Cold Email Sent at 2am That Still Reads Like a Person

A founder wrote back to one of my cold emails this month with a single line. It said the note read like it had been written by a language model.

He was right, and it was the most useful reply I had received in weeks, because I had been staring at the response rate for a month trying to work out why it was flat. The mechanics of the system were fine. The addresses were real, the mail was landing in inboxes, the targeting was tight. The words were the problem, and the words were the part I had paid the least attention to, because the agent produced them so easily.

This is the whole system as it stands now, with the fix in it. It runs mostly unattended. The part that is not automated is the part that should not be.

Finding people who might actually hire someone

The lists you can buy are worthless for this. A list is a set of people who have not asked to hear from you, sorted by how easy they were to scrape. What I want instead is a signal that a specific person, this week, has a problem I could take off their plate.

So the agent watches for events, not titles. Someone launched a product and the launch post mentions a feature that is “coming soon.” Someone raised a small round and the announcement is honest about being two people. Someone posted, in public, that they are stuck on a thing I have done a dozen times. Each of those is a person with a reason to read an email from a stranger, and the reason is written in their own words, which means the email can quote it back to them.

The sources for those signals are public. Launch sites, indie founder communities, the comment threads under funding news, the places engineers go to complain. The agent reads them on a schedule and builds a short list. The list is small on purpose. A good week is a few dozen names, not a few thousand.

The address rule that cut bounces to six percent

The single biggest mechanical improvement in this whole pipeline was a rule about which email address to send to.

Early on, when the agent could not find a person’s address, it fell back to something plausible. The company’s contact page. A support alias. A privacy address, because that is the one every site is legally required to publish. Those emails bounced, or went to a ticketing system, or went to a lawyer. When I audited a batch, every single bounce had gone to one of those fallback addresses. Not most. Every one.

The rule now is that the agent only sends to an address on a domain the person personally controls, and it has to find that address, not guess it. The chain is usually: the person’s public bio links to a site, the site is on a domain they own, and somewhere on that domain, or in a public repository, or in a talk they gave, there is an address at that domain. If the chain breaks, the person is skipped. No fallback, no guess.

On the last batch I measured, that chain resolved a real address for about a quarter of the people the agent flagged, and the bounce rate on those was around six percent. The quarter is fine. The other three quarters were never going to read a note sent to a support inbox anyway.

Sending reputation lives on its own subdomain

This one I learned by burning a domain, and I would like you not to.

In an earlier life the main domain had sent a large volume of mail in a short window. Nothing malicious, just too much, too fast, from a domain that had no history of sending. The reputation damage from that was real and it did not fade. Months later, a carefully written one-to-one email from that domain would land in spam for reasons no header could explain.

The fix is structural. Cold mail goes out from a dedicated subdomain that exists for nothing else. The root domain, the one on the website and the resume and the real correspondence, never sends cold mail. If the subdomain’s reputation ever gets damaged, it gets retired and replaced, and the root is untouched.

Three details that matter more than they look:

The copy rule

Back to the founder who called it out.

What the agent had been producing was competent. Correct grammar, relevant details, a clear ask. It was also, on reread, unmistakably machine-written, in a way that is hard to name and easy to feel. Stacked noun phrases. Three parallel clauses where one would do. An offer described in the abstract, as a capability, rather than in the concrete, as a thing I would do on Tuesday.

The rewrite rule that fixed it fits on an index card, and the agent now reads it before drafting anything:

  1. One observation. Something specific from what they posted, in plain words, that shows the note is not a template.
  2. One offer. The single concrete piece of work I would take off their plate. Not a list of services. One thing.
  3. One ask. A single sentence. Usually a question they can answer with a yes.
  4. Eighty to a hundred and fifty words. Anything longer is the agent explaining itself.
  5. Plain language throughout. “I am a freelance developer looking for contract work” beats every clever version of that sentence.

There is a sixth rule, which is that the agent never quotes a rate. If the person has posted a budget, the note can acknowledge it. If they have not, numbers wait until there is a conversation. Naming a figure in the first email is how you get filtered by someone who has not yet decided whether they like you.

The difference in the drafts before and after the rule is immediate and a little embarrassing. The new ones read like a person who has read the post. Because, in every way that matters, one has.

The gate that stops the second email

Every reply, of any kind, goes into a file, and every name in that file is excluded from every future batch. Automatically, before the agent ever drafts. This sounds like a courtesy, and it is, but it is also the only reliable defence against the failure mode where two runs, days apart, each independently decide the same person is a good target.

The same gate covers people who never replied but were already sent to, people who were sent to from a different lane, and people who asked, in any wording, not to hear from me again. The agent does not get to decide whether someone is on the list. It checks, and if the check says no, the name does not exist.

What I still do by hand

I read every reply. The agent can classify them and it does, but a reply from a real person to a cold note is the scarcest thing in this entire pipeline, and I am not going to let a classifier decide what it means.

I also spot-read drafts before a batch goes out. Not all of them. Enough to catch the day the agent drifts back toward the noun-wall, which it does, slowly, if nobody is watching. A rule in a file holds the line most of the time. A person reading three drafts holds it the rest of the way.

That is the system. Signal-driven targeting, real addresses only, an isolated sending domain that was warmed properly, a copy rule small enough to remember, a do-not-contact gate that runs before the draft, and a person reading the replies. The scrapers, the address-resolution chain, the warm-up schedule, and the exact rules file the agent reads are the parts I install rather than publish.