Email marketing means sending commercial messages by email to people who have agreed to receive them, so that they buy, come back or stay customers. The method comes down to four steps: build a list on a lawful basis, get delivered to the main inbox, write to one segment at a time, and measure what happens after the click.
The channel is still where the customers are: according to Ofcom's Online Nation 2025, Gmail alone reached 58% of UK online adults in May 2025, up from 55% a year earlier. What has changed are the rules. Since 2024 Gmail and Yahoo, and since 2025 Outlook, reject or send to spam anyone who doesn't meet specific technical requirements, while since 2021 Apple has made the open rate unreliable. On Google UK's first page for "how to do email marketing", checked on 10 October 2026, the AI Overview covers authentication in a single line ("verify your sender domain") and most results are beginner guides from software vendors. Below are the seven principles we think hold up in 2026, with the official thresholds and a check we ran on the domains of 50 large UK companies and organisations.
1. Build the list on consent, and know where UK law draws the line
In the UK, marketing emails to individuals need their specific consent, unless they're existing customers covered by the soft opt-in. Emails to companies are treated differently, and that's the distinction most shortcuts get wrong.
The reference is regulation 22 of the Privacy and Electronic Communications Regulations (PECR), explained in the ICO's guidance on electronic mail marketing. Three points come in handy every time someone suggests a shortcut:
- consent has to be specific and actively given: under UK GDPR a pre-ticked box or consent made a condition of the service doesn't count;
- an email asking for consent to marketing is itself marketing: in 2017 the ICO fined Flybe £70,000 and Honda £13,000 for exactly that;
- an individual's address found on a website, a social network or a bought-in list doesn't give you consent; PECR only lets you email "corporate subscribers" (limited companies, LLPs, Scottish partnerships, government bodies) without it, while sole traders and some partnerships count as individuals.
The exception for individuals is the soft opt-in (regulation 22(3)): you can email someone without explicit consent if you got their address during a sale or negotiations for a sale, you're promoting similar products or services, and you gave them a simple way to opt out both when you collected the address and in every message. It covers customers, not contacts collected at a trade fair or copied from LinkedIn. Since 5 February 2026 the Data (Use and Access) Act 2025 has extended a version of it to charities and raised the maximum PECR fine from £500,000 to £17.5m or 4% of global turnover.
In practical terms, double opt-in (the subscriber confirms by clicking a link in a second email) is the simplest way to have proof of consent, with date and time, if anyone ever asks for it. For a B2B company the most effective collection point is usually still a piece of content in exchange for the address, hosted on a B2B landing page built for the purpose. Emailing a company address without consent may be allowed under PECR, but the person behind it is still protected by UK GDPR, so you need a legitimate interest and an easy way to object. A necessary note: we're not lawyers, and borderline cases need advice from someone who works in data protection.
2. Delivery comes before copy: the Gmail, Yahoo and Outlook rules
Deliverability is the percentage of emails that reach the inbox rather than the spam folder or nowhere at all. Since February 2024 it no longer depends on reputation alone: the three big providers publish minimum requirements and enforce them.
Google asks all senders for SPF or DKIM, valid forward and reverse DNS records, a TLS connection and a spam complaint rate below 0.3%. Anyone sending 5,000 or more messages a day to Gmail accounts must have SPF and DKIM together, a DMARC record (even with a p=none policy), the sender's domain aligned with the SPF or DKIM domain, and one-click unsubscribe. The recommended spam rate threshold is lower, at 0.1%. On its enforcement timeline page Google says that since November 2025 non-compliant traffic gets temporary and permanent rejections.
Yahoo asks bulk senders for the same things and sets a deadline many people forget: unsubscribes must be honoured within 2 days. Microsoft fell into line with an announcement in April 2025: from 5 May 2025 anyone sending more than 5,000 emails a day to Outlook.com, Hotmail and Live must have SPF, DKIM and DMARC, and messages that don't meet the requirements are rejected with error code 550 5.7.515.
| Requirement | Gmail | Yahoo | Outlook.com |
|---|---|---|---|
| Since | February 2024 | February 2024 | 5 May 2025 |
| Bulk sender threshold | 5,000 emails a day | No fixed number | More than 5,000 emails a day |
| SPF and DKIM | Both | Both | Both |
| DMARC | Required, p=none is enough | Required, p=none is enough | Required, p=none is enough |
| One-click unsubscribe | Yes | Yes, within 2 days | Recommended |
| Spam complaint rate | Below 0.3%, ideally below 0.1% | Below 0.3% | Not set |
One piece of advice from Microsoft's documentation applies to everyone: marketing emails shouldn't be sent from the main domain but from a dedicated subdomain (Microsoft uses the example m.contoso.com for marketing and t.contoso.com for transactional email), so that a reputation problem with the newsletters doesn't block the sales team's email.
Our check: the DMARC records of 50 large UK organisations
To see how far these rules have become habit, on 10 October 2026 we queried the DNS of the main domains of 50 well-known UK companies and organisations, chosen across banking, energy, telecoms, retail, fashion, transport, food and drink, pharmaceuticals, insurance and industry. We read the DMARC record published at _dmarc.domain and checked for an SPF record.
| DMARC policy | Domains | Share | Examples |
|---|---|---|---|
| p=reject (rejects unauthenticated email) | 34 | 68% | Barclays, HSBC, Tesco, BT, Octopus Energy, Diageo |
| p=quarantine (sends it to spam) | 9 | 18% | E.ON, Three, John Lewis, Unilever, Rolls-Royce |
| p=none (monitoring only) | 7 | 14% | Asda, Burberry, AstraZeneca, Greggs, Transport for London |
| No DMARC record on the main domain | 0 | 0% | None |
| Total | 50 | 100% | 49 of the 50 domains publish an SPF record on the main domain |
The UK result is clearer than the one we got in Italy. Every one of the 50 domains has a DMARC record, the minimum Gmail, Yahoo and Microsoft require from bulk senders, and more than two-thirds reject unauthenticated mail outright. Only 7 are still on p=none, which protects nobody from someone spoofing the sender. When we ran the same check on 50 large Italian companies on 1 October 2026, 4 had no DMARC at all and 11 of the 46 with a record were on p=none. For a small business that sends its newsletter from its own domain without DMARC, the comparison is with brands whose emails land in the same inbox and almost all of them are authenticated. The check takes a minute with any DNS lookup tool, and the record is published from the registrar's control panel.
3. Write to one segment at a time
Segmenting means splitting the list into groups that get different messages, based on who they are and what they've done. A single newsletter for everyone is the most common reason people stop opening it, and people who stop opening hurt the sender's reputation with Gmail.
For an industrial manufacturer, for example, the purchasing department and the technical lead at the same customer want different things: the first reads about lead times and price lists, the second about specifications and certifications. Two segments, two emails. The criteria that work best are almost always behavioural: what they downloaded, which pages they visited, how long since they last clicked. It's the same reasoning we use in B2B SEO, where each role in the buying group searches in its own words.
4. One email, one goal, one real sender
Every email should ask for one thing only: read an article, book a demo, complete a purchase. The subject line promises it, the body explains it, the button makes it happen. When there are seven links and they all look the same, the reader clicks none of them. For the last part our collection of call to action examples comes in handy.
Two details that Twilio SendGrid's guide lists among good practice and that Google UK's AI Overview for this search leaves out: no no-reply addresses as the sender (whoever replies to a newsletter is the warmest contact you have) and a recognisable sender name, ideally a person with the company name alongside. Content comes after that, and if you're short of ideas on what to send, a content marketing plan also sorts out the newsletter calendar.
5. Measure clicks and conversions, not opens
The open rate no longer measures opens. On 7 June 2021 Apple announced Mail Privacy Protection, a feature that stops senders knowing when an email is opened and masks the recipient's IP address. In practice Apple's servers download the images, including the tracking pixel, and the platform records an open the person never made.
How much it weighs is shown by Litmus, which calculates email client shares from more than a billion opens: in July 2026 Apple accounted for 62.26% of opens, Gmail 27.03% and Outlook 5.83%, and the opens affected by Mail Privacy Protection were between 55% and 60% of the total. It's a worldwide sample of Litmus customers, not a UK figure, but it's enough to say that more than half the number you see in the report may not be a person.
UK benchmarks need reading through this filter. In GetResponse's report (2024 edition, 2023 data, senders with at least 500 contacts) the UK has an open rate close to the global average but lower click rates:
| Metric | United Kingdom | Global average |
|---|---|---|
| Open rate | 39.98% | 39.64% |
| Click-through rate (CTR) | 2.74% | 3.25% |
| Click-to-open rate (CTOR) | 6.86% | 8.62% |
| Unsubscribes | 0.15% | 0.15% |
| Spam complaints | 0.01% | less than 0.01% |
| Bounces | 3.21% | 2.33% |
An average open rate with a low click-to-open rate fits with plenty of automatic opens, although the report doesn't say how it handles them. Our rule is simple: the metrics that count are click rate, conversions and attributed revenue, measured with UTM parameters in Google Analytics and compared with the conversion rate of the other channels. Opens are only useful as a warning sign: if they collapse from one send to the next, it's almost always a delivery problem.
6. Clean the list before Gmail does it for you
List hygiene is the habit of removing addresses that bounce and contacts that no longer respond. There's an arithmetical reason for it: Gmail's 0.3% threshold means 3 complaints for every 1,000 emails delivered. On a B2B list of 2,000 contacts, 6 people pressing "report spam" on the same send are enough to go over it.
The UK average in GetResponse's data is 0.01% complaints, so the threshold looks a long way off. The real risk is old lists: addresses collected years ago, people who've changed company, contacts who don't remember signing up. In our view three things are worth doing before any important campaign:
- remove addresses with a permanent bounce (hard bounce) straight away: in the UK benchmark, bounces, temporary and permanent together, are 3.21% of sends;
- send anyone who hasn't clicked in six months a single email asking whether they want to stay, and remove those who don't reply;
- check your domain's spam rate in Google Postmaster Tools, which is the figure Gmail uses, not the platform's.
7. Work out ROI on your own numbers, not on 36 to 1
Email marketing ROI is the ratio between the margin the emails generate and what the platform, content and hours of work cost. The famous "$36 for every $1 spent", which Brevo's guide quotes as an average and which turns up among the sources of Google UK's AI Overview, isn't a measured average: it's a range declared in a survey.
In its 2025 survey of around 500 marketers worldwide, Litmus reports that 35% claim a return of between $10 and $36 per dollar spent, 30% between $36 and $50, and 5% over $50. And 21% don't measure ROI. It's an international, self-reported sample, useful for the order of magnitude, not for a business plan. For your own case you need the calculation described in our guide to marketing ROI, with the revenue attributed to email in Analytics and the real costs.
What to ask a platform before choosing it
The choice between Mailchimp, Brevo, Klaviyo, HubSpot, ActiveCampaign or Dotdigital depends on volumes, CRM integration and e-commerce. The feature lists look alike, so it's worth checking the five things that affect the principles above:
- DKIM signing with your domain, not the platform's, and clear instructions for SPF and DMARC;
- one-click unsubscribe header (RFC 8058) switched on by default;
- a double opt-in log with the date, time and wording of the privacy notice accepted;
- reports that separate automatic opens and filter out clicks from corporate spam filters;
- where the data is stored and how it's transferred out of the UK, with a data processing agreement ready to sign.
For a wider overview of the tools there's our selection of marketing tools for small businesses.
Something the industry rarely says: with the 2024 rules, email has become one of the few marketing channels where the companies delivering the messages publish the thresholds beyond which they'll block you. Elsewhere the penalty criteria remain largely undeclared; here they're written on a Google support page. That means delivery can be designed, and that a small, clean list, connected to a lead generation system that feeds it with real contacts, is worth more today than a big list nobody has ever cleaned.
Email marketing: frequently asked questions
Yes, but it works for senders with a list built on a lawful basis and an authenticated domain. Ofcom reports that Gmail alone reached 58% of UK online adults in May 2025. What no longer works are bought lists and campaigns sent without SPF, DKIM and DMARC, which Gmail and Outlook send to spam or reject.
Not to individuals. Under PECR, marketing emails to individuals and sole traders need specific consent or the soft opt-in, and a public address gives you neither. Corporate addresses of limited companies can be emailed without consent, but UK GDPR still applies to the person behind them. For particular cases, ask a data protection adviser.
It depends on volume, but it's worth having anyway. Gmail makes it mandatory from 5,000 emails a day, Microsoft above 5,000. Below that threshold it isn't a requirement, but it protects the domain from spoofing and improves providers' trust. Publishing a record with a p=none policy takes a few minutes.
It depends on how much you have to say. The right frequency is the one that doesn't push up unsubscribes and spam complaints: if both rise when you send more, you're sending too much or to the wrong segment. In our view a B2B company does well to start with one or two well-segmented emails a month and increase only if clicks and unsubscribes allow it.
It depends, and it matters less than people think. GetResponse's UK benchmark is 39.98%, but with Apple's Mail Privacy Protection some opens are recorded automatically. It's better to compare click rate and conversions, and use opens only to spot sudden drops in delivery.