How to audit a purchased list

Verification will tell you the addresses exist. It will not tell you whether mailing them is survivable.

Somebody bought a list. Perhaps it was you, perhaps it arrived with an acquisition, perhaps a client handed it over and said it was fine. The question is what to do now, and the honest answer starts with what verification cannot settle.

A clean verification result means the addresses exist. It does not mean those people agreed to hear from you, and under GDPR and similar regimes that is the question that carries the fine.

It also does not mean the list is free of spam traps. Pristine traps look identical to working mailboxes at the protocol level, and purchased data is the main way they reach a sender. A verifier will return valid on a trap, correctly, and mailing it is how you get listed.

And several platforms will simply refuse. Mailchimp suspends accounts for purchased lists. Zoho declines them outright. GetResponse holds imports for a human to read the provenance story. A clean file does not change any of those answers.

If you are going ahead anyway

Verify first, so you know the scale of what you are holding. A list that is 40% undeliverable is not a list and the vendor should be asked about it.

Read the composition rather than the total. A high share of role addresses, catch-all domains and very old free webmail domains tells you how the data was assembled.

Send to a small sample from a domain and IP you are willing to lose. Not your main sending infrastructure, which is the mistake that takes your transactional mail down with the experiment.

Watch complaint rate rather than bounce rate. Bounces damage reputation slowly; complaints above 0.3% at Gmail or Yahoo damage it immediately, and a purchased list is exactly where those come from.

Have an answer ready for your platform's compliance team, because on several of them you will be asked before the first campaign leaves.

Where this argument costs us something

The short version

  • Verification measures deliverability, never consent.
  • Test on infrastructure you can afford to lose, not on your main sending domain.
  • Check your platform's policy on purchased lists before you upload anything.

Questions people ask

Will verifying a purchased list make it safe to send?

No. It removes addresses that do not exist. Spam traps, consent and your platform's policy are all untouched, and those are the three things that decide the outcome.

Can you tell me whether a list was purchased?

Not definitively. Composition gives hints: a high share of role addresses, unusual domain spread and very old free webmail domains all point that way. It is a signal rather than proof.

See both numbers on your own list

100 free checks a month, no card. Addresses we could not get an answer on come back labeled, and we do not bill them.