Back to Blog
Sales Strategies 8 min read

How to Respond to "How Did You Get My Email?" Replies Without Earning a Spam Complaint

"How did you get my email?" is one reply away from a spam complaint. Here is how to respond to it, what never to say, and how to handle it at scale.

MC

Michael Chen

Technical Writer

How to Respond to "How Did You Get My Email?" Replies Without Earning a Spam Complaint

How to Respond to “How Did You Get My Email?” Replies Without Earning a Spam Complaint

A prospect just replied to your cold email with four words: “How did you get my email?” That reply is not a lost deal, but it is the single most dangerous reply type in your inbox, because the person’s next click is often the “mark as spam” button.

Most reps treat “how did you get my email” as a nuisance and either ignore it or fire back something defensive. Both responses raise your risk. Ignore it and the prospect reports you. Get defensive and you confirm every bad assumption they already had about cold outreach. This guide walks through what the reply actually signals, a four-part response framework, ready-to-use templates, and how to handle these replies at scale without a human reading each one.

Why “How Did You Get My Email?” Is a High-Risk Reply

Every other objection in cold email costs you a deal at worst. This one can cost you your sending infrastructure.

Here is the mechanism. Mailbox providers like Google and Microsoft weigh spam complaints heavily when they decide where your future emails land. A spam complaint rate above roughly 0.3% is the widely cited threshold under Google’s bulk sender guidelines where deliverability starts to degrade. A prospect who asks how you got their address is, by definition, a prospect who did not expect to hear from you and is already annoyed. If your reply lands wrong, they do not just delete it. They report it, and that complaint follows your domain.

So the goal of your response is not to win the argument. It is to de-escalate, answer honestly, and give the person a clean exit so they never reach for the spam button. A booked meeting is a bonus, not the objective.

What This Reply Actually Means

“How did you get my email” is not one question. It is three different people asking three different things, and the right response depends on which one you are talking to.

  • The genuinely curious. They are mildly surprised, not angry. They might actually be a fit and are just calibrating whether you are a real person or a scraper. A straight, confident answer usually moves them forward.
  • The privacy-conscious. They care about how their data is handled, often because they work in a regulated field or have been burned by spam. They want to know you are legitimate and that you will respect a “no.” Honesty and an easy opt-out matter more than your pitch.
  • The hostile. They are irritated and testing whether you will dig in. Any hint of evasion or a hard pitch gets you reported. Your only job here is a short, respectful acknowledgment and a clean removal.

You cannot always tell which one you are dealing with from four words. When in doubt, respond as if you are talking to the privacy-conscious prospect. That register is safe for all three.

What Never to Say

Before the templates, the failure modes. These are the replies that turn a recoverable moment into a spam complaint.

  • “It’s publicly available information.” Technically often true, emotionally infuriating. It reads as “your privacy is your problem.”
  • Ignoring the question and pitching anyway. “Great question! Anyway, do you have 15 minutes Thursday?” This is the fastest route to a report.
  • Vague deflection. “I came across your profile” when you clearly used a database. People can tell, and it erodes the trust you are trying to build.
  • Over-explaining your data stack. Naming the exact tool and scraping method invites a longer fight and can create compliance exposure you did not need.
  • Going silent. No reply reads as “caught and hiding.” Silence on this specific question increases the odds of a report, not decreases it.

The pattern across all five: they either dodge the question or treat the person’s discomfort as invalid. Do the opposite.

A Four-Part Response Framework

Every strong response to “how did you get my email” has the same four moves, in order. It takes two or three sentences total.

  1. Acknowledge without apologizing for existing. A light, human acknowledgment that the outreach was cold. You are not sorry you emailed. You are respectful that it was unexpected.
  2. Answer honestly and briefly. State your source in plain terms. You do not need the vendor’s name, just the truthful category: a public professional profile, a business directory, a data provider.
  3. Offer the exit first. Before any pitch, make removal effortless. Offering to remove them, unprompted, is what separates a legitimate sender from a spammer in the reader’s mind.
  4. Pivot to value, only if it fits. One sentence on why you reached out to them specifically. If the reply was hostile, skip this entirely.

The order matters. Leading with the exit is counterintuitive for reps trained to always be closing, but it is exactly what disarms the complaint reflex. The same logic drives good handling of “is this a bot?” replies: transparency early buys you permission to continue.

Templates by Scenario

Adapt these to your voice. The structure is what does the work, not the wording.

For the genuinely curious prospect:

Fair question, this was a cold email so it is a reasonable thing to ask. I found you through your company’s team page while researching [specific team or role], since we work with [role] on [specific problem]. If it is not relevant, say the word and I will close this out. If it is, I can send one short example of how it applies to you.

For the privacy-conscious prospect:

Totally understand wanting to know. Your email came from a business contact database we use for outreach, and this was a cold message, not something you signed up for. Happy to remove you right now, no hard feelings. If you would rather I share why I reached out to you specifically first, I can do that instead. Your call.

For the hostile prospect:

Understood, and sorry for the interruption. This was a cold email sourced from a public business listing. I have removed you from any further outreach. Have a good one.

Notice the hostile version has no pitch and no question. It closes the loop cleanly. That is the response that protects your domain, and it is worth more than the tiny chance of salvaging a deal with someone who is already angry. For the mechanics of processing that removal correctly, see handling unsubscribe and opt-out requests compliantly.

The Compliance Layer: What GDPR and CAN-SPAM Actually Require

This is not legal advice, but you should know the ground you are standing on, because “how did you get my email” is sometimes a compliance question wearing a casual disguise.

  • In the US, CAN-SPAM does not require you to disclose your data source. It does require a valid physical mailing address in your emails and a working opt-out that you honor promptly. So the honest answer above is a courtesy, not a legal mandate, but the opt-out is not optional.
  • In the EU and UK, GDPR is stricter. When you obtain someone’s personal data indirectly, Article 14 generally requires you to tell them the source of that data, and Article 21 gives them a clear right to object to direct marketing. A prospect asking how you got their email may be exercising a right, not just venting. Answer plainly and process the objection.
  • In California, the CPRA gives consumers a right to know the categories of sources from which their information was collected. Again, a truthful category-level answer covers you.

The practical takeaway is simple. Honesty about your source and an immediate, no-friction opt-out is not just good manners. It is the same behavior these laws require. The rep who de-escalates well and the rep who stays compliant are doing the same thing.

Handling “How Did You Get My Email” Replies at Scale

One rep can handle these thoughtfully. A team running 40 mailboxes and thousands of sends per week cannot, and that is where the risk compounds. Miss one of these replies for six hours and it becomes a spam complaint before anyone reads it.

At scale, three things have to happen automatically:

  1. Detection. The reply has to be recognized as a data-source or privacy question, not misfiled as a generic objection. It rarely uses the exact words “how did you get my email.” It shows up as “who is this,” “I never signed up for this,” or “where did you get my information.” Intent classification catches all of these; keyword rules miss most of them. This is the same classification discipline behind any real reply categories and triage workflow.
  2. Fast, correct response. Because complaint risk climbs with every hour of silence, these replies need a response measured in minutes, using the de-escalation framework above rather than a generic template.
  3. Suppression. When the person asks to be removed, they have to be pulled from every active sequence and every other mailbox targeting them, immediately, so a second email never lands.

This is exactly what an AI reply agent is built to do. Underfive reads each incoming reply, recognizes a privacy or data-source question regardless of how it is phrased, sends a calm, honest, on-brand response within minutes, and suppresses the contact across your connected tools if they ask out. It protects the thing that keeps your outbound alive, which is your sender reputation. You can see how the classification and auto-response layer works and why speed on these specific replies matters for deliverability.

The Bottom Line

“How did you get my email” is a test, and the passing answer is always the same: acknowledge that it was cold, tell the truth about your source, and offer the exit before you offer the pitch. Do that consistently and a reply that could have cost you a domain becomes a small moment of trust, and occasionally, a conversation.

Next step: pull the last month of your replies and search for phrases like “who is this,” “never signed up,” and “where did you get.” Count how many you missed or answered badly. That number is a direct measure of how much reputation risk is sitting unmanaged in your inbox, and it is usually the fastest case for putting a real system behind these replies.

how did you get my email cold email replies spam complaint cold email compliance GDPR cold email sender reputation reply handling

Share this article

MC

Written by

Michael Chen

Technical Writer

Ready to reply faster?

Underfive responds to your leads in under 5 minutes, 24/7. Start converting more leads today.

Book a Demo