← Back to Blog

When AI Agents Should Not Send Email

Actus · October 6, 2026

email automationAI agentsdeliverabilitycold emailActus Agentemail marketing
When AI Agents Should Not Send Email

When AI Agents Should Not Send Email

The fastest way to ruin a domain is to let an AI agent send email without rules. The agent writes a message, blasts it to a hundred contacts, and by the end of the week your domain is flagged, your open rate is seven percent, and your replies are asking to unsubscribe. The problem is not that the agent cannot write. The problem is that nobody defined what it is allowed to send.

This guide draws clear lines. It explains when an agent should draft email for a human to send, when it can send autonomously, and when email should not be automated at all. It also covers the technical limits that will damage deliverability if you ignore them.

Actus Agent can draft email, send it through connected accounts, and run campaigns. That capability is useful only if you know when to use it and when to stop. There is no shortcut for judgment. You can delegate research and writing. You cannot delegate the decision to hit send.

When to Let an Agent Draft Only

Drafting is safe. Sending is permanent. These situations require a draft step:

The first email to a new list. You do not know how the list will react. Let the agent write the email, review it yourself, send it to ten people, and read the replies. If the replies are good, let it draft more. If the replies are confused or angry, fix the message before it reaches the rest.

Any email that references pricing, contracts, or guarantees. An agent can summarize your offer. It should not invent terms. If the draft says "we guarantee same-day delivery" and your actual SLA is 48 hours, you created a legal problem. Review before sending.

Emails to customers who already paid. An angry customer email, a refund request, or a complaint requires empathy and context an agent does not have. The agent can draft a response that pulls in order details or past interactions. A human should approve the tone before it goes out.

Anything that could be interpreted as a commitment. If the prospect asks "can you integrate with X" and the agent replies "yes," you may have promised a feature you do not have. Draft only. Let a product or sales leader confirm.

Emails where the relationship matters more than speed. High-value prospects, strategic partnerships, referral sources, or long-time clients deserve a human writing to them. Let the agent draft background research or a rough outline. The final send should come from a person.

When an Agent Can Send Autonomously

Autonomous sending works when the content is predictable, the risk is low, and the recipient expects automation:

Transactional confirmations. Order confirmations, password resets, booking receipts, and account notifications are expected to be automated. Nobody wants a person writing those by hand. The agent can send them as soon as the event happens.

Follow-up sequences on low-stakes offers. If someone downloaded a lead magnet or signed up for a webinar, a three-email nurture sequence is standard. The agent can send it as long as the unsubscribe link works and the content was reviewed once when the sequence was created.

Internal notifications. An agent that emails your team when a lead hits a score threshold, when a form is submitted, or when a report is ready is fine. Internal emails are lower risk. If the message is wrong, your team will tell you.

Re-engagement campaigns where the worst outcome is an unsubscribe. A win-back email to inactive subscribers is low-risk. They are already disengaged. If they unsubscribe, you are cleaning the list. Let the agent send.

Survey or feedback requests. After a purchase, a support ticket close, or a completed project, asking for feedback is expected. The agent can send as long as the request is polite and one-time.

When Email Should Not Be Automated at All

Some email should never come from an agent, even in draft form:

Legal disputes or threats. If a customer threatens to sue, if a vendor accuses you of breach, or if a regulator sends a demand, only a person with legal oversight should reply. Do not let an agent near it.

Termination or cancellation notices. Firing an employee, ending a partnership, or canceling a contract requires precision and empathy. A person should write it. A lawyer should review it. An agent should not touch it.

Apologies for serious failures. If your product caused data loss, if a shipment was six weeks late, or if a service outage cost the customer money, a human apology matters. An agent apology feels like a PR script.

Cold email to a purchased list. If you bought a list, you do not have consent. Many jurisdictions consider that spam. An agent that sends to a purchased list is just automating a compliance violation. Do not do it.

Emails that sound personal but are not. Messages that start "I saw your post about X" or "I loved your recent article" only work if they are true and specific. An agent that fakes personal connection damages your reputation faster than a generic pitch. Either personalize for real or stay generic and honest.

Deliverability Limits That Will Break Your Domain

An agent can send fast. Your email infrastructure cannot. Ignore these limits and your domain gets flagged:

Warm up new sending domains slowly. A brand new domain should send 10–20 emails per day for the first week, then double weekly. Sending 500 emails on day one looks like spam to mailbox providers.

Do not send to unverified addresses. Bounce rates above 5% damage sender reputation. Verify emails before you add them to a sequence. An agent that guesses info@domain or uses old lists will create bounces.

Limit daily send volume per mailbox. A Gmail or Outlook account should send no more than 200–300 emails per day. If you need higher volume, use a transactional email service or rotate multiple sending addresses.

Do not reuse the same message body across thousands of sends. Mailbox providers fingerprint content. If 10,000 emails have identical body text, they flag it as bulk. Vary the message slightly per recipient or per batch.

Honor unsubscribe requests immediately. CAN-SPAM and GDPR require opt-outs to take effect within 10 business days. Best practice is instant. If the agent keeps sending after an unsubscribe, you are breaking the law and damaging deliverability.

Monitor your sender reputation. Check Google Postmaster Tools, Microsoft SNDS, or a service like MailTester regularly. If your reputation drops, pause sending and fix the issue before resuming.

Technical Safeguards to Require

Before you let an agent send autonomously, enforce these:

A suppression list check on every send. Before the email goes out, the agent must check whether the recipient unsubscribed, bounced, or marked previous mail as spam. No exceptions.

A daily send cap per campaign. If a bug causes a loop, you do not want the agent to send 10,000 emails before you notice. Set a hard daily limit per workflow.

A human approval gate for new campaigns. The first email in a new sequence should require manual approval. Once approved, the agent can send the rest of the sequence to other recipients.

Logging of every send. Store who received which email, when, and from which mailbox. If a recipient complains, you need to prove what was sent.

An emergency kill switch. If something goes wrong, you need a way to pause all agent sends immediately, across all workflows. Build that capability before the first send.

Example: An HVAC Follow-Up Sequence

A contractor asks Actus Agent to follow up on estimates that were sent but not yet accepted. The workflow:

  1. Pull all estimates sent in the last seven days with no reply.
  2. Draft a short follow-up: "Your AC replacement estimate is attached. If the number is higher than expected, the single-stage option saves $2,400 and most neighbors choose it. Let me know if you want that line only."
  3. Agent sends automatically only if: the recipient is already on the estimate list, they have not unsubscribed, their address has not bounced, and fewer than 50 emails were sent today.
  4. If any condition fails, the agent drafts the email and saves it for manual review instead of sending.
  5. After three days, if there is no reply, the agent drafts a second follow-up and queues it for approval. It does not send the second one autonomously.

That is a safe automation. The first touch is low-risk and expected. The second touch requires review because persistence can feel like pressure.

What Good Email Automation Looks Like

When an agent handles email well, these outcomes are visible:

  • Unsubscribe rates stay under 0.5% per send. People opt out because they are not interested, not because the email was rude or broken.
  • Replies are on topic. The recipient responds to the actual offer or question, not with "why are you emailing me" or "take me off your list."
  • Bounce rates stay under 2%. Most addresses are valid. The few bounces are because someone changed jobs, not because the list was scraped.
  • The sender's reputation holds steady or improves. Postmaster Tools shows consistent delivery to inbox, not spam folder.
  • A person can review every campaign's sends and replies in under 30 minutes. If it takes longer, the workflow is too complex or the volume is unmanageable.

What Bad Email Automation Looks Like

These are the warning signs that email automation is damaging your business:

  • Multiple recipients reply asking to unsubscribe or saying they never signed up. That means the list is stale or you are sending to people who did not consent.
  • Open rates drop below 10%. Either the subject lines are weak, or mailbox providers are routing your mail to spam.
  • The agent sends the same person multiple versions of the same message. That is a deduplication failure. It looks disorganized and wastes the recipient's time.
  • Customer support gets complaints about "spam from your company." That is a sign that sending is broken and needs to stop immediately.
  • You cannot explain why someone received an email. If you do not know which list they came from or how they got added, your process is not controlled.

How to Test Before Going Live

Before you let the agent send to your real list:

  1. Create a test list of internal email addresses and a few addresses you control at different providers (Gmail, Outlook, Yahoo).
  2. Run the agent workflow on the test list. Check that every email arrives, that the formatting is correct, and that the unsubscribe link works.
  3. Wait 24 hours. Check spam folders. If any test email landed in spam, fix the issue before sending to real recipients.
  4. Review the sent message for tone. Read it as if you were the recipient. If it sounds pushy, vague, or robotic, rewrite the template.
  5. Send to 10 real recipients manually to confirm the list is good and the message resonates. Read their replies. If three out of ten are confused, stop and revise.

A Simple Decision Tree

Here is a flowchart for whether an agent should send:

  • Is this a cold email to someone you have never contacted? → Draft only. Review and send manually.
  • Is this a reply to a customer complaint or legal issue? → Human only. Do not automate.
  • Is this a transactional confirmation (receipt, password reset, booking)? → Agent can send autonomously.
  • Is this a follow-up in a sequence the customer opted into? → Agent can send if unsubscribe works and the list is verified.
  • Does this email commit to pricing, terms, or deliverables? → Draft only. Human reviews and approves.
  • Is this going to more than 100 people at once? → Pilot with 10, review replies, then scale.

When in doubt, draft. You can always promote a draft workflow to autonomous later. You cannot undo a bad bulk send.

FAQ

Can an agent send on behalf of a person's individual inbox? Yes, if the person connected their Gmail or Outlook account and approved the workflow. The agent sends as that person. Make sure the person knows what is going out.

What if the agent gets the tone wrong? Stop the workflow, revise the prompt or template, test again on a small group, then resume. Tone drift is common when the agent is not given enough examples of good messages.

Should I let the agent send LinkedIn messages or Instagram DMs? The same rules apply. Platforms are stricter than email about bulk sending and automation. Draft is safer. Autonomous sending should be reserved for replies to inbound messages, not cold outreach.

How do I know if my domain is flagged? Check Google Postmaster Tools for your sending domain. Look at spam rate, reputation, and delivery errors. If spam rate is above 0.3%, pause and investigate.

Conclusion

An AI agent can draft email, send it, and run sequences. Whether it should depends on risk, consent, and deliverability. Draft when the stakes are high or the relationship matters. Send autonomously when the content is transactional, expected, or low-risk. Never automate legal issues, apologies, or cold email to lists you do not own.

Respect deliverability limits. Warm up new domains slowly, verify addresses, honor unsubscribes immediately, and monitor reputation. A fast sender with a ruined domain is useless.

Build safeguards before the first send: suppression checks, daily caps, human approval for new campaigns, and an emergency stop. Test on small groups before scaling. When the agent gets it wrong, pause and fix it instead of hoping the next batch is better.

If you want an agent that can draft email and send it through connected accounts with safety rules, start with Actus Agent.

When AI Agents Should Not Send Email | Actus