What GDPR and ePrivacy requires#
GDPR requires a lawful basis (usually consent) for marketing email and documented consent records.
What transactional email is#
Transactional email is triggered by a user action (receipts, password resets, alerts) and is exempt from most marketing consent rules. Marketing email promotes products and requires consent and unsubscribe links.
Why it matters#
Mixing the two on one domain or stream means a bad campaign can block password resets. Separating them protects critical mail.
How transactional email supports GDPR and ePrivacy compliance#
Regulators and recipients need to identify who sent a message and trust that opt-out mechanisms work. Transactional email contributes by mixing the two on one domain or stream means a bad campaign can block password resets. Separating them protects critical mail.
Implementation steps#
- Send transactional mail from a dedicated subdomain (for example mail.yourdomain.com) or separate stream.
- Send marketing from a different subdomain (news.yourdomain.com).
- Keep promotional content out of transactional messages to preserve their exemption.
- Apply DMARC to the organizational domain so both subdomains are covered.
Frequently asked questions#
Do transactional emails need an unsubscribe link?
Not under CAN-SPAM if purely transactional. Gmail's bulk-sender rules still expect one-click unsubscribe for anything sent at volume, so many senders include it anyway.