Verify, sunset, re-permission and warm up. The full 8-step process I use on every project, with the Swiss and German legal parts nobody else covers.
Most senders wait too long. By the time you notice something is wrong, the damage is already done. Here are the warning signs I look for in order of severity.
- Manual campaign creation takes hours
- Guessing the best send times
- One-size-fits-all messaging
- Requires constant attention
- Revenue is unpredictable
- Bounce rate creeping above 2% (target: under 1%)
- Complaint rate over 0.1% (Gmail’s danger line is 0.3%)
- Unsubscribe rate spiking after specific sends
- Deliverability warnings from your email tool
- Your email tool has paused sending or asked for a list review
- Gmail Postmaster Tools shows “Bad” or “Low” reputation
- Emails landing in spam consistently
- Your email tool has suspended your account
📊 The 0.3% math If you send 10,000 emails and 30 people mark you as spam, you’re at 0.3%. That’s Gmail’s ineligibility line. To get support back, your rate must stay under 0.3% for 7 consecutive days [2]. Google recommends staying under 0.1% for reliable inbox placement.
If you’re seeing any of these signs, cleanup isn’t optional anymore. It’s the only path back.
It’s rarely one thing. When I look into a broken list I usually find three or four of these together, and each carries a different risk.
| 🗂️ Where old lists come from |
|---|
| Old CRM imports nobody remembers |
| Partner, sponsor or JV lists (their consent, not yours) |
| Trade show badges scanned and never emailed |
| Two companies merged and their lists got combined |
| Inherited lists from the last marketer |
| Dormant COVID-era newsletters |
| Contest and giveaway sign-ups |
| Purchased lists (illegal in Switzerland and Germany, never do this) |
| LinkedIn, ZoomInfo, Apollo scrapes |
| Unsegmented shop customer dumps |
| Lists that failed a compliance audit |
| Contacts from suspended accounts |
| Migration where the consent proof got lost |
Email addresses go bad on their own. This is the part most senders underestimate.
📊 The decay rate ZeroBounce’s Email List Decay Report for 2026 analysed over 11 billion addresses. It found that 23% of an email list decays every year [1]. On a 50,000-contact list, that’s about 2,500 addresses going bad every quarter. Only 62% of submitted addresses in 2025 were valid and safe to send.
People change jobs, abandon accounts, switch providers. It happens quietly. You keep sending to addresses that no longer work, your bounce rate creeps up, your reputation drops, and one day a big campaign tips the balance.
The math compounds. Every dead address you keep is a bounce waiting to happen. Every bounce hurts your sender reputation. A worse reputation means more filtering. More filtering means lower engagement. Lower engagement makes ISPs treat you as spam. And spam treatment increases complaint rates.
This is why cleanup is not a one-off task. Decay is continuous, so cleanup has to be too.
The rules of email hardened significantly. If you haven’t updated your practice, you’re already behind.
⚠️ The bottom line If you send more than 5,000 emails a day to Gmail, Yahoo or Outlook users and you don’t have SPF, DKIM and DMARC set up correctly, your mail is getting bounced right now. Not filtered. Bounced.
Spam traps are email addresses set up specifically to catch senders with poor list hygiene. They look like normal addresses. You cannot tell them apart from real ones. If your list contains them, you’re being watched.
There are three types [7]:
- Pristine traps: addresses that were never used by a real person. Set up by anti-spam organisations and mailbox providers, hidden on public websites for scrapers to find. If you hit one, it’s almost certainly because you bought or scraped a list. Consequences: severe. IP blacklisting, domain blacklisting, sender reputation damage.
- Recycled traps: real addresses that were abandoned, hard-bounced for 6 to 12 months, then repurposed as traps by the provider. If you keep sending to hard-bounced addresses, you’re guaranteed to hit these eventually.
- Typo traps: common misspellings of major domains. gmial.com instead of gmail.com, yaho.com instead of yahoo.com. Prevented by real-time verification at signup.
Two more hidden threats to know about:
- List poisoning: bots submit spam trap addresses to your signup forms on purpose. This is why honeypot fields, reCAPTCHA and double opt-in matter for hygiene, not just security.
- Role addresses: info@, sales@, support@. Multiple people read them, complaint rates are higher, and abandoned role addresses often become recycled traps. Filter these out at signup or during audit.
Every verifier catches typo traps easily. Recycled traps are harder. Pristine traps are almost impossible to spot. The only defence is prevention: never buy lists, always use double opt-in, verify at signup.
Before you touch a single tool, sort every contact into one of three buckets. This is the mental model I use on every project and it stops you from doing something reckless (like sending a re-permission email to people you had no right to email in the first place).
| 🟢 Confirmed | 🟡 Re-Permission | 🔴 Parked |
|---|---|---|
| Documented double opt-in | Engaged but consent is thin | No defensible consent |
| Send today | Ask to reconfirm* | Do not email |
| Keep in main list | Move to a separate flow | Suppress or delete |
*Only where the law allows. See Step 5.
Double opt-in means the subscriber confirmed their sign-up through a separate confirmation email. It’s the standard way to prove consent in Switzerland and Germany. The whole point of cleanup is to move contacts up the tiers where legally possible, and to stop pretending the bottom tier is a marketing asset.
Before you clean, measure. You need a clear picture of what’s broken so you can prove recovery later.
Pull these numbers from your last 3 to 6 months of sends:
- Bounce rate total, split into hard and soft
- Complaint rate per campaign
- Open rate trended over time
- Click rate trended over time
- Unsubscribe rate per campaign
- List growth vs list decline (are you growing?)
Then check the external tools:
- Google Postmaster Tools v2 for domain reputation and spam complaint rate
- Microsoft SNDS (Smart Network Data Services, Microsoft’s dashboard for Outlook and Hotmail) if you have consumer volume
- Yahoo Sender Hub Insights for Yahoo mail delivery
- Your DMARC report tool (Postmark, dmarcian, EasyDMARC) for authentication pass rates
Screenshot everything. Note the date. This baseline is what you’ll compare against in 4 weeks, 8 weeks and 12 weeks. Without it, you can’t prove the cleanup worked.
Not everyone on your list is equally at risk. Before you verify, break the list into engagement tiers. This does two things: it tells you where the damage is concentrated, and it feeds directly into the warm-up ramp later.
Standard tiers I use:
- Active (30 days): opened or clicked in the last 30 days
- Recent (30 to 90 days): opened or clicked in the last quarter but not last month
- Cool (90 to 180 days): opened or clicked in the last 6 months but not last 3
- Cold (180 to 365 days): opened or clicked in the last year but not last 6 months
- Dormant (365+ days): no opens or clicks in over a year
Apple Mail Privacy Protection has messed up open rates since 2021. Prefetching creates fake opens. If you can, weight clicks more than opens. Any click is a stronger signal of a real human than any open.
You need to know what’s deliverable before you do anything else. Verification catches invalid addresses, spam traps, disposable domains and role accounts before they hurt your sender reputation.
The tool I recommend is Bouncer [3]. Bouncer is European. The company is based in Wrocław, Poland. Uploaded emails are stored only in EU data centres, there’s a signed DPA (data processing agreement) and verification data auto-deletes after 60 days. For a Swiss or German sender who has to answer to Swiss and EU privacy law, where your data lives matters.
Pricing is pay-as-you-go from about $8 per 1,000 emails, dropping to around $0.002 at high volume. Accuracy is 99.5% claimed, 97 to 98% in independent tests, up to 200,000 emails per hour, 100 free credits to try.
To be fair, Bouncer isn’t the only good option. Here’s how the main tools compare:
| Tool | Where | GDPR | Starting price | Best for |
|---|---|---|---|---|
| Bouncer | 🇪🇺 Poland | ✅ EU data + DPA | ~$8 / 1k | Swiss + German senders |
| ZeroBounce | 🇺🇸 USd | ✅ (US data) | ~$16 / 2k | Big US brand credibility |
| MillionVerifier | 🇭🇺 Hungary | ✅ | ~$29 / 5k | Tightest budgets |
| NeverBounce | 🇺🇸 US | ✅ | ~$8 / 1k | Mailchimp shops |
| Kickbox | 🇺🇸 US | ✅ | ~$5 / 500 | Good all-rounder |
Reading the results:
- Deliverable: safe to send.
- Undeliverable: hard bounces. Remove immediately.
- Risky / catch-all: the domain accepts everything, so you can’t confirm the mailbox exists. Put in a separate group and test in small batches.
- Disposable: temporary addresses like Mailinator. Remove.
- Role: info@, sales@, support@. Handle separately.
- Unknown: the verifier couldn’t complete the check. Retry in 24 hours, then remove if still unknown.
Verification tells you if the address works. It says nothing about whether you’re allowed to email it. Those are two different questions, and in Switzerland and Germany the second one is the one that gets you into trouble.
For every contact that survived verification, capture these four things:
- ✅ Source: where did the address come from?
- ✅ Timestamp: when did they sign up?
- ✅ IP address: captured at sign-up if you have it
- ✅ Method: single opt-in, double opt-in (DOI), offline, existing purchase?
If you can’t answer these for a contact, that contact doesn’t belong in the Confirmed tier. Full stop.
This is tedious. It’s also where the real legal protection lives. When someone challenges you, and in Germany someone will, your consent documentation is the whole story.
This is the step almost every English-language article gets wrong, and it’s the heart of why sakto exists. The consent rules are not the same across the German-speaking world, and treating Switzerland and Germany as one market is a real, expensive mistake. Both countries have laws called UWG (Unfair Competition Act), but they enforce them very differently.
| 🇨🇭 Switzerland | 🇩🇪 Germany + EU | |
|---|---|---|
| Law | UWG Art. 3(1)(o) [8] + revised DSG (Sept 2023) | §7 UWG + GDPR + ePrivacy |
| B2C mass mail | Opt-in required | Opt-in required (DOI effectively mandatory) |
| B2B | Meaningfully more flexible | Same rules as B2C. No B2B carve-out. |
| Existing customer exception | ✅ Yes, own similar goods, opt-out flagged | ✅ Yes but narrow, courts read “similar” strictly |
| Warning letters (Abmahnung) | ❌ Not a thing under Swiss law [4] | ⚠️ Yes, an industry. Fast, expensive. |
| Fines | Up to CHF 250’000 on the individual (revised DSG) | Injunctions + costs (typically €3’000+ per case) |
| Re-permission to non-consented contacts | 🟡 Generally OK if promo-free | 🔴 Itself illegal [6] |
Switzerland is more flexible in practice. There’s an existing customer exception, business recipients have a reduced protection interest, and one-to-one emails don’t count as “mass advertising”. Combined with the fact that Switzerland has no Abmahnung system (paid cease-and-desist warning letters), the day-to-day risk is much lower than across the border. Germany is the opposite. Every uninvited advertising email is against the law, DOI is effectively required, and consent has to name which company and which products it covers [5].
If your list includes contacts from other EU countries, GDPR still applies uniformly. If it includes US contacts, CAN-SPAM applies (much softer, no opt-in requirement, just opt-out). If it includes Canadian contacts, CASL applies (strict, similar to GDPR).
Once you know which contacts you can legally re-permission, the mechanics are simple and boring on purpose:
| Day | What happens |
|---|---|
| Day 0 | Re-permission email: “Do you still want our emails?” |
| Day 1 | One gentle reminder to anyone who didn’t click |
| Day 3 | Non-responders auto-move to suppression. Done. |
Short window. Clean exit. Works identically in Brevo, Klaviyo, ActiveCampaign, Mailchimp. The tool doesn’t matter, the three-day window and the automatic removal do.
Some senders prefer a longer sequence: 3 emails over 10 to 14 days. That works too. The key is that non-responders end up automatically suppressed, not sitting in your active list gathering dust.
English only. German versions come in a follow-up post because the legal nuances deserve their own space.
All three follow the same rules. Clear sender identity, explicit purpose statement, one-click unsubscribe, link to your privacy policy, and no promotional content dressed up as re-permission.
🟢 Template A – Short and warm
Best for engaged contacts with thin formal consent
Subject: Still want to hear from us? Preview: One quick click keeps you on the list.
Hi [First name],
We’re tidying up our list so we only email people who want to hear from us. If that’s you, click below and nothing changes. If we don’t hear back, we’ll quietly stop.
[Confirm my subscription]
Thanks, [Sender], [Company]
[Privacy policy] · [Unsubscribe]
- 🇨🇭 Compliant
- 🇩🇪 Only for contacts with an existing consent basis
🟡 Template B – Longer, with reasoning
Best for existing customers you want to re-anchor
Subject: A quick note about your subscription Preview: We’d like to keep sending you [useful thing], with your permission.
Hi [First name],
You’re getting this because you [bought from us / signed up] a while ago. We take permission seriously, so we’re checking in.
Confirm below and you’ll keep getting: –
- [Concrete non-promo value point]
- [Concrete non-promo value point]
- [Concrete non-promo value point]
Do nothing and you’ll come off the marketing list automatically.
[Yes, keep me subscribed]
[Sender], [Company] [Privacy policy] · [Unsubscribe]
- 🇨🇭 Strong fit for the existing customer exception
- 🇩🇪 Only with a genuine prior consent basis. Keep value points informational, not sales-y.
🔴 Template C – Transactional-style double opt-in
Best for anything touching Germany. The safest option.
Subject: Please confirm your subscription Preview: Confirm your email to complete your request.
Please confirm you want to receive emails from [Company] by clicking below.
[Confirm]
If you didn’t request this, ignore this email.
[Company legal name, address] [Privacy policy] · [Unsubscribe]
- 🇨🇭 Compliant and conservative
- 🇩🇪 The only style I’d send anywhere near a German list. No logo. No welcome line. No slogan. If in doubt, make it plainer [6].
Here’s a mistake I’ve watched people make more than once. They clean the list, feel triumphant, and immediately send at full cleaned volume the next day. If your domain has been quiet or your reputation took a hit from the dirty list, that sudden jump looks exactly like a spammer just starting to send, and the email providers slow your mail down anyway. All that cleanup work, wasted.
Ramp up instead. Over about four weeks, start with your most engaged contacts (this is where Step 2 pays off) at low volume and increase step by step.
| Week | Who you send to |
|---|---|
| Week 1 | Most engaged 25% only |
| Week 2 | Most engaged 50% |
| Week 3 | Most engaged 75% |
| Week 4 | Full cleaned list |
Three numbers to watch daily:
- 🎯 Bounce rate under 2% (hard bounces near zero)
- 🎯 Complaint rate under 0.1%
- 🎯 Send pattern steady, not spiky
And monitor at the source, not only in your email tool’s dashboard:
- Google Postmaster Tools v2 (v1 retired Oct 2025)
- Microsoft SNDS (dashboard for Outlook and Hotmail)
- Yahoo Sender Hub Insights (launched Oct 2025)
These first-party tools show problems 24 to 48 hours before your email tool does.
Cleanup is what you do when things went wrong. A sunset policy is what you set up so they don’t go wrong again. It’s an automated system that removes inactive subscribers before they hurt you.
How it works:
- Someone stops opening or clicking for X days
- They get a short re-engagement sequence (2 or 3 emails over 10 to 14 days)
- If they engage, they go back to active
- If they don’t, they get moved to suppression automatically
Typical inactivity thresholds:
- Daily senders: 60 to 90 days of no engagement
- Weekly senders: 90 to 180 days
- Monthly senders: 180 to 365 days
The exact number depends on your sending cadence and buying cycle. B2C consumables might sunset after 90 days. B2B software with annual purchase cycles might wait 365 days. The rule: whatever your natural buying cycle is, plus some cushion.
Exceptions worth building in:
- Recent customers: if someone bought last month, they haven’t disengaged, they’re just busy. Extend their window.
- High-value accounts: VIPs, enterprise clients. Handle personally, not automatically.
- Known seasonality: ski shop customers go quiet in July. Don’t sunset them for it.
Manual sunsetting always gets skipped under pressure. Automate it as a workflow in your email tool, and the dead weight never accumulates in the first place.
When someone unsubscribes, hard-bounces or fails re-permission, do not delete them. Suppress them.
Why suppression beats deletion:
- Proves you honoured their opt-out (required by GDPR)
- Prevents accidental re-adds through imports or integrations
- Keeps your unsubscribe history for audits
- Under German law, keeping a Sperrliste (suppression list) is a legitimate legal interest
A suppression list is not a “do not send” folder inside one campaign. It’s a global list applied across every campaign, every workflow, every tool. If you use multiple sending tools, the suppression list has to sync across all of them.
Only remove someone from suppression when they explicitly opt back in themselves. Never through an automated re-add.
If your email tool has already suspended your account, the order of operations changes. Panic-cleaning at this point makes things worse.
Step by step:
- 1. Do not send anything. Not a test, not a transactional, not an apology email. Silence.
- 2. Read the suspension notice carefully. What specifically triggered it? Bounce rate? Complaints? Trap hits? The recovery depends on the cause.
- 3. Contact the email tool’s support. Ask what they need. Most will give you a checklist.
- 4. Verify the full list before doing anything else. Non-negotiable.
- 5. Segment aggressively. Only the most engaged 10 to 20% should be in the first send.
- 6. Rebuild trust one send at a time. Start smaller than you think. 500 addresses. Then 1,000. Then 2,500.
- 7. Watch Postmaster Tools daily. You need to see reputation recovering before you scale.
- 8. Consider warming a subdomain. If your main domain reputation is destroyed, sending from updates.yourdomain.com (properly authenticated) gives you a cleaner starting point.
Recovery takes weeks, sometimes months. There’s no shortcut. Domain reputation is like credit: easy to damage, slow to repair.
Different email tools handle unengaged contacts differently. Know your tool’s rules.
Brevo:
- Suspends accounts with high bounce rates (>5% total, >2% hard)
- Auto-suppresses hard bounces after the first one
- Charges by monthly send volume, not by contacts, so keeping dormant contacts isn’t as expensive as with others
- The {{doubleoptin}} variable doesn’t work in raw HTML templates. Use a Brevo landing page instead.
Klaviyo:
- Charges by “active profiles”. Dormant contacts still count against your bill. Suppression removes them from the count.
- Sunset policy is a financial decision as much as a deliverability one.
- Native segments for engaged/unengaged make setup easy.
Mailchimp:
- Similar contact-based pricing to Klaviyo
- Auto-cleans unsubscribes but not inactive contacts
- Sunset policy has to be built manually via automations
ActiveCampaign:
- Charges by contact
- Suspends accounts with sustained deliverability issues, not immediately
- Segmentation is powerful, use it aggressively
Whatever tool you use, know its specific gotchas before you start.
Cleanup isn’t a one-off. Set the guardrails before you close the project:
- ✅ Tag the source of every new contact
- ✅ Capture IP and timestamp at sign-up (your legal proof)
- ✅ Quarterly hygiene reviews (monthly if you send to 50k+)
- ✅ Written import policy: no list enters your database without verification and a consent check first
- ✅ Sunset policy in place (see above)
- ✅ Double opt-in on every signup form
- ✅ Honeypot fields and reCAPTCHA to block bot signups
Get this right once and you never repeat this cleanup.
Sometimes cleanup is unnecessary or counterproductive. Skip it if:
- Your list is under 1,000 contacts and everyone is engaged. Not worth the effort.
- Your list is brand new (less than 6 months). Decay hasn’t set in yet.
- Your metrics are already excellent (bounce <1%, complaints <0.05%, opens above your industry benchmark). Don’t fix what isn’t broken.
- You’re mid-launch for a big campaign. Don’t destabilise sending in the middle of a promo. Wait until after.
Cleanup is a tool. Use it when you need it, skip it when you don’t.
Twelve mistakes I see over and over:
| ❌ Don’t | ✅ Do |
|---|---|
| Email non-consented German contacts to “ask permission” | Suppress them. It’s illegal to ask. |
| Buy or rent lists | Grow organically. Always. |
| Send at full volume right after cleanup | Warm up over 4 weeks |
| Trust catch-all verdicts blindly | Segment and test in small batches |
| Treat CH and DE as the same market | Split by jurisdiction |
| Skip consent documentation | Capture source, timestamp, IP, method |
| Keep unengaged contacts “just in case” | Suppress them. They hurt your good subscribers. |
| Put logos or slogans in a DOI email | Keep it as plain as a password reset |
| Delete instead of suppress | Suppress always. Keep the audit trail |
| Do this once and forget | Quarterly reviews, always |
| Skip DMARC | Publish DMARC. Start at p=none. |
| Rely on open rates alone | Track clicks too, especially post-Apple MPP |
Once cleanup is done, keep watching. Set up a simple dashboard with these metrics.
Daily during warm-up, then weekly:
- Bounce rate (target: <2%, aim for <1%)
- Complaint rate (target: <0.1%, hard ceiling: 0.3%)
- Unsubscribe rate (target: <0.5% per campaign)
- Open rate (trend over time, not absolute)
- Click rate (more reliable than opens post-Apple MPP)
Weekly:
- Google Postmaster Tools domain reputation
- Microsoft SNDS colour status (green/yellow/red)
- Yahoo Sender Hub inbox delivery rate
- DMARC pass rate (should be 99%+ once set up correctly)
Monthly:
- List growth vs list decline (net new active contacts)
- Sunset flow performance (how many going to suppression)
- Consent documentation coverage (% of contacts with full audit trail)
- Verification budget spent vs list health improvement
If any of these move in the wrong direction for 2 weeks straight, investigate immediately. Small problems become big ones fast.
- ✅ Diagnose the damage. Baseline all metrics before you touch anything.
- ✅ Segment by engagement (Active, Recent, Cool, Cold, Dormant).
- ✅ Verify the whole list (I use Bouncer, EU-hosted).
- ✅ Audit consent: source, timestamp, IP, method.
- ✅ Split by jurisdiction. CH ≠ DE.
- ✅ Sort into Confirmed / Re-Permission / Parked.
- ✅ Only re-permission contacts you may legally re-permission.
- ✅ Run Day 0 / Day 1 / Day 3, auto-suppress non-responders.
- ✅ Use plain, promo-free confirmation for anything DE-facing.
- ✅ Warm up over 4 weeks, watch bounces <2%, complaints <0.1%.
- ✅ Monitor Postmaster v2, SNDS, Yahoo Sender Hub.
- ✅ Set up SPF, DKIM and DMARC properly if not already done.
- ✅ Build a sunset policy so this doesn’t happen again.
- ✅ Suppress, never delete.
- ✅ Set quarterly hygiene reviews. Decay never stops.
Inherited a mess? Open rates quietly dropping? This is what we do at sakto. We handle the diagnosis, the verification, the jurisdiction split, the re-permission build, the warm-up and the sunset policy setup, so you come out the other side with a smaller, healthier, legally sound list that reaches the inbox.
sakto is a Swiss email marketing agency, Brevo-first, built for e-commerce and B2B senders who want their email to work and stay on the right side of Swiss and German law.