Definition
Email permission is the authorisation a sender receives from a recipient to send commercial or promotional email messages. It is the foundation of legitimate email marketing and sits at the centre of anti-spam legislation worldwide, including CAN-SPAM in the United States, GDPR in Europe, and CASL in Canada. Permission transforms email from an intrusive channel into an anticipated one, improving engagement, deliverability, and long-term subscriber value.
Permission exists on a spectrum rather than as a binary condition. Explicit permission, also known as express opt-in, occurs when a subscriber actively and unambiguously agrees to receive marketing emails, typically by ticking a checkbox or submitting a signup form. Implied permission arises from an existing customer relationship, such as a purchase or a service agreement, where the recipient has a reasonable expectation of receiving commercial communication. Transactional permission is a subset of implied permission that applies to messages required to complete a transaction, such as order confirmations or password resets, and does not extend to marketing content.
Best Practices
Implement confirmed opt-in (double opt-in) as the default permission mechanism. Requiring new subscribers to confirm their email address via a verification message eliminates invalid addresses, prevents accidental signups, and provides clear evidence of consent for regulatory compliance. The marginal drop in signup volume is offset by significantly higher list quality.
Document the type of permission you hold for each subscriber, including the date, source, and explicit consent language used at the point of collection. Maintain this record as part of your subscriber database so you can demonstrate compliance during audits or regulatory inquiries.
Establish a permission renewal cycle for dormant subscribers. Review your list every six to twelve months and send a re-confirmation request to subscribers who have not engaged within that period. Remove or suppress those who do not re-confirm to keep your list clean and protect sender reputation.
Understand the distinction between permission and consent under GDPR. Consent must be freely given, specific, informed, and unambiguous, while permission is a broader marketing concept. GDPR consent cannot be inferred from silence or pre-ticked boxes and must be as easy to withdraw as it was to give.
Was this useful?
Related Glossary Terms
Consent Refresh Campaign
A consent refresh campaign asks subscribers to confirm they still want to receive email, refreshing proof of consent and cleaning the list while respecting privacy laws.
Email Address Regex Validation
Email address regex validation uses pattern matching to verify that an address conforms to the standard local-part and domain format.
Email B2B Consent
The legal requirements for B2B email marketing consent, covering GDPR legitimate interest, CASL implied consent, CAN-SPAM exemptions, and jurisdiction-specific best practices.
Email CASL Requirements
Email CASL requirements are Canada's anti-spam rules requiring consent, identification, and an unsubscribe mechanism for commercial electronic messages.
Email Compliance Automation
Email compliance automation uses automated processes to manage unsubscribe processing, consent record-keeping, data retention enforcement, and regulatory monitoring within required legal timeframes.
Email Confirmed Opt-In Flow
A confirmed opt-in flow is the complete signup sequence that ends only when a subscriber verifies their address, ensuring consent and validity.
Frequently Asked Questions
Single opt-in adds a subscriber to your list immediately after they submit a form, whereas double opt-in requires the subscriber to confirm their email address by clicking a link in a verification message. Double opt-in provides stronger evidence of consent and higher list quality.
In many jurisdictions, you may send marketing emails to existing customers based on implied permission, provided you offer a clear unsubscribe option and the products or services are similar to those the customer previously purchased. This varies by country; GDPR requires explicit consent.
Permission marketing, a concept popularised by Seth Godin, refers to marketing communications that are anticipated, personal, and relevant because the recipient has given explicit permission to receive them. It contrasts with interruption marketing, which forces messages on unwilling audiences.
Permission does not have a fixed legal expiry date, but best practice recommends renewing permission every twelve to eighteen months if the subscriber has not engaged with your emails. A subscriber who has not opened an email in over a year may no longer remember giving permission.
Purchased email lists almost never include valid permission. The individuals on those lists have not consented to receive emails from you, and sending to them violates anti-spam laws, damages sender reputation, and results in extremely low engagement.