Somebody bought a list. Now what?

A file has arrived from a data vendor, or from a colleague who found it, and somebody wants it in the platform this week. The decision that matters is made before the import, not after.

Selling a list and being allowed to mail it are different things. A vendor's assurance that data is opt-in is a claim about their collection process that you cannot verify and would be responsible for.

The order the work happens in

  1. Take a random sample of a thousand

    Randomly across the file, not the first thousand rows, which are frequently sorted by something that makes them look better than the rest.

  2. Verify the sample and read the shape

    A high invalid rate tells you the data is old. A high catch-all share tells you it is corporate. Both change what the file is worth and whether the rest is worth checking.

  3. Look for the tells that are not about validity

    Addresses in a pattern the vendor generated, the same person at six domains, job titles that no longer exist. Those say the file was built rather than collected.

  4. Ask the vendor for the collection record

    Where and when each address was collected, and what it was consented to. A vendor that can't produce this is selling you a liability with a spreadsheet around it.

  5. Decide before you import anything

    If the answer is no, the file never touches the platform. An imported list is much harder to un-import than it is to refuse.

What each result means here

The same four results and their flags, read against this job. A catch-all worth keeping in one situation is one to exclude in another.

ResultWhat to do with it
ValidEvidence the file has real addresses. Not evidence that you may mail them.
InvalidCount the share. Above about a third, the file is old enough that the survivors will not remember consenting to anything.
Catch-allCount the share. A high proportion means a corporate file, where pattern-generated addresses hide behind servers that accept everything.
UnknownCount the share. A large unresolved group usually means many small or badly configured domains, which is common in scraped data.
Role flagA high role share is a strong tell that the file was scraped from websites rather than collected from people.
Disposable flagAny meaningful share of throwaway domains means the original collection point was a giveaway, not a relationship.

How you know it is finished

You have the sample's numbers, an answer from the vendor about collection, and a written decision. If the decision is to mail it, the numbers are what you will show when somebody asks why.

What this does not fix

A thousand-address sample is inside the 100 free monthly credits twice over at $5 for 1,000, which makes the audit cheaper than the meeting about whether to do it.

Questions people ask

Can I make a purchased list safe by verifying it?

No. Verification removes addresses that do not exist. It cannot create consent for you, it cannot detect pristine spam traps, and a purchased file is where both of those problems live.

What sample size tells me enough?

A thousand addresses drawn randomly gives you a usable picture of the invalid, catch-all and unresolved shares. Taking them from the top of the file measures the vendor's sorting instead.

What invalid rate should stop the import?

There is no universal line, but above roughly a third the file is old enough that the working addresses belong to people who will not recognize you, and the complaint risk outweighs the reach.

Try it on the file in front of you

100 free checks a month, no card. Addresses we could not get an answer on come back labeled as unknown, and those are not billed.