Back to Blog

Brevo Banned Cold Email? Anti-Spam Policy & Deliverability

Hero image for Brevo Banned Cold Email? Anti-Spam Policy & Deliverability

Brevo Just Banned Cold Email? What Its Anti-Spam Policy Means for Your Deliverability

You think your cold email is compliant with CAN-SPAM? What if your email platform itself decides it's spam and suspends your account?

That is not a hypothetical. Brevo—formerly Sendinblue—has a published anti-spam policy that explicitly prohibits cold email. It bans lists that are scraped, acquired, or purchased from a third party. It applies that ban to transactional and marketing messages alike. The stated consequence is account suspension or restriction.

This is not a gap in the product. It is a deliberate boundary. And it signals something larger: email platforms are now enforcing their own definitions of spam that go beyond legal compliance. If you are running cold campaigns on shared infrastructure, you are playing a game where the rules just changed.

The Policy Is Not Vague—It Is Surgical

Brevo's anti-spam policy is specific in a way terms-of-service documents usually are not. Three requirements stand out:

  • Consent must be active. The contact has to tick a checkbox to subscribe, and that checkbox cannot be pre-ticked.
  • Consent must be explicit. The contact must know what kind of messages they will receive and for what purpose.
  • You must be able to provide proof of opt-in for every contact at any time. Not just a receipt—a retrievable record of each person joining.

Partner opt-in and co-registration are permitted but constrained: every partner's name must be displayed and easily available, and the cap is ten partners. Read those together and the shape is clear. Brevo is built for a list that people joined. Its compliance model assumes a retrievable record of each person joining. A cold list has no such record by construction. The prohibition on purchased and scraped lists is not a separate rule—it is a restatement of the consent requirement.

Why Shared Infrastructure Changes Everything

The key insight here is not about Brevo's policy alone. It is about a shift in leverage. Historically, deliverability battles played out between senders and ISPs like Gmail or Outlook. You warmed domains, managed complaint rates, and avoided spam traps. The email platform itself was largely neutral—it just forwarded what you sent.

That is changing. Platforms like Brevo, HubSpot, and Mailchimp now enforce their own anti-spam policies because they sit on shared IP pools and shared sending infrastructure. One bad actor can tank reputation for thousands of customers. So the platform pre-judges your sending behavior based on its risk model. If your list is cold, you are a liability.

Brevo's policy is explicit about the logic: "A shared bulk platform means a shared reputation." That is why the prohibition is enforced. The same logic applies to your own domain: marketing and cold outbound merged onto one domain converge on the worse behavior.

The Irony: CAN-SPAM Compliance Is Irrelevant Here

Here is where it gets uncomfortable for many senders. You can be fully CAN-SPAM compliant—including an opt-out mechanism, accurate subject lines, and a physical mailing address—and still violate Brevo's policy. CAN-SPAM requires a way to unsubscribe. Brevo requires active, explicit opt-in before you send the first message. Those are different standards.

Legal compliance does not equal platform compliance. And the platform controls your domain reputation, your deliverability, and your account access.

This is not a theoretical edge case. If you are a sales development rep sending cold campaigns with a Brevo account, you are operating outside the platform's acceptable use policy. The risk is not that your emails get flagged as spam by ISPs—it is that Brevo itself suspends your account. And once your account is suspended, you lose access to your domain, your contact data, and any warm reputation you had built.

What This Means for Your Deliverability Strategy

If you are running cold email campaigns, you now face a choice: use a platform that explicitly allows cold outreach, or change your outreach strategy. There is no middle ground on shared infrastructure like Brevo.

But the implications run deeper. Even if you are not on Brevo, the trend is real. Email platforms are increasingly defining spam on their own terms. The legal floor is not the same as the platform's ceiling. If a platform decides cold email is risky, it will ban it. Period.

This shifts the deliverability battle from ISPs to ESPs. The question is no longer just "Will Gmail deliver my email?" It is now "Will my email platform let me send it in the first place?"

What To Do About It: Three Concrete Moves

If you are currently using Brevo or a similar platform and need to run cold campaigns, here is what you can do today.

  • Separate your sending surfaces. Do not run transactional or marketing email from the same platform you use for cold outreach. Use a dedicated cold email infrastructure—platforms built for cold sending often have their own IP pools, warming protocols, and policies that align with one-to-one outreach. Keep your transactional and newsletter sends on Brevo or another reputable platform. Keep cold outbound on a separate stack.
  • Verify your list sources. If you are on Brevo and want to stay, you need to prove active opt-in for every contact. That means unticked checkboxes, explicit language, and retrievable timestamps. If you cannot produce that record, you are at risk. Audit your current lists. Remove any contacts where the opt-in trail is unclear or missing.
  • Warm your own domains. Cold email works when you control your domain reputation, not when you rely on a platform's shared reputation. Set up dedicated sending domains, warm them gradually over four to six weeks, and monitor deliverability metrics like bounce rate, complaint rate, and spam trap hits. This gives you portability. If a platform bans you, you can move your domains to a different provider without starting from zero.

These moves are not about gaming the system. They are about aligning your infrastructure with the reality that platforms now enforce their own consent standards. If you ignore this, you are betting your account on a policy that is explicitly designed to suspend you.

The Unresolved Tension: Who Decides What Spam Is?

The question that lingers is bigger than Brevo. As more platforms adopt similar policies, who actually decides what constitutes spam? Historically, it was ISPs and receivers. Now it is the sending platforms themselves. They are acting as gatekeepers, not just transmitters. And their incentives are not aligned with every sender's goals.

A platform like Brevo wants to protect its shared IP reputation. That is a valid business interest. But it means that even legitimate cold outreach—manual, targeted, research-based, with a clear opt-out—gets treated the same as blast spam. The platform does not care about the nuance of your outreach strategy. It cares about the risk profile of your list.

This creates a gap. There is a difference between spam (unsolicited bulk emails that deceive or harm) and cold email (targeted, one-to-one outreach that is legally compliant but lacks prior opt-in). But platform policies flatten that distinction. They treat any list without active opt-in as a compliance violation.

Is that the right trade-off? For platforms managing shared reputation, maybe. But for senders who are thoughtful about outreach, it leaves you with fewer legitimate tools. And if the trend continues, the definition of spam will be increasingly set by infrastructure providers, not by regulators or recipients.

So here is the open question: If you are a responsible sender who follows the law, warms your domains, and monitors your metrics, should you be forced to choose between platform access and outreach strategy? Or is there a middle ground where platforms distinguish between high-quality cold outreach and bulk spraying?

The answer is not clear yet. But the risk is. And if you are on Brevo—or any shared infrastructure—that risk is not theoretical. It is published, in plain language, on the vendor's legal page. Your move.

Keep building your outbound system