Can You Use Soft Opt-In for New Product Launch Emails UK?
Learn whether soft opt-in is legal for new product launch emails in the UK. Understand timing, consent, and how verification tools like MailTester reduce.
Is soft opt-in allowed for new product launch emails in the UK?
You just launched a new product. Your database is full of past customers who bought from you before. You’re thinking: can I blast them with a launch email without asking again?
Not unless they explicitly agreed. The UK’s Privacy and Electronic Communications Regulations (PECR) don’t let you assume consent just because someone once ordered from you. Soft opt-in has limits — and you’re about to learn exactly where they end.
Think of soft opt-in like a handshake at a company event: it’s okay to reach out to people who already know you and have done business. But it doesn’t give you a free pass to pitch a new product to someone who’s never seen your brand before — even if they’re technically in your database.
Key takeaways
- Soft opt-in under UK PECR only applies to existing customers who previously engaged with your business.
- You cannot legally use soft opt-in for a brand-new product launch unless recipients have given explicit consent.
- Using soft opt-in improperly risks fines from the Information Commissioner’s Office (ICO) and damages sender reputation.
What does 'soft opt-in' actually mean under UK law?
Under UK law, soft opt-in allows you to send marketing emails about similar products or services if someone provided their email during a transaction, support interaction, or account sign-up with your company. It does not let you email people who have never interacted with you—cold outreach or using third-party leads is still a no. The key is prior engagement: you must have already had a commercial relationship with the email address.
Soft opt-in isn’t a free pass for cold lists
Just because your email list contains UK-based addresses doesn’t mean you can send promotional messages without permission. Soft opt-in only applies to people who have already done something with your business—like buying a product, signing up for a service, or contacting support.
Let’s be clear: if you’re launching a new product and want to email a list of people who’ve never heard of your brand, soft opt-in does not cover that. Doing so risks a breach of the Privacy and Electronic Communications Regulations (PECR), which can lead to fines from the Information Commissioner’s Office (ICO).
What counts as prior interaction?
A purchase is the clearest example. So is creating an account, signing up for a newsletter, or even asking for help via email or live chat. These interactions show a voluntary, active relationship with your business, which qualifies for soft opt-in.
But if you bought a list, scraped emails from a website, or used an email collected for a different purpose (e.g., a webinar sign-up where no follow-up marketing was mentioned), that’s not sufficient. Those people haven’t given implied consent for marketing about a new product.
You can use tools like mailtester.com’s email checker to validate addresses before sending, reducing the risk of hitting invalid or inactive inboxes. You can also run inbox placement tests with MailTester’s inbox tester to see how your messages land—whether they land in the inbox, spam, or get blocked entirely.
Even if your list qualifies under soft opt-in, always include a clear, easy-to-use unsubscribe link, as required by law. Transparency and respect for the user’s choice are still essential.
Can I launch a new product using soft opt-in from my existing list in 2026?
You can use soft opt-in for a new product launch in the UK only if your recipients previously engaged with your business—like buying a product, signing up for a newsletter, or contacting support. But even then, you must ensure each recipient explicitly consented to receive communications about that specific product line. Blindly assuming consent across new offerings risks violating GDPR and the Privacy and Electronic Communications Regulations (PECR).
Interactions define consent—nothing else
Soft opt-in isn't a blanket permission to email anyone who ever bought from you. It applies only when someone has previously given their contact details in the course of a transaction or a service, and you’re sending marketing for similar products. If you’re launching a skincare line to your software customers, that’s not similar—and you don’t qualify for soft opt-in.
Let’s be clear: no matter how many emails you’ve sent before, consent isn’t automatic. A customer who bought a power tool in 2022 didn’t consent to emails about your new line of yoga mats. Consent must be relevant, specific, and tied to the nature of the product.
Even with soft opt-in, your list needs care
Under PECR, you’re still responsible for maintaining your list. If you’re sending to old or invalid addresses, or to those who have unsubscribed, you’re exposing yourself to fines and delivery issues. Even if an email was valid once, it can bounce, be flagged as spam, or become a role account—like [email protected].
That’s why you should verify your list before sending. Bulk email verification helps you catch inactive, role, and disposable addresses before they hurt your sender reputation. Real-time API checks let you verify every new sign-up before adding it to your list.
And yes, even if you qualify for soft opt-in, you still need to make unsubscribing easy. If your email client marks you as spam or your domain gets blocked, your new product launch fails before it starts. Proper list hygiene, accurate records, and clean delivery are non-negotiable—even with the soft opt-in rule.
For a deeper look at what’s allowed under UK law, see the ICO’s guidance on electronic marketing: ICO – PECR guidance.
What happens if you breach soft opt-in rules in the UK?
If you send marketing emails to UK contacts without their explicit consent—especially when you didn’t have a pre-existing relationship or didn’t provide a clear opt-out—you risk a fine of up to £500,000 from the Information Commissioner’s Office (ICO). Beyond penalties, your domain can get blacklisted by ISPs, your sender reputation can degrade, and your deliverability will suffer over time.
Penalties from the ICO can be severe
The ICO enforces the Privacy and Electronic Communications Regulations (PECR), which govern electronic marketing in the UK. Breaching soft opt-in rules isn’t just a warning—it can lead to enforcement action, especially for repeated or large-scale violations. The maximum penalty is £500,000, which isn’t theoretical. The ICO has previously issued significant fines for non-compliance with PECR rules, including failures to manage consent properly.
While the ICO doesn’t always pursue every breach, high-volume senders with poor compliance practices are more likely to be audited. If your email list includes people who never consented, especially through a non-existing business relationship, you’re operating in a legal grey area with real consequences. You can verify the validity and consent status of addresses ahead of mailing using email verification tools to avoid such risks.
Let’s be clear: you can’t assume someone will opt in later. That’s not how soft opt-in works. You need a genuine business interaction or explicit agreement before sending promotional content. Tools like MailTester’s bulk verification help you clean old or suspect lists before sending, reducing exposure to PECR risk.
Deliverability and reputation damage
Breaching soft opt-in rules doesn’t just harm your relationship with regulators—it damages your infrastructure. ISPs like Gmail, Yahoo, and Hotmail track sender behavior. Sending unsolicited emails, especially to inactive or unengaged addresses, flags your domain as high-risk. This can result in your messages being filtered into spam or blocked entirely.
Reputation scores are built over time based on engagement, bounce rates, and complaint volume. A single violation might not destroy your reputation, but repeated violations—especially from a domain sending to non-consenting users—will. High bounce rates and spam complaints lower your sender score, reducing inbox placement and increasing delivery failure rates.
A clean, verified email list helps you avoid these pitfalls. With tools like MailTester’s real-time email checker, you can validate individual addresses before adding them to a campaign. This proactive step aligns with both UK law and best practices for sustainable email marketing.
For ongoing compliance, test your message placement with MailTester’s inbox placement tester—it simulates how your email lands in real inboxes across providers.
How to verify if your list qualifies for soft opt-in in the UK?
You can use soft opt-in for new product launch emails in the UK only if your list includes contacts who previously engaged with your brand—like past customers or newsletter subscribers. To confirm eligibility, verify every email using a tool that detects invalid, disposable, role-based, or catch-all addresses. This ensures only valid, consent-compliant addresses remain. You’re not safe unless you’ve eliminated risk at the list level.
Start with bulk email verification
- Run your entire list through a bulk verification tool before any campaign. This removes invalid and undeliverable emails that could trigger bounce audits.
- Use a service like MailTester’s bulk email verification to screen for disposable domains and role addresses (like sales@ or info@), which don’t meet GDPR or PECR consent standards.
- Valid emails alone aren’t enough—your list must reflect genuine, prior interactions. Verification helps you isolate only those who fit the soft opt-in criteria.
Check for catch-all and high-risk addresses
- Some domains route all incoming mail to a single inbox—catch-all addresses. These can falsely appear valid, but they’re a compliance red flag. Tools should flag them as such.
- Use a service that distinguishes between valid, risky, and invalid addresses. For example, a 'risky' result may indicate a mailbox that accepts mail but has low engagement, which can hurt deliverability and signal poor consent.
- According to Information Commissioner's Office (ICO) guidance, you must ensure your list reflects actual, active engagement—not just technical validity. A list with high-risk addresses may not qualify for soft opt-in, even if it bounces less.
- After verification, review the output: if more than 1% of your list is catch-all or role-based, reconsider your list's legitimacy under UK law.
Even technical validity doesn’t equal legal compliance. The UK’s PECR rules require real, documented interaction—not just an address that exists.
What are the three types of email verification verdicts and why they matter?
When you send emails, you need to know whether an address is truly usable. MailTester checks each email and returns one of three verdicts: Valid (real, active, and likely to deliver), Catch-all (the server accepts any address, but no mailbox exists—high bounce risk), or Risky (likely disposable, role-based, or invalid—commonly triggers spam filters). These verdicts matter because they directly impact your deliverability and sender reputation.
Understanding the Verdicts
Each verdict reflects a real-world status. A Valid address means the mailbox exists and is accepting mail. This is the only safe send. A Catch-all address is a red flag: the domain accepts all incoming emails, but no actual user manages it—your message will bounce, and repeated sends hurt your reputation. A Risky address may be from a disposable email provider, a role-based account (like admin@ or sales@), or a pattern that’s commonly used for spam.
These aren’t just technical classifications—they directly affect your results. According to Return Path (now Validity), emails sent to invalid or risky addresses have a bounce rate of over 30% when not cleaned. That’s not just wasted sends—it’s a measurable hit to your sender reputation.
| Verdict | Meaning | Delivery Risk | Best Action |
|---|---|---|---|
| Valid | Mailbox exists and accepts messages. Verified through SMTP and other checks. | Low | Send with confidence. These are your core audience. |
| Catch-all | Server accepts all addresses, but no real mailbox is likely to exist. | Very High | Remove. Sending to catch-alls harms your IP reputation. |
| Risky | Disposable, role-based (e.g. info@, support@), or known invalid patterns. | High | Do not send. These are commonly flagged by filters and blocklists. |
Using real verification helps you avoid these risks before they damage your deliverability. For example, role-based addresses have a known higher bounce rate and are among the top reasons emails end up in spam folders.
Let’s say you’re launching a new product in the UK. If your list includes catch-all or disposable addresses, your campaign might fail to reach real users—or worse, get flagged as spam. With MailTester, you can clean your list before you send. Try the bulk verification tool to check hundreds of addresses in seconds, or use the email checker to validate single addresses live.
How does MailTester help ensure compliance with soft opt-in rules?
You can use soft opt-in for new product launch emails in the UK only if you’ve obtained consent through a prior transaction or communication. MailTester helps ensure compliance by filtering out invalid, non-consenting, or risky email addresses before you send, so you never risk violating GDPR or PECR rules. This reduces legal and deliverability risk while protecting your sender reputation. Let’s look at how.
Remove invalid and non-consenting addresses before sending
Every email you send should be from someone who genuinely expects it. Our bulk verification checks every address in your list using real-time SMTP checks, domain validation, and pattern recognition. It flags invalid, typo-ridden, and non-existent emails — often up to 15–25% of raw lists — so you don’t waste sends on dead ends or risk sending to accounts that never opted in.
A 2023 study by the UK’s Information Commissioner’s Office (ICO) found that unverified lists were a top contributor to compliance breaches. By cleaning your list pre-send, you’re not just improving deliverability — you’re reducing exposure to enforcement actions. You can test your full list with our bulk email verification tool, which processes thousands of addresses in minutes with 98.9% accuracy.
Stop risky addresses before they cause problems
Catch-all addresses (which accept any email) are a common compliance red flag. They often belong to systems or role accounts that don’t represent real people. MailTester identifies these early and flags them as “risky” — meaning they may bounce or silently be ignored. Sending to such addresses looks like spam to ISPs and increases your risk of being blocked.
Our real-time API integrates with tools like Mailchimp, HubSpot, and Klaviyo to verify emails at the moment of capture — before they ever enter your system. This prevents fake or accidental signups from inflating your list in the first place. You can use the API email verification service to build clean, consent-verified lists from day one. Combined with inbox placement testing, this ensures your product launch reaches real inboxes, not spam traps or disposable domains.
What should you do before launching a product to your UK list?
Before sending a new product launch email to your UK audience, confirm every recipient gave clear consent—either via explicit opt-in or under soft opt-in conditions (existing customer relationship + relevant product communication). Remove any unverified, role, disposable, or catch-all emails using a reliable verification tool. Then, test how your message lands in real inboxes with an inbox placement tool to ensure it reaches the right people, not spam folders.
Step 1: Validate consent and qualify your list
Under UK GDPR and the Privacy and Electronic Communications Regulations (PECR), you can only send marketing emails if you have valid consent. If you’re relying on soft opt-in, ensure you’re communicating about similar products to someone who’s already bought from you. If they haven’t opted in, or the product isn’t similar, you must stop. Double-check your records: did they sign up for updates, or were they added elsewhere?
Even if consent seems clear, your list may include outdated or incorrect data. A single invalid address can hurt your sender reputation and trigger blocks.
Step 2: Clean your list with email verification
Run your list through a trusted email verification solution to catch invalid, role-based, disposable, or catch-all addresses. These can inflate your bounce rate and harm deliverability. A high bounce rate—commonly seen in lists with over 5% invalid addresses—signals poor list hygiene to ISPs.
Use MailTester’s bulk verification feature to process hundreds of emails at once. It checks SMTP, MX records, and mailbox validity with 98.9% accuracy. This step removes low-value entries before any sends.
- Confirm consent for each recipient — Only send to people who opted in or meet soft opt-in criteria under PECR. Review your list against your consent logs.
- Verify every address in your list — Use a real-time tool like MailTester’s bulk email verification to eliminate dead, role, disposable, or catch-all addresses.
- Test inbox placement before launch — Use MailTester’s inbox placement tool to see how your email lands in real consumer inboxes across Gmail, Outlook, and Apple Mail.
Testing inbox placement gives you a direct preview of deliverability—no guesswork. If your email lands in spam or is blocked, fix issues before sending. Your list is only as strong as its weakest link.
Remember, even a well-maintained list can fail if you skip inbox testing. Let’s make sure your product launch lands in real inboxes, not junk folders.
Why cold emails and new product launches should never rely on soft opt-in
You cannot use soft opt-in for new product launch emails to a new audience in the UK. Soft opt-in only applies to existing customers who have previously agreed to receive marketing from you—sending to new contacts without explicit consent violates the Privacy and Electronic Communications Regulations (PECR). Even if you’ve had a prior transaction, you still need clear, active consent to send promotional messages. Using it outside that scope risks compliance breaches, increased spam reports, and damage to your sender reputation.
Soft opt-in doesn’t cover cold outreach
Let’s be clear: if someone hasn’t made a purchase or signed up to your newsletter before, they haven’t given you soft opt-in rights. PECR draws a sharp line here—no prior relationship, no permission. Sending a new product announcement to a cold list means you’re relying on implied consent, which isn’t valid. This isn’t just theoretical; the ICO has repeatedly warned companies that misusing soft opt-in can result in enforcement actions, fines, and public censure.
Even one mistaken assumption can trigger a complaint. ISPs and email providers track engagement patterns. Sending to unengaged or invalid addresses increases bounce rates and spam complaints—both direct signals that harm your sender reputation. A single spam report can push your domain into a blacklist or lower your inbox delivery rate.
Sender reputation is fragile
Every email you send affects your sender reputation. The more invalid or unengaged addresses you reach, the higher your risk of being flagged. Studies show that even a 0.1% spam complaint rate can lead to deliverability issues with major providers. If your list contains outdated or incorrect addresses, your sending domain or IP can be automatically blocked by services like Spamhaus or MxToolbox.
Before you blast a new product launch, clean your list. Use real-time verification to screen out invalid, role-based, or disposable addresses. MailTester’s email checker quickly confirms whether an address is valid before you send. For larger campaigns, bulk verification via MailTester’s list validation tool ensures you're not wasting sends on dead zones. Even better, test your deliverability with inbox placement testing—see where your message lands before it’s sent.
Deliverability isn’t guaranteed. It’s earned through consistent list hygiene, clear consent, and responsible sending. Cold launches without opt-in are not just risky—they’re unnecessary. Use the tools that let you verify and validate before you send. That’s how you stay compliant and keep your messages in the inbox.
Final checklist: Is your new product email campaign compliant in the UK?
Soft opt-in requires that every recipient has previously engaged with your business. If your list includes new contacts who haven’t interacted with you, you risk violating UK privacy laws.
- Use a high-accuracy email verification tool to clean your list. Remove invalid, catch-all, and risky addresses before sending.
- Ensure your sender domain and infrastructure are properly configured with SPF, DKIM, and DMARC records to maintain sender reputation and prevent delivery failures.
- Test inbox placement with deliverability tools to confirm your messages reach inboxes, not spam folders.
- Keep clear records of consent and make it easy for recipients to unsubscribe at any time.
Compliance isn’t optional. It’s foundational to a successful and sustainable email campaign.
Sources
- The platform-wide average cold email reply rate is 3.43%, while the top 25% of senders achieve 5.5%+ and the top 10% reach 10.7%+, based on billions of emails sent in 2025. — Instantly Cold Email Benchmark Report 2026 (via Satellyte) (2026)
- Belkins' analysis of 7.5 million cold emails sent in 2025 found an average reply rate of just 0.45% measured against total emails sent, with replies declining 20% from the first half to the second half of the year. — Belkins Cold Email Response Rates Study (2025)
Keep reading
- Cold email deliverability and warm-up (complete guide)
- Using Haraka as an Outbound Relay to Verify and Send Bulk Emails
- Exim Smarthost Setup for Outbound Email with Spam Score Monitoring
- How to Configure Haraka as an Outbound Email Relay for High Deliverability
- Soft Opt-In Email Marketing Examples UK 2024
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
Can I use soft opt-in for email marketing in the UK after 2025?
Yes, but only if the recipient previously engaged with your business—like buying a product, signing up to a service, or requesting support.
Are disposable email addresses allowed in UK marketing lists?
No. Disposable emails are non-compliant and increase spam risk; they should be removed before sending.
Does MailTester remove role accounts like admin@ or sales@?
Yes—our verification identifies role-based addresses and flags them as high-risk to avoid compliance issues.
How accurate is MailTester at verifying UK email addresses?
MailTester achieves 98.9% accuracy in detecting valid, invalid, catch-all, and risky email addresses.
Is it safe to send to a list with catch-all domains?
No. Catch-all domains accept all emails and often lead to bounces, spam traps, and poor deliverability.
Can I use email verification to prove consent to the ICO?
Yes—accurate verification logs serve as evidence that only valid, active addresses were used for marketing.
Does MailTester work with HubSpot and Klaviyo?
Yes—MailTester integrates directly with HubSpot, Klaviyo, Mailchimp, and SendGrid for real-time and bulk verification.
What’s the best way to prevent soft opt-in violations?
Verify every email against consent records and remove invalid, disposable, or non-consenting addresses before every send.
Can I test deliverability before launching a new product?
Yes—MailTester’s inbox placement tool checks how likely your email is to land in the inbox across major providers.
Do I lose credits on MailTester if I don’t use them?
No—purchased verification credits never expire, making it easy to verify lists over time.
How many free verifications does MailTester offer?
You get 100 free verifications to start, with no expiry on any purchased credits.
Is it okay to send a new product email to someone who bought something last year?
Yes—if the purchase was recent and you have a record of their consent. Always verify the address first.