Permission Pass

Email Marketing

Also: Consent Check · Pre-Send Permission Check

What it checksValid opt-in status before send
BlocksUnconsented and stale contacts
When it runsRight before send, not just at signup
Related toConsent, suppression lists, sender reputation

Quick definition

A permission pass is the check a sending platform or marketer runs to confirm a contact has given valid, current consent to receive email before a campaign goes out. It confirms opt-in status, checks suppression lists, and blocks any recipient who hasn't affirmatively agreed to be contacted.

How it varies across Australia

Australian senders operate under stricter consent expectations than many global email platforms assume by default. Businesses that build permission checks into every send tend to sit well below industry spam complaint rates, while those relying on a one-off list clean sit noticeably higher.

See deliverability and data benchmarks across Australian industries

What it actually means

A permission pass works like a bouncer checking ID at the door, not the sign that said 'over 18s welcome' six months ago. Consent can go stale. A contact who opted in during a signup promotion two years ago and hasn't opened an email since is a different risk than someone who joined last week. The permission pass is the check that runs right before send, confirming the contact is still eligible under your consent rules, not just eligible when they first joined the list.

This matters because email deliverability rewards senders who only mail people who want the mail. Internet service providers watch engagement signals closely and a list full of stale or unconsented contacts drags down sender reputation fast. One aggressive send to an old, unengaged segment can tip a domain into the spam folder for weeks.

A permission pass usually checks three things. Consent type, whether it's explicit opt-in or inferred. Suppression status, whether this person has unsubscribed or bounced. And recency, whether the relationship has gone quiet long enough to need re-permission. Businesses that build this into their sending pipeline as a standing filter, rather than an annual audit, tend to have healthier open rates and fewer spam trap hits.

Consent decays the same way inventory does, quietly and then all at once.

How it shows up

A permission pass shows up as a pre-send filter in your email service provider, quietly removing contacts who fail consent checks before the campaign fires. It also shows up in suppression list growth, in the gap between total subscribers and actually-mailed subscribers, and in re-engagement campaigns aimed at contacts approaching their consent expiry window. When it's missing, it shows up later as spam complaints, blacklisting, or a sudden drop in inbox placement that nobody can explain until someone checks who actually got mailed.

The Australian context

Australia's Spam Act 2003 requires consent, a clear sender identity and a working unsubscribe on every commercial email. Consent under the Act can be express or reasonably inferred from an existing relationship, but inferred consent has limits and doesn't last forever. A permission pass built around Australian rules needs to track consent type, not just presence of an email address, and should treat a long silence from an inferred-consent contact as a signal to stop rather than push harder. The Australian Communications and Media Authority (ACMA) enforces the Spam Act and has fined businesses for exactly this failure, mailing lists built on consent that had quietly expired.

Where people get this wrong

Treating consent as permanent once captured.Engagement decays and inferred consent can lapse, so a contact eligible a year ago may not be eligible today.
Running list hygiene only once a year instead of at send time.Deliverability damage happens per campaign, so an annual clean-up misses the sends that quietly build spam trap hits in between.
Confusing suppression list checks with a full permission pass.Suppression only catches unsubscribes and bounces, it doesn't verify that remaining contacts still have valid, current consent.

Related terms

Common questions

What's the difference between a permission pass and list hygiene?

List hygiene is periodic cleaning, removing bounces, duplicates and unsubscribes on a schedule. A permission pass is a check that runs before every send, confirming consent is still valid for that specific campaign. Hygiene is maintenance, a permission pass is a gate.

Does a permission pass slow down sending?

Not meaningfully in a modern email service provider. The check runs automatically against your suppression and consent data in milliseconds per contact. The larger cost is upfront, building clean consent tracking, not the pass itself.

How often should consent expire?

There's no universal rule, but many Australian senders treat twelve to eighteen months of silence as a trigger for re-permission rather than an automatic cut-off. The right window depends on your sending frequency and industry norms.

Is a permission pass required by law in Australia?

The Spam Act 2003 doesn't name a permission pass specifically, but it does require valid consent for every commercial email sent. Building a pre-send permission check is the practical way most businesses stay compliant rather than relying on memory.

Debrief

Get the next one

No spam. No fluff. Just the next article, straight to your inbox.

Keep exploring

About New Rebellion

New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.

How we think →