You’ve just collected a new email address from a customer. You’re excited to send them an offer. But is that email truly valid for marketing under French law? The answer hinges on something many brands overlook: consent.

The French data protection authority, CNIL, doesn’t allow vague or passive agreements. For email marketing, consent must be freely given, specific, informed, and unambiguous—meaning no pre-ticked boxes, no implied agreement, and no bundling with a purchase.

Think of it this way: if you’re asking for consent, you’re asking for a yes—clear, intentional, and recorded. CNIL expects proof, not assumptions. In practice, that means double opt-in is not optional. It’s a legal necessity.

Key takeaways

  • Consent for email marketing under French CNIL rules must be freely given, specific, informed, and unambiguous.
  • Pre-ticked boxes, implied consent, or bundling marketing consent with another transaction are invalid under CNIL standards.
  • Organisations must demonstrate active opt-in; double opt-in is required to prove lawful consent under CNIL guidance.

CNIL defines 'active' consent as a clear, deliberate action—like clicking a confirmation link after subscribing. Simply entering an email during a purchase or signing up isn’t enough unless you verify the user’s intent through a confirmed opt-in. Silence, pre-checked boxes, or scrolling past a consent prompt don’t count as valid consent under French law.

What counts as a valid opt-in under CNIL?

For consent to be valid, the user must take a positive step. The simplest example is a confirmation link sent after a user submits their email. They must open that link and click it to confirm their subscription. This action proves they’re aware and have willingly opted in.

Pre-ticked boxes, bundled consent, or accepting terms of service without a clear opt-in step don’t meet CNIL’s standard. The GDPR and CNIL reinforce that passive actions—like not unsubscribing, not replying, or allowing a checkbox to remain checked—do not constitute valid consent. You can’t assume permission simply because someone didn’t say no.

Let’s be clear: if a user signs up on your site and you send them an email without requiring them to click a confirmation link, you’re relying on implied consent. CNIL sees that as a violation. The European Court of Justice has affirmed that consent must be “freely given, specific, informed, and unambiguous,” and that means an active choice.

This isn’t just about avoiding fines—it’s about trust. Users who didn’t take a deliberate action haven’t agreed to receive emails. Sending to them reduces deliverability, increases spam complaints, and risks reputation with ISPs and mailbox providers. Even if your mail lands in an inbox, you’re violating consent standards.

You can use tools like MailTester’s bulk list verification to identify and clean invalid or inactive addresses before sending. Removing non-confirmed emails helps maintain sender reputation and keeps your list compliant. It’s a small step, but it matters.

The same applies to your real-time API: MailTester’s verification API checks each email as it enters your system, catching role accounts, disposable domains, and invalid formats before you even send. This reduces bounce rates, improves deliverability, and supports compliance from the start.

If your email list contains addresses collected without valid consent under French CNIL rules, you risk fines up to €20 million or 4% of your global annual turnover—whichever is higher. Even a single non-compliant address can trigger an investigation, especially if multiple users were added without authorization. Such lists are more likely to be flagged as spam, harming your sender reputation and reducing inbox placement—even if the rest of your emails are fully compliant.

Fines and enforcement under CNIL

French data protection authority CNIL enforces GDPR rules with real teeth. While they may start with a warning, repeated or systemic failures can lead directly to substantial penalties. The maximum fine—up to 4% of global annual revenue—means even mid-sized companies can face significant losses. Regulatory scrutiny is especially high when automated data collection methods, like scraping or form harvesting without opt-in, are involved.

You don’t need a massive list to get in trouble. CNIL has pursued organizations for violating consent rules with just a few non-compliant addresses, particularly if they were added without clear, documented consent. If you send to an address that never opted in—or if consent was obtained in a misleading way—the risk of an audit remains high.

Reputation, deliverability, and spam flags

Even if CNIL doesn’t take action, your email delivery suffers. Spam filters and inbox providers like Gmail, Outlook, or Yahoo monitor sender behavior. A list containing unconsented addresses sends red flags. You’ll see higher bounce rates, more spam complaints, and faster placement in the spam folder—even if your messaging is otherwise valid.

Sender reputation relies on consistency. If your list includes ghost addresses, role accounts, or unverified entries, your domain's reputation can erode quickly. This reduces message deliverability across the board. The longer you use poor-quality data, the harder it is to recover.

Let’s be clear: compliance isn’t just about avoiding fines—it’s about keeping your messages in front of real people. That means checking every address for validity, consent, and behavior before sending.

The right tools help. Use bulk list verification to test your entire list—find invalid, catch-all, or risky addresses before any campaign goes out. Real-time verification API integration stops bad addresses at the gate. And inbox placement testing shows how your emails land in real inboxes, not just spam folders.

It’s not enough to send to any email. You must send to the right email, with the right consent. That’s how you stay compliant and stay deliverable.

Why verifying your list is essential under CNIL rules

You must verify every email address before sending marketing messages under CNIL rules because invalid, role-based, or disposable addresses often signal prior non-consensual data collection. CNIL prioritizes genuine opt-ins, and sending to forged or placeholder emails risks violating the principle of legitimate consent. A clean list isn’t just efficient—it’s a technical component of compliance.

Invalid or fake addresses reveal compliance risks

A high number of invalid or syntactically incorrect email addresses in your list can indicate that data was scraped or acquired without consent. CNIL treats such data as inherently non-compliant, especially if it came from third-party sources without verifiable opt-in records.

Even one unverified address can weaken your case if you’re audited. Tools like MailTester help you identify and remove these addresses before sending—protecting your sender reputation and reducing the risk of enforcement actions.

Role accounts, disposable domains, and catch-alls are red flags

Role accounts like info@, admin@, or support@ are frequently used to mask bulk data collection. CNIL expects marketing messages to be sent only to individuals who explicitly opted in. Sending to a role account suggests the data was never tied to a real person.

Disposable email domains (like tempmail.org) are commonly used to sign up for services without intent to engage. Catch-all email systems (which accept all incoming mail regardless of the recipient) often serve as backdoors for abuse—accepting messages without confirming consent.

These address types aren’t just dead ends—they’re signals of poor data hygiene. Using a tool like MailTester’s bulk verification helps you filter out such addresses in real time. This reduces the risk of sending to non-consenting recipients and aligns with CNIL’s emphasis on data specificity and control.

Let’s be clear: you can’t claim consent for an address that wasn’t ever a real human. A verification tool that returns real-time results—like the MailTester API—lets you scrub new signups instantly and maintain a list that’s both deliverable and compliant.

For context, the European Data Protection Board (EDPB) has stated that consent must be “specific, informed, and unambiguous” — meaning a single address from a role or disposable domain undermines that standard. You can review the EDPB’s guidance on consent here. It’s not just about avoiding bounces—it’s about proving consent exists on a per-address basis.

How to verify list accuracy before launching a campaign

Before you send a single email, run your entire list through a bulk verification tool that checks domain validity, delivery feasibility, and flags role accounts or disposable addresses. This step prevents bounces, avoids spam traps, and ensures you’re only targeting real, active users—critical for compliance with French CNIL rules on consent.

Start with a real-time verification pipeline

  1. Use a bulk verification service like MailTester to test all your email addresses at once. It checks whether the domain exists, if the mailbox is deliverable, and catches problematic addresses before they hit your inbox.
  2. Review each address's verdict. Invalid addresses (non-existent) will bounce immediately. Risky ones may be catch-all boxes or disposable domains—common signals of low engagement or abuse.
  3. Flag and exclude role accounts like info@, sales@, or support@. These often represent shared or automated inboxes, making it hard to prove valid consent under CNIL’s standards for legitimate interest. RFC 5322 defines standard syntax, but does not validate intent—your list must reflect actual individuals.
  4. Drop all addresses with “catch-all” or “risky” status. Catch-alls accept any address at a domain, making verification unreliable. Disposable addresses are typically short-lived and used for spam evasion. Both increase your risk of being flagged or blocked.
  5. Recheck using a real-time API if your list grows dynamically. Tools like MailTester’s verification API integrate into your workflow, validating new signups in real time, reducing invalid data at the source.

Verify inbox placement and delivery readiness

Even if an address is valid, it may not land in the inbox. Run an inbox placement test via MailTester’s inbox tester to see how your campaign performs across major providers like Gmail, Outlook, or Yahoo. This helps predict deliverability and avoid being caught in spam filters—especially important when targeting French users subject to CNIL’s strict consent rules.

Remember: CNIL requires clear, affirmative consent for email marketing. Sending to a list with invalid, disposable, or role-based addresses makes compliance nearly impossible. You can’t prove consent to a non-existent user or a shared inbox. Verification isn’t just about deliverability—it’s a core part of the legal foundation for your campaign.

What do 'valid', 'invalid', 'catch-all', and 'risky' mean in verification?

You're not just checking if an email exists—you're assessing its actual deliverability and risk. A valid address is confirmed to receive messages and has an active inbox. An invalid address is rejected by the server as non-existent or out of domain. A catch-all address accepts all incoming mail, often meaning it’s not properly verified or used for spam traps. A risky address is likely a temporary, role-based, or bot-generated email—common in scraped lists. These verdicts help you remove dead or dangerous addresses before sending, which reduces bounces and protects sender reputation.

Understanding email verification verdicts

Let’s break down what each status actually means when you verify an email list.

Verdict Meaning Why it matters for email marketing
Valid Confirmed delivery-capable email with an active inbox. The server accepts mail and does not immediately reject it. These are the addresses you want to keep. They’re likely to reach an actual inbox and engage with your content.
Invalid Server explicitly rejects the address as non-existent, out of domain, or malformed (e.g., [email protected]). These addresses will bounce immediately. Keeping them hurts deliverability and can damage your sender reputation.
Catch-all Any message sent to this domain is accepted, regardless of the local part ([email protected]). Common in shared hosting or poorly configured servers. High risk: you can’t tell if the address is real or just a placeholder. Often a sign of low-quality or scraped data.
Risky Indicates temporary email, role-based domain (like [email protected]), or known disposable email provider. These often go to spam folders or are ignored. High volume of ‘risky’ addresses suggests list contamination—or worse, a bot-driven list.

If you're building a list for marketing, only “valid” emails should be included. “Invalid” and “catch-all” should be removed. “Risky” ones should be flagged or excluded—especially in regulated markets like EU, where under the French CNIL rules, any consent claim must be verifiable. For consent to be valid, you need proof it came from a real, active person, not a role address or a disposable email.

Verification tools like MailTester’s bulk verification help you catch these risks early. You can also test deliverability with inbox placement testing to see how your messages land across providers like Gmail and Outlook. This matters in Europe, where CNIL emphasizes that consent isn't just a checkbox—it must be demonstrably tied to a real, functional inbox.

Can you reuse old lists without re-consenting?

No. You cannot legally reuse old email lists without re-consenting if you’re sending after 2024, even if the data was collected years ago. Under CNIL’s current enforcement guidance, consent must be demonstrably obtained and renewed for any data used in marketing campaigns past the GDPR transition period. If your records lack a clear consent date or confirmation, treat the data as invalid. Re-engagement campaigns with unverified lists risk fines, especially if senders can’t prove consent was valid at the time of use.

Why historical data isn’t a free pass

Even if you collected emails before 2018, the GDPR’s principle of “consent must be current” applies regardless of when the data was gathered. CNIL consistently emphasizes that outdated or unverified consents don’t meet the standard for lawful processing. If your records don’t show when consent was given or how it was obtained, you’re failing the burden-of-proof test. Let’s be clear: a 2015 opt-in checkbox doesn’t count if you can’t prove it met current consent requirements.

How to handle unverified or outdated lists

If you’re unsure whether consent exists—or if records are missing—assume it doesn’t. The safest path is to re-verify every address before sending. Use tools that check validity, inbox placement, and sender reputation to prevent hard bounces and flag potentially harmful addresses. This isn’t just about compliance; it’s about protecting your sender reputation. Sending to invalid or role-based addresses increases your risk of blacklisting.

MailTester’s bulk verification lets you scan entire lists for validity, catch-alls, and risky addresses in minutes — all without sending a single email. You can also run inbox placement tests to see how likely your messages are to land in inboxes, not spam. For ongoing campaigns, integrate with Mailchimp, Klaviyo, or HubSpot, and use our real-time API to validate addresses at the point of entry.

Even if the law doesn’t change tomorrow, CNIL’s enforcement has become more focused on intent and record-keeping. You can’t rely on outdated processes. The best defense isn’t compliance theater—it’s using data that’s both valid and verified. Learn more about ensuring your data meets standards at MailTester’s email list verification.

How MailTester supports compliance with CNIL standards

MailTester helps you meet French CNIL rules for email consent by filtering out invalid, high-risk, or low-integrity addresses before you send. This reduces the risk of violating GDPR and CNIL’s strict requirements on valid consent, especially when using email for marketing. You’re not just cleaning lists—you’re reducing your legal exposure.

  • Our 98.9% accurate verification model combines real-time SMTP checks and DNS lookups to confirm each address is both valid and actively receiving mail.
  • We flag role accounts (like admin@, sales@) and disposable email domains—common signs of consent that's not meaningful under CNIL guidelines.
  • Catch-all addresses are detected and marked as risky, since they can’t reliably prove consent or engagement, violating the requirement for a genuine opt-in.

Seamless integration with common mailing tools

  • Connect directly to Mailchimp, HubSpot, Klaviyo, or SendGrid—no manual exports or spreadsheets. Let’s clean your list before every send with automated verification.
  • Run a verification sweep on your entire list in minutes, so only engaged, compliant addresses get into your campaigns.
  • Use the bulk verification tool to test entire segments at once. Identify risk early, without sending to invalid or suspect addresses.

Consent isn’t just about checkboxes—it’s about verifying who’s actually receiving your messages. CNIL emphasizes that consent must be specific, informed, and freely given. If an email is undeliverable, or routed through a role account or temp domain, the consent doesn’t hold. With MailTester, you’re not guessing—your deliverability and compliance are grounded in actual address status.

For real-time validation of individual addresses before a single message goes out, use our email checker. It’s built to verify authenticity at scale with zero false positives on working domains.

“Email marketing under GDPR requires more than just opt-in—it requires ongoing validation of address quality and consent integrity.” — European Data Protection Board, guidance on processing personal data via email

For teams that process large volumes, our verification API enables real-time checks during signup or during campaign prep. This is critical for meeting CNIL’s expectations around data accuracy and responsibility.

When to test inbox placement before sending to French audiences

You should always test inbox placement before sending email campaigns to French audiences, especially if you’re targeting individuals in regulated industries or relying on consent-based marketing. French data protection standards under the CNIL are strict, and even minor missteps in consent or sender reputation can result in deliverability failures. Use inbox placement testing tools—like MailTester’s inbox tester—to verify that your emails land in inboxes, not spam folders. A low placement score is a clear signal: your message is being flagged, likely due to weak consent signals or a poor sender reputation.

Why inbox placement matters for French compliance

French audiences are among the most privacy-conscious in Europe, and the CNIL actively scrutinizes email campaigns that miss the mark on consent. If your messages end up in spam folders, you’ve failed not just technically, but legally. The CNIL emphasizes that consent must be freely given, specific, and demonstrable—meaning a vague “opt-in” or unverified list is risky. Poor inbox placement is a symptom of deeper issues, such as sending to invalid or outdated addresses, failing SPF/DKIM/DMARC checks, or having a history of spam complaints. These same signals can trigger CNIL scrutiny, especially if you’re processing data for marketing purposes.

How to properly test before sending

Run your campaign through an inbox placement tool before full launch. MailTester’s inbox tester checks actual inbox routing across real providers like Gmail, Outlook, and Apple Mail, simulating how your message will land for real users in France. You get a score, real-time feedback, and insights into what might be triggering spam filters. Common red flags include mismatched sender domains, missing authentication, or overly aggressive language—especially if your consent signals are weak. Addressing these before sending saves time, prevents bounces, and keeps your sender reputation intact.

For deeper validation, use MailTester’s bulk verification to clean your list before testing, ensuring you’re not sending to addresses that fail basic syntax or existence checks. Clean, accurate lists improve deliverability and reduce the risk of spam trap hits. Even if your consent is technically valid, sending to invalid addresses can still harm your reputation and trigger filters, especially in sensitive regions like France.

For context, the European Data Protection Board (EDPB) has emphasized that consent must be “granular and specific” when processing personal data under GDPR—a standard the CNIL enforces rigorously. You can review their guidelines at edpb.europa.eu. Always test, verify, and retest. A few minutes of pre-send testing prevents weeks of compliance risk.

If the French data protection authority (CNIL) notifies you about improper consent in your email campaign, pause all sending to the affected list immediately. Then trace every email back to its source and verify whether consent was obtained properly at the time of capture. Use a trusted email verification service to scrub invalid or non-compliant addresses before resuming outreach.

Immediate actions to take

  1. Suspend all sending to the contested segment. Continuing to send can deepen the violation. CNIL expects swift compliance, not a delay while you "catch up."
  2. Review the origin of every address in the list. Was the email captured via a signup form, a purchased list, a third-party source, or a contact scraped from public web pages? Only opt-in methods—especially explicit, documented consent—meet the CNIL’s standards under GDPR and French data law.
  3. Assess consent validity at time of capture. Did you obtain clear, specific, and freely given consent? Was the purpose of use clearly stated? CNIL may consider silence, pre-checked boxes, or vague language as invalid consent.

Verify and clean before resuming

Once you've flagged questionable addresses, use verified data cleaning to test validity and compliance. A service like MailTester’s bulk email verification can detect invalid, disposable, or catch-all addresses—common signs of poor list hygiene or low-quality origins.

Email verification is not a substitute for consent—it doesn’t prove intent or legality—but it helps eliminate addresses that are more likely to be non-compliant or trigger bounces and spam complaints.

For ongoing campaigns, integrate real-time verification via the API email checker to prevent invalid or risky addresses from entering your list. This minimizes future risk and supports consistent deliverability.

Refer to the CNIL’s official guidance and the GDPR.eu resource site to understand the latest enforcement practices. When in doubt, err on the side of user control—consent must be easy to withdraw and clearly documented.

Keep your campaigns compliant with ongoing list hygiene

Email lists degrade over time. Invalid addresses, inactive accounts, and changed domains accumulate. Treating list hygiene as a one-time task creates compliance risk and harms deliverability.

Re-validate your lists every quarter, especially before high-volume or high-stakes campaigns. This ensures you’re only sending to active, valid addresses—reducing bounce rates and maintaining sender reputation.

Integrate verification in real time as new contacts join your list. This prevents invalid emails from entering your system in the first place. Use MailTester’s API to verify addresses the moment they’re added, not after campaigns begin.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Does CNIL allow pre-checked opt-in boxes for newsletters?

No. Pre-ticked boxes do not constitute valid consent under CNIL guidelines. Users must actively opt in.

CNIL recommends retaining records for at least 5 years, but best practice is to store them indefinitely for audit purposes.

Is double opt-in required by CNIL for all email marketing?

Yes. Double opt-in is the most defensible method for proving active consent in France.

Can a business send promotional emails to existing customers?

Yes, but only if the customer previously agreed to receive such emails and consent has not been withdrawn.

It doesn’t assess intent, but it flags high-risk addresses like catch-all or disposable domains that are common in non-consensual lists.

Fines up to €20 million or 4% of global annual revenue, whichever is higher, under GDPR and CNIL enforcement.

A valid verification record is strong supporting evidence but does not replace documented consent.

Yes, if you cannot confirm they actively opted in. CNIL treats all consent claims as time-sensitive.

No. A click is not sufficient on its own. Active confirmation via email link is required.

How often should I verify my email list for CNIL compliance?

At a minimum before each major campaign, and quarterly for ongoing maintenance.

Can MailTester help with GDPR compliance beyond CNIL?

Yes. Its list hygiene and verification capabilities support broader GDPR compliance by reducing non-consensual data use.

What happens if my emails go to catch-all domains?

They’ll be accepted but not delivered to a real person. This can hurt sender reputation and signal poor list quality to spam filters.