This guide assumes email consent management is already deployed and passing. It covers what breaks at scale and how mature teams operate it.
Edge cases that break a working setup#
- Bundling marketing consent into terms of service acceptance.
- Losing consent records during a CRM migration.
- Mail forwarded through mailing lists or personal forwarders, which alters headers and content.
- Acquisitions and rebrands that introduce domains nobody audited.
- Vendors silently changing their sending infrastructure.
Operating it as infrastructure#
- Assign an owner for each sending domain and each vendor relationship.
- Put DNS records under version control or a change-review process.
- Alert on authentication pass rate drops and reputation changes, not just outages.
- Run a quarterly audit against the setup steps below.
- Document runbooks for the three most common failures.
Reference: the baseline setup#
- Use an unchecked checkbox or a dedicated signup form; never pre-tick.
- Record timestamp, IP, source, and the exact wording shown at consent.
- Use double opt-in for marketing lists where feasible.
- Separate consent for different purposes (newsletter vs partner offers).
- Refresh consent for contacts older than two years with no engagement.
Frequently asked questions#
Is double opt-in required by law?
Not explicitly in most jurisdictions, but it is the easiest way to prove consent under GDPR and CASL and it improves list quality.