Manage unsubscribes, bounces, and compliance

How opt-outs, suppression lists, Do Not Disturb, and re-subscribes work, and the CAN-SPAM and GDPR basics every sender should know.

Unsubscribes and bounces aren't just deliverability signals — they're also the mechanism through which you stay compliant with email marketing law. This article covers how opt-outs and suppression work in the platform, plus the CAN-SPAM and GDPR basics that shape why the system works the way it does.

How an unsubscribe works

Every marketing email includes a working, one-click unsubscribe link automatically. When a contact clicks it:

  • They're recorded as opted out of marketing email. This is tracked at the contact level, not just for that one email.
  • They stop appearing in future campaign and workflow sends automatically — you don't maintain an exclusion list by hand.
  • The event fires through the Email Events workflow trigger with an "Unsubscribed" filter, so you can build automations off it: tag the contact, remove them from other active nurture workflows, or notify a team member if it's a high-value contact worth a personal follow-up.

Unsubscribing is specific to marketing communication. Depending on how your account separates message types, a contact can still be eligible for genuinely transactional messages (receipts, appointment confirmations, password resets) even after opting out of promotional email — those categories are legally and functionally distinct.

Suppression lists and bounces

A suppression list is the set of addresses your account won't send marketing email to, regardless of what list or workflow would otherwise include them. Contacts land on it through:

  • An explicit unsubscribe click.
  • A spam complaint (the "Complained" Email Event) — this is treated more seriously than an unsubscribe, since it signals active harm to your sender reputation, not just disinterest.
  • A hard bounce, once you or an automation has processed it — continuing to send to a permanently invalid address helps no one and actively damages deliverability for everyone else on your list.

Suppression is different from deleting a contact. A suppressed contact still exists in your CRM with full history — they're just excluded from future marketing sends. This matters for compliance: you need to retain the record of why someone was suppressed (their opt-out request itself is a record you may need to produce).

Do Not Disturb (DND)

DND is a broader flag than marketing-email suppression — depending on how it's configured, it can also affect SMS and other channels, not just email. A contact can be set to DND:

  • Automatically, from an unsubscribe or spam complaint.
  • Manually, by a team member who wants to stop all outreach to that contact for any reason (a personal request, a legal hold, an internal decision).
  • Through a workflow action you build yourself.

Check a contact's DND status before assuming a delivery problem is technical — a contact silently not receiving anything, campaign or workflow, with no bounce or error showing, is very often simply flagged DND.

Re-subscribing a contact

Clearing DND or removing suppression is possible, but treat it carefully:

  • If a contact unsubscribed deliberately, re-adding them to your list without a fresh, explicit opt-in is both a poor practice and a compliance risk — you no longer have valid permission to email them.
  • If suppression happened due to a hard bounce and the contact has since provided a corrected email address, that's a legitimate case for re-enabling sends to the new address (the old one should generally stay suppressed).
  • If DND was set manually by mistake (a team member toggled the wrong contact), clearing it is reasonable once you've confirmed the mistake.

When in doubt, the safer path is a fresh opt-in — a new form submission, a checkbox confirmation, something that creates a clear record of renewed consent — rather than silently re-enabling sends to someone who previously opted out.

CAN-SPAM basics

CAN-SPAM is the U.S. federal law governing commercial email. The core requirements it holds you to:

  • Don't use false or misleading header information. Your From Name, From Address, and Reply-To must accurately reflect who's sending the message.
  • Don't use deceptive subject lines. The subject must reflect the actual content of the message.
  • Identify the message as an ad, if it is one — this doesn't require literal words like "Advertisement," but the message shouldn't be disguised as something it isn't.
  • Include your physical postal address. This is a real requirement, not a suggestion — most email footers include it for exactly this reason.
  • Provide a clear, working opt-out mechanism, and honor opt-out requests within 10 business days (the platform processes them immediately, well inside that window).
  • Monitor what others do on your behalf. If a partner or affiliate sends email for your business, you're still responsible for their CAN-SPAM compliance.

Penalties for violations are per-email, not per-campaign, which is why even a small compliance gap can become expensive at scale.

GDPR basics (if you have EU contacts)

If any of your contacts are in the EU (or you're a business operating there), GDPR adds requirements beyond CAN-SPAM:

  • Consent must be affirmative and specific. A pre-checked "yes, email me" box doesn't count — the contact has to actively opt in, and ideally you can show a record of when and how they did.
  • You need a lawful basis for processing their data, which for marketing email is almost always consent (as opposed to, say, "legitimate interest," which is a much higher bar to justify for cold outreach).
  • Contacts have a right to access, correct, or delete their data — not just unsubscribe from email, but request full removal of their record.
  • Double opt-in is strongly recommended for EU contacts specifically, since it creates a clear, timestamped record of consent that satisfies GDPR's documentation expectations far better than a single-click signup.

GDPR compliance is a bigger topic than this article covers in full — if you regularly market to EU residents, it's worth a proper legal review beyond following these basics.

What done looks like

You can explain the difference between an unsubscribe, a suppression, and a DND flag; you know where to check a contact's status when a delivery question comes up; and your signup flow captures consent in a way you could actually produce a record of if asked.

Frequently asked questions

Does an unsubscribe from one campaign apply to all future email, or just that campaign?

It applies to future marketing email generally, not just the campaign it came from. The platform doesn't ask a contact to unsubscribe separately from every campaign or workflow — one click opts them out of promotional email as a category.

Is a hard bounce the same as an unsubscribe for compliance purposes?

No. A bounce means the message couldn't be delivered; an unsubscribe means a real person actively declined future email. Both result in suppression from future sends, but only the unsubscribe reflects an actual preference — a bounce is a data-quality issue, not a consent issue.

How long do I have to honor an unsubscribe request under CAN-SPAM?

Ten business days is the legal maximum. In practice, the platform processes unsubscribe clicks immediately, so this is rarely something you need to actively manage — it matters most if you're handling opt-out requests manually, such as ones that arrive by reply email instead of the unsubscribe link.