Back to blog
Engineering18 min read

Free Cold Email Prompt Generator (Personalised at Scale)

A free cold email prompt with six required inputs, a test for real personalisation versus merge fields, a tiered plan for scale, and CAN-SPAM, PECR and CASL rules checked at source.

NH
Nafiul Hasan
Founder, Prompt Architects

TL;DR: A cold email generator is only as good as its inputs. Give the model six: prospect, trigger, problem, proof, ask, constraints. Copy the prompt below, fill all six, and it writes a 90-word email. Skip one and you get mail-merge filler. Genuine personalisation does not scale linearly, so tier your list.

What is the best AI cold email generator prompt?

The best cold email prompt is a form, not a request. It has six required slots, and the email is never better than the weakest slot you fill.

Most AI prompts for outbound email fail in the same place, and it is not the writing. People type "write a cold email to a VP of Sales at a logistics company" and then blame the model for the sludge that comes back. The model did nothing wrong. It was asked to write about a person it knows nothing about, so it wrote the most statistically ordinary sales email in its training data. That is the correct answer to that question.

Here is the prompt. Paste it into ChatGPT, Claude or Gemini, replace the bracketed fields, and delete nothing.

ROLE
You write cold outbound email for a B2B seller. You are not a copywriter being
clever. You are a person with a specific reason to write to a specific person
today.

INPUTS
PROSPECT:     [name, role, company, headcount, and what this role is measured on]
TRIGGER:      [the checkable thing that happened, with a date and where I saw it]
PROBLEM:      [the specific problem I believe the trigger creates for them]
PROOF:        [one piece of evidence I can defend if challenged]
ASK:          [one small next step, not a demo and a call and a link]
SENDER:       [my name, my company, one line on what we actually do]

CONSTRAINTS
- Body: 90 words maximum. Count them and report the count.
- Subject line: 5 words maximum, lowercase, no colon, no question mark.
- Exactly one ask. No second ask in a P.S. No calendar link plus a reply request.
- Banned words: leverage, synergy, solutions, space, journey, reach out,
  circle back, touch base, quick question, hope this finds you well,
  I wanted to, just following up.
- No flattery. Do not compliment the company, the product, or the person's
  career unless the compliment is a specific checkable observation.
- Do not claim I read, used, tested or attended anything unless I said so in
  the INPUTS.
- Do not invent statistics, customer names, case studies or results. If PROOF
  is thin, write a weaker email rather than a fictional one.
- The TRIGGER goes in the first sentence, in plain language, not as
  "I saw that..." or "I noticed that...".
- End with a question answerable in one line.

OUTPUT
1. Subject line
2. Body, with the word count
3. WEAKEST INPUT: name the input that carried the least weight and tell me
   exactly what to go and find to strengthen it.

That last output line is the part people skip and the part that actually improves the next email. The model names which of your six inputs was thin, and it usually names TRIGGER or PROOF.

The six inputs, and why each one exists

Prospect is not a job title. It is a job title plus the number that person gets asked about in their Monday meeting. A VP of Customer Success is measured on net revenue retention. Write to the number.

Trigger is the reason you are writing today rather than last March, and it must be checkable by the recipient in under ten seconds. A funding round, a job ad, a pricing page change, a new integration on their changelog. If you cannot say where you saw it, you do not have a trigger.

Problem is a hypothesis, not a diagnosis. You are guessing, and the email is stronger when it admits that. "That usually means X breaks" invites a correction, and a correction is a reply.

Proof is one thing you can defend. One named account, one number, one before and after. Not three. Three reads as a brochure.

Ask is small. The lower the cost of saying yes, the more replies you get, and a reply beats a booked meeting that never happens.

Constraints are where the model earns its keep. Humans are bad at counting words and good at rationalising a fourth sentence. Models are the opposite.

Why does every AI cold email sound the same?

Because the prompt gave the model nothing that only you know. Strip out the company name and the ninety percent of AI-written cold emails are interchangeable.

Run this diagnostic on your last ten sends. Delete every sentence that would still be true if you swapped in a different company from the same list. If more than two sentences survive, you wrote a real email. If none do, you wrote a template with holes in it.

The three sentences your prospect has read a thousand times this year:

  • "I hope this email finds you well."
  • "I came across [Company] and was impressed by what you're building."
  • "Many companies in the [industry] space struggle with [generic problem]."

None of them carry information. They carry the appearance of effort, which is worse than no effort, because the recipient can tell the difference and now knows you tried to fake it.

What counts as real personalisation in a cold email?

A merge field proves you own a spreadsheet. An observation proves somebody looked. The gap between them is the whole game, and it is testable in about four seconds.

The swap test

Take the personalised sentence. Change the name and the company to a different prospect on the same list. Does it still read fine?

If yes, it is a merge field. Hi {{FirstName}}, I saw {{Company}} is growing fast survives any swap you can throw at it, which is exactly the problem. It is mail merge wearing a personalisation costume.

If the sentence collapses into nonsense after the swap, it is an observation. Good personalisation is brittle by design.

The so-what test

An observation without a consequence is trivia. "You raised a Series A in March" is trivia; the prospect was there. "You raised in March and have posted four SDR roles since, so somebody is about to own a ramp problem nobody owned last year" is a hypothesis about their week.

The reply comes from the second half of that sentence, never the first.

Merge fieldObservation
ExampleHi {{FirstName}}, I saw {{Company}} is growing"Your careers page has two implementation roles asking for NetSuite, which reads like a customer you have not onboarded yet"
What it provesYou have a CSV with two columnsSomebody spent four minutes on their site
Survives the swap testYes, which is the problemNo
Cost per prospectZeroMinutes, and they are real minutes
What the reader learnsNothing they did not knowThat you understood a consequence
Scales linearlyYesNo, and pretending otherwise is the trap

The honest part: research does not scale linearly

Writing scales. Research does not. A model can produce fifty variations of a paragraph in under a minute and none of that changes the fact that somebody has to read fifty careers pages.

Do the arithmetic with your own numbers rather than mine. Say deep research runs fifteen minutes per account. Fifty accounts is twelve and a half hours, which is most of two working days before you have sent anything. Two hundred accounts is a fortnight. There is no prompt that makes that number smaller, and any tool that claims otherwise is either using public firmographic data and calling it research, or making things up.

So stop trying to personalise everything equally. Tier the list instead.

TierVolumeResearch unitWhat personalisation means here
A. Named accounts10 to 25Per prospect, 10 to 20 minutesA one-of-one first line nobody else on earth could have received
B. Segments100 to 300, in groups of 20 to 40Per segment, onceOne shared, checkable trait that is genuinely true of everyone in the group
C. Everything elseThe restNoneNo personalisation theatre at all. Short, honest, and openly untargeted

Tier B is where most teams get the leverage, and it is the tier almost nobody builds properly. The trick is that the observation is true of the segment, not the individual. "You are running Shopify Plus and posting for a retention marketer" is checkable, specific, and true of thirty companies at once. That is one research pass producing thirty relevant emails, and none of them are lying.

Tier C deserves a word of defence. The best-performing broad email I have seen does not pretend. It says who it is going to and why, out loud: "I'm writing to heads of RevOps at Series B companies running Salesforce and Outreach. If that's not you, ignore this." Nobody feels tricked, and honesty reads better than a costume.

How do you run one prompt across 50 prospects?

Split the prompt into two kinds of field: the ones that change per segment, and the ones that change per prospect. Then fill the second kind with short facts, never sentences.

This is the entire trick. Fifty prospects does not mean fifty essays. It means five segment observations plus fifty short factual fields, and a short factual field takes seconds to collect.

# SEGMENT FIELDS — change 5 times across 50 prospects
SEGMENT_NAME:        {{segment_name}}
SEGMENT_OBSERVATION: {{segment_observation}}   # checkable, true of the whole group
SEGMENT_PROBLEM:     {{segment_problem}}       # the consequence you're betting on
PROOF:               {{proof}}                 # one defensible piece of evidence
ASK:                 {{ask}}                   # one small next step

# PROSPECT FIELDS — change 50 times, one short fact each
FIRST_NAME:          {{first_name}}
ROLE:                {{role}}
COMPANY:             {{company}}
PROSPECT_DETAIL:     {{one_checkable_detail}}  # 8 words max, no adjectives

# INSTRUCTIONS
Write the email using SEGMENT_OBSERVATION as the opening line and
PROSPECT_DETAIL as the single specific hook in sentence two.
If PROSPECT_DETAIL is empty, do NOT invent one. Write the email without it
and flag the gap at the end.
Apply all CONSTRAINTS from the base prompt.

The rule that makes this safe is the one about an empty PROSPECT_DETAIL. Without it, a model handed a blank field will confidently fill it, and you will send fifty emails containing fifty invented facts. With it, you get a flag and a slightly plainer email.

If you want the underlying mechanics rather than the sales use case, reusable prompt variables for teams covers the same pattern applied to engineering work, and building a brand-voice context covers the half of this that keeps every output sounding like your company rather than the model's default.

There is no global answer. Three of the major regimes disagree with each other on the single most important question, which is whether you need permission before the first message.

United States (CAN-SPAM)United Kingdom (PECR + UK GDPR)Canada (CASL)
Consent before the first email?NoNot under PECR for corporate subscribers. UK GDPR lawful basis still requiredYes. Express or implied
B2B carve-outNone. The FTC states the law "makes no exception for business-to-business email"The electronic mail rule does not apply to corporate subscribers. Sole traders and some partnerships count as individualsNarrow. A conspicuously published address, no "no unsolicited" notice, and the message must be relevant to their role
Identify yourselfAccurate headers, honest subject line, disclose it is an adMust not disguise or conceal identityBusiness name, plus name of anyone you send on behalf of
Address requiredValid physical postal addressValid contact address for opt-outMailing address plus phone, email or website, valid at least 60 days
Opt-out handlingHonour within 10 business days. Mechanism live for at least 30 daysAct on it promptly. Keep a do-not-contact list and screen against itWithin 10 business days, at no cost to the recipient
Maximum penaltyUp to $53,088 per emailICO guidance is flagged as under review following the Data (Use and Access) Act; cap not verified for this postCAD $1,000,000 for an individual, $10,000,000 for any other person

The United States is an opt-out regime

CAN-SPAM does not ask permission. It asks for honesty and an exit. The FTC's compliance guide is blunt that there is no B2B exemption, that each violating email carries its own penalty, and that hiring an agency does not transfer your liability: "you can't contract away your legal responsibility to comply with the law."

The trap here is the opt-out mechanism, not the sending. It must work for at least thirty days after you send, you cannot charge for it, and you cannot demand anything beyond an email address to process it.

The UK exempts companies, not people

This is the one most teams get half right. The ICO's PECR guidance on electronic mail marketing says you may email any corporate body, and adds that keeping a do-not-email list for objectors is good practice. Sole traders and several partnership types are classed as individual subscribers, so they need consent like anyone else.

But PECR is only the first gate. The ICO's business-to-business marketing guidance is explicit that UK GDPR still applies to any personal data, and it carries two points that scraped-list outbound routinely ignores.

First, sourcing. If you collect personal data from somewhere other than the person, you must provide privacy information "within a reasonable period of obtaining the data and no later than one month from the date of collection", subject to exceptions. Most cold outbound never does this.

Second, professional networks. The ICO's position is that people on professional networking sites are "unlikely to be on the sites exclusively in their business capacity", and that where somebody is using such a platform in a personal though professional capacity, "sending them direct marketing messages is not considered B2B marketing". That undercuts a common assumption about LinkedIn-sourced lists.

Both ICO pages currently carry a banner saying the guidance is under review following the Data (Use and Access) Act, so re-check before you rely on it.

Canada asks first

CASL runs the other way. ISED's guidance on getting consent states that businesses must obtain consent before sending commercial electronic messages, and be ready to prove it. Consent is express or implied, and implied consent is time-limited: up to two years from an existing business relationship, or six months from an inquiry.

The B2B route that outbound teams actually use is section 10(9)(b) of the Act. Implied consent exists where the recipient "has conspicuously published" the address, the publication carries no statement refusing unsolicited commercial messages, and "the message is relevant to the person's business, role, functions or duties in a business or official capacity". All three conditions, every time. A published address alone is not enough, and neither is relevance alone.

Penalties are set by section 20(4) of CASL: a maximum of $1,000,000 for an individual and $10,000,000 for anyone else.

The EU is not one rule

PECR is the UK's implementation of the ePrivacy Directive. Every member state implemented the same directive separately, and they did not land in the same place, so "GDPR-compliant cold email" is not a meaningful phrase on its own.

Germany is the clearest counterexample. Section 7 of the Act against Unfair Competition, published in English on the Federal Ministry of Justice's own portal, treats advertising "using an automated calling machine, a fax machine or electronic mail without the addressee's prior express consent" as an unacceptable nuisance. Note what it does not do. The preceding clause on telephone advertising explicitly softens the standard for business recipients, requiring only "presumed consent" from a market participant rather than express consent from a consumer. The email clause draws no such distinction. A B2B cold email that is lawful in London can be unlawful in Berlin, and the statute itself confirms it implements Article 13 of the ePrivacy Directive.

I could not verify the EU-level texts directly for this post. EUR-Lex returns HTTP 202 and an AWS WAF challenge page to automated requests, on every URL form I tried, so the GDPR and ePrivacy Directive are cited here at one remove through national implementations and regulator guidance rather than quoted from the official journal. If you need the primary text, open EUR-Lex in a browser.

Deliverability is a separate gate

Legal and delivered are different problems. Google's sender guidelines require SPF or DKIM for all senders, valid forward and reverse DNS, TLS, and a spam rate reported in Postmaster Tools below 0.3%. Above 5,000 messages a day to Gmail accounts, you also need SPF and DKIM and DMARC, DMARC alignment on the From domain, and one-click unsubscribe on marketing mail.

None of that is law. You can be perfectly CAN-SPAM compliant and still land in spam, which is a good argument for tiering your list on quality rather than pushing volume.

What an AI cold email generator cannot do

It cannot find your prospects, verify their addresses, warm your domain, send anything, or tell you whether your sequence is legal where the recipient lives. It writes.

That is worth saying plainly, because the category is full of tools that blur it. A prompt is a writing instrument. Here is the honest division of labour:

  • Finding and verifying contacts. A data provider. Not us, and not any prompt tool.
  • Sending, sequencing and reply detection. A sending platform. Not us.
  • Domain warmup and deliverability monitoring. A deliverability tool plus Google Postmaster Tools. Not us.
  • Legal review of your programme. A lawyer in the recipient's jurisdiction. Definitely not us, and not a chatbot.
  • Writing, structuring and varying the message. This is the part a prompt actually owns.

Prompt Architects sits in that last bucket. It turns a rough instruction into a structured one, stores the result, and fills variables so a template survives contact with fifty prospects. It runs inside ChatGPT, Claude and Gemini through the browser extension, and through an MCP server for Claude Code or Cursor. It does not send mail.

If you want the same fillable-form pattern applied elsewhere, the code review prompt generator uses identical mechanics for engineering, the translation prompt generator applies it to tone-preserving translation, and the free SOP generator prompt applies it to process documentation. Same six-slot idea, different domain.

The uncomfortable summary is that the prompt is the easy half. Anyone can copy the block at the top of this page. The half that decides whether you get replies is the fifteen minutes somebody spends on a careers page, and no generator will ever do that for you.

Free Chrome Extension

Stop rewriting prompts. Start shipping.

Works with ChatGPT, Claude, Gemini, Grok, Midjourney, Ideogram, Veo3 & Kling. 5.0★ on the Chrome Web Store.

Create An Account

Frequently asked questions

Free Chrome Extension

Stop rewriting prompts. Start shipping.

Works with ChatGPT, Claude, Gemini, Grok, Midjourney, Ideogram, Veo3 & Kling. 5.0★ on the Chrome Web Store.

Create An Account