Cold Email Deliverability Terms: CASL, BIMI, and Block Lists

Our deliverability FAQ covers SPF, DKIM, and warm-up. This covers what it left out: CASL, BIMI, block lists, seed testing, bounce classes, and complaint rate.

Anshul
Anshul Bhatia
Founder
September 2, 2026 · 9 min read

Our cold email deliverability FAQ covers the mechanics most cold senders build around first: SPF, DKIM, DMARC, warm-up pacing, and the legal basics under CAN-SPAM and GDPR. But it doesn't cover what comes up after that setup is done. A compliance checklist. A deliverability dashboard. Either one can drop a term nobody explained.

Nobody wants to reread a full FAQ to find one definition. Here are the nine terms a cold sender hits most often once the basics are in place, each with a plain definition and the specific reason it matters when the mail is unsolicited, not opted-in. If SPF, DKIM, and warm-up are still unsettled, start with the FAQ instead. If they're done, keep going.

CASL (Canada's Anti-Spam Legislation)

CASL sets a stricter baseline than CAN-SPAM: consent has to exist before you send, not just an easy way to opt out after. It recognizes two kinds of consent, express (someone said yes) and implied (an existing business relationship opens a narrow window to email without asking first). But the shortcut "B2B email is exempt" is wrong. The exemption only applies when the two companies already have a relationship, a past purchase, a referral, a signed contract, not simply because both sides are businesses. According to a summary of CASL's penalty structure, Canada's regulator can fine individuals up to $1 million CAD and organizations up to $10 million CAD per violation. This is general information, not legal advice; a program sending into Canada deserves an actual legal review.

For a cold sender, the exposure sits in that exemption. And treating any Canadian business as automatically exempt because the message is B2B is one of the more common ways an outbound program picks up CASL risk without anyone noticing.

Read the exemption narrowly.

BIMI (Brand Indicators for Message Identification)

BIMI puts a verified brand logo next to a message in the inbox, and it depends entirely on authentication already being in place. BIMI Group's own requirements call for SPF, DKIM, and an aligned DMARC record. They also want an SVG Tiny PS version of the logo and a published DNS BIMI record. Most setups also need a Verified Mark Certificate. But that's an added cost most domains skip, and it comes before a major mailbox provider will display the logo at all. And the DMARC record has to reach an enforcement level, p=quarantine or p=reject. That's a step past the p=none starting point our FAQ recommends for a brand-new cold-sending subdomain. Validity's own explainer is direct about the mechanism: BIMI doesn't move inbox placement on its own. It sits on top of deliverability already earned, as a trust signal once a message has already reached the inbox.

That's the whole stake for a cold sender. BIMI is worth planning for once a subdomain has earned the enforcement-level DMARC record it depends on, not before. And most cold-sending subdomains sit at p=none for good reason, which is why sending infrastructure setup usually settles this order before BIMI ever comes up.

Block list vs. blacklist

Both terms name the same thing: a list of IP addresses or domains that a mail server, spam filter vendor, or industry group has flagged as a spam source. Current documentation has shifted toward "block list." Suped's own comparison lays out why: newer tools and style guides favor it, while legacy tool names (DNSBL, RBL) and a lot of bounce-message text still say "blacklist." No dated statistic exists on how far that shift has actually gone industry-wide. This is a documentation trend, not a measured one. And we're not going to pretend otherwise.

Know both terms anyway: a tool's dashboard might use one, and the bounce message sitting in your inbox right now might use the other, for the identical concept.

Seed testing

Seed testing means sending a message to a controlled panel of test addresses spread across the major mailbox providers, then checking where each copy actually landed: inbox, promotions, or spam. That's different from the passive monitoring our FAQ already covers, Postmaster Tools and SNDS, which report aggregate signals after the fact rather than per-message placement.

But the difference matters more in cold outbound than in marketing email. A cold-sending domain has no engagement history to fall back on if placement quietly slips. Seed testing is often the one method that surfaces a problem a week or two ahead of bulk metrics showing anything wrong at all.

Hard bounce vs. soft bounce

A hard bounce means the address or domain doesn't exist, and it's permanent. Suppress that address immediately. Don't retry it. A soft bounce is temporary, a full inbox, a server timeout, a size limit. And it's worth monitoring for a pattern before you decide to remove the address. Litmus's glossary draws the same line, treating the two as separate failure types rather than one general "bounce" category.

But the distinction carries more weight on a list built through an enrichment waterfall than on an opt-in list. A waterfall typically produces more hard bounces than an opted-in signup would. And that's the exact failure our FAQ's verification-before-every-send answer exists to prevent. This is the vocabulary underneath it.

Complaint rate

Complaint rate is the share of recipients who mark a message as spam or junk, a different measurement from both bounce rate (a delivery failure) and unsubscribe rate (someone opting out through the proper channel). Our FAQ already covers the two thresholds that matter here, Google's 0.30 percent hard ceiling and the 0.10 percent many senders target instead, so there's no need to re-derive them here.

A bounce is a passive failure signal. A complaint is not. It's a recipient actively telling the mailbox provider your message was unwanted, and it degrades reputation faster than a bounce does, because providers weight an active complaint accordingly.

Feedback loop (FBL)

A feedback loop is the arrangement some mailbox providers set up with senders: every time a recipient clicks "mark as spam," the provider forwards a report back to the sending platform. Litmus's glossary lists it alongside the complaint metric it feeds, and that's the distinction worth holding onto. A feedback loop is the plumbing. Complaint rate is the aggregate number that plumbing produces.

Most cold-sending infrastructure providers already wire feedback-loop data into their own dashboards, whether or not anyone asked for it. So this one rarely means new setup work for a cold sender. This entry exists mainly so the term isn't a mystery the first time it shows up in a vendor's documentation. It's not a lever you need to go pull.

Engagement-based filtering

Mailbox providers route mail partly on how recipients have historically treated messages from a given sender: opens, replies, deletes without reading, moves to a folder. That behavioral layer sits on top of authentication and reputation checks, not in place of them.

This is the mechanism behind our FAQ's own answer on personalization: a repliable cold email affects deliverability only indirectly, through the engagement it generates, not through better copy on its own. It's also the mechanism behind why a cold email lands in spam even when authentication is clean and the list was verified before send. And engagement is often the one variable nobody in that scenario checked.

Spam trap

A spam trap is an email address built to catch bad list hygiene, not a real inbox anyone reads. There are two common types. A pristine trap never belonged to a real person; a mailbox provider or blocklist operator plants it purely to see who's sending to addresses nobody ever opted in. A recycled trap did belong to someone once. The person abandoned it, and after enough time passes, the provider reactivates the address as a trap instead of leaving it dormant.

But hitting either type reads differently than an ordinary hard bounce. A hard bounce says an address is wrong. A spam trap hit says the list itself was sourced badly, and providers weight it that way, not as a one-off. This is exactly the outcome our FAQ's bounce-and-verification guidance exists to prevent. Skip that step, and a spam trap is one of the ways it shows up later.

Where this leaves you

That covers the terms our FAQ's own scope left out. For the mechanics these terms sit on top of, domain and mailbox architecture, warm-up pacing, blacklist recovery steps, the deliverability FAQ is still the place to go. And if a term here connects to a decision further back in the rest of the cold outbound stack, that's worth checking before the next send, not after.

Frequently asked questions

Is CASL the same as CAN-SPAM?

No. CASL requires opt-in consent before you send a message, either express or implied through an existing relationship. CAN-SPAM allows opt-out based sending as long as you meet its disclosure requirements: accurate sender information, a working unsubscribe link, and a physical address. The two regimes start from opposite defaults.

Does the B2B exemption in CASL cover cold outbound?

Generally, no. The exemption requires an existing relationship between the two companies, a past transaction, a referral, a signed agreement, not just a business context. Cold outreach to a company you've never dealt with typically doesn't qualify, which is the exact gap that catches outbound programs treating "B2B" as automatic cover.

Do I need BIMI for cold email to work?

No. BIMI is a trust and visibility layer sitting on top of DMARC enforcement, not a deliverability requirement on its own. Most cold-sending domains never reach the DMARC enforcement level BIMI depends on, and inbox placement is decided by reputation and authentication long before a logo ever enters the picture.

Is "block list" the same thing as "blacklist"?

Yes, same concept, different eras of terminology. "Block list" is the current documentation standard across most vendors and style guides. "Blacklist" persists mainly in legacy tool names, like DNSBL and RBL, and in bounce message text that hasn't been updated in years.

What's the difference between complaint rate and bounce rate?

Bounce rate measures delivery failures: an address or domain that doesn't accept the message. Complaint rate measures recipients actively marking your mail as spam, which is a stronger and faster-acting negative signal, because it's a direct action against your sender reputation rather than a passive delivery problem.

How is seed testing different from checking Postmaster Tools?

Postmaster Tools reports aggregate, domain-level signals after messages have already gone out. Seed testing checks actual inbox-versus-spam placement across providers before or during a send, which often surfaces a placement problem a week or two before aggregate metrics show any degradation at all.

Supporting

  1. McInnes Cooper: Canada's Anti-Spam Legislation (CASL): 10 FAQs
  2. SMARTe: CASL Compliance for B2B Cold Email in Canada
  3. BIMI Group: official requirements
  4. Validity: What is the BIMI email protocol?
  5. Suped: Should I use blacklist or blocklist in email marketing?
  6. Litmus: Email Deliverability Glossary
Written by
Anshul

Anshul Bhatia

Founder
IIT Kharagpur. Builds GTM systems for B2B SaaS.

Anshul builds the outbound systems behind Lead Line Partners. Clay workflows, AI enrichment, and research-first sequencing for teams that want more with less.

More posts
GTM ToolkitComparison · 8 min read

Apollo vs Nooks vs Aircall: Which Parallel Dialer Fits Your Team

Apollo, Nooks, and Aircall all get called a parallel dialer. Only one of them runs a power dialer instead, and that decides more about fit than any feature list.

By Anshul Bhatia
GTM ToolkitGuide · 13 min read

1:1 ABM Landing Pages, Automated: The Vendor-Neutral Build

Every top-ranking guide to 1:1 ABM pages sells its own platform. Here is the vendor-neutral architecture instead: a data source, a render layer, and a QA gate you can build this week.

By Anshul Bhatia
GTM ToolkitComparison · 16 min read

What a Six-Figure ABM Platform Actually Does, Job by Job (And What Replaces Each Job)

Six-figure ABM contracts bundle five or six distinct jobs into one line item. Here's what each job delivers, what an engineered stack replaces it with, and where the platform legitimately wins.

By Anshul Bhatia

Ready to engineer your GTM motion?

Tell us how your motion runs today. We'll show you what we'd engineer.

Contact us