Email Automation
For Business
Operational emails often span the CRM, finance system, marketing platform and personal inboxes. We document the flows, assign ownership and move the important ones into a monitored system with clear consent and failure handling.
Read the email
Decide what it needs
Record the action
Email becomes tracked work with an owner.
Owned
EVERY FLOW HAS A RESPONSIBLE PERSON
Monitored
DELIVERY, BOUNCES AND COMPLAINTS
£140k
ICO FINE, HELLOFRESH, JAN 2024
Email flows need someone to own them
Receipts, invoice reminders and sales follow-ups can run through different systems. Without a shared inventory, it is hard to see which messages overlap or what happens when a trigger fails.
We trace important messages from the event that triggers them to delivery and any reply. The review includes duplicate sends, authentication, unsubscribe handling and consent records.
Your team gets a documented process for changing templates, investigating failures and approving new flows.
WHAT YOU HAVE TODAY
- Outlook and Gmail rules nobody documented
- Several platforms with overlapping sequences
- SPF and DKIM half-set, no DMARC report ever read
- Unsubscribe is a link to a 404
- No idea what bounced, who complained, or why
- Consent stored as "they're on the list"
WHAT WE LEAVE YOU WITH
- One place every email is defined, named and version-controlled
- Transactional and marketing on the right sender, not muddled
- SPF, DKIM and DMARC aligned, monitoring ownership agreed
- One-click unsubscribe that works (RFC 8058)
- Bounces, complaints and silent failures alerted
- Consent logged per subscriber, exportable for ICO
What reliable email automation needs
Each flow needs a defined trigger, sending rules, approved content and a way to detect failures.
Triggers
What kicks the email off. A sale, a sign-up, a CRM stage change, a timer, a Stripe webhook, an internal alert. Defined once, reused everywhere.
Logic
Branches, waits, quiet hours, frequency caps, suppression. The bit that stops you sending two reminders in an hour or chasing a customer who's already paid.
Content
Templates, merge fields, plain-text alternatives and appropriate unsubscribe controls. Test missing data, long values and mobile rendering before approval.
Delivery
SPF, DKIM, DMARC aligned. Dedicated IP or warmed shared pool. Transactional split from marketing. Compliance with Google, Yahoo and Microsoft's May 2025 Outlook.com bulk-sender rules.
Observability
Record send attempts and provider delivery events. Alert the owner to failures, unusual delays and complaints, with a retention policy for the logs.
Problems we find in email setups
The audit checks authentication, consent evidence, suppression and the handling of replies. It also identifies messages with no named owner.
Receipts going to spam
Missing authentication or alignment can contribute to rejection or spam placement. We check the domain configuration, message headers and provider responses for the affected receipts.
Half-built journeys
A sequence can stop early, use an obsolete trigger or send a reminder after the customer has acted. We test complete flows, including cancellation and reply paths.
PECR drift
Pre-ticked consent boxes and lists without evidence of permission need review. A products-and-services soft opt-in can include qualifying sales negotiations, but all its conditions must be met. See the ICO's electronic mail guidance.
Unsubscribe doesn't unsubscribe
An opt-out needs to reach every connected marketing flow. Google requires one-click unsubscribe for marketing and subscribed messages from bulk senders to personal Gmail accounts, with requests honoured within two days.
Nobody watches the dials
We monitor bounces, complaints, queue delays and failed triggers. Google's sender guidance recommends reported spam rates below 0.1%, avoiding 0.3% or higher.
How we take it into live use
We audit the current setup, fix the agreed delivery and permission issues, then build the selected flows.
We keep existing email platforms where they fit. The proposal explains any replacement and the work needed to migrate templates, records and suppression lists.
BOOK AN EMAIL AUDITAudit
We catalogue every email leaving your business. Which template, which sender, which list, on whose consent. We pull DMARC reports, check SPF and DKIM, score you against the Google, Yahoo and Microsoft bulk-sender rules. You get a one-page report and a prioritised fix list.
Foundations sprint
Correct authentication records, separate transactional and marketing flows, and connect unsubscribe handling and alerts. Existing consent evidence can be consolidated. Missing permission cannot be reconstructed by assuming consent.
Build the automations
We build the agreed onboarding, renewal, sales or internal flows and test their triggers, delays and stop conditions. Test recipients receive the messages before a live rollout is approved.
Hand back something you can run
A single inventory of every automated email, who it goes to, why, and on whose authority. Dashboards your operations lead checks. A written list of which changes a marketer can make in the ESP and which need a developer. Optional retainer if you'd like us watching the dials with you.
Email flows that keep the business running
These messages sit inside the operating process. Customers notice quickly when one is late, wrong or missing.
Transactional
Receipts, order confirmations, shipping updates, password resets, invoices, contracts.
Lifecycle
Welcome series, onboarding nudges, activation reminders, renewal warnings, win-back.
Sales
Cold sequences, meeting confirmations, proposal chase, quote follow-ups, hand-off to a human at the right moment.
E-commerce
Abandoned-cart, post-purchase, replenishment and review-request flows, subject to the permissions and rules that apply to each recipient.
Support
Auto-acknowledgements that don't lie about response times, ticket updates, CSAT and NPS surveys.
Internal
Weekly digests, KPI roundups, anomaly alerts, "this thing needs a human" pings to the right person.
Compliance
Document signature reminders, retention notices and audit exports. A request for marketing consent can itself be marketing, so it needs review before sending.
AI-assisted
Inbound triage and draft personalisation, with agreed review rules, access controls and a record of the approved message.
Operational and compliance risks
Sender guidance sets technical requirements. The HelloFresh decision shows why consent evidence also needs checking.
HelloFresh, £140,000.
In January 2024 the ICO fined HelloFresh £140,000 for a campaign involving 79 million emails and 1 million texts. The consent wording did not properly cover the marketing sent.
Consent and suppression records
Record how permission was obtained, which messages it covers and when it was withdrawn. Suppression needs to survive list imports and platform changes.
The 2024 bulk-sender change.
For bulk mail to personal Gmail accounts, Google requires SPF, DKIM and DMARC, From-domain alignment and one-click unsubscribe for marketing and subscribed messages. We check the current requirements against your sending volume and message types.
Sources: ICO HelloFresh decision, Google sender guidelines, Microsoft sender announcements.
Operational messages need an owner and a record
AM2PM assessment reminders and status updates are part of the recruitment workflow rather than a separate marketing campaign. The system knows the candidate, the event that triggered the message and what should happen next.
When this is worth discussing
We work best when there is a real operating problem, enough volume to measure and people from the affected teams who can make decisions.
Usually a good fit
- An established UK business, usually with annual revenue above £10m
- A repeated process with a known cost, delay, error rate or capacity problem
- A senior sponsor and a day-to-day owner who understand the work
- Access to the relevant staff, systems, sample records and security requirements
We may point you elsewhere
- A standard product already covers the process well
- The requirement is a one-off small build with no wider operating case
- There is no owner or access to the people and data needed to test the result
- The plan relies on AI making high-impact decisions with nobody responsible for review
Questions before connecting the systems
We're already on Mailchimp / HubSpot / Klaviyo. Do you replace it?
Usually no. We use the platform you've already trained your team on, and we put proper engineering around it. We'll only suggest a move if the current tool is the reason things are breaking, and we'll tell you what the migration costs before you commit.
What about transactional? Stripe, Auth0, the app itself.
We review receipts, password resets and other operational messages alongside marketing. Separate senders or subdomains can help manage the streams, but providers may still link their reputation. Authentication and monitoring are needed for both.
We B2B email cold prospects. Are we breaking the law?
PECR generally permits marketing email to corporate subscribers without prior consent, but the sender must be identified and an opt-out provided. Sole traders and some partnerships need consent or a valid soft opt-in. UK GDPR still applies to personal data, including named business email addresses. See ICO B2B marketing guidance.
Why does any of this need a developer? It's just email.
A developer can help with duplicate triggers, failed webhooks, unsaved consent records and missing template data. If the existing platform can handle the flow without custom code, we use that capability.
How long until something visible changes?
The first phase inventories the flows, fixes authentication and gives one important message a clear owner, monitoring and failure path. Other messages follow after that pattern is working.
How much does it cost?
Audit is fixed-fee. Foundations sprint is priced per finding. The build phase is scoped against your flow list, fixed price per phase. You get the number before we touch a record.
Do you do "AI emails"?
We can add reply triage and draft personalisation where the source information is sufficient. Before rollout, you approve which messages need human review and which fixed templates can send automatically. Logs retain the evidence needed to investigate mistakes under an agreed retention policy.
Talk to us about your email setup
Send us the current flow list, sending domains, platforms and recent failures. We will identify the messages that need central ownership and the first automation worth rebuilding.