Skip to content
← BlogCompliance6 min read

Why you'll never accidentally email someone who already said no

One unsubscribe, one bounce, one manual exclusion — and that address is blocked from every campaign in the workspace, checked again at the moment each message sends.

By David Lara, Founder

Founder-reviewed ·How we research and correct articles

Someone unsubscribes from your campaign in March. A teammate builds a new list in June from the same CRM export, and that person is back in an inbox three months later — because the unsubscribe lived in one campaign’s settings, not anywhere the new list-build checked. That’s the single most common way outbound teams damage trust with people who already told them, explicitly, to stop.

The fix isn’t “be more careful.” It’s a suppression list that applies everywhere, automatically, without anyone remembering to check it.

What lands on the list, without you doing anything

Four things add an address to suppression the moment they happen, no manual step required:

  • A one-click unsubscribe. The standard header-based mechanism Gmail and Yahoo require — click, done, suppressed.
  • An opt-out written into a reply. “Please remove me,” “stop emailing me,” or anything functionally equivalent gets caught the same way a formal unsubscribe does, even though it arrived as an ordinary message rather than through the unsubscribe link.
  • A hard bounce. An address that no longer exists gets suppressed permanently — there’s no scenario where continuing to send to a dead address helps anyone, and every attempt is a small hit to sender reputation.
  • A manual exclusion. Add a specific address, a list, or an entire domain to a block list yourself — existing customers, a competitor’s domain, anyone who shouldn’t be contacted regardless of a future import.

None of those require a teammate to remember to cross-reference a spreadsheet before the next send. They’re recorded once, against the person’s record, and stay there.

The part that actually matters: checked at send time

A list of suppressed addresses is only useful if something checks it before a message goes out — and the moment that check happens matters as much as the list itself. Norbelys checks suppression status at the moment each individual message is about to send, not just once when a campaign was first built.

Manual cross-checkingNorbelys suppression
Applies across every campaign
Checked at send time, not just import time
Catches opt-outs written into a reply
Auto-adds hard bounces
Requires someone to remember to run it

That distinction is what actually protects you. An unsubscribe that happens on Monday needs to block a sequence step that fires Thursday, even though the audience was defined the previous week — a check that only ran once, at build time, has no way to catch what changed since.

Why cross-campaign matters as much as cross-time

A suppression list that only applies within one campaign solves half the problem. The person who unsubscribed in Q1 doesn’t stop being suppressed just because a different campaign, built by a different teammate, pulls a fresh list in Q3 — the exclusion follows the address, not the campaign it originated in.

How an address gets suppressed, and what happens after

  1. The trigger happens

    A one-click unsubscribe, an opt-out written into a reply, a hard bounce, or a manual exclusion you add yourself.

  2. It's recorded against the address

    Not against one campaign — against the person's record in the workspace, so it applies regardless of which campaign or list touches them next.

  3. Every future send checks it first

    Any campaign, sequence, or step that would otherwise reach that address is checked against suppression at the moment the message is about to go out.

  4. The send is skipped, not queued

    A suppressed address doesn't get delayed or held for review — it's simply excluded from that send, the same way it will be from every send after it.

The compliance case, plainly

CAN-SPAM requires honoring an opt-out within a fixed window and never re-adding that address to a list afterward. GDPR treats a withdrawal of consent the same way — once given, it has to stick, not just be recorded somewhere nobody checks before the next campaign. A per-campaign checkbox technically satisfies neither: the point of the rule is that the opt-out follows the person, not the list they unsubscribed from. The regulatory detail varies by jurisdiction, but the requirement is consistent — an opt-out has to hold everywhere.

Suppression, answered directly

Does suppression apply across every campaign, or just the one someone unsubscribed from?

Across every campaign in the workspace. Suppression is recorded against the person's record, not against a single campaign, so a future campaign built from a different list still excludes them.

What if a reply says 'unsubscribe' instead of using the unsubscribe link?

It's caught and treated the same way — the address is suppressed and any active sequence stops, whether the opt-out came through the formal one-click mechanism or was written into an ordinary reply.

Can I manually add addresses or entire domains to a block list?

Yes. Manual exclusions work alongside automatic suppression — add specific addresses, a list of addresses, or a whole domain, useful for existing customers, competitors, or anyone you've decided shouldn't be contacted regardless of a future import.

When exactly is suppression checked — when I build the campaign, or when it sends?

At send time, for every individual message. That's what catches an unsubscribe that happened after the campaign was built but before a later step actually fires.

The list you never have to remember to check

The best suppression list is the one nobody has to think about — no export to reconcile, no teammate to remind, no manual cross-check before a send. It’s included on every Norbelys plan and checks itself at the moment that actually matters. Start on any plan, import your list once, and stop worrying about whether someone who already said no is about to hear from you again.