The Email & CRM Vault

Email contingency planning: what to do when you get it wrong

Written by Beth O'Malley | 09/2026

 

Two situations, and almost nobody plans for either:

The first is when something goes wrong with your email. The link was broken, the discount code did not work, the merge field failed, or it went to a segment it should never have touched. Somebody is now standing behind your desk asking what you are going to do about it (#BeenThereDoneThat). 

The second is when something goes wrong with your business and email is how you tell people. The service is down, the product has been recalled, the deliveries are delayed, or you have charged people twice. Email is suddenly the most important channel you own, and it needs to work in the next hour rather than next Tuesday.

They look like different problems, and they share a spine. How well you handle either one is decided before it happens, by work nobody wanted to do when there was no incident to justify it.

 

 

 

Part one

You sent the wrong thing (OOPSIE). Now what?

The instinct after a mistake is to apologise immediately and to everybody, because the discomfort of having got it wrong wants resolving. Which is why most apology emails exist: they make the sender feel better, and they do very little for the recipient.

So before you draft anything, two questions.

 

Mistakes that do not need a follow-up

  • A spelling or grammar mistake in body copy. A small number of people noticed, most of them did not care, and an apology email will tell everybody else that something was wrong before they go looking for it.

  • A design glitch, a spacing issue, a wonky image. Irritating to you, invisible to almost everybody, and not worth a second send.

  • A minor factual slip nobody will act on. The wrong year in a footer, a job title slightly off, a statistic rounded badly.

  • Something only you would ever have spotted. Which is most of what makes email people wince.

Worth remembering that a correction is a send, and every send has a cost. It goes to people who never noticed, it consumes attention you will want later, and it carries the same complaint and unsubscribe risk as any other email. Sending one for a typo means paying all of that to resolve your own embarrassment.

 

Mistakes that do need a follow-up

  • A broken or wrong link in an email whose whole purpose was that link. The clearest case. The email did not do the job it was sent to do, so it needs doing again.

  • A wrong price, code, or discount. Anybody who acted on it is now in a situation you created, and somebody has to decide whether you honour it.

  • The wrong date, time or venue for something people are attending. People will act on this and the cost of the error lands on them.

  • Personalisation that failed at scale. Hello FIRSTNAME once is a joke. Across a whole send it undermines every claim you have ever made about knowing your customers.

  • A send to the wrong segment. Particularly anything commercially or personally sensitive, or anything that reveals something about a group somebody did not want revealed.

  • A broken unsubscribe. Fix it and tell people, because the alternative is that they use the spam button instead and you pay for it in reputation.

  • Anything with legal, regulatory or safety implications. Not a judgement call. Get advice and send.

The common thread is consequence. If somebody could take an action, waste money, miss something, or be embarrassed because of what you sent, you owe them a correction. If the only injury is to your pride, you do not.

 

Correct without apologising (sorry NOT sorry)

A correction and an apology are two different emails, and most businesses reach for the second when the first would have been better.

A correction leads with the fix. The working link, right there. The code is this. The session starts at two, not three. Short, useful, gets people what they came for, and the apology is a single clause rather than the subject of the email.

An apology leads with the regret, and it is the right shape only when the mistake cost somebody something real, in the an emotional or physical sense. Use it sparingly, because a business that apologises for everything has no way of signalling that this one matters.

  • Send the correction to non-openers as well as openers where it makes sense. Somebody who has not opened yet does not need an apology, they need the correct email.

  • Keep the subject line plain. Correction, or the fixed version of the original. Not a joke, and not a second attempt at being clever.

  • One email, not a sequence. The correction goes once. Chasing it with a further explanation makes a small thing into a large one.

Why a well-handled mistake can be good for you

The part people find surprising, and it is worth understanding because it changes how you approach the whole thing.

Correction emails get opened (because humans love it when other humans fuck up).  Reliably, and at rates your normal campaigns do not reach, because curiosity is a strong driver and because a message that admits something went wrong reads as human in an inbox full of marketing. People want to know what happened.

  • A cluster of opens and clicks in a short window is a positive event. Which is exactly the pattern that supports your sender reputation, so a correction handled well does you a small favour with the mailbox providers.

  • Visible fallibility builds trust rather than eroding it. A brand that only ever speaks in polished announcements is harder to believe than one that occasionally says we got that wrong.

  • Service recovery is a real effect. People whose problem was handled quickly and gracefully frequently rate a business higher than people who never had a problem, because the recovery is memorable in a way a smooth experience is not.

None of which is an argument for making more mistakes. It works because it is rare, because it is straight, and because you did not milk it. A business that discovers corrections perform well and starts manufacturing charming little errors will be found out immediately.

 

How to write it

  1. Lead with the fix, not the feeling. What the person needs in order to carry on, in the first line.

  2. Say what happened, plainly and briefly. One sentence. The internal cause is not interesting to anybody outside your building.

  3. Do not blame the platform, the intern, or a technical error. Everybody knows what a technical error means, and passing it to a junior person in public is the worst thing you can do with a mistake.

  4. Match the tone to the cost. A light touch works when the error cost nobody anything. It reads badly when somebody has lost money or missed something.

  5. Apologise once, if at all. Twice in one email reads as anxiety and it draws attention away from the fix.

  6. Tell people what you have changed, only if it is true. A specific change is reassuring. A vague promise to review our processes is noise.

 

And then do the internal bit

  • Log it, including the near misses. What happened, what it cost, what changed. A team that documents failures stops repeating them, and a team that deletes the evidence repeats them every time somebody new joins.

  • Find the root cause rather than the person. Almost every send error is a process failure. Somebody was rushed, the approval step was skipped because it always gets skipped, or two people assumed the other had checked.

  • Build the pre-send check that would have caught it. One specific check, added to a list somebody really runs. Not a new policy.

 

Part two

The emails you should have written before you needed them

The second kind of contingency, and the one that costs businesses the most, because it arrives without warning and everything about your normal working process is too slow for it.

The scenarios are predictable, which is the point.

  • A service or platform outage.

  • A product recall or a safety issue.

  • Fulfilment or delivery failure, especially at peak.

  • A pricing or billing error, including double charges.

  • A data or security incident.

  • Your website going down during a promotion.

  • Stock running out mid-campaign.

  • An event cancelled or moved.

  • Anything affecting a specific subset of customers rather than everybody.

Every one of those has happened to somebody this month, and in most businesses the response is assembled from scratch while people are panicking.

 

SPEED matters, polish doesn't (and you can't polish a 💩) 

The gap between an incident starting and your communication landing is where the anger grows. People who hear it from you first are measurably calmer than people who find out from a support queue, a forum or somebody else's social post, because hearing it elsewhere adds the sense of having been kept in the dark to whatever the original problem was.

There is a commercial argument too, and it is the one that gets budget. A proactive email sent quickly prevents a large volume of support contacts, each of which costs real money and ties up people you need for the actual incident.

 

Why it takes too long

Worth being specific about where the time goes, because the fix depends on it.

  • Sign-off. Legal, comms, leadership, and a chain of approvals designed for a working week. Incidents do not respect Fridays.

  • Nobody knows who decides. So the first hour is spent establishing authority rather than drafting.

  • Access. The person who can send is on leave, the login needs a code from a phone in a drawer, or nobody outside one team can build a send.

  • No template, so drafting starts from a blank page. Slow, and it produces worse writing under pressure than anybody would produce calmly.

  • And the big one, which nobody anticipates. You cannot work out who to send it to.

 

The data problem

The one I would most want you to take away, because it is invisible until the moment it matters and then it becomes the whole problem.

The incident affects a specific group. Customers who bought a particular product between two dates. People on a certain plan. Orders shipped to one region. Everybody who used a form in a particular window.

Can you build that audience in ten minutes? Most businesses cannot, and they do not find out until the day it counts.

  • The order data lives somewhere your email platform cannot see. So the segment exists commercially and does not exist for sending.

  • There is no shared identifier linking the systems. The email address is in one place and the transaction is in another, joined by nothing reliable.

  • The same person appears several times with different details. Duplicates that nobody minded until they had to be resolved under pressure.

  • The attribute you need to filter on was never synced. It is in the warehouse, or the ERP, or a spreadsheet somebody maintains.

I sat with a client recently where exactly this happened. The data was spread across several systems with no clean join between them, so building the affected audience meant going through and manually connecting contacts to the right people. Hours of work, at the precise moment when hours were the one thing we did not have.

The communication was excellent when it went out. It went out far later than it should have, and not one minute of that delay was caused by the writing.

 

 

What a contingency pack contains

  1. Pre-approved templates, signed off while nothing is happening. Legal and comms review them once, calmly, and the approval covers the template rather than each individual use.

  2. A named decision-maker, and a deputy. One person who can authorise a send, and somebody who can do it when the first person is on a plane.

  3. Out-of-hours contacts for everybody involved. Including whoever holds platform access, because incidents are disproportionately weekends and evenings.

  4. A confirmed sending route. Which platform, who has access, and proof that somebody can log in and send outside office hours. Test it.

  5. Saved audience definitions for the likely scenarios. Built in advance and verified, so the segment is a click rather than a project.

  6. A holding statement that needs no approval. We are aware, we are investigating, we will update you by a stated time. Pre-agreed so it can go within minutes.

  7. An agreed approval shortcut for incidents. Written down in advance, because the normal chain will not work and somebody will otherwise spend the first hour asking permission to ask permission.

  8. A decision on which sending stream and domain incident mail uses. More on this below, and it is more important than it sounds.

 

The template set worth having

  • The holding note. We know, we are looking into it, you will hear from us by a specific time. Buys you hours and costs you nothing.

  • The initial notification. What has happened, who it affects, what it means for them, what they should do, and when you will update them next.

  • The update. Progress, revised timing, and anything that has changed for them. Sent even when there is no progress, because silence is worse.

  • The resolution. It is fixed, here is what happened, here is what we have changed.

  • The goodwill or compensation note. Separate from the resolution, and only where something was truly lost.

Each one written with placeholders rather than specifics, so the drafting on the day is filling gaps rather than composing prose under pressure.

 

Deliverability during an incident, which nobody thinks about

An incident email is an unusual send by definition. Unplanned, to a segment you do not normally mail, often at a volume and time that does not match your pattern, and sometimes to people who have not heard from you in a long while.

  • Sudden pattern changes are a negative signal. Providers weigh consistency, so an unexpected large send to an unfamiliar audience is exactly the shape they look at carefully.

  • Do not let a crisis be the first time you send to a segment. If a group has been suppressed for a year, an incident email to them will generate complaints from people who no longer recognise you.

  • Decide the stream and domain in advance. Incident communication is service mail rather than marketing, and it should not be sitting behind a promotional reputation that might be throttled on the day you need it most.

  • Keep your transactional stream separate and healthy. The argument for separation is usually made about order confirmations. The version that convinces people is that your incident comms need a route that works when everything else is on fire.

 

Practise it once a year

Pick a scenario, gather the people, and run it as an exercise without sending anything. Time how long it takes to get from we have a problem to this is ready to go.

Almost every business that does this finds the same two things. The writing is quick, and the audience build is not. Which tells you where the work is before it costs you anything.

 

The conclusion

Both halves of this come down to the same thing. The quality of your response is decided before the incident, not during it.

For your own mistakes, that means having a test you apply rather than a feeling you follow. Does it harm the audience, and does it create friction. If not, let it go and log it. If so, correct it quickly, plainly, once, and take the small engagement benefit that comes with being straight with people.

For everything else, it means the templates, the approvals, the access and above all the ability to build the audience, all sorted while nothing is happening. Because when something does happen, the only variable you control is how fast you can reach the right people, and that is a data problem dressed up as a communications one.