India's IT Act and Email Consent Requirements in 2026
Ensure compliance with India's Information Technology Act and email consent rules in 2026. Verify your list with MailTester to avoid legal risk and.
What does India's IT Act actually require for email consent?
You send a marketing email to someone in India. They don’t know you. They didn’t sign up. And yet, your campaign gets flagged. Why? Because India’s Information Technology Act, 2000 — updated in 2023 — doesn’t just care about whether the email exists. It cares about whether the person actually wanted to receive it.
It’s not enough to have a valid email address. You need consent — real, documented, and revocable. Think of it like a door: you can’t just walk in even if you know the address. You need permission, and you must make it easy to leave.
Under the IT Act, consent must be clear, informed, and unambiguous. It can’t be hidden in fine print, pre-checked, or assumed. You must get it before sending marketing messages. And if someone says no later — you have to stop, immediately.
Key takeaways
- Consent under India’s IT Act must be explicit, not inferred — pre-ticked boxes or silence do not count.
- Consent must be obtained before sending any marketing email — no exceptions.
- Users must be able to withdraw consent at any time, and you must honor the request without delay.
How does email consent under the IT Act differ from GDPR or CAN-SPAM?
India’s Information Technology Act doesn’t require a strict opt-in like GDPR, nor does it allow the "negative option" of CAN-SPAM. Instead, it focuses on proving that consent was clear, informed, and verifiable—meaning organizations must keep records showing users agreed. Unlike the US, India lacks a national do-not-email registry, so email senders must still validate consent before sending.
Why "clear agreement" matters more than "opt-in" in India
Under the IT Act, you don’t need a double-opt-in like in GDPR, but you do need to prove the recipient agreed. The law places the burden on your organization to show consent wasn’t obtained through deception or confusion. This makes documentation—not just intent—critical.
GDPR demands explicit opt-in with clear affirmative action, while India’s approach is more flexible, as long as the consent was unambiguous. That flexibility comes with a trade-off: if you can’t produce the proof, you’re in breach.
How CAN-SPAM’s opt-out model doesn’t work in India
CAN-SPAM allows businesses to send commercial emails if they include an easy opt-out mechanism—known as a "negative option." India’s law doesn’t accept this. You must obtain opt-in consent before sending marketing emails. Sending to a user who hasn’t agreed in advance is not allowed.
Even though India has no formal do-not-email registry like the US, the principle is the same: you can’t bombard someone without their confirmation. Without a registry, enforcement depends on complaints and evidence of consent, not centralized tracking.
According to the Indian Computer Emergency Response Team (CERT-In), improper consent is a common reason for emails being flagged or blocked—even if they technically pass technical checks. This means validity checks alone aren’t enough. You need to verify the legitimacy of consent as well.
That’s where tools like MailTester's email checker help. While it doesn’t assess consent legality, it verifies that the address is real, active, and not a disposable email. Validating address quality is a foundational step before relying on consent records.
Use bulk verification to weed out invalid or risky addresses before sending—especially important when managing lists compiled from multiple sources. Even if consent is documented, sending to a bounced or fake address increases spam complaints and harms sender reputation.
The real challenge isn’t just compliance—it’s proving compliance. India's approach requires more than a checkbox; it demands a paper trail. If you’re unsure whether your email list has valid consent, start by verifying the technical validity of the addresses you’re using.
Which email addresses are legally risky under India’s IT Act?
You risk legal exposure under India’s Information Technology Act, 2000 if you send marketing emails to addresses obtained from public sources, web scraping, or third-party lists without explicit consent. Role accounts like admin@, info@, or sales@ are often not valid endpoints for marketing and may lead to bouncebacks or spam complaints. Disposable email domains (like tempmail.com) frequently indicate low intent and can expose you to compliance risks if used for commercial outreach. You’re not just risking deliverability—you’re risking liability.
Public data and scraping: even if accessible, not always compliant
Just because an email is public doesn’t mean it’s fair game. The IT Act requires consent before sending commercial communications, and scraping lists from websites or social media profiles violates that principle. Even if the email is visible on a company website, using it without explicit permission could count as unsolicited communication under Section 70A. This isn't just about spam—it’s about data privacy rights. The Data Protection and Privacy Bill, while not yet law in full, reinforces this idea: consent is not assumed, even if data is publicly available.
Role accounts and disposable domains: high risk, low value
Role accounts like support@, billing@, or team@ are not individual users. They’re often monitored by IT teams, and any unsolicited email to them may get flagged as suspicious or automatically routed to spam. Sending campaigns to these addresses does not meet the "explicit consent" standard and may result in increased spam complaints, harming your sender reputation.
Disposable email domains—like mailinator.com, temp-mail.org, or 10minutemail.com—are designed for short-term use. Users sign up quickly, often with no intent to engage. Using them for marketing is not only ineffective—it’s a red flag. If your list contains these domains, it suggests you’re not verifying legitimacy, which directly contradicts IT Act requirements around data handling and user consent.
Let’s be clear: validation is more than checking syntax. It’s about verifying real human intent. Tools like bulk email verification can filter out role accounts and disposable domains before you send. They also assess deliverability and inbox placement, so you don’t just comply—you land in inboxes.
For real-time checks, use the real-time verification API to validate each email at point of collection. This prevents consent breaches before they happen. You’re not just testing deliverability—you're building a compliant, trustworthy email strategy.
How to verify a list before sending emails in India?
Before sending emails in India, scrub your list by removing invalid, role-based, and disposable addresses using real-time email verification. Test each address for deliverability and compliance risk, and ensure no opted-out users remain. This reduces bounces, avoids spam traps, and helps meet the spirit of India's IT Act regarding consent.
Step 1: Remove invalid and role-based email addresses
Start by filtering out obvious non-deliverable addresses—those with typos, missing domains, or generic formats like admin@, sales@, or support@. These often get flagged or bounce, hurting sender reputation. Tools like MailTester’s bulk verification automatically detect these and flag them as invalid or risky.
Step 2: Test for deliverability and compliance risk
Not all valid-looking addresses are actually usable. Some domains use greylisting, temporary blocks, or catch-all policies that cause delays or false positives. Use MailTester’s real-time verification API to simulate an email send and assess whether an address can receive messages. This detects issues like inactive inboxes, server-side rejections, and known spam traps.
Step 3: Confirm no opted-out recipients remain
Under the IT Act, consent is central. If someone previously opted out, re-engaging them—even with a valid address—can breach compliance. Match addresses against your suppression list. This includes those who unsubscribed, complained, or were flagged as inactive over a set period. Tools that offer inbox placement testing, like MailTester’s inbox tester, can help confirm whether your messages land in the primary inbox or get filtered.
Why consistency matters
India’s IT Act does not define a single standard for consent, but the principle is clear: emails must be sent only with prior permission. This means your list must be built responsibly—through opt-ins, not scraped data. Regular verification ensures ongoing compliance and protects your reputation with ISPs and mailbox providers.
For more on how mailbox providers evaluate sender trust, see the RFC 5322 standard for email format and delivery, which governs how messages are processed across networks.
What does MailTester do to support compliance with India’s IT Act?
You can reduce the risk of sending unsolicited emails under India’s IT Act by validating addresses before sending. MailTester checks for invalid or non-existent addresses, identifies role accounts and disposable domains that violate consent rules, and delivers a clear report showing each address's validity and risk level—helping you avoid violations of Section 43A and the consent requirements in Rule 4(1) of the IT Rules.
How MailTester helps with consent compliance
- Flags invalid or non-existent email addresses—these can’t provide valid consent, so removing them reduces the chance of sending to non-consenting users.
- Detects role accounts (like
info@,support@,sales@) that don’t represent real individuals and can’t legally give consent under the IT Act. - Identifies disposable domains (like
@10minutemail.comor@tempmail.org), which are commonly used to bypass consent mechanisms and are often linked to low engagement or spam. - Provides a detailed risk rating for each address—indicating validity, deliverability, and compliance risk—so you can make informed decisions before sending mass emails.
What you get in the report
After verification, MailTester delivers a report showing exactly which addresses are valid, which are risky, and which should be excluded. You’ll see the specific reason for each result—such as “catch-all domain,” “role account,” or “disposable email”—so you can audit compliance with India’s IT Act requirements. This transparency helps maintain sender reputation and supports your organization's legal position.
For example, the IT Act requires that consent is freely given and specific. Sending to a role account or temporary email violates that principle. MailTester helps you stay aligned with this requirement by catching these red flags early.
For real-time verification at scale, use the MailTester API or verify your full list with the bulk email verifier. If you’re testing inbox placement, the inbox placement tester can show you where your messages land in real inboxes—important for maintaining trust, especially in regulated markets like India.
How accurate is email verification in the Indian context?
MailTester achieves 98.9% accuracy in India, as verified through real SMTP testing and DNS validation—no guesswork or third-party data. It identifies invalid, catch-all, and temporary delivery issues like greylisting, so you know exactly which addresses are safe to send to, reducing bounces and protecting sender reputation across Indian domains.
Real SMTP testing behind the accuracy
Unlike tools that rely on outdated databases or heuristic rules, MailTester performs actual connection attempts to mail servers in India—confirming whether an address is technically deliverable. This approach works even for newer or lesser-known domains, which are common in India’s growing tech ecosystem.
Each verification checks for hard bounces (permanently invalid addresses), soft bounces (temporary issues like full inboxes), and greylisting (a delay tactic used by some Indian providers to combat spam). These distinctions matter: sending to a greylisted address might still result in a bounce later, so knowing the issue upfront saves time and improves deliverability.
What verification doesn’t do—and why that matters
MailTester tells you if an email is technically valid, but it doesn’t confirm legal consent under India’s Information Technology Act, 2000, or the newer rules around explicit approval for commercial messages. You still need to ensure you have permission to send, especially for promotional content.
However, verifying addresses reduces the risk of sending to someone who can’t legally consent. If an address fails verification—especially if it’s a role account (like info@ or sales@), a disposable domain, or a catch-all—you’re less likely to send to someone who might not even know about your email, which helps avoid privacy complaints.
For deeper insight, you can test real inbox placement using MailTester’s inbox placement tester, which helps check whether messages land in the inbox or get filtered—something increasingly important in India, where email filtering practices vary widely between providers.
Want to clean your entire list? Run it through MailTester’s bulk verification tool, or integrate it with your CRM or email platform via the real-time verification API. Both are designed to work reliably across Indian domains without needing to update rules for local quirks.
For more on email protocols and authentication practices that affect deliverability globally—including in India—refer to RFC 5321 (SMTP) and RFC 5322 (email format), which underpin how verification tools like ours operate.
Can you legally send to a catch-all domain in India?
No, you cannot legally assume consent just because a domain accepts all mail. Sending to a catch-all domain in India does not grant permission to send unsolicited emails. Even if the mail is technically delivered, the recipient never opted in, and doing so increases the risk of spam complaints, sender reputation damage, and breaches under India’s Information Technology Act, 2000, which requires explicit consent for commercial communications.
The mechanics of catch-all domains
Catch-all domains route all incoming email to a single inbox, regardless of whether the local part (before the @) exists. That means you could send to [email protected] and it would still be delivered.
This doesn’t mean the person behind that address consented to receive your email. The domain simply has no validation layer to detect invalid addresses — it’s a configuration quirk, not a signal of interest.
Legal and deliverability risks in India
Under India’s IT Act, consent must be freely given, specific, and informed. Sending to a catch-all doesn’t prove consent — in fact, it’s the opposite. You’re sending to a non-specific or unknown user, which can trigger spam filters and complaint systems.
Even if your message reaches the inbox, mass emails to catch-alls are commonly reported as spam. This harms your sender reputation, which affects inbox placement across providers like Gmail, Outlook, and others. According to industry standards, consistently high complaint rates (over 0.1%) can lead to delivery throttling or blacklisting — a risk not worth taking.
MailTester’s email checker can help identify catch-all domains before you send, so you know whether an address is valid, risky, or likely to cause issues. By filtering them out early, you reduce bounce rates, improve deliverability, and stay compliant with consent rules.
Let’s be clear: a catch-all is not an audience. It’s a technical edge case. You must validate every email address and only send to verified, opt-in recipients — especially in markets with strict consent laws like India. The fact that a domain accepts mail is not permission to send.
How to avoid spam traps during email campaigns in India?
Spam traps are outdated or abandoned email addresses used to catch spammers. In India, where email consent is governed by the Information Technology Act, 2000, and its rules on unsolicited communications, sending to inactive or unverified addresses risks harming your sender reputation. To stay compliant and avoid spam traps, clean your list regularly, validate addresses before sending, and suppress bounces instead of re-engaging them. This keeps your deliverability high and your list healthy.
Keep your list clean and active
- Remove inactive or abandoned email addresses from your list. These are common spam traps, especially if they were once valid but now serve no real user.
- Use MailTester’s bulk verification to identify outdated or unverified addresses that may be older spam traps.
- Never send to addresses that have bounced in the past. Bounced emails often point to hard failures or dormant inboxes—re-engaging them signals poor list hygiene to internet service providers.
- Archive suppressed emails instead of trying to re-engage them. This prevents accidental triggers of spam trap detection systems.
Verify before you send
- Test individual addresses with MailTester’s email checker before adding them to a campaign. This confirms validity and flags catch-all or risky domains.
- Use the real-time verification API to validate addresses at the point of capture, avoiding bad data from the start.
- Run inbox placement tests via MailTester’s inbox tester to simulate how your emails land in real-world mailboxes—this helps detect potential delivery issues, including spam traps.
- Ensure your sender authentication (SPF, DKIM, DMARC) is properly set up. These standards help verify your email’s origin and reduce the risk of being flagged as spam, even when targeting old or invalid addresses.
Spam traps don’t just hurt deliverability—they can get your IP blocked. Cleaning your list is not optional; it's mandatory for compliance with India’s IT Act and global email standards.
India’s Information Technology Act requires that commercial communications only be sent with prior consent, and using old or inactive addresses undermines that principle. Tools like MailTester help you meet that standard by proving each address is valid and responsive. Regular list hygiene isn’t a one-time fix—it’s part of maintaining trust with email providers and regulators alike. Use real verification, not guesswork.
How does sender reputation affect deliverability under the IT Act?
Under India’s Information Technology Act, consent is required for sending commercial emails, but even with consent, a poor sender reputation can still trigger spam filters, reduce inbox placement, and lead to blocked messages—especially if your list contains invalid addresses, high bounce rates, or generates spam complaints. Sender reputation isn’t just a technical metric; it directly impacts legal compliance by determining whether your emails reach the inbox at all.
Reputation isn’t optional—it’s foundational
Even if you have explicit consent under Section 703 of the IT Act, your messages can still be routed to spam folders if your sender reputation is negative. Email providers like Gmail, Outlook, and Yahoo use algorithms to evaluate sender behavior in real time. If your sending pattern shows high bounce rates, frequent complaints, or invalid addresses, your reputation drops—regardless of consent.
Bounce rates above 2% are commonly flagged as problematic by major email providers. Spam complaints, even from a single user, can trigger a reputation penalty. According to the 2023 Email Deliverability Report by Return Path, senders with consistently high complaint rates see their inbox placement drop by over 50% within weeks. This means compliance with consent rules isn’t enough—your list health determines whether you’re delivered at all.
Prevent problems before they start
Let’s be clear: you can’t fix a damaged sender reputation overnight. The best defense is to clean your list before sending. Validating every address in advance helps remove invalid addresses, catch-all domains, and disposable email services—each of which harms your deliverability and risks violating the IT Act’s standards on unsolicited communication.
MailTester helps reduce these risks by identifying invalid or risky addresses before you send. With a 98.9% accuracy rate, its bulk verification tool detects non-existent accounts, role-based addresses, and domains that reject messages. You can test entire lists with confidence, verify addresses in real time via its API, or run inbox placement tests to check how your messages appear in real mailboxes.
Use our bulk verification tool to clean your list, reduce bounces, and protect your sender reputation—so your compliant messages actually reach the inbox.
What happens if you violate India’s email consent rules?
If you send emails without valid consent under India’s Information Technology Act, you risk fines up to ₹5 crore (around $580,000) for data breaches under Section 43A, face regulatory scrutiny for failing to keep consent records, and could suffer long-term damage to your brand’s reputation—especially if violations are repeated.
Financial and legal consequences
Section 43A of the IT Act allows for compensation claims if a data breach occurs due to negligent handling of personal data. While the law doesn’t specify a fixed penalty amount, courts have interpreted it to allow damages up to ₹5 crore in serious cases. This isn't hypothetical—regulatory bodies like the Data Protection Board (established under the 2023 Digital Personal Data Protection Act) can impose such penalties after investigations, particularly when personal data is exposed or misused.
Even if no breach occurs, failing to maintain documented proof of consent can be seen as negligence. The Information Technology Act treats data processing without proper consent as a failure to implement reasonable security practices, which can lead to enforcement actions, audits, and public disclosure.
Reputational and operational fallout
Repeated violations aren’t just a legal headache—they hurt your business. If your email campaigns are flagged by Indian ISPs or email providers, your sender reputation can degrade quickly, especially if recipients report you as spam. Over time, this leads to higher bounce rates, lower inbox placement, and reduced engagement.
Let’s be clear: a single misstep is manageable. A pattern of non-compliance is not. Once a brand’s name appears in official notices or public databases like Spamhaus (a global email blacklist), recovery takes months—if possible at all. Even if you later comply, the trust you lost is hard to regain.
That’s why verifying email lists upfront matters. You can’t rely on guesswork. With MailTester’s real-time email checking, you can validate hundreds of addresses in seconds and avoid sending to invalid, catch-all, or high-risk domains before they harm your reputation. Verify single addresses or bulk-check entire lists to ensure only valid, opt-in recipients receive your messages.
Final checklist: Are you compliant with India’s IT Act before your next send?
India’s Information Technology Act requires explicit, documented consent for any marketing email. Ensure every recipient has actively opted in, and that your records reflect the date, method, and specific consent language.
Verification and list hygiene
- Confirm all email addresses are valid—no role accounts (e.g., sales@, info@), disposable domains, or catch-all addresses.
- Use a trusted verification tool like MailTester to test your list in bulk and identify invalid or risky addresses before sending.
- Remove hard bounces and invalid domains to maintain sender reputation and reduce deliverability risk.
Compliance beyond the send
- Include a functional, visible unsubscribe link in every email.
- Process opt-out requests within 10 business days to meet legal timelines.
- Store consent records for at least two years, as recommended by industry standards and best practice.
Sources
- The effective spam-complaint target for 2026 has tightened to below 0.1%, down from the historical 0.2–0.3% tolerance, as mailbox providers raise the bar for senders. — Validity 2026 Email Deliverability Benchmark Report (via The Agile Brand Guide) (2026)
- Roughly one in six legitimate commercial emails (16.5%) never reaches the inbox globally — 6.7% is filtered to spam and 9.8% disappears without a bounce. — Validity 2025 Email Deliverability Benchmark Report (2025)
Keep reading
- Anti-spam laws and compliance: CAN-SPAM, GDPR, CASL (complete guide)
- Email Verification Provider for CASL-Compliant Existing Client Communications
- CNIL Guidance on Double Opt-In for French Email Campaigns
- Best Practices for Japanese Opt-In Email Verification in 2026
- Recovering a Damaged List with Segmentation: Reducing Unsubscribe Rates
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
Is double opt-in required under India's IT Act?
The IT Act does not explicitly mandate double opt-in, but it requires that consent be clear and informed. A double opt-in process strengthens compliance by providing verifiable proof.
Can I use a public email list in India for marketing?
No — using public or third-party lists without explicit consent violates the IT Act’s requirement for informed agreement.
How often should I verify my email list for compliance?
At minimum, verify before any major campaign and periodically during the maintenance cycle, especially if the list is over 6 months old.
Does MailTester help with GDPR compliance too?
Yes — MailTester’s list hygiene and verification capabilities support GDPR requirements, including lawful basis and data minimization.
Are WhatsApp numbers covered by the IT Act’s consent rules?
The IT Act applies to electronic communications, including SMS and WhatsApp messages, where consent must be obtained explicitly.
What if someone claims they never gave consent?
Without proper records, you cannot prove consent. Use MailTester to log verification results as part of your consent audit trail.
Can I rely on a customer’s purchase history as consent?
Past purchases may imply tacit consent for product-related communication, but only if clearly defined at the time of purchase. Marketing must be opt-in.
How does greylisting impact email deliverability in India?
Greylisting can delay delivery temporarily. It’s common with Indian ISPs and requires sender reputation stability, which verification helps maintain.
Does the IT Act require consent to be in writing?
No — consent can be implied through digital action (e.g., clicking a checkbox). But it must be verifiable and not assumed from silence.
Can I use email verification tools to prove consent?
Verification confirms address validity, but not consent. Use it alongside consent logs to demonstrate compliance.
Do I need to notify users when I verify their email?
No — verification is internal. But users must be informed about data use when they first consent.
How do I handle consent when acquiring email addresses during a trade fair in India?
Collect consent on the spot with a signed or digital form. Store it securely and verify addresses before sending any follow-ups.