes out. Skip them and the campaign becomes the very reputation problem it was meant to prevent.

  • Authentication is live. SPF, DKIM and DMARC must be set up and passing for the domain you send from. As of 2026, Gmail, Yahoo and Microsoft all require SPF, DKIM and DMARC from senders above roughly 5,000 messages a day, and a re-permission send to an old list often crosses that line.
  • You have a dedicated subdomain. Send from something like news.yourdomain.com, not your primary domain. A subdomain carries its own sending reputation, so if the campaign goes badly your main domain's mail — invoices, replies, password resets — keeps landing.
  • One-click unsubscribe works. Marketing mail to Gmail, Yahoo and Apple must support one-click unsubscribe (the List-Unsubscribe-Post header defined in RFC 8058) and show a visible unsubscribe link. A re-permission email is marketing mail; it needs both.
  • You can measure per batch. Connect Google Postmaster Tools, plus the Yahoo and Microsoft equivalents, before you send. Without them you cannot see your complaint rate, and you are flying blind on the one number that decides whether to keep going.

Your abort condition is a number, not a feeling

As of 2026, Gmail asks bulk senders to keep the spam-complaint rate reported in Postmaster Tools below 0.1% and warns never to reach 0.3%. Decide before you send that if any batch crosses roughly 0.3% complaints, or bounces spike above a few percent, you stop the campaign then and there. Providers revise these thresholds — check the current Gmail, Yahoo and Microsoft guidance before you rely on a specific figure.

How to run the campaign, step by step#

Work through these in order. The sequence is what keeps the risk bounded: your best contacts and smallest batches go first, so early signals to the inbox providers are positive and any problem shows up while it is still small.

  1. 1

    Segment by engagement

    Sort the list by last activity. Anyone who opened or clicked in the last few months goes in the first batch. The truly cold addresses — the ones most likely to be traps or complainers — go last, or not at all. Emailing your best segment first builds positive history before the harder addresses arrive.

  2. 2

    Write a clear re-opt-in email

    Say who you are, why they are getting this, and give exactly one thing to do: confirm. Remind them where they signed up and roughly when. Make the confirm a single obvious button, and keep a visible one-click unsubscribe alongside it. The structure is laid out in the next section.

  3. 3

    Warm the subdomain first

    If the subdomain is new, do not open with your largest batch. Send low volumes to your most engaged contacts over several days so the subdomain builds a sending history before harder addresses arrive. A brand-new subdomain sending thousands of messages on day one looks exactly like a spammer.

  4. 4

    Send in small, stoppable batches

    Split each engagement tier into batches small enough that one bad batch cannot wreck the whole send — a few hundred to a few thousand, scaled to your normal volume. Send one, wait, read the numbers, release the next. Batching a re-permission send is what turns a single high-risk blast into a series of low-risk experiments.

  5. 5

    Read the numbers before the next batch

    After each batch, check the delivered rate, bounce rate, spam-complaint rate, and how many people re-confirmed. Rising complaints or bounces mean the next, colder tier will be worse — stop, do not push through. Healthy numbers mean you may proceed to the next batch.

  6. 6

    Delete the non-responders

    When the campaign closes, keep everyone who re-confirmed and remove everyone who did not — including people who opened but never clicked confirm. This is the hard part and the whole point. The addresses you delete were the ones dragging your deliverability down.

What a re-opt-in email should contain#

The email itself is short and single-purpose. Every extra ask lowers the confirm rate, so cut anything that is not the reminder, the confirm, and the consequence. Here is the structure that reconfirms the most people without tripping filters.

Re-opt-in email structure
SubjectDirect and honest — "Still want to hear from us? Confirm to stay subscribed." No trickery; deceptive subject lines break CAN-SPAM.
OpeningRemind them who you are and why they are getting this: "You signed up at example.com back in 2023, and we've been quiet."
The askOne clear action — a single "Yes, keep me subscribed" button. Nothing else competes with it.
The stakesState plainly what happens if they do nothing: "If we don't hear back by [date], we'll remove you from the list."
The exitsA visible one-click unsubscribe next to the confirm, plus your valid physical postal address in the footer.

Platform and inbox-provider differences#

Your email service provider handles the sending mechanics, but the rules that decide whether the mail lands come from the inbox providers. The requirements below are the ones that bite a re-permission send hardest, verified against each provider's own guidance as of 2026 — always re-check the live page before you rely on a number.

Provider / toolWhat matters for a re-permission sendWhere to verify
Gmail (Google)SPF, DKIM and DMARC required above ~5,000 messages/day to personal Gmail; spam-complaint rate below 0.1% and never 0.3%; one-click unsubscribe required for marketing mail.Gmail Email sender guidelines + Postmaster Tools
YahooParallel requirements to Gmail: authentication, low complaint rates, and one-click unsubscribe for bulk marketing mail. Monitor reputation in the Yahoo sender tools.Yahoo Sender Hub best practices
Microsoft (Outlook.com)Runs its own regime: SPF, DKIM and DMARC expected above ~5,000/day. Non-compliant bulk mail can be junked or rejected; recommends one-click unsubscribe.Outlook.com Postmaster / SNDS
Your ESPEnforces its own list-quality and complaint limits, and may suspend an account that mails a stale list. Most ESPs let you throttle sends into batches — the control this whole method depends on.Your ESP's acceptable-use and deliverability docs

How the batched send flows#

The picture below is the whole method at a glance: the list is sorted warmest-first, each tier is broken into small batches, and every batch passes through a checkpoint that can stop the campaign before the next one goes out.

Diagram of a batched re-permission send: an old list sorted by engagement flows into small sequential batches, each followed by a checkpoint reading spam-complaint and bounce rates that either releases the next batch or aborts the campaign
Every batch is followed by a go/stop checkpoint — the abort condition is what keeps one bad batch from becoming a reputation problem.

A subdomain limits the damage — it does not dodge the rules

Sending from news.yourdomain.com keeps a bad reaction off your primary domain's reputation, which is the reason to use one. But it will not let you slip under the bulk-sender requirements: Google counts sending volume across a primary domain and its subdomains together, so splitting a big send across several subdomains does not lower the threshold. Use a subdomain to isolate reputation, not to avoid authentication.

What to do when it doesn't work#

A re-permission campaign fails in a handful of predictable ways. Match your symptom to the table, and in almost every case the fix is to stop, narrow the audience, and slow down rather than push more volume through.

SymptomLikely causeWhat to do
Spam complaints climb toward 0.3%You reached a colder tier, or people no longer recognise youStop immediately. Do not send the next batch. Tighten the segment to only your most recently engaged contacts and revisit the sender name and subject line.
Bounce rate spikes on a batchThat tier holds many dead addresses and probable spam trapsHalt and run the remaining addresses through list validation before any further sending. High bounces on cold tiers are a signal to shrink the list, not to keep going.
Confirms are very low but complaints are fineThe email is unclear, or the audience genuinely lapsedThat is a valid result — most of a truly old list will not reconfirm. Accept it and remove the non-responders; a small confirmed list is the goal, not a failure.
Mail is landing in spam / promotionsNew subdomain with no history, or authentication not alignedConfirm SPF, DKIM and DMARC pass and align, then warm the subdomain with smaller, warmer batches over several days before increasing volume.
Your ESP flags or pauses the accountComplaint or bounce rates crossed the provider's thresholdDo not open a new account to get around it — that follows you. Work with the ESP, prove you are reconfirming and pruning, and resume at lower volume once metrics recover.

A faster way — and where AI Emaily honestly fits#

A re-permission campaign is a sending job, and AI Emaily does not send it. We are a receiving-side email client, not an email service provider, a mail-merge tool, or a deliverability platform — we do not blast a list, warm a subdomain, or read your Postmaster Tools spam rate. For the send itself, use your ESP; that is the right tool, and this method works with any of them.

Where AI Emaily fits is the wave that comes back. A re-permission send generates real inbound — confirmations, "yes, keep me," the occasional "who are you," unsubscribe-by-reply, and out-of-office — all landing in the mailbox you actually read. AI Emaily triages that inbound, drafts replies in your voice from a context brain you set, and its spam protection flags anything that looks like a phishing reply, with approve-before-send, undo, and a full audit trail. We build AI Emaily, and it comes with a 7-day free trial on the Pro and Autopilot plans. That is the honest scope: we handle the responses, not the campaign.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

The send is your ESP's job. The replies are ours.

A re-permission campaign brings a wave of confirmations, questions and complaints back to your inbox. AI Emaily triages that inbound, drafts replies in your voice and flags phishing — with approve-before-send, undo and a full audit trail. Try it on a 7-day free trial.

  • 7-day free trial
  • Cancel anytime
  • Every provider