Help Center
DocsCompliance
CAN-SPAM essentials, one-click unsubscribe, suppression, per-country rules, and the consent audit log
| Field | Description |
|---|---|
| Physical postal address | US anti-spam law requires a valid physical mailing address in commercial email. Laureo adds your business postal address to the footer by default. It is a per-campaign switch: when a campaign keeps it on and no address is on file, that campaign holds its sends until you add one. |
| Working unsubscribe | Cold email ships with a one-click unsubscribe by default. The footer opt-out style and the one-click header are per-campaign switches, so you choose how each campaign offers an opt-out. Whenever an opt-out is offered, it stays functional. |
| Honest subject and sender | The subject must not deceive the recipient about the message, and the sender identity must be accurate. |
When its opt-out signals are enabled, cold email carries a standards-based one-click unsubscribe (the list-unsubscribe header) and a footer link, so a recipient can opt out directly from their mail client. When someone opts out this way, or when a reply that asks to opt out is honored (automatically or after you confirm it, depending on your reply mode below), the address is added to your organization-wide suppression list. Suppression is global across Cold Outreach and Campaigns: a suppressed address is removed from current sequences and excluded from every future import and send. While an address is suppressed, there is no way to send to it.
An opt-out can be undone, one address at a time. Any opt-out record can be removed, whatever created it: one Laureo read from a reply, one recorded from your own opt-out link, and one a recipient sent in one tap from their mail app. A suppression is the other half of that panel, and it follows its own rule. What decides it is the reason on the row, never how the row was recorded. In the Source column, a row that reads Soft bounce or Manual can be removed one address at a time; a row that reads Spam complaint, Hard bounce or Imported stays permanent, whether it was added by hand or arrived in an uploaded file. It is never a switch and never a bulk action. An admin with organization-wide outreach access opens the Opt-outs and suppressions panel on Analytics, uses Remove on that one row, reads a plain warning that removing the record lets your sequences email that person again, types REMOVE, and writes a short reason. The removal is recorded in the consent log with your name, the date and that reason, the row carries that line afterwards, and a workspace can remove at most twenty in a day.
The Source column says how each address came off your list, and a second line beneath it says what the recipient actually did. You will see one-click from the mail client when their mail app sent the standards-based opt-out, unsubscribe page when they opened the link and pressed the button, reply to the unsubscribe address when they emailed the opt-out address, set do-not-contact in the CRM when someone here recorded it after reading a reply, and applied automatically while the plan was lapsed when cold outreach was paused for billing. A row that names no campaign, or that reads Last campaign sent to this address, is telling you the record cannot be tied to one message with certainty.
Alongside the act, Laureo records what it can about the device that performed it: the date, a one-way hash of the network address, the browser or mail client string, and whether the request looked automated. The line reads Recorded, with the date and the kind of client when that evidence exists and No device evidence recorded when it does not, which is what older records look like. The network address itself is never stored, and none of this evidence leaves the consent log: it is not exported with a contact and it is not visible to anyone without organization-wide outreach access.
Where the suppression list works one address at a time, a blocked domain shuts out a whole company at once. In Cold Outreach settings, the Blocked domains card lets you add or remove domains, each entered as a registrable root such as acme.com. The block matches every address at that domain and at its subdomains, so acme.com also covers mail.acme.com. It is enforced at every stage: leads at a blocked domain are dropped on import, skipped at enrollment, and never sent to. Use it for competitors, customers you handle elsewhere, or any organization you want kept out of cold outreach entirely.
Four opt-out controls, with org defaults and per-campaign overrides.
In Cold Outreach settings, under Unsubscribe & opt-out, you set the defaults for four opt-out controls. Each is an org-wide default that a campaign can override in its Delivery & compliance section, so one campaign can differ without changing the rest. The defaults ship compliant. First, pick a footer style:
| Field | Description |
|---|---|
| Unsubscribe link | The footer shows a visible unsubscribe link and a one-click opt-out page. This is the default. |
| Reply to opt out | The footer asks the recipient to reply to opt out, with no link. It reads more personally. How a reply that asks to opt out is then handled is set separately, under When a reply asks to opt out. |
| No opt-out text | The email body carries no opt-out line. Recipients can still opt out through the one-click header and reply detection when those are enabled. Providing a lawful opt-out path remains your responsibility. |
A one-click unsubscribe header toggle controls the standards-based list-unsubscribe header (RFC 8058) that lets recipients opt out in one tap from their mail app. It is on by default, and we recommend leaving it on: it reduces spam complaints, which hurt deliverability far more than an unsubscribe does. Major inbox providers require this header at higher daily sending volumes.
A When a reply asks to opt out control decides what happens when Laureo's reply detection reads a reply as an opt-out request. Unsubscribe automatically adds the address to your suppression list right away; Ask me to confirm raises it for you to approve first; Do nothing leaves durable suppression to you, though the reply still stops the sequence. This control needs AI reply detection turned on.
An Include business postal address toggle adds your business address line to the footer. US anti-spam law requires a postal address in commercial email, so it is on by default. When it is on and no address is on file, a campaign that keeps it on holds its sends until you add one.
A one-click bare-email preset, and the check that stops you from removing every opt-out path by accident.
A campaign sets its opt-out controls in its Delivery & compliance section in the sequence builder, each starting on your org default. Two affordances there are worth calling out.
The Plain email button is a one-click preset for a bare, personal-looking cold email. In a single action it turns the opt-out text off, the one-click header off, and the postal line off, leaving the reply opt-out mode untouched. Reach for it when you want the message to read like an ordinary one-to-one note and you intend to carry your address and opt-out in your signature instead, the pattern described below.
Because that posture can leave a campaign with no working opt-out path, both the builder and the settings card watch for it. When a campaign has no unsubscribe link, no one-click header, and no reply handling to honor a reply that asks to stop, they show a plain-text warning and ask you to acknowledge it once with an I understand action. The acknowledgment is recorded a single time for your organization, a deliberate speed bump so you never strip every opt-out path without meaning to.
A pattern for a plain, personal cold email that still offers a lawful opt-out.
If you turn the footer opt-out text or the postal line off to make a cold email read like a normal one-to-one message, you can still meet your obligations by carrying the same information in your email signature. A short signature with your name, your company, your business postal address, and a plain line such as “If you would rather not hear from me, just reply and I will stop” gives the recipient a real mailing address and a real way to opt out, without a marketing-style footer. Pair it with the reply opt-out mode set to Unsubscribe automatically or Ask me to confirm, so a reply asking you to stop is actually recorded and honored. This is how a bare, personal-looking cold email can still stay inside the rules. The lawful basis for it remains your responsibility.
Several countries restrict cold email more tightly than the US. Germany, Austria, and Italy generally require prior consent even for B2B outreach, and Canada's anti-spam law (CASL) is strict. When a lead appears to be in one of these jurisdictions, Laureo flags the send with a warning so you can make an informed decision. The flag is advisory and does not silently skip the lead. You are responsible for confirming you have a lawful basis to contact recipients in regulated jurisdictions.
Laureo keeps an audit log of suppression and consent events (unsubscribes, confirmed removal requests, and list-source attestations), so you have a defensible record of how each address was handled. Undoing an opt-out is written here too, as a suppression_removed event carrying the admin who removed it, the typed confirmation and the reason they wrote. This is also where a promoted lead's pending opt-in status is recorded, keeping your marketing-consent data honest.