← Blog
October 2026·7 min read

AI SDR Exclusion Lists: Keep an Outbound Agent Away From Your Customers

Who an outbound agent should never cold email, where the check has to live, and what it should do when the CRM does not answer.

The most expensive cold email an AI SDR will ever send is usually a good one. Well researched, nicely personalized, and delivered to someone whose company already pays you, three weeks before renewal.

The pages that rank for excluding customers from outbound are mostly written by the sequencing vendors, and they agree on the basics. Pull customer and pipeline status from the CRM. Match at the account level. Remove people from sequences when their status changes, because by default most tools only block new enrollments. Audit the list now and then. Good advice, and all of it is below.

All of it also assumes a person built the list.

An agent changes that. Mira finds prospects from LinkedIn, funding news, hiring signals and job boards, which means a good share of the people it wants to email have never touched your CRM as contacts. Their company might have. An exclusion list that filters a CRM view never sees them, because they were never in the view. This page is about closing that gap. It sits next to our MCP tool permission matrix for outbound agents, which covers what the agent may touch, and our guide to AI SDR reply handling, which covers what it does once someone writes back.

Who goes on the list

Not everything here is a hard block. Some groups get stopped outright and some get routed to a person, and the difference matters more than the length of the list.

Current customers

Block, whole account

Every address at the company, including people who have never logged in to your product and do not know their employer pays you. They will find out, usually from the person who signed the contract.

Open opportunities

Block, whole account

Any stage before closed. A cold email to the CFO while your AE is negotiating with the VP of Sales is how a deal picks up a new objection.

Accounts a rep owns

Draft for the owner

If a person on your team has claimed the account, the agent can research and write. The owner decides whether it goes out.

Opted-out addresses

Block, address

Covered in detail in the permission matrix. Listed here so nobody builds a second exclusion system that forgets it.

Competitors

Block, domain

Mostly to keep your sequences out of their inboxes. Mildly embarrassing, rarely expensive.

Closed-lost in the last few months

Hold

The decision is fresh and somebody on your side remembers why it went the way it did. Let that person choose when to try again.

The first two rows cause nearly all the damage. If you only have an afternoon, build those and skip the rest.

Match the company, then the parent

Agents find people by email address, and email addresses are a terrible key for this. Your customer record says acme.com. The VP the agent found on LinkedIn works at the UK subsidiary and has an acme.co.uk address. A contact-level exclusion lets that email through without blinking.

Match on the domain first. Then keep a short table of known aliases and parent companies for every customer and every open deal, maintained by whoever owns the account, because the agent cannot guess that two domains belong to the same company and should not be trusted to try. When the agent has only a personal Gmail address for someone, it should look up the employer from the research it already did and check that company. No employer found, no send.

Check at the send, every time

Most setups check exclusions when a contact is enrolled. That is the wrong moment for an agent, and honestly it was the wrong moment for people too.

Our sequences run five to eight touches across email and LinkedIn, which can stretch over several weeks. A prospect who was a stranger on day one can be in an open opportunity by day nine, because your AE met them at a conference and logged it. The agent queued step four a fortnight ago. If the only check happened at enrollment, step four goes out to someone your AE is actively working.

So put the check inside the send tool itself, the one the agent calls to actually deliver a message, and run it against live CRM data on every call. Do not put it in the prompt. Prompts get edited every time someone tweaks the tone of voice, and models skim. The agent cannot talk its way around a function that returns an error.

When the CRM does not answer, do not send

None of the guides we read cover this one, and it is the failure we worry about most.

The send-time check is a lookup. Lookups fail. OAuth tokens for HubSpot expire on their own schedule, and a badly written MCP server will return an empty list where it should have returned an error. An agent that asks "is acme.com a customer?" and gets nothing back will read nothing as no. Then it sends. From the agent's side the logic was perfectly sound, and that is exactly the problem.

The rule is simple to state. Any error or empty result from the exclusion check (timeouts count) blocks the send and posts an alert to your approvals channel in Slack. The agent may not retry its way past it more than a couple of times, and it may never decide on its own that the check is broken and skip it. Expect this to delay a batch of sends now and then, usually on a Monday morning when a token quietly lapsed over the weekend. We will take that trade every week of the year over one cold pitch to a customer's CEO.

The OpenClaw MCP Integration Kit ships a troubleshooting runbook for auth failures for this reason. Expired auth is the most boring bug in agent infrastructure, and the one most likely to email the wrong person.

Expansion

If you want to sell a second product into a current customer, the account owner sends that email, and the agent's job is to draft it for them.

Why we care about this more than most

After the free pilot, we get paid per qualified meeting, and a qualified meeting is one where the prospect shows up. Current customers show up. Of course they do, it looks like a call from their own vendor. On a naive count, an agent with a leaky exclusion list would actually book more meetings.

Those meetings are worthless to the client, and to us. The client's AE spends thirty minutes discovering they are pitching their own customer, and the customer leaves wondering whether anyone at the vendor talks to each other. We would rather the agent skip ten good prospects than book that one call. If you run your own agent, decide the same thing in writing before the first campaign, because the agent will not decide it for you.

Log the skips

Every blocked send should leave a record with the address, the matched domain, the rule that fired and the time. Count them by rule once a week. A sudden jump in "open opportunity" skips usually means a sales team is busy, which is good news. A sudden drop to zero usually means the CRM sync broke, and the fail-closed rule above is the only thing standing between that and a bad week.

It also gives you something to show the account owners. People trust an agent faster when they can see it leaving their accounts alone. The rest of the setup, from ICP to cadence, lives in our outbound automation playbook. If you would rather have someone else run the agent, here is how Mira works.