CRM Solid logo
Home/Blog/Cold DM Outreach in 2026: The Spam Filter Reads Your Behaviour, Not Your Copy

Cold DM Outreach in 2026: The Spam Filter Reads Your Behaviour, Not Your Copy

Your cold DM has two readers: a person who decides whether to reply, and a classifier that decides whether they ever see it. This is what the platforms actually publish about how they detect spam, why volume is the lever that kills you, five real messages rewritten, and the platforms where cold DM is already finished.

Written by

Emirhan Güven

July 16, 2026
43 min read
Article
Share this article:

Your cold DM has two readers. A person decides whether to reply to it. A classifier decides whether that person ever sees it, and whether you still have an account next week. Almost every cold outreach guide written in the last five years optimises hard for the first reader and pretends the second one does not exist, which is how people follow good-sounding advice straight into a permanent restriction.

This piece is about both readers. It covers what the platforms themselves publish about how they detect spam, why the volume lever is the one that kills you, what personalisation has to actually contain to count, what the message-length research does and does not say, and where the follow-up curve turns negative. It also names the platforms where cold outreach by DM is finished, because on several of them it is, and pretending otherwise wastes your time.

The two judges reading your message

The human judge is asking one question: is this about me, or is it about you? That question gets answered in the notification preview, before your message is even opened. Everything you have read about hooks and openers is an attempt to win this judge.

The machine judge is not reading your message the way you think. It is scoring an account and a pattern. Your words are one input among many, and by the published evidence they are not the most important one. This judge does not care that your copy is charming. It cares that you just opened forty first-conversations in an hour and thirty-eight of them went unanswered.

These two judges want opposite things from you at scale. The human judge rewards effort that does not compress: research, specificity, a reason that only applies to them. The machine judge punishes the shape that effort-free sending produces: high fan-out, low reciprocity, uniform text, fresh accounts. Every technique that makes cold DM cheap makes it more detectable. That tension is the whole subject.

The uncomfortable version: if a tactic lets you send ten times more messages for the same effort, it is a tactic that makes your account pattern ten times more distinctive to a classifier trained on exactly that pattern. There is no clever workaround that survives contact with this, because the thing being measured is the thing you are doing.

What platform spam detection actually measures

Start with a number the platform published itself. In LinkedIn's Community Report for July to December 2025, 98.6% of the spam and scam content it removed was stopped by automated defences rather than by human reviewers. For fake accounts, 97.8% were stopped by automatic defences and only 2.2% by manual review.

Read that as an engineering statement rather than a PR one. Whatever decides your fate on LinkedIn is a model, running at population scale, on features that are cheap to compute for every account continuously. Human review is a rounding error. You are not being read. You are being scored.

Meta says the quiet part out loud in its Spam Community Standard. The prohibited conduct includes posting, sharing, engaging with content or creating assets "either manually or automatically, at very high frequencies." Note "manually". Doing it by hand is not a defence. Then the sentence that matters most: "We may place restrictions on accounts that are acting at lower frequencies when other indicators of Spam (e.g., posting repetitive content) or signals of inauthenticity are present."

That is a public description of a composite score. Frequency alone triggers it. Frequency below the threshold still triggers it if other signals stack. There is no safe volume, only a volume that is safe given everything else about you.

X's Authenticity policy, updated April 2025, reads like a feature list for a classifier. Under Content Spam it prohibits "Sending bulk, aggressive, high-volume unsolicited replies, mentions, or direct messages" and "repeatedly posting or sending direct messages consisting of links shared without commentary, so that this comprises the bulk of your post/direct message activity" and "repeatedly posting identical or nearly identical posts in a duplicative manner popularly known as 'Copypasta', or sending identical direct messages." Under Engagement Spam it names "engaging in indiscriminate following: following and/or unfollowing a large number of unrelated accounts in a short time period, particularly by automated means."

Every one of those is a behaviour. Not one of them is about whether your value proposition is compelling.

Here is the signal hierarchy as best it can be reconstructed from what the platforms publish. The right-hand column separates what is documented from what is inference, because nobody outside these companies has seen the models.

SignalWhat it measuresDocumented, or inferred?
RateSends per hour and per day, relative to account age and historyDocumented. Meta: "at very high frequencies". Instagram warns about "sending too many messages".
UniformityIdentical or near-identical text across many recipientsDocumented. X: "sending identical direct messages".
ReciprocityRatio of conversations you start to conversations that get a replyInferred. No platform publishes this, but it is trivially computable and it separates outreach from conversation.
Graph distanceMessaging people with no mutual connection, follow, or prior interactionPartly documented. X states a user following you "is not on its own a sufficient indication of user intent".
Recipient reactionReports, blocks, ignored or dismissed requestsDocumented. LinkedIn names invitations "ignored, left pending, or marked as spam" as a restriction trigger.
Client fingerprintUnofficial client, datacentre IP, headless browser, extensionDocumented. LinkedIn bans third-party software that automates activity on its site.
Account provenanceAge, photo, history, phone number reuse, devicePartly documented. X's enforcement includes locking accounts and demanding a phone number.
ContentKeywords, link patterns, attachmentsDocumented, and listed last on purpose. X's example is "links shared without commentary".

The practical reading: content signals are the cheapest to evade and therefore the least load-bearing. Anyone can swap words. Nobody can fake a conversation that gets replied to. That is why the reciprocity and reaction signals do the real work, and why the entire "spin your template so it isn't duplicate" industry is solving the wrong problem.

Which brings up spintax specifically, since it is the most common answer to "how do I avoid the duplicate check". Spintax genuinely does defeat naive exact-match duplicate detection. It does nothing to your rate, your reciprocity, your graph distance, or your report rate. It makes eight thousand identical messages into eight thousand messages with identical structure, identical intent, identical send pattern, and identical outcome. The classifier has other columns.

The signal you cannot engineer around

Telegram's Spam FAQ contains the single most useful sentence in the whole cold DM literature, and it is not from a growth blog. Explaining why an account got limited, Telegram writes that people report messages they did not ask for, and that the offending message could have been anything: "It could have been a photo, an invite link or a simple 'hello'."

A simple hello. There is no copy on earth that survives a recipient who did not want to hear from you. The report button does not have a quality threshold. It has an annoyance threshold, and annoyance is set by relevance and context, not by craft.

This is the part that breaks the standard mental model. In email, you have a visible feedback loop: bounces, unsubscribes, and a spam-complaint rate you can watch. Google's sender guidelines tell bulk senders to keep Postmaster-reported spam rates below 0.10% and to never reach 0.30%. You get a dial. You can see the needle.

In DM, there is no dial. Blocks are invisible to you. Reports are invisible to you. Ignored requests are invisible to you. The first feedback you get is the enforcement itself, arriving days after the behaviour that caused it, with no per-message attribution. You are flying an aircraft where the stall warning is the crash.

Every platform confirms that recipient reaction is the input, in its own words:

  • Telegram: "When users press the 'Report spam' button in a chat, they forward these messages to our team of moderators for review." A first offence gets you limited for "a few days or so", and "Repeated offences will result in longer periods of being blocked." While limited, you can still message people who have your number saved, and you can always reply to anyone who messages you first. Note the shape of that penalty: it removes exactly your ability to start conversations with strangers and leaves everything else intact. It is a surgical anti-cold-DM sanction.
  • WhatsApp: the Business Messaging Policy states that "People can block or report businesses and our systems will limit the amount of messages a business can send or calls a business can initiate if the business' quality tier is low for a sustained period of time."
  • LinkedIn: its invitation restrictions page names three triggers, and two of them are about how recipients responded: many invitations sent in a short time, and many invitations "ignored, left pending, or marked as spam by the recipients." Not opened and disliked. Ignored. Silence is a negative signal.
  • Instagram: the help page is four sentences long and says "Instagram has limits in place to stop direct messages that people may not want to get, like spam" and that if you were warned about sending too many messages and continue to do so, "you may not be able to send more direct messages for a period of time." It does not publish a number, and that is deliberate.

None of these platforms will tell you the threshold. Publishing it would turn it into a budget. So the operating question is never "how many can I send", it is "what is my report rate", and you cannot measure your report rate, so it becomes "how confident am I that this person wants this message". That is a targeting question wearing a compliance costume.

Why volume is the wrong lever, with the arithmetic

Suppose you want forty conversations this month. There are two routes.

Route A: 8,000 DMs at a 0.5% reply rate. Route B: 400 DMs at a 10% reply rate. Both produce forty replies. Sales teams pick Route A almost every time, because 8,000 sends feels like work and 400 feels like you are not trying. Now price the two properly.

Take our own default sender pacing as a concrete unit of capacity, since these are real numbers from a real product rather than a hypothetical. CRM Solid's rate limiter ships at 20 messages per hour, 50 messages per day, a 10 second minimum gap between messages, a maximum of 10 consecutive sends before a 2 minute break, and an automatic 2 hour penalty pause when Telegram returns a peer-flood error, escalating to 8 hours on repeat. Those defaults exist because they approximate a busy human, and a busy human is the only pattern the classifiers are not looking for.

At 50 per day, one account sends about 1,500 messages a month. Route A therefore needs six accounts running flat out, every day, with zero slack. Route B needs one account working a third of a day. Now count what six accounts actually cost:

  • Six phone numbers, six warm-up periods, six sets of profile history that has to look real.
  • Six independent chances of a restriction, and restrictions correlate: the same list, the same script, and the same infrastructure means when one goes, the others are already flagged.
  • 7,960 people who now associate your brand with a message they did not want. That cost never appears in any dashboard and never goes away.
  • A list that is now burned. Those 8,000 contacts cannot be approached again by anyone at your company with a clean slate.

Route B costs one account, a research step, and 400 people who mostly did not mind. The forty conversations are also not the same forty conversations, which is the part that gets missed.

Sopro's State of Prospecting 2026 is worth reading here because the methodology is published rather than implied. It combines a Sapio Research survey of 442 B2B sales and marketing decision-makers in the UK and US, run in October 2025 with a 4.7 percentage point margin of error, with campaign data covering 126,032,914 outreach emails and 25,127,388 multi-channel data points from 2016 to 2025. It is a prospecting agency reporting on its own book of business, which is a real bias, and it is still an order of magnitude more transparent than the DM benchmark posts you will find on page one of Google.

Two findings from it are directly relevant to the volume question. First: when they used AI to filter audiences by genuine suitability rather than surface firmographic fit, the lead rate barely moved, but leads from the refined audience were 356% more likely to convert into closed deals. Same volume of leads, wildly different quality. If you optimise for reply count you will never see this, because reply count is exactly the metric that did not change.

Second, and more uncomfortable: over-contacted prospects are twice as likely to reply, but half as likely to convert, compared to fresh prospects. The people who answer everything answer you too. Volume-driven outreach preferentially harvests the least valuable respondents in your market and then reports them as success.

Sopro's own framing of deliverability is the line worth stealing: it is "no longer a simply technical issue; it's behavioural." That was written about email, where you at least have SPF and DKIM to hide behind. In DM there is no technical layer at all. Behaviour is the whole thing.

Personalisation that is real, and merge-tag theatre

Here is a test that costs nothing and settles most arguments. Take your message, swap the recipient for any other person on your list, and ask whether the sentence is still true. If it is still true, it is not personalisation. It is a variable.

"Hi {{first_name}}, I saw {{company}} is growing fast" passes no version of that test. Every company on every list is growing fast, or was, or claims to be. The merge tag is doing zero work, and worse, the recipient has seen that exact shape three times this week, which means the tag is now a negative signal. It marks you as automated more reliably than no personalisation at all.

Sopro's report has the perfect parody of this failure mode, quoting the kind of message you get when personalisation is treated as a box to tick: "I saw your post about [your holiday], which really reminded me of our cloud accounting software." The research happened. The relevance did not. The two are not the same operation and one does not imply the other.

A workable hierarchy:

TierWhat it isExampleDoes it survive the swap test?
TokenA field from your CRM pasted into a sentence"Hi Sara, hope things are going well at Northwind."No. True of everyone.
ObservableSomething public you actually looked at, stated back"You posted last week about killing your SDR team's dialer."Partly. True of a few hundred people, not one.
ConsequentialAn observation that changes what you are proposing"You killed the dialer, so I'm not going to pitch you a dialer. The reason I'm messaging is the thing that usually breaks next."Yes. Only makes sense sent to this person.

Only the third tier is personalisation in any sense a recipient would recognise. The first two are proof that you have a tool. And the third tier is expensive: it needs a human, or a model with genuinely good context, to read something and form a view about it. Three to five minutes per prospect, realistically.

Which produces the honest conclusion most cold DM content refuses to reach. If your average contract value cannot support five minutes of research per prospect, cold DM is not your channel. Do the sum. At five minutes each, one person does roughly 90 researched DMs a week. At a 10% reply rate and a 20% reply-to-meeting rate, that is under two meetings a week per head. If that does not clear your cost of sale, no template, no AI writer and no account rotation scheme will fix it, because the only thing that would fix it is sending more, and sending more is what destroys the reply rate you just modelled.

Three to five minutes of research is also the number that decides whether AI helps you. Used to draft the sentence, it saves you thirty seconds and costs you the specificity that made the message work. Used to surface the fact worth reacting to (this account changed pricing, this person just took over the team, this company's job posting contradicts its homepage), it saves you the expensive part and leaves the judgement to you. Sopro found 58% of B2B sales and marketing decision-makers now use AI for writing outreach messages and only 11% are not using AI in prospecting at all, while 70% expect AI to make outreach more efficient but not more human. Those numbers describe a market that automated the wrong half of the job.

Message length: what the data says, and what it does not

The length research is real, well-powered, and about email. Say that clearly before quoting it.

Gong's analysis of more than 28 million cold emails puts the highest reply rates at 100 words or fewer, with three to four sentences performing best. Lavender, working from its own corpus across roughly fifty thousand active inboxes, puts the optimal cold opener tighter still, at 25 to 50 words. Both agree on direction and disagree on magnitude, which is what honest data usually looks like.

Now the caveat that matters: none of this is DM data, and DM is not short email. The differences are structural.

  • No subject line. Email gets a free 60-character audition before the body counts. A DM's first line is doing both jobs at once.
  • The notification is the message. On a lock screen you get roughly two lines. Whatever falls past that is read only if the first two lines earned it. This is the real length constraint and it is a hard one.
  • Chat UI makes length visible as a shape. A long email looks like an email. A long DM looks like a wall, and it renders as a wall before a single word is read. You are judged on silhouette.
  • Reply cost is different. Email replies are a task. DM replies are a reflex. Which means a DM that asks for a two-word answer gets one, and a DM that asks for a considered answer gets nothing, because considered answers are what the inbox is for.

Reasoning from those mechanics rather than from email data, here is what actually constrains a first cold DM per platform. These are practical working budgets, not published platform limits, and you should treat them as a starting point to test rather than as findings:

ChannelPractical first-message budgetThe binding constraint
Telegram25 to 45 wordsNotification preview, and a stranger's very low tolerance before the report button
X DM20 to 40 wordsThe reader is in a feed-scrolling headspace, not a work headspace
LinkedIn connection noteUnder 300 charactersA hard platform limit, and the note is read on the invitation card with no formatting
LinkedIn message after connect40 to 70 wordsSlightly more patience, still a chat window
Instagram DM20 to 35 wordsMessage requests show a truncated preview; you are auditioning for the accept
Email50 to 100 wordsGong and Lavender, above

The rule that survives all of this: one screen, no scroll, on a phone, with the ask visible without expanding. If you have to check whether it fits, it does not.

Five cold DMs, diagnosed and rewritten

Abstract advice about personalisation is easy to agree with and impossible to act on. So here are five real message shapes, the specific reason each one fails, and a rewrite. One of them cannot be rewritten, and that is the most useful example in the set.

1. The Telegram agency pitch

Hi ???? I hope you're doing well!
I'm Alex from GrowthLab. We help SaaS companies scale their outbound and generate 30 to 50 qualified meetings per month with our proven system. We've worked with 200+ clients and would love to show you how it works.
Are you free for a quick 15 min call this week? ????

Diagnosis: 58 words, three separate spam signals, and a request for a stranger's calendar in the first contact. "I hope you're doing well" is the tell that a template starts here. "200+ clients" is social proof, which sounds like it should help and does not, for reasons covered below. "Proven system" is unfalsifiable. The emoji are not the problem; the fact that they are load-bearing is. And the whole message would be word-for-word identical to the next 500 recipients, which is precisely the "sending identical direct messages" pattern X names by name and every other platform detects the same way.

The rewrite:

Your changelog says you shipped a self-serve tier in April and your careers page still only lists enterprise AEs. If that's deliberate, ignore me. If it isn't, I've watched three companies get stuck exactly there. Worth ten minutes?

39 words. It cannot be sent to anyone else, because the observation is specific and the conclusion depends on the observation. It gives an explicit exit ("if that's deliberate, ignore me"), which lowers the perceived cost of engaging and which no template ever does because templates are optimised to prevent the no. And the ask is ten minutes rather than a call this week, which is a smaller commitment and reads as less presumptuous.

The honest cost: that message took eight minutes to write and required actually reading a changelog and a careers page. There is no version of this that scales to 8,000 sends. That is the point.

2. The X DM after a follow

Thanks for the follow! Since you're into AI, I thought you might like my newsletter where I break down the latest tools every week. Free to subscribe here: [link]

Diagnosis: this one is not just weak, it is explicitly against the rules if it is automated. X's automation rules state: "You may not send unsolicited Direct Messages in a bulk or automated manner, and should be thoughtful about the frequency with which you contact users via Direct Message." And it closes the loophole most auto-DM tools are built on: "The fact that a user is technically able to receive a Direct Message from you (e.g. because the user follows you, has enabled the ability to receive Direct Messages from any account, or because the user is in a pre-existing Direct Message conversation with you) does not necessarily mean they have requested or expect to receive automated Direct Messages from you." On the replies-and-mentions side X is even blunter: "a user following your account is not on its own a sufficient indication of user intent to receive an automated response."

So the auto-welcome-DM, the single most common X growth tactic of the last decade, is a policy violation as written, not a grey area. It also carries a link with essentially no commentary, which is the exact Content Spam example in the Authenticity policy.

The rewrite, sent by a human, to one person, because there is no compliant automated version:

Your thread on why model evals lie was the first thing I've read that matched what we actually see. The part about held-out sets leaking through prompt templates: did you ever find a fix, or is it just a known tax?

No pitch. No link. It is a question you would only ask someone who wrote that specific thread, and it is answerable in one line. This is not a sales message and it should not be. It is the first message in a relationship that might become one. If that feels too slow, note that the fast version is a written policy violation that puts the account at risk, so "slow" is doing a lot of unearned work in that objection.

3. The LinkedIn connection note

Hi Priya, I'd love to connect and grow my network with like-minded professionals in the SaaS space!

Then, forty seconds after acceptance:

Thanks for connecting Priya! Quick question, are you currently looking for ways to reduce your customer acquisition costs? We've helped companies like yours cut CAC by 40%. Open to a chat?

Diagnosis: the note is a lie of omission and the recipient knows it, because everyone knows what happens forty seconds after they accept. That gap is why LinkedIn's invitation restrictions count invitations "ignored, left pending, or marked as spam" against you. People have learned to leave these pending, and pending is a penalty. The follow-up then commits the cardinal error: it asks a stranger a qualifying question that only benefits the asker, which is why it reads as an interrogation rather than a conversation.

Also worth stating plainly: LinkedIn's Professional Community Policies say "Do not use our invitation feature to send promotional messages to people you don't know or to otherwise spam people" and ban "untargeted, irrelevant, obviously unwanted, unauthorized, inappropriate commercial or promotional, or gratuitously repetitive messages." The connect-then-pitch sequence is the thing that sentence was written about.

The rewrite, which is one message rather than two, sent with the invitation:

Priya, you spoke at SaaStock about running support and sales off one queue. We tried it, it broke at about 40 conversations a day, and I'd like to know whether yours did too or whether we did it wrong.

41 words, inside the 300-character limit. It states why this person and not another. It has no ask at all, which is correct for a connection note: the ask is the connection. And it offers her the more attractive position in the conversation, which is being the person who knows the answer.

4. The Instagram creator outreach

Hey! ???? Love your content! We're a fast-growing brand and we'd love to partner with you. We can offer you free products in exchange for a post. Let me know if you're interested!!

Diagnosis: this lands in Message Requests, where it competes with forty identical messages, and the recipient's decision is made from a truncated preview that reads "Hey! ???? Love your content!". You have lost before the message is opened. "Free products in exchange for a post" is also an offer to pay someone in inventory, which tells them exactly where they rank.

The rewrite:

Your resole video is why I stopped buying cheap boots. We make the welt tooling in the background of your shot at 4:12. Paid review, you keep the gear, you can hate it publicly. Interested?

35 words. The preview line does work. It proves you watched the thing, at a timestamp. It names money before it names product, which reverses the insult. And "you can hate it publicly" is the credibility move: it is the sentence a scammer cannot send.

5. The one that cannot be rewritten

Hello, we noticed your business could benefit from our WhatsApp marketing service. Reply STOP to opt out.

There is no rewrite. This message is unfixable, not because of the copy, but because of the channel. WhatsApp's Business Messaging Policy is unambiguous: "You may only contact people on WhatsApp if: (a) they have given you their mobile phone number; and (b) you have received opt-in permission from the recipient confirming that they wish to receive subsequent messages or calls from you."

Both conditions. A number you scraped fails (a). A number a lead-gen vendor sold you fails (a) and (b). "Reply STOP to opt out" is an opt-out mechanism bolted onto a message that required an opt-in to exist, which is like adding a fire exit to a building you were not allowed to enter.

Cold WhatsApp is not a hard channel or a risky channel. It is a closed channel, and any tool that offers it to you is offering to break a rule on your behalf using your business account as the collateral. This is why our own outreach sequences run on Telegram, email, X and the social inbox and not on WhatsApp: there is no compliant way to build the feature. We use WhatsApp for conversations people started, in the unified inbox, and WhatsApp Learning is deliberately read-only, meaning it studies your past exported chats to learn how you write and never sends a message to anyone.

The advice that tests badly

Now the section that will annoy people, including us, because it contradicts things we have said.

Sopro analysed 650,000 prospecting emails sent in 2025, all of them written for a specific prospect rather than templated, and scored each one for the behavioural bias it leaned on. Then they compared lead rate against the baseline across all 650,000. The results invert most of the standard cold outreach playbook:

TechniqueLead rate vs baselineTypical example
Near-term result promised+52.5%"See impact in week one."
Distinctiveness stated+30.4%"The only tool that does X."
Framed as a habit that is easy to start+16.3%"Set once, then it runs each day."
Collaboration framing+16.1%"We'll do this together."
Optimistic tone+6.4%"There's scope to lift conversion."
Opportunity-led opening+4.5%"There's a clear opportunity to..."
Authority signals-12.2%"Multi-award winning." "Featured in the FT."
Social proof-12.4%"Used by 2,000 companies."
Explaining your reasoning-19.8%"We warm inboxes gradually, which reduces spam flags."
Educational or advisory content-24.2%"In 10,000 sends, personalised subject lines lifted replies 30%."
Empathy-27.3%"I know it's tough keeping pipeline steady."
Customer-first framing-30.7%"You're likely focused on hitting revenue targets."
Reciprocity, giving something first-32.3%"Here's a short guide, no sign-up."
Problem-led framing-45.7%"Many sales teams struggle to maintain pipeline momentum in Q4."

Look at the bottom row. "Lead with the prospect's pain" is the most widely taught opener in B2B outreach, and it tests at minus 45.7% against baseline. Lead with empathy: minus 27.3%. Give value first: minus 32.3%. Cite your customers: minus 12.4%. Four pillars of the standard playbook, all negative.

Now the caveats, because a table this convenient deserves suspicion:

  • This is email, not DM. Nothing here was measured in a chat window. The mechanics differ, and the direction may not transfer cleanly.
  • It is correlational. Nobody randomised which prospects got empathy. It is entirely possible that writers reach for empathy when they have nothing specific to say, in which case empathy is a symptom of a weak message rather than its cause.
  • It is one agency's book of business. B2B, UK and US, largely mid-market, across their client mix. Your market may behave differently.
  • The scoring is AI-assigned. Sopro says they moved from keyword matching to model-assessed tone and intent, which is better and also introduces a classifier's opinion into the independent variable.

With all of that said, the direction fits the mechanics too well to dismiss. Sopro's own explanations are the useful part. On problem-led framing: starting with a problem "makes readers defensive". On empathy: "For many offerings, you cannot know their exact challenges. Leading with guessed problems and positioning yourself as the fix can make you sound presumptuous or arrogant if the assumption misses the mark." On social proof: "real social proof comes from other people building your credibility. In an outreach email, you're landing in someone's inbox as a stranger and saying, 'Everyone loves me, trust me on that.'"

All three failures share one structure: they are moves that work once you have permission, deployed before you have it. Empathy from a colleague is warmth. Empathy from a stranger who guessed your problem is presumption. A case study from a vendor you are evaluating is evidence. A case study from a vendor you have never heard of is a stranger asserting their own popularity. The technique is not wrong. The sequence position is.

That transfers to DM more strongly than to email, not less, because DM is a more intimate channel and the permission gap is therefore wider. The one that survives the transfer best is distinctiveness at +30.4%, because saying the one true specific thing about what you do is the only move on the list that does not require the reader to already trust you.

And notice that both winners are compatible with 35 words while most of the losers structurally are not. Empathy takes a sentence. Explaining takes two. Social proof takes a clause plus a number. Problem-led framing takes an entire paragraph before you get to the point. The length data and the bias data are pointing at the same thing from different directions.

Timing: one lever that matters, and three that do not

The lever that matters is trigger recency. A message that references something that happened this week is a different object from the same message sent to the same person about the same thing eight weeks later. It has a reason to exist now, which is the single hardest thing for a cold message to have. Funding, a hire, a launch, a pricing change, a job posting that contradicts the strategy, a competitor's move, a post they wrote: any of these buys you a legitimate "why now", and "why now" is what separates outreach from noise in the recipient's head.

The levers that do not matter, in descending order of how much ink has been spilled on them:

Best hour to send. For email this is at least arguable, because email sits in a pile and position in the pile is a function of arrival time. A DM is a push notification. It arrives on a lock screen, alone, at whatever moment it arrives. There is no pile and no position. It also arrives in a timezone you probably guessed wrong. Every "send DMs at 9am Tuesday" claim you will read is either email research being smuggled across channels, or one vendor's dataset with unpublished confounds. Do not spend a sprint on this.

Day of week. Same reasoning, less evidence.

Follow-up delay tuning. Whether the bump lands at 48 or 72 hours is not what is limiting you. Whether it should exist at all is, and that is the next section.

There is one timing lever nobody talks about because it is boring, and it matters more than all three of the above: the gap between your own sends. Our defaults put a 10 second floor between messages and force a 2 minute break after 10 consecutive sends. Ten seconds sounds arbitrary until you notice that a human genuinely cannot open a chat, read a name, and send a considered message faster than that. Sub-second gaps are not fast, they are a signature. This is what people mean by flood wait avoidance, and it is why our sequences back off automatically for two hours on a peer-flood error rather than retrying, since retrying into a flood wait is how a temporary limit becomes a permanent one. The Telegram ban avoidance guide goes through the rest of the pacing rules.

On the receiving side, timing flips from marginal to decisive: how fast you answer a reply matters enormously, and DM breaks most of the assumptions the email-era speed-to-lead research was built on. That is its own subject, covered in the speed-to-lead piece.

The follow-up curve, and where it turns negative

Be honest about the state of the evidence: there is no credible public dataset on DM follow-up curves. There are dozens of blog posts with confident numbers, almost all of which trace back to email studies or to a vendor's unpublished internals. So reason from mechanics instead, and be explicit that this is reasoning.

The mechanics are an asymmetry. Each additional follow-up adds a small, declining amount of reply probability. It adds a non-declining, arguably increasing amount of report probability, because the thing that makes someone report you is not the first unwanted message, it is the evidence that you will not stop. A second message proves the first was not a mistake. A fourth proves you are a system.

In email, the cost of that is a spam complaint, and Google's threshold gives you a budget: stay under 0.10%, never touch 0.30%. In DM, the cost is a report against a single account with no budget, no visibility, and a penalty that lands on your whole operation. The asymmetry is much worse.

TouchWhat it plausibly buysWhat it costsVerdict
1. OpenerThe whole reply rateBaseline report riskObviously send it
2. One bump, 3 to 5 days later, adding something newA real increment. People miss messages. This is the cheapest reply you will ever buy.Small. Two messages still reads as a person.Send it
3. Third touchA small increment, mostly from people who were going to reply anywayNow it reads as a sequence, because it is oneOnly if you have a genuinely new reason
4. "Just bumping this to the top of your inbox"Close to nothing. This message contains no information.This is the shape people report. You have proven you are automated.Do not send
5. "Should I close your file?"Replies from irritation, which do not convertManufactured scarcity from a stranger reads as manipulation, because it isDo not send

The rule we would defend: two touches on DM, three if the third carries genuinely new information, then stop. Not "stop for now". Stop, and move the contact to a status that means something, so that when a real trigger appears in six months you approach them fresh rather than as touch seven of a sequence they already resented. That is a CRM job, not a sequencing job, and it is why contact records with proper status and lead scoring matter more to outreach outcomes than the sequencer does.

Two mechanical requirements make this rule enforceable rather than aspirational. First, stop-on-reply, which in our sequences defaults to on: the instant someone replies on any channel, every remaining step for that contact is cancelled. The alternative, a sequence that keeps firing at someone who already answered, is the single fastest way to earn a report, and it happens constantly when the sequencer and the inbox are different products that do not talk to each other. Second, a shared record across channels, so that a Telegram touch and an email touch and an X touch count against the same person rather than each running their own independent five-step campaign at someone who now thinks your entire company is harassing them.

The follow-up question people should ask instead of "how many": what would make touch two worth sending? If the honest answer is "nothing, I just want to check in", you have your answer, and it is that the first message did not earn a reply and repetition will not fix that.

Where cold DM has already closed

This is the section most vendors will not write, because most vendors sell the thing. Cold DM is not uniformly viable across platforms. On several it is finished, and the finish is not subtle: it is written in the terms you agreed to.

ChannelWhat the platform actually saysVerdict for cold outreach
WhatsAppYou may only contact people who gave you their number and opted in to receiving messages. Blocks and reports drive a quality tier that throttles your sending.Closed. Not a cold channel under any reading.
Facebook Messenger (API)A 24-hour standard messaging window that only opens when the person contacts you. Outside it you need approved message tags, one-time notifications, or sponsored messages.Closed to initiation. Excellent for conversations people start.
Instagram (API)Same windowed model, and Meta's docs state that one-time notifications, news messaging and sponsored messages are each "not available for IG Messaging API".Closed to initiation.
Instagram (manual)"Limits in place to stop direct messages that people may not want to get." Warnings escalate to a sending block. No published numbers. Cold messages land in Requests.Narrow and shrinking. Viable at genuinely small volume with a real reason.
LinkedInNo third-party software that automates activity, at all. Invitations restricted for volume, ignored invites, or suspected automation. 98.6% of spam enforcement is automated.Open by hand, closed to tooling. The gap between those two is the whole risk.
X"You may not send unsolicited Direct Messages in a bulk or automated manner." Identical DMs prohibited. Being followed is not consent. Separately, AI reply bots on posts and mentions need prior written approval from X.Narrow. One-to-one and human, or not at all.
TelegramNo published quota. Report-driven limits where a "simple hello" is a stated example. Star Messages let anyone charge strangers for the right to message them.The most open, and actively closing.
EmailNot a DM channel, but the honest comparison. Published thresholds, measurable complaint rates, an actual feedback loop.Open, and the only channel that tells you when you are failing.

The Telegram row deserves expanding, because it is the clearest signal of where this is all heading. In March 2025 Telegram shipped Star Messages, letting people set a fee, paid in Telegram Stars, for incoming messages from anyone outside their contacts. Contacts still message free. Specified users and groups can be excepted. Everyone else pays.

It is implemented at the protocol level, not as a UI filter: the API documentation shows senders must supply an allow_paid_stars parameter or receive an ALLOW_PAYMENT_REQUIRED error, and there is a bulk endpoint for checking payment requirements across many users at once. That last detail is the one to sit with. Telegram built an efficient way for a sender to check, in bulk, which of their targets have put a price on being contacted. They are not fighting cold DM. They are metering it.

Telegram's own framing is that this lets people "filter out unwanted messages and avoid inbox overload" and keep chats "focused and free from spam". Read it as a market clearing: the platform has decided that a stranger's attention has a price, and is collecting a cut of it. Once one platform proves you can charge rent on the cold inbox, the pressure on the others to do the same is obvious. This is why the long-run answer to "how do I get more replies from cold DM" is probably "you do not, and you should be building something else in parallel".

LinkedIn's row deserves a note too. Its policy against third-party automation is absolute, with no volume exemption and no "safe tool" carve-out. Its prohibited software page warns that members who use these tools "risk having their accounts restricted or shut down" and that "any prohibited tools they're using may become non-operational without notice". Both halves of that sentence have been repeatedly demonstrated in public. Anyone selling you LinkedIn automation is selling you a bet against an adversary that catches 98.6% of spam automatically and has your entire graph, and the stake is a professional network you spent years building and cannot export.

What grew while cold DM shrank

The honest alternative is not a clever new cold channel. It is that the cost of a stranger's attention went up, and the cheapest attention now comes from people who have already shown you something.

Sopro's survey found that 80% of recipients are more likely to engage with outreach sent on their preferred channel, and that B2B buyers now name an average of 2.9 preferred channels when asked how they want to be contacted, up from 2.5 the year before. The implication is not "be everywhere". It is that channel choice is the recipient's, not yours, and cold DM is a channel you chose for them.

What that leaves, in rough order of how much it costs to build:

  • Conversations people start. A live chat widget on a pricing page is a person who is already thinking about you. The economics are not comparable to cold DM and it is not close.
  • Intent you can see. Live Visitors shows who is on which page right now, with UTM and ad-click attribution, and fires an alert when a visitor goes hot. Messaging someone who read your comparison page twice this week is not cold outreach, it is a response with a delay.
  • Reach earned in public. Slow, unglamorous, and the only thing that makes the eventual DM land, because Sopro's data has 61% of vendors reporting that buyers are less trusting of prospecting than before and 71% saying most outreach they receive feels sales-led rather than helpful. Familiarity is the counter to both.

The uncomfortable part: all three are slower than cold DM, and none of them fill a pipeline this quarter. If you need meetings in three weeks, they do not help, and anyone who tells you otherwise is selling a content strategy. The correct response is to run cold DM as a small, careful, deliberately unscaled channel while you build the ones that compound, not to pretend either half is sufficient alone. The channel benchmark piece has the wider picture on where conversations are actually happening.

If you are doing it anyway: the operating checklist

Assume you have read all of the above and decided cold DM is still worth it for your market. Reasonable. Here is what "carefully" actually means in settings and rules rather than vibes.

On the list. Cut it until it hurts, then cut it again. The 356% conversion difference in Sopro's filtered-audience test came from removing people, not adding them. If you cannot articulate why this specific person, in one sentence, without using their industry or company size, remove them.

On the accounts. One account per real human, with a real history. Account rotation exists in our sequences and it is a load-balancing tool, not a stealth tool: rotating six accounts through one identical script does not disguise the script, it just distributes the evidence. If your plan depends on rotation making a bad pattern safe, your plan is to lose six accounts instead of one.

On the pacing. Start well under the defaults, not at them. The 20 per hour and 50 per day figures are ceilings for an established account, not targets for a new one. A two-week-old account sending 50 DMs a day is a two-week-old account sending 50 DMs a day, and no copy fixes that.

On the flood-wait response. When the platform pushes back, stop. Our sequences take an automatic 2 hour penalty pause on a peer-flood error and escalate to 8 hours on repeat, because the alternative behaviour, retrying immediately, is the single clearest bot signature available and it converts a temporary limit into a permanent one. If your tool retries into a rate limit, replace your tool.

On stop-on-reply. On, always, across every channel, sharing one contact record. This is not a nice-to-have. See the follow-up section.

On what AI is for. Research and triage, not authorship. Our AI Agents are worth being precise about here, because the distinction is the whole ethical question: they read incoming messages and reply in your voice across Telegram, X, email and the social inbox, with personas, knowledge bases, a rules engine, rate limits, human handoff and per-contact pause. They answer people who messaged you. They do not initiate cold conversations with strangers, and we did not build that, because on most of these platforms it is a policy violation and on the rest it is a bad idea.

On measurement. Track reply rate, but do not optimise it. Optimise reply-to-meeting and meeting-to-close, because those are the metrics the over-contacted-prospect finding poisons. A rising reply rate with a falling close rate means you found the people who answer everything.

On the law. Everything above is platform terms, which bind you regardless of what your jurisdiction permits. The legal layer sits on top of it and is a separate exercise: GDPR legitimate interest versus consent, ePrivacy, CAN-SPAM, CASL, and the question of where DM sits in all of it. The compliance piece covers that ground properly. Being legal does not make you compliant with the platform, and the platform is the one that can delete you tomorrow without a hearing.

Common questions

What is a good reply rate for cold DM outreach in 2026?

Nobody can tell you honestly, and treat anyone who does with suspicion. There is no credible public dataset for DM reply rates the way there is for email, and the numbers circulating in blog posts are overwhelmingly vendor self-reports with no methodology, frequently citing each other in circles. What we can say from mechanics: an untargeted templated DM performs terribly, and a researched one-to-one message to a well-chosen person performs many times better. Measure your own baseline and ignore the benchmarks.

Does spintax stop my messages getting flagged?

It defeats exact-match duplicate detection and nothing else. Your send rate, your ratio of conversations started to conversations answered, your graph distance from recipients, your client fingerprint and your report rate are all untouched by rewording. Spintax is useful for avoiding the crudest checks and for making messages read less robotically. It is not a cloaking device, and treating it as one leads people to send more, which is the actual problem.

Is it safe to use LinkedIn automation tools if I keep the volume low?

No, and volume is not the variable. LinkedIn's prohibition on third-party software that automates activity has no volume threshold in it. Low volume reduces how quickly you trip a behavioural signal; it does nothing about the client fingerprint, which is a separate detection route entirely. You may get away with it for a long time. The expected cost is your account and your entire connection graph, which you cannot export or rebuild.

Can I cold DM people on WhatsApp if I add an opt-out line?

No. WhatsApp's Business Messaging Policy requires that the person gave you their number and separately opted in to receiving messages, both conditions, before you contact them at all. An opt-out line at the bottom does not retroactively create the opt-in the policy requires. Blocks and reports feed a quality tier that throttles your business account. WhatsApp is a channel for conversations that already exist.

Should the first message ask for a meeting?

Usually not, and the reason is arithmetic rather than etiquette. A meeting ask converts the reply decision into a calendar decision, which is a much bigger commitment from someone who does not know you. A question that can be answered in one line converts a stranger into a correspondent, and correspondents book meetings. The exception is when you have a strong trigger and the ask is small and specific, in which case skipping the dance is respectful of their time.

Does AI-written outreach get detected by the platforms?

The question assumes the classifiers care what wrote the text, and the published policies suggest they mostly care what the account did. A model-written message sent one at a time by a real human with a real reason looks like a human message. A human-written message blasted to 4,000 people at four per minute looks like spam, because it is. The AI risk is not detection, it is that AI makes sending cheap, and cheap sending produces the exact behavioural pattern that gets caught.

Where to start

Pick twenty people. Not two hundred, twenty. Spend an hour, so three minutes each, finding the one true thing about each of them that changes what you would say. Send twenty messages of under forty words, by hand, one at a time. Send exactly one follow-up to the silent ones five days later, carrying something new. Then count meetings, not replies.

If twenty researched messages produce nothing, the problem is your offer or your targeting, and eight thousand messages would have hidden that from you for another quarter while burning your list and your accounts. If they produce something, you now have a message worth scaling carefully, in that order, which is the only order that works.

When you are ready to run it as a system rather than a spreadsheet, multi-channel sequences handle the pacing, the flood-wait backoff and the stop-on-reply logic, and keep the replies in one place so the second message knows what the first one said. There is a free plan; the pricing page has the details.

Enjoyed this article?

More research-backed writing on omnichannel sales, AI agents, and outreach that survives contact with the platforms.

Explore More Articles

We value your privacy

We use cookies to improve our site, analyze traffic, and personalize ads. You can accept all, reject non-essential, or customize your choices. Read our Cookie Policy.