Checks the named legal obligations for the recipient's country first, then the sequence, the research, the ask and the two reply rates that get mixed together.
We have not measured this one. It is published for the compliance layer, which is checkable against primary sources, rather than for the copywriting, which is ordinary and which the file admits is ordinary.
What it knows, concretely. First, that the obligations follow the recipient and differ by country in ways that change what you may send: the United States regime is opt-out, which is why cold email there is lawful by default, while Canada is consent-based with defined implied-consent routes, and the European rules turn on whether the recipient is a corporate subscriber or an individual, which is why a message to a limited company in the United Kingdom sits under different rules than the same message to a sole trader. Second, a ladder of asks ordered by what they cost the recipient, together with the claim that the size of the ask moves reply rate further than the wording does, which reframes most copy edits as edits to the wrong thing. Third, the specific measurement error that makes cold email programmes look like they are working: reporting one reply rate when there are two, a total and a positive, and letting unsubscribes and "wrong person" replies inflate the number that gets shown to whoever approves the budget.
Who it is not for. If you have a warm list of people who asked to hear from you, most of the compliance layer does not apply and the sequence advice is beside the point. If you send fewer than about twenty of these a month by hand, the research discipline is the only section worth reading. And if the real problem is that nobody wants the product, this audit will pass a sequence that will never work.
Measuring one skill honestly costs about twenty model sessions: five runs with it, five without, on real material, each output graded alone by a session that is not told the other arm exists, against a rubric written by somebody who never saw the skill. We have not spent that on this one yet, so it ships labelled rather than ships silently.
How it would be measured. Tier A on the compliance layer and Tier B on the copy. The objective half gives both arms the same four-message sequence aimed at a list split across the United States, Canada, Germany and the United Kingdom, with a missing postal address, a subject line that does not match the body, an opt-out promise of thirty days, and no lawful basis recorded, then scores against a rubric built from the statutes and the regulators' own published guidance. The copy half would need blind pairwise preference, judged by people who sell into the stated market.
The file splits cleanly into a half that can be graded and a half that cannot, and that is the reason it is still waiting.
The compliance half has a genuine objective spine. A fixture can carry a sequence aimed at four jurisdictions with a fixed set of defects: no postal address, an opt-out promise shorter than the statute requires, a subject line that misdescribes the body, no record of a lawful basis for the European recipients. Each of those is a criterion a grader can mark from the regulator's own text without an opinion.
The copy half has no spine at all. A strong assistant already writes a decent cold email, and whether the rewrite is better is a preference judgement that needs blind pairwise comparison by people who actually buy in that market. Standing up that panel honestly is the expensive part, and running only the half that is easy would produce a number that flatters the file.
The rule that decides pass or fail was written down before any run was executed and it does not move afterwards. It is in the method note on the hub, along with the full results table including every skill that was tested and cut.
Stated plainly, because a skill that claims everything is useful for nothing.
name and description in the file's frontmatter, so you can also invoke it by name.Read the regulators directly. The American guide is a single readable page from the agency that enforces it, and the Canadian and British regulators both publish plain-language guidance that is more authoritative than any summary, including this one. If your list sits in one country, the primary source is faster than a skill and it is correct by definition.
A lawyer is the right answer at any real scale, and the honest framing is that this file is for arriving at that conversation with the questions already sorted rather than for avoiding it. An hour of advice on your specific list, in your specific jurisdictions, is cheap next to a regulator's attention.
For the copy, a competent salesperson who sells into your market beats every framework. They know which ask the buyer will answer because they have watched it happen, and no general rule about ladders of commitment substitutes for that. This file is most useful where that person does not exist yet, or where the sequence has to be defensible to somebody who was not in the room.
---
name: cold-email-audit
description: Audits a cold outbound email or sequence in two layers. First the named legal obligations that bind it, routed by where the recipient is, covering CAN-SPAM in the United States, CASL in Canada, GDPR with the ePrivacy rules in the European Union, and PECR with UK GDPR in the United Kingdom, including the corporate subscriber distinction and the legitimate interests balancing test. Then the structure: what each message in a sequence is for, why a research line that would suit a hundred other companies is not personalisation, the ladder of asks ordered by what they cost the recipient, the breakup message, subject line and preview text constraints, and the difference between a total reply rate and a positive one. This skill should be used before a cold sequence is sent, when a list spans more than one country, or when a sequence is being extended because it is not working.
---
# Cold email audit
## The claim this skill is built on
Two things sink cold email programmes, and neither of them is the copy.
The first is that the obligations are not the same everywhere and almost nobody routes for it. A team in one country writes one sequence, buys a list that spans four, and sends the same message to all of them. In the United States that message may be entirely lawful without any prior relationship. Sent to an individual in several European countries, the identical message may require prior consent that was never obtained. The text did not change. The recipient did.
The second is that the reply rate being reported is usually two different numbers added together, and the larger of the two is made of people telling you to stop.
So this audit runs the compliance layer first, because a message that must not be sent does not need a better subject line, then the structural layer, and it ends with the measurement, because the measurement is what decides whether anyone repeats the exercise.
**Nothing in this file is legal advice.** It is a structural summary of named obligations written to help you work out which questions you have. The statutes change, the regulator guidance changes faster, enforcement practice differs by country, and none of it accounts for your specific facts. Where money or volume is involved, get advice from a qualified lawyer in the recipient's jurisdiction.
## Layer 0. Which rules bind this message
Jurisdiction follows the recipient, not your company. A company incorporated anywhere emailing an individual in Germany is dealing with the German implementation of the European rules. Segment the list by recipient country before anything else, and where you do not know the country, treat the stricter regime as the one that applies.
### United States: the CAN-SPAM Act of 2003
CAN-SPAM is an **opt-out** regime, not an opt-in one, and this single fact is why cold outbound is a normal business practice in the United States and a legal problem in much of Europe. There is no requirement for prior consent. There are requirements about how the message is constructed. As published by the enforcing agency, a commercial message must:
- **Carry accurate header information.** The From, To, Reply-To and routing information must identify who actually sent it.
- **Use a subject line that is not deceptive.** It has to reflect the content of the message. A subject prefixed with "Re:" on a message that is not a reply is the textbook example.
- **Identify itself as an advertisement**, in some clear way, where the message is commercial and was not solicited.
- **Include a valid physical postal address**, which may be a street address, a registered post office box, or a private mailbox registered with a commercial mail receiving agency.
- **Explain how to opt out**, clearly and conspicuously.
- **Honour opt-outs within ten business days**, keep the opt-out mechanism working for at least thirty days after the message was sent, and neither charge a fee nor demand any information beyond an email address and opt-out preferences as a condition of unsubscribing.
You remain responsible where another company sends on your behalf. Hiring an agency does not move the obligation. Penalties are assessed per offending message and the maximum figure is adjusted annually for inflation, so check the current amount rather than quoting one from an article.
### Canada: CASL, in force since 1 July 2014
CASL is **consent-based**, which makes it the regime American senders most often break by assuming their home rules travel. Sending a commercial electronic message requires consent, plus identification of the sender including a mailing address and one working contact method, plus an unsubscribe mechanism that stays valid for at least sixty days and is actioned within ten business days.
Consent comes in two forms and the difference matters.
**Express consent** is an affirmative act by the recipient, obtained with a clear statement of what they are agreeing to and who is asking. A pre-checked box does not produce it. Express consent does not expire until it is withdrawn.
**Implied consent** is narrower than people hope and every route into it is bounded, some by a clock and some by scope:
- An existing business relationship arising from a purchase, contract or similar transaction: bounded by a clock, generally two years from the transaction.
- An enquiry or application made by the recipient to you: bounded by a shorter clock, generally six months.
- **Conspicuous publication of a business email address**: bounded by scope rather than by a clock. It applies only where the address was published without any statement that unsolicited messages are unwanted, and only where your message is relevant to that person's business role or functions. A generic pitch to an address you found on a company contact page, unrelated to what that person does, is outside the scope even though the address was public.
Maximum administrative penalties are large, up to one million Canadian dollars for an individual and ten million for an organisation per violation, and the point of citing them is not the number but that the regulator has real teeth.
### European Union: GDPR together with the ePrivacy rules
Two instruments apply at once and they do different jobs.
The **ePrivacy Directive**, as implemented in each member state's own law, governs the act of sending unsolicited electronic marketing. The general rule for messages to natural persons is prior consent. There is a narrow exception, often called the soft opt-in, for messages to your own existing customers about similar products where an opt-out was offered when the address was collected and is offered in every message since. **Member states differ on whether the consent rule extends to legal persons**, meaning companies, so business-to-business practice that is normal in one member state is not automatically normal in the next. Check the national implementation, not the directive.
**GDPR** sits underneath and governs the processing of the personal data itself. A named person's work email address is personal data. You need a lawful basis under Article 6. In practice that is consent, or legitimate interests under Article 6(1)(f). Recital 47 states that processing for direct marketing purposes may be regarded as a legitimate interest, which is the sentence everyone quotes, and it does not override the ePrivacy consent requirement for the channel. Both have to be satisfied.
Relying on legitimate interests is not a checkbox. It requires a documented assessment with three parts: a **purpose test**, identifying the legitimate interest; a **necessity test**, showing the processing is actually needed for it; and a **balancing test**, weighing that interest against the individual's rights, interests and reasonable expectations. Write it down before the send, not after a complaint. Alongside it sit transparency duties: where you obtained the data from a source other than the individual, Article 14 requires you to tell them, normally within a month of obtaining it or at the latest at first contact. And Article 21 gives an absolute right to object to direct marketing, with no balancing available once it is exercised.
### United Kingdom: PECR together with UK GDPR
The Privacy and Electronic Communications Regulations distinguish between an **individual subscriber** and a **corporate subscriber**, and this is the distinction that decides the answer.
Unsolicited electronic mail to an **individual subscriber** requires prior consent, subject to the soft opt-in for existing customers. Individual subscribers include sole traders and, in most of the United Kingdom, unincorporated partnerships, so a one-person consultancy is treated as an individual and not as a business.
Unsolicited mail to a **corporate subscriber**, meaning a limited company, a limited liability partnership or a public body, is not caught by that consent requirement. Business-to-business cold email to a company is therefore permitted, and it is not unregulated. You must still identify yourself, provide a valid address for objections, and stop when asked. And because you are emailing a named person at that company, UK GDPR still applies to their personal data: you need a lawful basis, normally legitimate interests with the same documented assessment, you owe the transparency information, and the right to object still binds you.
Penalties under PECR were historically capped well below the UK GDPR maximum. That gap has now closed. The Data (Use and Access) Act 2025 received royal assent on 19 June 2025 and the relevant provisions have been in force since 5 February 2026, raising the PECR ceiling to £17.5 million or 4 percent of global annual turnover, whichever is higher. Price a PECR breach at UK GDPR levels, and check the current position rather than repeating this paragraph, which is a summary and not legal advice.
### The routing rule
- Recipient in the United States, message correctly constructed. **Send.** No prior consent required.
- Recipient in Canada. **Do not send unless you can name the consent route** and, for the published-address route, state in one sentence why the message is relevant to that person's role. If you cannot, the address does not belong on the list.
- Recipient in the European Union. **Check the member state's implementation.** If the recipient is an individual and you have no consent and no soft opt-in, do not send. If they are a company contact, the answer depends on the country and you need to have looked it up.
- Recipient in the United Kingdom at a limited company or LLP. **Send**, with identification, an objection route, and a documented legitimate interests assessment.
- Recipient in the United Kingdom who is a sole trader or in an unincorporated partnership. **Treat as an individual.** Consent or soft opt-in only.
- **You cannot tell where the recipient is, or whether the entity is incorporated.** Do not send to that segment. Enrich it or drop it. Guessing here is how a single list produces a complaint in the one jurisdiction where the regulator was interested.
## Layer 1. The research, and what personalisation actually is
A merge field is substitution, not personalisation, and the recipient can tell instantly, because the sentence remains true and grammatical with any other company's name dropped into it.
**The test: could this line be sent unchanged to a hundred other companies?** If the only thing that would need to change is the merge field, it is decoration. A second, harder test: **did the research change the ask?** If you would have asked for exactly the same thing before reading anything about them, the research did no work and you should stop paying for it.
What a genuine observation looks like: it is specific to this organisation, it is recent or otherwise verifiable, and it connects to the reason you are writing. Useful sources are the ones that reveal a decision in progress. A job posting for a role that implies a build-or-buy choice. A public changelog or release note. A documented migration. A conference talk. A change to a pricing or documentation page. A public review naming the problem you solve. What does not qualify: praise for a post, a compliment about the website, or the observation that the company is growing.
Budget honestly. Three minutes of research per prospect at fifty a day is two and a half hours of somebody's time before a single message is written. If that is not affordable, the correct response is to cut the list, not to cut the research, because an unresearched list is where both the compliance risk and the complaint rate come from.
## Layer 2. The ask, which moves the number more than the copy does
The size of the ask determines reply rate more reliably than the wording of the message, because replying is a cost decision before it is an interest decision. A ladder, smallest first:
1. **A one-word answer.** "Is onboarding still handled by your team, or has that moved?"
2. **A redirect.** "If this is not you, who should I be asking?" This is easy to answer even when the answer is no, and it produces routing information.
3. **Permission to send something.** "Want the two-paragraph version?" The recipient commits to nothing but a yes.
4. **An asynchronous artefact.** A short recorded walkthrough, a one-page teardown, a specific example. Costs them attention on their own schedule, not a diary slot.
5. **A short call with a stated agenda and a stated length.** Fifteen minutes, with what will be covered written down.
6. **A trial, a pilot, or money.**
The rule: **a first cold message asks for something on rungs one to three.** Opening with a thirty-minute call is asking a stranger for the most expensive thing they own, from the lowest-trust position you will ever occupy. Work up the ladder as the exchange earns it.
Two corollaries. **One ask per message**, because two asks is zero asks: the recipient has to choose, choosing is work, and the reply does not happen. And avoid the false-choice calendar prompt in a first message, the one offering Tuesday at two or Thursday at three, because it presumes a decision that has not been made and reads as a script.
## Layer 3. The sequence
Each message has a job, and a message with no job should not be sent.
1. **Relevance and a reason.** Why this person, why now, and one small ask.
2. **New information.** A different angle, a proof point, a specific example. Not a reminder.
3. **A different problem.** The same product seen from another role's point of view, in case you guessed wrong about which pain applies.
4. **A shorter, more direct restatement.** Two sentences and the ask.
5. **The breakup.**
**"Just bumping this to the top of your inbox" is worse than sending nothing.** It contains no new information, it costs attention you have not earned, it is the pattern most reliably reported as spam inside a sequence, and it teaches the recipient that opening your messages is not worth doing, which poisons the ones that follow.
**Every message must stand alone.** Threads get read out of order, mobile clients collapse quoted text, and a large share of recipients only ever see the most recent message. So every message states who you are and why you are writing in one clause, and never depends on a previous one being read. A follow-up that opens "Following up on my last note" is broken for the majority of the people who see it.
**Touch count.** Most replies arrive on the first four messages, and the incremental return past roughly four to six touches is small and increasingly negative, since the people still not replying at message seven are disproportionately the people about to press the spam button. The published benchmarks in this area come from sending tools reporting on their own customers and vary widely, so treat them as directional and check your own data. Space messages three to five business days apart, and never same-day.
**The breakup, and the pattern that actually gets answered.** Stop selling and ask what would have had to be true. "If this had been worth a conversation, what would have needed to be different?" Or the negative confirmation: "Am I wrong that this is not a priority this year?" These get replies because they cost one line, they contain no ask, and people correct a wrong statement more readily than they answer an open question. What to avoid: manufactured finality, guilt, and the closing that says you will assume they are not interested when you have three more messages scheduled. If you say you will stop, stop.
## Layer 4. Subject line and preview text
**Length.** On a phone in portrait, expect roughly 30 to 40 characters to be visible before truncation, and on a desktop list view roughly 60. These vary by client, device and font size and should be checked against your own audience's clients rather than trusted. The practical consequence is to front-load: put the specific noun in the first four words.
**Preview text.** Most clients construct the preview from the first text in the body unless a preheader is set. A message that opens "Hi Alex," spends its preview on a greeting. Preview length varies roughly from 35 to 100 characters by client. Treat the subject and the first line as one unit, because that is how they are read.
**Honesty is a cost decision, not a moral one.** A subject line that promises something the body does not deliver costs more than a boring one. It converts a neutral non-reader into someone who feels tricked, and that is precisely the population that reports messages as spam, and the complaint rate is the metric with a hard threshold attached by the mailbox providers. In the United States a deceptive subject line is also a named statutory violation. A dull, accurate subject line has a floor. A misleading one has a cliff.
Two to five words, lower case, no "Re:" or "Fwd:" on a message that is neither, no manufactured urgency, and no question mark doing the work a specific noun should do.
## Layer 5. Measurement, in order
1. **Did it arrive?** Bounce rate and, if you have it, seed placement. Nothing below this means anything if this is broken, and diagnosing it is a separate job.
2. **Total reply rate.** Every human response, including negatives.
3. **Positive reply rate**, reported separately, as a share of messages sent rather than as a share of replies.
4. **Meetings held**, not booked.
5. **Opportunities created.**
6. **Revenue and cycle length.**
**Open rate is not on this list and should not be used for a decision.** Image proxying by the major mail clients pre-fetches tracking pixels regardless of whether a human looked, which inflates opens, and corporate security gateways click every link in a message before delivery, which inflates clicks. Both effects vary by audience, so the error is not even a consistent bias you could correct for.
**The most common self-deception in this field is the merged reply rate.** A programme reports nine percent replies. Seven points of that is "unsubscribe", "wrong person", and "no thanks". Two points is interest. Reported as one number, it looks like a working channel. Reported as two, it is a two percent channel with an unusually annoyed audience. Always report both, and classify replies into interested, referred, not now, not me, and hostile, because the mix tells you which layer is broken: mostly "not me" is a targeting problem, mostly "not now" is a timing or offer problem, mostly hostile is a list problem.
**Sample size.** A test on fifty prospects cannot distinguish a two percent reply rate from a five percent one. Expect to need several hundred contacts per variant before a difference is worth acting on, and change one thing at a time. The unit of analysis is the sequence and the list, not the individual message.
## Worked example: a rewrite
**Before.**
> Subject: Quick question
>
> Hi {{first_name}},
>
> I hope this email finds you well! I came across {{company}} and was really impressed by what you are building in the space.
>
> We help companies like yours streamline operations and drive efficiency with our platform. Our clients typically see significant improvements.
>
> Do you have 30 minutes on Tuesday at 2pm or Thursday at 3pm for a quick chat?
Six defects. The subject promises a question and is not one. The opening is a pleasantry that costs the entire preview. "Impressed by what you are building" passes to a hundred other companies unchanged, so it is not personalisation. The value claim names no customer, no number and no mechanism. The ask is on rung five in the first message. And there is no identification of the sender, no postal address and no opt-out, so it fails the American construction rules as well as the Canadian and British identification requirements.
**After.**
> Subject: your March pricing page change
>
> Alex, your pricing page moved usage overage from per-seat to metered last month, and your docs still describe the old model in three places. That combination usually means billing reconciliation is being done by hand somewhere.
>
> We built the reconciliation step for two other metered-billing teams after the same switch. One cut a four-day monthly close to under a day.
>
> Is that still being handled manually on your side, or has it been sorted?
>
> [Sender name], [Company], [Full postal address]
> Reply "stop" and I will remove you and not contact you again.
What changed and why. The subject names a specific, checkable, dated thing, so it survives truncation and is accurate. The first line is a verifiable observation that could not be sent to another company, and it leads directly to the hypothesis, so the research changed the ask. The proof point has a number and a shape rather than an adjective. The ask is on rung one: a yes or no that can be answered in one word, including by the person who is not the right person. Identification and postal address satisfy the construction requirements in the United States, Canada and the United Kingdom at once. The opt-out is stated in plain terms and will be honoured.
**Verdict: send, for United States, United Kingdom corporate and Canadian recipients where the published-address route genuinely applies. Hold for European individual recipients** until either consent exists or the national implementation has been checked and a legitimate interests assessment written down.
## Failure modes
**Assuming one country's rules travel.** The American opt-out model is the outlier, not the default, and a list bought as "global" is several legal regimes in one spreadsheet.
**Treating a legitimate interests claim as a sentence rather than a document.** The assessment has three named parts and it has to exist before the send. Quoting Recital 47 in an email to your own team is not an assessment.
**Confusing substitution with personalisation.** A first line built from three merge fields is a template with holes and reads as one. The hundred-companies test settles it in five seconds.
**Adding touches to a sequence that is not working.** If messages one to four produced nothing, messages five to eight are not the missing element. The list, the ask or the offer is wrong, and extending the sequence converts a low reply rate into a complaint rate.
**Asking for a call in message one.** The most common single defect, and the one with the clearest fix, since moving the ask down the ladder costs nothing and changes the economics of replying.
**Reporting a merged reply rate.** The number that gets shown to whoever approves the budget is inflated by people asking to be removed, and the programme scales on the strength of its own annoyance.
**Optimising open rate.** It is measured through proxies and gateways that open and click without a human involved, so the metric responds to changes that did not happen.
**Sending the breakup and then not stopping.** It destroys the credibility of everything you said before it, and it is the message most likely to be reported.
## What this skill does not do
- It is not legal advice and it cannot be. It names obligations and points at primary sources so you arrive at a lawyer with the right questions, and it does not know your facts.
- It cannot see your list, so it cannot tell you which jurisdictions you are actually in, whether an entity is incorporated, or whether an address is a person or a role.
- It does not cover deliverability. Authentication, list hygiene, warm-up and sending pattern decide whether any of this arrives, and that is a different audit.
- It does not judge the offer. A structurally perfect sequence for something nobody wants passes every check in this file and gets no replies.
- It carries no jurisdiction outside the four named. Australia, Brazil, India, Japan and others have their own rules and the absence of a section here is not an all-clear.
- Figures, thresholds and penalty amounts move, and the ones stated are dated on purpose. Verify each against the current published source before you rely on it.
These skills all ask your assistant to check things against your actual codebase, your actual schema, your actual design system. Locul keeps that context current on its own, from the files you already have, on your machine. Mac and Windows, free to start.