AU Cold Outreach (Spam Act compliant)
Build a Spam Act 2003-compliant B2B cold email outreach system. Handles the express-vs-inferred consent decision tree, mandatory sender-ID and unsubscribe requirements (functional 30+ days, honoured within 5 business days), and the burden-of-proof record-keeping. Produces the 4-touch sequence (connection, value, light CTA, graceful close) plus compliance checklist per send.
Consent audit → sequence design (4 touches) → per-email compliance checklist → segment-specific copy patterns (professional services, trades, healthcare, hospitality, tech, retail) → record-keeping for 3+ years.
When to use
Triggers:
- "Write cold emails for [segment]" / "Draft a B2B outreach sequence"
- "Help me with cold email" / "Set up outbound"
- "Is this email legal in Australia?" / "Spam Act compliance for my sequence"
- Any AU SME wanting B2B outreach with a legal / risk-aware approach
Don't fire for:
- B2C marketing (different consent rules, often express only)
- Transactional emails (receipts, confirmations — Spam Act carve-out)
- Existing-customer nurture (different rules — usually covered by inferred consent from the prior relationship)
The Spam Act 2003 in 90 seconds (AU context)
The Australian framework (enforced by ACMA) has three pillars:
- Consent. Either express (they opted in) or inferred (prior relationship, or the email address is conspicuously published for business purposes).
- Identification. Every email clearly identifies the sender (legal name + contactable address, not just a reply-to).
- Unsubscribe. A functional opt-out mechanism; must work for at least 30 days; unsubscribes honoured within 5 business days.
Penalties: up to $2.2M AUD per day for serious or repeated breaches. The burden of proof that you had consent is on the sender — so records matter.
Inferred consent is the key difference from CASL (Canada) and makes AU B2B cold email workable. But "inferred" has limits. You can't infer consent from:
- A personal Gmail / Hotmail / Outlook address
- A generic info@ / sales@ address if the business owner hasn't published it for the specific purpose you're emailing about
- A LinkedIn profile unless the address is listed in the profile's public contact fields
- A scraped list from a broker — "this address was on a database" is not inferred consent
Inferred consent you can rely on:
- The specific individual's work email listed on their company's website, adjacent to their role, in a context relevant to your outreach (e.g. a GM of Operations emailing a CFO about operations software)
- An email published in a directory / association membership list in the context relevant to your outreach
- A prior genuine interaction (conference, webinar, mutual connection) that the recipient would recognise
Workflow
Step 1 — Target definition + consent audit
Before drafting a single message, lock down:
- Target segment. Specific: "Independent Australian accounting firms with 3–20 staff, serving SME clients, with a public email for the principal or office manager".
- Consent model per prospect type. For each source, classify:
- Express (they gave you the email for this purpose)
- Inferred — strong (individual email + relevant public context)
- Inferred — weak (generic mailbox, role-based, tangentially relevant)
- No consent (scraped, unrelated)
Only emails in the first three categories go into the sequence. No-consent prospects get nothing.
- Record the consent basis per prospect. One column on the list:
consent_type | source_url | source_date. This is your burden-of-proof record.
Step 2 — Sequence design (4 touches)
Standard AU B2B cold sequence:
Touch 1 — Connection (Day 0)
- Opens with a specific hook tied to the prospect's public context (not "I saw your company online")
- Frames the sender's relevance in one sentence
- A small, soft question — not a meeting CTA
- Clear sender identification
- Unsubscribe link at the foot, plus legal name + physical address (even if PO Box)
- Target length: 60–90 words
Touch 2 — Value touch (Day 3)
- References Touch 1 without guilt-tripping ("following up" is fine, "I haven't heard back" is not)
- Adds one piece of genuine value (resource, observation, data point specific to their world)
- No ask at all, or the same small question
- Target length: 70–100 words
Touch 3 — Light CTA (Day 7)
- Only now introduces a meeting / call CTA
- Offers two concrete times OR a scheduler link — not both
- Acknowledges a "no" gracefully and offers a gentler alternative
- Target length: 60–80 words
Touch 4 — Graceful close (Day 14)
- "Last email from me unless you'd like to continue"
- No manipulative last-chance framing
- Leaves the door open for future outreach after 6+ months
- Target length: 40–60 words
Step 3 — Every-email compliance checklist
Every individual send, regardless of touch number, must include:
☐ Sender legal name (not a brand, a legal entity)
☐ Sender ABN (optional but strong)
☐ Sender physical address (can be a PO Box)
☐ Sender email identity consistent across the sequence
☐ Unsubscribe link (plain-text or HTML) — functional for 30+ days
☐ Unsubscribe mechanism in place: ≤ 5 business days to remove
☐ No deceptive subject line
☐ No deceptive "from" name
☐ Consent basis recorded on the list for this recipient
☐ Suppression list checked (don't email past-unsubscribers)
If any box is unticked, don't send.
Step 4 — Subject line guidance
Good AU B2B cold subject lines share traits:
- Specific, not salesy
- Mention either the prospect's context or a tangible value — not both
- 5–9 words, lowercase
- Natural — a human would actually write this to a stranger
Good examples:
Quick thought on [specific thing they do][Prospect's competitor/peer] mentioned [topic]3 min question on [specific workflow]
Prohibited:
- ALL CAPS
FREE/URGENT/LIMITED TIME/ACT NOW- Fake re: or fwd: prefixes
- Emoji in the subject (noise; some spam filters weight against)
Step 5 — Copy patterns by segment
Different segments respond to different framings. Rough defaults:
| Segment | Opener pattern | CTA pattern | |---|---|---| | Professional services (accountants, lawyers, consultants) | Specific observation about their practice | "Worth 15 min to compare notes?" | | Trades / construction | Direct mention of an operational pain | "Want to see how [peer] does it?" | | Healthcare / NDIS | Compliance or documentation angle | "Happy to send a 1-pager — interested?" | | Hospitality | Seasonal / event-specific angle | "Keen to explore if it fits your Q[X]?" | | Tech / SaaS founders | Technical detail, not business speak | "Fancy a 20-min architecture convo?" | | Retail / ecommerce | Revenue or conversion angle | "Want the numbers on how [peer] moved the needle?" |
Don't use "I help [industry] with AI" openers. Don't use "What if I told you..." Don't use synthetic urgency.
Output format
For each campaign, produce:
- Sequence document — 4 email drafts (Touch 1–4), with merge tags for personalisation
- Compliance checklist — one-page PDF / markdown, tick-and-sign format, kept with the campaign's audit trail
- List prep CSV — columns:
email, first_name, last_name, company, role, consent_type, source_url, source_date, touch_1_sent, touch_2_sent, ... - Subject line bank — 5 variants per touch for A/B testing
- Escalation paths — if a prospect replies positively, what happens next (handoff to the operator, next-step sequence, etc.)
Record-keeping requirements
For every send, keep:
- Timestamp of send
- Recipient email
- Template version used
- Unsubscribe link used
- Consent basis (copied from the list)
Keep these records for at least 3 years. ACMA can and does request proof during investigations.
What this skill does NOT do
- Send the emails. Your ESP does (Mailchimp, ActiveCampaign, Brevo, HubSpot, Instantly, Smartlead, etc.). The skill produces the content + compliance metadata.
- Source the list. Your research workflow does. The skill does not scrape, purchase, or enrich lists.
- Manage deliverability. Domain warming, SPF/DKIM/DMARC, IP reputation — separate concerns.
- Legal sign-off. For anything contentious — targeting regulated industries, claims that could be challenged, high-volume campaigns to large lists — have a privacy or commercial lawyer review before sending.
Tier access
Base. Cold outreach is a core growth lever for most AU SMEs. The skill is intentionally accessible — and the compliance piece is risk-reducing rather than scope-expanding. Pro-tier members get the additional variant-by-segment library; Partner-tier members get a review cycle on their actual sequences before send.
Related skills
thl-linkedin-outreach-personaliser(internal, admin-only) — different channel, tighter voice rulesseo-audit— complementary inbound workflowclaude-4-7-extended-thinking-for-sme— use extended thinking for "should I email this prospect or not" edge cases on consent
References
- →Draft a cold email sequence for independent AU accounting firms.
- →Is this email I'm about to send legal under the Spam Act?
- →Set up outbound for our bookkeeping software — target 3–20 staff SMEs.
- →Help me unsubscribe someone who replied asking to stop.
Source
official
Author
Tech Horizon Academy
Version
1.0
Complexity
Compatible With
Prerequisites
- Target segment definition
- Prospect list with consent metadata (or the sources to build it)
- ESP access (Mailchimp/ActiveCampaign/Brevo/HubSpot/Instantly/Smartlead)
- Legal sender name + physical address
Best For
Tags
