Skip to content
India

Cold outreach in India — what works in 2026

Two of India's four outbound channels cannot legally carry a cold first touch. Which ones can, what TRAI and the DPDP Rules changed, and how to sequence the rest.

21 Jan 2026 13 min readBy Autocloz Editorial, Growth team
Cold outreach in India — what works in 2026

Four outbound channels reach Indian buyers, and two of them cannot legally carry a cold first touch. SMS runs on a registration regime where consent is inferred from a pre-approved content template, so there is no shape of message that reaches a stranger. WhatsApp requires a Meta-approved template before a business can speak first, and since July 2025 charges per message for it. That leaves email and LinkedIn as the channels where an unsolicited opener is structurally normal, and turns SMS, WhatsApp and calling into follow-up channels you earn.

The four channels, and which of them can carry a first touch at all

The distinction that matters in India is not which channel converts. It is which channel has a legal mechanism for reaching somebody who has never heard of you.

  • Email. No Indian telecom registration applies. Governed in practice by the receiving mailbox providers' sender requirements and by data-protection law. A cold first touch is ordinary.
  • LinkedIn. A platform's own rules rather than a regulator's. A connection request or InMail to a stranger is the product working as designed.
  • WhatsApp. Business-initiated contact requires a template Meta approved in advance, in a named category, and the recipient's number has to be one you hold lawfully. Possible, but never spontaneous.
  • SMS. Registered sender, registered header, registered content template, scrubbed against preference registers on the access provider's DLT platform. There is no route for a message to somebody outside that structure.
  • Voice. A registered sender calling from a designated number series, with the series itself now announcing the category of the call.

That ordering is a legal fact, not a performance claim. Anyone quoting you a reply-rate multiplier between Indian channels should be asked where the number came from, because no public dataset supports one.

Cold SMS is closed in India, and the closing mechanism is the content template

The Telecom Regulatory Authority of India runs commercial messaging through the Telecom Commercial Communications Customer Preference Regulations, and the Second Amendment Regulations, 2025, notified on 12 February 2025, tightened the structure considerably.

The provision that ends the cold-SMS conversation is a proviso added to the definitions: in the case of commercial messages, consent "may be clearly and reasonably inferred from the registered Content Template". Read that carefully. Consent is not a checkbox you collected and can produce on request — it is inferred from the fact that a specific message body was registered, by a specific registered sender, for a specific purpose. A message to somebody who never transacted with you does not fit any template you could get registered, because the template registration process itself asks what relationship produces the message.

Two further provisions from the same amendment make the shape of the system obvious.

Headers now carry their own category label. Schedule-I is amended so that the SMS header is an 11-character alphanumeric string, with the type of commercial communication identifiable "by suffixing '-P', '-S', '-T', and '-G' for Promotional, Service, Transactional, and Government Messages, respectively". Your recipient can see what kind of message arrived before opening it, which removes the trick of dressing a promotion as a service update.

Consent has a lockout after opt-out. The amendment provides that a sender "shall be allowed to re-acquire consent of such customer only after ninety (90) days from the date of revoking consent or opting-out", while the customer may opt in again at any time of their own accord. Consent-seeking messages themselves go through a short code — the regulation specifies 127xxx or such other code as the Authority prescribes — and must clearly name the Principal Entity or brand.

The mechanics of the registration itself, and what the same amendment changed about enforcement, are an operational subject of their own: the DLT stack, the enforcement thresholds and the cost model is where that belongs, and what DLT registration involves is the shorter definition.

WhatsApp opens with an approved template, and since July 2025 it opens per message

WhatsApp is the channel Indian buyers actually read, and it is also the channel with the strictest opening rule.

Non-template messages can only be sent inside an open customer service window, which lasts 24 hours and opens when the WhatsApp user messages the business. Outside that window, a business-initiated message must use a template Meta approved in advance, in one of the marketing, utility or authentication categories. There is no setting that changes this, and a platform that appears to let you send free-form text to a cold number is either inside a window you did not notice or about to fail.

The economics changed on 1 July 2025, when Meta moved the Business Platform from conversation-based pricing to per-message pricing — charging when a template message is delivered rather than for a 24-hour conversation window. Marketing templates are charged on delivery. Utility and authentication templates are charged outside the customer service window and, since the same date, utility templates delivered inside an open window are free. All messages, template messages included, are free for 72 hours inside an open free entry point window.

India then got its own billing track. Meta's pricing documentation records billing localisation launching for eligible Indian customers on 1 January 2026 with INR as a currency option, a requirement that eligible customers migrate every WhatsApp Business Account in their portfolio to INR by 31 December 2026, a higher India marketing rate effective 1 January 2026, and a higher India authentication-international rate effective 1 April 2026. Rates move; the structure is what to plan against. How the Business Platform is actually assembled, from WABA to template to webhook covers the setup, and the Meta WhatsApp Cloud API integration is the direct path for a team that wants no reseller in between.

Calling now announces its own category through the number series

The February 2025 amendment also restricts senders from using ordinary ten-digit numbers for telemarketing. TRAI's accompanying press release of 12 February 2025 puts it plainly: "While the 140 series will continue to be used for promotional calls, the newly allocated 1600 series is designated for transactional and service calls."

Two consequences for an outbound team.

The recipient can classify your call from the caller line identification alone, before answering. A promotional call announces itself as promotional. That is the intent of the design.

The series constrains what you may say on it. The regulation's reasoning is explicit that promotional auto-dialled or robo calls "should be permitted through 140-series numbers only" and that service and transactional auto-dialled calls belong on 1600 or another series allotted for the purpose. Misusing a 1600-series number for promotion is called out as deserving stringent treatment precisely because customers are expected to trust that series.

There is a counterpart obligation pointing the other way. A new regulation 34A prohibits call-management applications from blanket-blocking or tagging the designated commercial series as spam, while preserving each consumer's right to manage their own preferences individually. The trade is legibility for reachability: your call is labelled, and in exchange it is not silently filtered as a class.

Email is the one channel where the rules are not Indian at all

The most useful thing to understand about cold email into India is that the Indian telecom regime does not reach it. TRAI's framework governs commercial communication on licensed telecom networks. Ordinary internet email is not that.

What governs it instead is the receiving side. A message to an Indian professional lands at Google Workspace, Microsoft 365 or a hosted provider, and the requirements that decide whether it is accepted are the same authentication and complaint-rate rules that apply anywhere — SPF and DKIM published, DMARC alignment on the domain the recipient reads, complaint rate low enough that the provider keeps taking your mail. The seven levers that decide which folder a message lands in apply unchanged to an Indian recipient list.

The Indian layer that does apply is data protection, and it applies to the contact record rather than to the transport.

The DPDP Act and its Rules: what binds now and what starts in May 2027

India's data-protection regime is now complete on paper and staged in time, which is a combination that produces a lot of confident wrong statements. Here is the primary record.

The Digital Personal Data Protection Act, 2023 was enacted on 11 August 2023. The Digital Personal Data Protection Rules, 2025 were notified by the Ministry of Electronics and Information Technology as G.S.R. 846(E) on 13 November 2025. Rule 1 stages what starts when: rules 1, 2 and 17 to 21 came into force on publication; rule 4, which governs Consent Manager registration, comes into force one year after publication; and rules 3 and 5 to 16 together with 22 and 23 come into force eighteen months after publication, placing them in mid-May 2027.

The rules in that eighteen-month tranche are the ones an outbound team will feel.

  • Rule 3 — the notice. It must be "presented and be understandable independently of any other information", and must give "an itemised description of such personal data" and the specified purposes, plus a link by which the person may withdraw consent "with the ease of doing so being comparable to that with which such consent was given".
  • Rule 6 — security safeguards. Encryption or masking, access control, logs and monitoring, and retention of those logs and the personal data "for a period of one year" for detection and investigation.
  • Rule 7 — breach intimation. Affected individuals told "without delay", and the Data Protection Board given an initial description without delay and detailed information "within seventy-two hours of becoming aware of the breach".
  • Rule 14 — data principal rights. A grievance redressal system responding "within a reasonable period not exceeding ninety days".

The penalties under the Act are on a scale that makes this worth engineering rather than documenting: the Press Information Bureau's summary of the notification puts the maximum at up to ₹250 crore for failure to maintain reasonable security safeguards, up to ₹200 crore for failure to notify a breach or for violations concerning children, and up to ₹50 crore for other violations.

None of this is legal advice, and whether a given B2B contact record and a given outreach purpose sit inside consent or inside a legitimate use under the Act is a question for a lawyer on your facts. What is safe to say is procedural: an outbound programme that already records where a contact came from, when, and under what wording will have a much shorter path to compliance than one that does not.

A sequence shape that fits those constraints

Put the rules together and the sequence almost designs itself. The first touch goes on a channel that permits one; the channels that need permission come later, once the prospect has given it.

  1. Open on email or LinkedIn. These are the only two openers that do not require a pre-registered artefact.
  2. Add a call on the correct series where you have a number and a reason, accepting that the series labels the call.
  3. Move to WhatsApp only after the prospect has replied, or has explicitly asked for it. A reply opens the 24-hour customer service window, and inside that window you are sending free-form text at no per-message charge rather than paying for a marketing template that a stranger will report.
  4. Reserve SMS for people already inside a registered relationship, where a registered content template genuinely describes the message.
  5. Write in the language the prospect works in. Many Indian B2B conversations run in English and switch registers midway; a sequence that can carry a Hindi or regional-language template matters because Meta approves templates per language, and the product must be able to send the language that was approved rather than defaulting to one.

Autocloz's free plan covers 5 users and 10 mailboxes across email, calling, LinkedIn, SMS and WhatsApp in one login, with INR-native pricing and GST captured at checkout rather than a dollar list price converted at the till — start free if you want the whole sequence in one place before you register anything.

What this playbook cannot promise, and what Autocloz does not do

The honest boundaries are worth more than another paragraph of encouragement.

No reply-rate claim here is measured. There is no public dataset comparing channel performance for Indian B2B outreach, and any specific multiplier — including ones that have appeared on this site in the past and have since been removed — is an assertion rather than a finding. Everything above is an argument from what the rules permit.

Autocloz does not register anything with an access provider. Principal Entity registration, header registration and content-template registration happen on the DLT platform of an access provider, against your own entity, with physical verification and biometric authentication of your authorised person under the February 2025 amendment. The product carries fields to pin the ids you obtained — an SMS template row holds a dlt_template_id and a carrier_campaign_id — and it does not validate those ids against any registry. Treat them as your record, not as a check.

WhatsApp template gating is real; SMS template gating is weaker. The WhatsApp dispatcher refuses to send when a step names no template, when the linked template is not found in the workspace, or when its status is anything other than Meta's approved — and it treats the 24-hour window as closed unless it has evidence otherwise. The SMS dispatcher refuses when the linked template is missing or is not active. It does not check the registered id.

Quiet hours in the send gate use the sending account's time zone, not the recipient's. The per-lead time zone is honoured by the campaign sending window; the account-level gate is separate. For a list spanning Indian and overseas contacts, segment the campaigns or set the account to the strictest zone you send into.

Suppression is keyed to the identifier. An opt-out recorded against a phone number blocks that number. Making it block the same person's email as well requires writing the suppression against the wildcard channel, which is what makes one list gate every channel rather than one.

No software can tell you whether a specific message is lawful. Whether a content template describes your message honestly, whether an inferred consent covers a given contact, and whether your processing sits inside consent or a legitimate use under the DPDP Act are decided on evidence a product cannot see. Treat this as a description of published material — TRAI's Second Amendment Regulations of 12 February 2025 and the accompanying press release, the DPDP Rules at G.S.R. 846(E) of 13 November 2025, and Meta's own Business Platform pricing documentation — and take advice for your own situation.

Frequently asked

Can you send cold SMS to Indian mobile numbers?

Not in the way cold email works. Under TRAI's Telecom Commercial Communications Customer Preference Regulations every commercial SMS travels under a registered Header and a registered Content Template on an access provider's DLT platform, and the February 2025 amendment added a proviso stating that consent for commercial messages "may be clearly and reasonably inferred from the registered Content Template". Consent is therefore tied to a pre-approved message and a registered sender, not to a list you assembled. A lawyer should advise on your own programme.

Do I need an approved template to message someone on WhatsApp first?

Yes. WhatsApp's Business Platform only permits non-template messages inside an open customer service window, which lasts 24 hours and opens when the user messages the business. Any business-initiated first contact therefore requires a Meta-approved template in the marketing, utility or authentication category. There is no configuration that lets a business open a WhatsApp conversation with free-form text.

When do the DPDP Rules actually start applying to my outreach data?

The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E) on 13 November 2025, and rule 1 stages the commencement. Rules 1, 2 and 17 to 21 took effect on publication, rule 4 on Consent Manager registration takes effect one year after publication, and rules 3 and 5 to 16 plus 22 and 23 take effect eighteen months after publication — which places the notice, security-safeguard, breach-intimation and data-principal-rights obligations in mid-May 2027. Building for them earlier is cheaper than retrofitting.

Which outbound channel should an Indian B2B team lead with?

Email and LinkedIn are the two channels where an unsolicited first touch is structurally normal, because neither is governed by the DLT registration regime that gates SMS and neither requires a pre-approved template the way WhatsApp does. That is an argument about what the rules permit, not a claim about which converts better — no public dataset supports a reply-rate comparison across Indian channels, and any specific multiplier you are quoted should be treated as marketing until somebody shows the method.

What are the -P, -S, -T and -G suffixes on Indian SMS headers?

They are message-type identifiers appended to the sender header so a recipient can tell what kind of message arrived without opening it. TRAI's Second Amendment Regulations of 12 February 2025 amend Schedule-I to provide that the type of commercial communication can be identified from the header structure "by suffixing '-P', '-S', '-T', and '-G' for Promotional, Service, Transactional, and Government Messages, respectively". The header itself is an 11-character alphanumeric string.

Does India have an equivalent of the CAN-SPAM Act for email?

No single statute plays that role. India's telecom commercial-communication regime under TRAI governs calls and SMS on licensed telecom networks and does not reach ordinary internet email, while the Digital Personal Data Protection Act, 2023 and its 2025 Rules govern the processing of personal data regardless of channel. The practical consequence is that cold email into India is shaped by the receiving mailbox providers' requirements and by data-protection law rather than by a telecom regulation, and legal advice on your own facts is worth taking.

Share
Free to start

Stop reading. Start sending.

Every tactic in this article is implemented behind the Autocloz dashboard.