Cold email for nonprofits: reaching donors and partners without feeling like spam
Nonprofits can email people who've never given before — but the legal rules and the ethical bar are both stricter than most fundraising teams assume.
By David Lara, Founder
Founder-reviewed ·How we research and correct articles
A nonprofit emailing a stranger to ask for money sits in different territory than a SaaS company emailing a stranger to sell software — both legally and ethically — and treating them the same is how well-meaning development teams end up burning trust they can’t afford to lose. This isn’t a reason to avoid outbound email. It’s a reason to be more careful about who you’re reaching and how, not less.
Three outreach targets that are actually appropriate
Corporate sponsorship and CSR contacts. Companies publish CSR budgets, sponsorship programs, and giving priorities specifically so nonprofits can find and reach the right person. Emailing a named CSR or community-giving contact about a specific program that matches their stated priorities isn’t a cold ask in any uncomfortable sense — it’s exactly the outreach that role exists to receive.
Foundation and grant program officers. Program officers publish their focus areas, past grantees, and application windows precisely to be found by organizations that fit. A tightly targeted email — referencing a specific past grant they’ve made in your space — is closer to a qualified inquiry than a cold pitch.
Warm-adjacent donor prospects, sourced publicly. People who’ve given to causes in the same space, board members of comparable organizations, or attendees of a public event your organization also participated in are a meaningfully different audience than a purchased list of random consumer emails. The line that matters: you can point to a specific, public reason this particular person might care, not just a demographic guess.
The legal picture is stricter than most fundraising teams assume
There’s a common assumption that nonprofit email is exempt from spam law because it’s not “commercial.” That’s not accurate. The CAN-SPAM Act doesn’t carve out a blanket nonprofit exemption — the FTC has been explicit that CAN-SPAM doesn’t draw a line between commercial and nonprofit senders the way people expect. What is treated differently is the type of message: a receipt or thank-you for an existing donation is a transactional message and handled more leniently, but a solicitation email asking someone who hasn’t given before to donate is functionally treated like any other outreach email — it needs an honest subject line, a real physical address, and a working opt-out that gets honored.
If your donor or partner list includes anyone outside the country your organization is based in, the picture gets stricter, not looser. Nonprofits sending to EU-based donors or partners have a narrower legitimate-interest basis under GDPR than commercial senders do in some interpretations, and Canadian recipients fall under CASL, which has its own strict consent requirements. None of this is a reason to avoid international outreach — it’s a reason to know which rulebook applies before the first email goes out. How GDPR, CASL, and CAN-SPAM compare is worth reading in full before building a cross-border list.
There’s a practical reason to take this seriously beyond the legal exposure: nonprofits depend on trust in a way few commercial senders do. A donor who feels spammed doesn’t just unsubscribe — they may talk about it, and a nonprofit’s reputation with donors, grant makers, and partner organizations is a smaller, more interconnected world than a typical commercial market. The cost of getting this wrong compounds in a way it doesn’t for a company selling software to a stranger who’ll never think about the vendor again either way.
Before a nonprofit's first outreach send
Write down the specific, public reason for each contact
A published CSR priority, a stated grant focus area, a public affinity signal — not just a role or a demographic. If there's no specific reason, that contact doesn't belong on the list yet.
Build the suppression list before the first send, not after
Anyone who has previously asked not to be contacted, unsubscribed from a newsletter, or explicitly declined needs to be excluded from day one — not caught after a complaint.
Separate CSR contacts, grant officers, and donor prospects
Each group has a different reason for the email and a different appropriate ask. One undifferentiated list flattens that distinction and reads as generic to all three.
Cap volume and check the unsubscribe link actually works
Send a real test to confirm the opt-out link functions before the list goes out, and keep monthly volume modest enough that a small team can review replies and honor requests promptly.
What principled outreach actually looks like in practice
The floor is the same regardless of legal classification: identify your organization clearly in the first line, be honest about how you found the recipient, make the ask specific rather than a generic “support our mission,” and put a working one-click unsubscribe in every message — then actually honor it immediately, not at the end of a batch process. A development team that treats an unsubscribe request as a suggestion rather than a hard stop is the fastest way to turn a lukewarm prospect into someone who tells others the organization spams people.
Volume discipline matters more here than almost anywhere else in outreach. A monthly send of 40 carefully chosen CSR contacts and program officers, each with a real reason for the email, does more for a fundraising pipeline than a blast to 4,000 scraped addresses ever will — and it does it without the domain damage a low-relevance blast causes for every other email the organization needs delivered, including the newsletter and receipts your actual donors rely on.
Common questions about nonprofit outreach email
Is it legal for a nonprofit to email someone who's never donated before?
In most cases yes, but it isn't exempt from spam law just because it's a nonprofit. The message needs an honest subject line, a real sender address, and a working unsubscribe link, the same as any other outreach email — and cross-border sends add GDPR or CASL requirements depending on the recipient's country.
Should a nonprofit ever buy a donor prospect list?
No. Purchased consumer lists convert poorly for donation asks specifically, and sending to a list with no real relevance signal puts the sending domain at risk for every other email the organization needs delivered, including receipts and program updates to actual donors.
What's different about emailing a grant officer versus a general donor?
Program officers publish their focus areas and application windows specifically to be found, which makes a well-targeted email closer to a qualified inquiry than a cold ask. A general donor prospect has no equivalent invitation, so the bar for relevance and specificity should be higher, not lower.
The operational side nonprofits usually underinvest in
Development teams are often small, and the same one or two people handle donor emails, grant outreach, and the newsletter — all from one sending domain. That makes deliverability discipline more important, not less: a low-relevance solicitation blast can quietly damage the inbox placement of the newsletter and receipt emails your existing donors actually expect to receive. A domain that’s properly warmed up, a suppression list that’s actually enforced, and separate segments for CSR contacts, grant officers, and donor prospects — rather than one undifferentiated list — protect the organization’s ability to reach the people who already support it while it reaches for the people who might.
Consider a mid-size land trust or arts organization running its own outreach: one coordinator maintains the monthly newsletter to 6,000 existing supporters, sends receipts for every donation as it comes in, and wants to start reaching 50 corporate CSR contacts a month about a new sponsorship tier. If that CSR push goes out from the same under-managed sending setup as the newsletter, a spike in low-reply outreach can quietly erode the sender reputation that keeps the newsletter and receipts landing in inboxes rather than promotions tabs or spam folders. Splitting those streams — with the CSR list warmed up and monitored separately, on its own cadence — protects the channel that 6,000 people are already relying on while the organization builds a new one.
That’s the case for treating deliverability as infrastructure rather than an afterthought, even for an organization with no marketing department and no dedicated IT staff. The tooling doesn’t need to be complicated to matter — it needs to exist at all, which is often the actual gap at organizations running fundraising email off whatever was set up years ago and never revisited. A coordinator wearing five hats doesn’t have time to manually track which contacts already asked not to be emailed, or to notice a slow decline in newsletter open rates until donations start dipping months later — the protection has to be built into the sending system itself, not into someone’s memory of who complained last quarter.
Run outreach an organization can stand behind
Norbelys includes the pieces this kind of careful outreach actually needs on every plan: warmup so a nonprofit’s sending domain builds real reputation before a solicitation push, enforced suppression lists so an opt-out is honored instantly and permanently, working one-click unsubscribe by default, and audience segments to keep CSR contacts, grant officers, and donor prospects in their own lists instead of one undifferentiated blast. The Starter plan fits a small development team running its first structured outreach push without the volume or budget of a commercial sales org. See the plans and start sending outreach your donors and partners would recognize as coming from an organization that respects them.