Email is the one channel where a vendor's mistake can damage an asset you cannot rebuy. A bad quarter of paid search costs money; a bad quarter of email can burn a sending domain, land you on blocklists and cost you the inbox placement it took years to earn. It is also the channel where the law is most specific about what has to happen in every message and who remains responsible when someone else presses send. This page covers the terms to fix before an outsourced programme starts, and how to tell a deliverability-literate vendor from a volume seller.
The duties you cannot outsource
The FTC's CAN-SPAM compliance guide sets out requirements that apply to commercial messages regardless of who sends them: header information must not be false or misleading, subject lines must not deceive, the message must be identified as an advertisement, it must include a valid physical postal address, it must tell recipients how to opt out, opt-out requests must be honoured promptly, and the sender must monitor what others do on its behalf. That last requirement is the one buyers miss. The guide is explicit that a company whose product is promoted in a message may be legally responsible even when another company actually sends it, and that you cannot contract away your responsibility to comply. So the vendor contract can allocate cost and blame between you, but it cannot move the legal duty. Ask to see how the vendor handles unsubscribes, and test one yourself before launch.
Deliverability is the whole job
A vendor who talks about creative and cadence but not about authentication, warm-up and list hygiene is selling the visible half of the work. Sending domain authentication, a properly warmed sending reputation, suppression of hard bounces and long-term non-openers, and separation of transactional from promotional streams determine whether anything gets read at all. Ask which sending domain or subdomain will be used and who owns it, because sending from a vendor-controlled domain means the reputation you build leaves with them. Ask for their process when a campaign shows a complaint spike: pausing, diagnosing and re-warming rather than pressing on. And ask what they refuse to send, since the fastest way to lose inbox placement is a purchased list, which also puts consent on shaky ground from the first message.
Consent, lists and ownership
Settle three ownership questions in writing before the first send. Who owns the list, including growth during the engagement, and in what format is it exportable on exit. Who owns the sending domain and the platform account. Who holds the consent record for each subscriber, meaning the timestamp, source and wording someone agreed to, because that record is your defence if a complaint escalates and it is worth more than the address itself. Then agree what the vendor may not do: no purchased or rented lists, no appended addresses, no scraping, no re-permissioning campaigns to addresses that already opted out. As you compare email marketing agencies, ask each one how they grew a client's list last year. Vendors who grew it through genuine opt-in describe the mechanics happily; the others describe results.
What good reporting looks like
Open rates have become an unreliable headline metric because of privacy protections that pre-fetch images, so a vendor still leading with them is reporting on autopilot. More useful: delivered rate and bounce composition, complaint rate by campaign, click-through on the segments you care about, unsubscribe rate as a trend, revenue or qualified enquiries per send, and list growth net of churn. Ask for these to be agreed at the start and reported unfiltered, including the campaigns that underperformed. Ask for a quarterly deliverability review rather than a monthly campaign recap, since inbox problems build slowly and are cheapest to fix early. And check the numbers against your own analytics and order data, because the only figures worth acting on are the ones you can reproduce outside the vendor's dashboard.
Questions people ask about outsourced email marketing
Are we liable if the agency breaks the rules?
Potentially, yes. The FTC's CAN-SPAM guide states that both the company whose product is promoted and the company that sends the message can be legally responsible, and that you cannot contract away your compliance responsibility. Monitoring what a vendor does on your behalf is part of the duty, not an optional extra.
Should the vendor send from our domain or theirs?
Yours, using a subdomain you control, with authentication configured on your DNS. That keeps the sending reputation with you when the relationship ends. A vendor insisting on their own sending infrastructure is asking you to rent an asset that should be yours.
How quickly must we process unsubscribes?
Promptly, and the FTC's guide sets an outer limit measured in business days after receipt. In practice, configure the platform to suppress immediately and verify it yourself by unsubscribing from a test address. Do not charge a fee, require a login, or ask for any information beyond an email address to opt out.
Is a purchased list ever acceptable?
Treat it as never. Purchased lists produce complaints and spam-trap hits that damage the sending reputation for every future campaign, and the consent record behind them is usually unverifiable. The recovery cost is far higher than the cost of building a list slowly through genuine opt-in.