Help Center β€Ί Deliverability β€Ί Don't risk getting blocked: identify your compliant and non-compliant lists
πŸ“¨ Deliverability

Don't risk getting blocked: identify your compliant and non-compliant lists

πŸ“… Last updated: June 2026
⏱ 8 min read
βœ… All plans

This reference page provides concrete examples of compliant, non-compliant, and borderline contact acquisition lists, alongside standard operating protocols to ensure your sending operations strictly respect digital consent laws and global deliverability standards.

Mastering these rules enables you to aggressively protect your sender reputation, maximize your inbox engagement rates, and completely neutralize the risk of domain blacklists or account suspensions.

I. Valid Examples of Fully Compliant Contact Lists

Compliant lists are built entirely on verified, direct user consent. They form the only secure foundation for long-term marketing operations.

1. Direct Opt-In Form Submissions

Contacts who voluntarily provided their email address through a clear form on your website represent your most reliable traffic base. These subscribers explicitly chose to receive your content, which drastically reduces spam complaint ratios.

  • Voluntary Consent: The subscriber understands exactly what they requested (e.g., a newsletter, lead magnet, or promotional offers).
  • Legal Security: This structure is fully compliant with European GDPR regulations and global anti-spam directives.
  • Pro Tip: Always include an explicit checkbox stating "I want to receive promotional emails" linked directly to your active Privacy Policy page.

2. Explicit Checkout Checkbox Subscriptions

Adding a subscriber during a checkout flow is valid, but the consent must remain entirely voluntary. The simple act of completing a purchase does not automatically grant you permission to send marketing blasts.

  • Active Opt-In: The newsletter subscription checkbox must remain unchecked by default. The customer must execute a deliberate click to opt-in.
  • Clear Wording: Do not hide the consent parameters. Use exact phrasing like: "Yes, I want to receive news, tips, and exclusive offers by email."
  • Proof Logs: The system logs the exact timestamp and opt-in action to guarantee GDPR compliance during potential audits.

3. Documented Offline Subscriptions

You can legitimately collect contacts offline (e.g., trade shows, physical storefronts, or scheduled sales calls), provided the consent remains completely voluntary and explicit.

  • Clarity: Never use ambiguous phrasing. Explain precisely what the user will receive.
  • Active Registration: The user must sign a physical intake sheet or actively check a digital tablet form acknowledging the marketing subscription.
  • Pro Tip: Preserve physical copies, scanned images, or CRM logs demonstrating the explicit offline consent to protect yourself from future spam complaints.

4. Transactional Service Emails

You are permitted to send required operational messagesβ€”such as purchase receipts, password reset links, or package tracking updatesβ€”to existing customers even if they never checked a marketing opt-in box. These are classified strictly as transactional emails.

πŸ›‘
The Marketing Separation Rule
If you inject any promotional content (upsells, coupon codes, new product launches) into a transactional email, it instantly becomes a marketing email. Doing so without explicit consent violates anti-spam laws and will rapidly destroy your sender reputation. Keep your operational and marketing templates strictly separated.

II. Examples of Non-Compliant (Forbidden) Lists

Broadcasting to any of the following list structures violates SystemeScale Terms of Service and will trigger permanent account suspension.

1. Purchased or Rented External Lists

Buying or renting external email lists from data brokers is the fastest way to destroy your business infrastructure. These contacts have never heard of your brand and never consented to your emails.

  • Immediate Spam Reports: Unsolicited recipients will aggressively hit the "Report Spam" button, instantly tanking your domain metrics.
  • Massive Bounces: Data broker lists are loaded with dead addresses, outdated domains, and active spam traps designed specifically to catch bad senders.
  • Total Ban: The importation and use of purchased lists is strictly forbidden on SystemeScale.

2. "Partner" or Third-Party Shared Lists

Even if a partner business operates in the same niche and "shares" their list with you, broadcasting to them is illegal. Presumed interest never replaces explicit, direct consent to your specific business entity.

  • Sending to shared lists constitutes a direct GDPR violation and violates global anti-spam regulations.

3. Social Media Data Scraping

Exporting or extracting email addresses from Facebook groups, LinkedIn connections, or webinar attendee rosters without providing an explicit secondary opt-in form is forbidden.

  • A user logging into a social platform or joining a group does not grant you the right to harvest their data for marketing blasts. If you want to market to a social audience, you must direct them to a SystemeScale landing page to complete a verified opt-in flow.

4. Public Database Scraping

Extracting addresses listed publicly on corporate websites or directories is highly illegal. An address being visible on the internet does not constitute marketing consent.

5. Internal Employee Broadcasts

You must never route internal corporate memos or employee communications through an external marketing autoresponder.

  • Marketing platforms mandate unsubscribe links. If an employee clicks unsubscribe, they will stop receiving vital internal updates. Internal messages should always route through dedicated operational tools (e.g., Google Workspace, Microsoft Teams, Slack).

III. Borderline Cases Requiring Manual Verification

1. Dormant or Cold Contacts

If you possess a list that hasn't received an email from you in over 6 months, their original consent has gone "cold." Suddenly blasting a massive promotional payload to them will likely trigger massive spam complaints as they won't remember your brand.

Action Required: Before resuming normal operations, deploy a strict re-engagement campaign. Send a polite, plain-text email asking: "Would you like to continue receiving our updates?" Only retain contacts who actively click to confirm.

For detailed instructions, refer to: Re-engagement campaign: practical guide to wake up your inactive subscribers.

2. Migration Verification

If you are moving a massive list from an external agency or previous platform, you must definitively verify that you hold opt-in proof for every row of data before initiating your warmup sequence. Do not import suspicious or undocumented segments.

πŸ’‘
Compliance Summary
Always obtain clear, documented consent before importing a contact. Provide immediate, visible unsubscribe links on all broadcasts. Never rely on purchased data. Clean your lists frequently to maintain elite deliverability thresholds.
Was this article helpful?