✓ Existing permissioned contact lists
✓ Small teams reviewing verification files
✓ Cross-vendor result and return decisions
— Cold outreach or purchased-list validation
— Guaranteed inbox placement
— Legal permission certification
— An email campaign builder
Two independent records
Keep the permission/source record and the technical verification record as separate fields or linked records. They answer different questions and may change at different times. An opted-out contact does not become subscribed because a mailbox exists. A technical failure likewise does not erase the historical fact of an opt-out.
Do not infer missing authority
A business card, old invoice or public address is not a complete answer to every marketing-permission question. Follow the applicable platform requirements and obtain qualified advice where necessary. This guide supplies an operational separation, not a legal determination or a universal consent rule.
A practical handoff
For each included record, the internal owner should be able to explain the intended use and the source of authority. That explanation need not be exported to the verifier. If the owner cannot do so, hold the record out of the proposed send workflow and investigate the missing evidence first.
Put it into practice
An operational permission register can identify the intended message category, source record, relevant evidence location and the person responsible for reviewing uncertainty. It should not contain invented consent dates or a generic “legal” checkbox. Keep access proportionate, and do not export this richer context to a verifier unless there is a specific justified requirement. A fictional customer might be an active member, a former donor and an opted-out newsletter subscriber at the same time. Flattening those relationships into one contact-level green flag destroys useful distinctions. The verification observation can be attached separately without resolving which communications are appropriate. If records conflict, the authorised owner should investigate the relevant evidence rather than ask a technical tool to choose. This guide does not determine consent, lawful basis or jurisdiction-specific obligations. It helps keep the question visible so a technical result is not mistaken for the answer.
Where the safety evidence stops
This guide draws on Mailchimp audience requirements. Merchant-controlled records describe the provider’s own capabilities, terms or standards; they do not independently validate those claims. These records do not establish independent confirmation of the product claims.
Verify any current price, plan limit, label direction, compatibility rule, or commercial term that would materially change the decision. The dated source ledger shows the underlying records so this conclusion can be checked and updated.
Sources used for this page
These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.
- Mailchimp audience requirements — Merchant documentation · mailchimp.com · Merchant-controlled · checked 2026-09-27