A contact unsubscribes from a newsletter, but their address remains on a list prepared for an event follow-up. A CRM field says “do not email,” while an agency export was made before that change. These are not only data-cleanup problems: they can send a message after a person has asked not to receive it.
Keep suppression rules connected to the systems that build, approve, and send campaigns. The goal is to apply the person’s preference within its stated scope, preserve enough information to prevent accidental re-import, and stop a send when the current status cannot be verified.
Separate preferences from campaign targeting
A suppression record captures a preference or objection that must affect marketing use. A campaign exclusion is different: it removes an otherwise eligible person from one particular send because of audience fit, duplication, timing, or another targeting choice.
Do not use one field for both jobs. If an account has separate subscription types, channels, or brands, record which one a choice covers. UK Information Commissioner’s Office guidance explains that an opt-out may apply to a particular method or activity, while an objection may have a broader scope. Use the notice the person saw and the preference they gave to determine the scope; do not silently broaden or narrow it.
For campaign decisions, keep three states distinct:
- Suppressed: a current preference or objection blocks this type of marketing.
- Eligible: the person meets the organization’s current permission and campaign rules.
- Unresolved: the available records do not establish whether this send is allowed. Hold the record out until an owner resolves the conflict.
“Not opted in” and “not opted out” are not necessarily the same state. HubSpot, for example, distinguishes subscription statuses and lets an account manage different subscription types. Check the current preference model and applicable rules in the platform you use.
Map every place that can send or export an audience
List the systems that can create or change a marketing audience, not only the CRM and email service. Include event platforms, webinar tools, advertising audiences, customer messaging products, spreadsheets, agencies, and co-marketing partners where applicable.
For each system, document:
- the preference fields it stores and the scope each field represents;
- the identifier used to match a person, such as an email address or platform subscriber key;
- whether changes are sent immediately, on a schedule, by export, or manually;
- who can import, edit, or override the status;
- how the team checks that a preference reached the send platform; and
- what happens if a sync or identity match fails.
The identifier matters. HubSpot’s documentation says email subscription preferences are tied to an email address, while Salesforce Marketing Cloud describes suppression lists that filter subscriber keys. Those are product-specific examples, not a universal data model. Confirm what each system uses before mapping records between tools.
Set a clear rule for conflicts
Choose one system or event log as the authoritative record for each preference, then define how changes move to other systems. A CRM can own the contact relationship while the email service owns its native unsubscribe event; the process needs to preserve both facts rather than overwrite one with a stale import.
When records conflict, apply the preference that is current and relevant to the message being prepared. If the scope is unclear, or the systems cannot confirm which record is newer, pause the affected recipient or audience and ask the owner to resolve it. Never treat an ordinary audience import or a list’s presence in a campaign tool as permission to send.
Keep a limited audit trail: the preference or objection, its scope, the source and time received, the processing result, and the systems updated. Restrict access to the record. The ICO recommends retaining only the minimum information needed for a suppression list and clearly marking it so the information is not reused for the marketing the person objected to. Handle a separate deletion request under the process that applies to the request; do not assume that an opt-out and an erasure request mean the same thing.
Put a suppression check immediately before the send
Run the check after the campaign audience is finalized and again if the audience or send time changes. Include these cases:
- Apply the relevant global, channel, brand, and subscription-type preferences.
- Match records using the identifier and normalization rules approved for that platform.
- Check records added by manual import, event registration, partner transfer, or a late CRM update.
- Confirm that the sending platform has applied its configured suppression or exclusion controls.
- Save the audience version, check time, rule version, rejected-record count, and operator.
Suppression tools differ. Salesforce Marketing Cloud distinguishes suppression lists from campaign exclusion lists, even though both can filter a send audience. Map each tool’s behavior to the organization’s preference rules instead of assuming similarly named fields mean the same thing everywhere.
Use test contacts or a controlled internal preview to verify that the right categories are blocked. Do not use real opted-out contacts as test recipients. If the preference sync is delayed, the identifier match fails, or a platform cannot show what it suppressed, hold the affected send until the issue is understood.
Check vendors and shared campaigns
When a vendor or partner receives an audience, agree which party records a preference, who updates the sending system, how changes are returned, and what evidence is available before a campaign goes out. Limit transfers to the fields and records needed for the approved work. A contract does not replace operational checks: the FTC’s CAN-SPAM guidance says a business cannot contract away its responsibilities for commercial email by hiring another company to send it.
A pre-send suppression worksheet
- Campaign, channel, brand, and subscription type: ______
- Authoritative preference record and owner: ______
- Systems that can add or send audience members: ______
- Matching identifier and normalization rule: ______
- Conflict and unresolved-record rule: ______
- Sync method, expected timing, and failure alert: ______
- Suppression check time and audience version: ______
- Test record and result: ______
- Vendor or partner confirmation, if applicable: ______
- Approver and evidence retained: ______
For customer communication during a service problem, see the guide to pausing customer marketing while an issue is active. Before sharing campaign data with an agency, use the partner-access checklist.
If preferences are arriving in several tools with no clear owner, request a marketing diagnostic to review the sync and pre-send control.
Sources and scope
- UK Information Commissioner’s Office: Respect people’s preferences — channel-specific opt-outs, suppression lists, minimum information, and the difference between suppression and screening lists under UK guidance.
- U.S. Federal Trade Commission: CAN-SPAM Act compliance guide — commercial email opt-outs and responsibilities when a sender hires another company.
- HubSpot Knowledge Base: Manage your contacts’ messaging subscriptions — HubSpot subscription types, statuses, and email-address association.
- Salesforce Help: Using a Suppression List — subscriber-key suppression and how Marketing Cloud distinguishes suppression from exclusion lists.
This article describes an operational control, not a universal legal rule. Requirements vary by jurisdiction, message type, and platform. Confirm the rules for the markets and channels you use with qualified counsel. Accessed October 9, 2026.
How did this article land?
Choose one reaction. You can change it anytime.
