Somebody bought a list. Now what?
A file has arrived from a data vendor, or from a colleague who found it, and somebody wants it in the platform this week. The decision that matters is made before the import, not after.
Selling a list and being allowed to mail it are different things. A vendor's assurance that data is opt-in is a claim about their collection process that you cannot verify and would be responsible for.
The order the work happens in
Take a random sample of a thousand
Randomly across the file, not the first thousand rows, which are frequently sorted by something that makes them look better than the rest.
Verify the sample and read the shape
A high invalid rate tells you the data is old. A high catch-all share tells you it is corporate. Both change what the file is worth and whether the rest is worth checking.
Look for the tells that are not about validity
Addresses in a pattern the vendor generated, the same person at six domains, job titles that no longer exist. Those say the file was built rather than collected.
Ask the vendor for the collection record
Where and when each address was collected, and what it was consented to. A vendor that can't produce this is selling you a liability with a spreadsheet around it.
Decide before you import anything
If the answer is no, the file never touches the platform. An imported list is much harder to un-import than it is to refuse.
What each result means here
The same four results and their flags, read against this job. A catch-all worth keeping in one situation is one to exclude in another.
| Result | What to do with it |
|---|---|
| Valid | Evidence the file has real addresses. Not evidence that you may mail them. |
| Invalid | Count the share. Above about a third, the file is old enough that the survivors will not remember consenting to anything. |
| Catch-all | Count the share. A high proportion means a corporate file, where pattern-generated addresses hide behind servers that accept everything. |
| Unknown | Count the share. A large unresolved group usually means many small or badly configured domains, which is common in scraped data. |
| Role flag | A high role share is a strong tell that the file was scraped from websites rather than collected from people. |
| Disposable flag | Any meaningful share of throwaway domains means the original collection point was a giveaway, not a relationship. |
How you know it is finished
You have the sample's numbers, an answer from the vendor about collection, and a written decision. If the decision is to mail it, the numbers are what you will show when somebody asks why.
What this does not fix
A thousand-address sample is inside the 100 free monthly credits twice over at $5 for 1,000, which makes the audit cheaper than the meeting about whether to do it.
Questions people ask
Can I make a purchased list safe by verifying it?
No. Verification removes addresses that do not exist. It cannot create consent for you, it cannot detect pristine spam traps, and a purchased file is where both of those problems live.
What sample size tells me enough?
A thousand addresses drawn randomly gives you a usable picture of the invalid, catch-all and unresolved shares. Taking them from the top of the file measures the vendor's sorting instead.
What invalid rate should stop the import?
There is no universal line, but above roughly a third the file is old enough that the working addresses belong to people who will not recognize you, and the complaint risk outweighs the reach.
Try it on the file in front of you
100 free checks a month, no card. Addresses we could not get an answer on come back labeled as unknown, and those are not billed.