Prove your compliance
Use the Compliance page to see what applies where you send, then download consent evidence and opt-out records as CSV files you can hand to a reviewer.
Grant officers, procurement teams and boards ask the same questions every year. Where is your proof of consent? How do you honor an unsubscribe? Can you show us the records? Mailsoftly keeps that paperwork for you as you go, and the Compliance page is where you collect it.
This guide walks you through the page region by region, then produces the two files a reviewer usually asks for: a consent evidence report and an opt-out list. Both are plain CSV, so they open in any spreadsheet and attach to any questionnaire.
The page says so itself in one line: it helps you stay organized, and it is not legal advice. Nothing here replaces your own counsel or your privacy officer. What it does replace is the scramble to reconstruct records after the question arrives.
Open the Compliance page and pick where you send
Open Settings, then look under the Account group for Compliance. The page opens on the region that fits your workspace, and you can change it at any time. Two top tabs split the world into North America and Europe, and a quieter row underneath picks the country inside the active group.
- North America holds United States and Canada
- Europe holds EU and UK, and Türkiye
- Whichever region you last looked at is the one that opens next time
Each tab carries the short name of the rules it covers, so you can tell at a glance which regime you are reading. Pick the region your recipients actually live in, not the one your office is in. If you send to donors in several places, work through each tab in turn.
Every teammate can open this page and download the files. It is not restricted to admins and it is not tied to a particular plan.

Open the Compliance page in Mailsoftly
Read what the law asks of you in that region
The first card, What the law asks of you, sets out the obligations that apply to your recipients in that region in plain language. It is deliberately short: four items, no jargon, and a one line explanation under each.
- United States, under CAN-SPAM and CPRA: your postal address in every email, honest headers and subject lines, a working opt-out honored within 10 business days, and access or deletion requests from California residents
- Canada, under CASL and PIPEDA: consent before you send, identifying yourself in every message, an unsubscribe that works for 60 days, and the plain fact that you carry the burden of proof
- EU and UK, under GDPR and PECR: a lawful basis for every email, proof of consent covering who, when, how and what they agreed to, withdrawal that is as easy as giving, and requests answered within one month
A Good to know panel on the right adds the two things people most often get wrong in that region, such as the fact that pre-ticked boxes are not valid consent in the EU, or that implied consent expires in Canada.
Read this card once with your program in mind, then move down the page. The next two cards tell you which of these Mailsoftly is already doing and which parts are yours.

Check what Mailsoftly already handles
The Handled for you card is the one to screenshot for a questionnaire. Four items, each with a green check, and each one is true of every send on the platform rather than a setting you have to remember to turn on.
- Unsubscribe link in every campaign. It is added to every campaign by default, so a reviewer looking at any message you sent will find the way out
- One-click unsubscribe headers. Gmail, Yahoo and Outlook read these and show their own unsubscribe button next to your sender name, which is what large mailbox providers now expect from bulk senders
- Opt-outs honored immediately. Someone who opts out is excluded from the very next send, with no queue and no waiting period
- Consent recorded for every contact. Date, source and list membership are written to an audit trail as they happen, which is what makes step 5 possible
That last item is the quiet one, and it is the one procurement actually cares about. Mailsoftly is not reconstructing consent when you ask for it; the record was written when the contact arrived and it cannot be edited afterwards.
Read this card as "by default", not as "impossible to change". The unsubscribe footer is part of every campaign as the platform ships, and if your organization has an unusual arrangement in place, confirm what your workspace is actually sending before you quote this card in a written answer.

Put your postal address on file
The Needs you card holds the parts that are yours rather than the platform’s. On the United States and Canada tabs it starts with Postal address on file, because both regimes require a real physical address in commercial email. A green check means an address is saved and shows you what it is; an amber exclamation means it is missing.
- Press Edit, or Add address if there is none yet, and you land on your Company settings
- Save the mailing address your organization actually receives post at, including the suite or unit number
- Come back and confirm the row has turned green, then make sure the same address appears in your email footer
For nonprofits and public bodies this is usually the registered or main office address, and it is worth using the same one that appears on your filings so a reviewer comparing documents finds a match.
The remaining rows in this card are the two downloads, and they are the reason most people open this page.

Download the consent evidence report
Consent evidence report answers the question every regime asks in some form: who consented, when, and from where. Choose a scope in the list picker next to it, either All contacts or one specific list, then press Download. The CSV arrives immediately.
The file has nine columns:
- Email, First Name and Last Name identify the person
- Recipient Type reads individual or business
- Consent Date carries the moment the record was created, and the column header names the time zone it is printed in, taken from your own profile
- Consent Source says how the address arrived: import, form, api, manual, webhook, automation and so on
- Source Detail names the specific thing where one was captured, such as the form name or the import file
- Status reads consented or opted_out
- Opt-out Date is filled in for anyone who has opted out, and blank for everyone else
Choosing one list rather than All contacts is the usual move for a grant report, because it scopes the evidence to the program the funder is asking about.
The consent date comes from the contact’s own recorded history where one exists. For addresses that were already in your account before that history began, the file falls back to the date the contact record was created. That is a record date rather than a captured consent event, so if a reviewer asks for the original opt-in paperwork on an older list, expect to supply it from wherever you collected it.
Read the column headers as written. They are produced in English on every workspace, whichever language you use Mailsoftly in, so it is worth adding a one line key when you forward the file to a reviewer.

Download the opt-out list, then answer requests one by one
Opt-out list is the second download and the simpler one: every unsubscribed address with its date. Press Download and you get three columns.
- Opt-out Date, again in the time zone from your profile
- Scope, which reads all when the person opted out of everything, or campaigns when they only opted out of campaign mail
This is the file to hand to whoever runs your other systems. If your fundraising database, your case management tool or your event platform also emails people, that list is what keeps them from mailing someone who told you to stop. It is also the file to keep when you close out a program, so the record of who opted out survives the campaign that caused it.
The last row of the card, Data subject requests, is a signpost rather than a tool. When one person writes in asking what you hold or asking to be removed, press Open contacts, find them, and work from their profile. The Activity tab on a contact shows how that contact was created and how their subscriptions changed, which is the individual version of the evidence report and usually enough to answer the question in one reply.
Download both files on a fixed schedule, once a quarter is plenty, and keep them where your board minutes live. A dated file you already had beats a fresh export when someone asks what your records looked like at the time.
One more thing worth knowing when you answer a question about reversing an opt-out: when a recipient opts themselves out, no one on your team can undo it from the inside. Only that person can resubscribe. That is a limit on your own staff, and in a compliance review it reads as a feature rather than a missing button.
With the region set, your address on file, and both exports in hand, you can answer the standard consent and opt-out questions from your own records instead of from memory.


Ready to try it in your own account?
Free to start with your Google Workspace or Microsoft 365 account. No credit card required.