Should you buy lead lists?
No, with one real exception, and the exception is a definition rather than a loophole. One verb covers three different transactions: a marketplace CSV, a licensed database subscription, and a list you sourced yourself. Separate them and the answer stops being an opinion, because the thresholds, the statutes and the enforcement record are all published.
By Kshitij Maheshwari, co-founder · Updated August 2026 · 14 min read
The short answer, in one table
Three transactions hide behind one verb, and they get three different answers.
| What you are buying | What you actually get | Legal position | Deliverability risk | Verdict |
|---|---|---|---|---|
| A marketplace CSV scraped or resold file |
A static file. Nobody in the chain has a relationship with the people in it. | No lawful basis you can document. A supplier's contractual promise does not discharge your own duty as controller (CNIL, SAN-2024-003, 31 January 2024). | Highest. Seeded spam traps (addresses that catch scrapers), hard bounces, and complaint rates that blow past Google's 0.30% limit and Amazon SES's 0.1%. | No |
| A licensed database Apollo, ZoomInfo, Cognism and similar |
Query access to a maintained dataset, exported record by record under a license. | Defensible where the vendor documents its lawful basis and its notification duty, but the vendor's terms put lawful use on you (Apollo Terms of Service, 10 August 2026). | Moderate. Stale records still bounce, so the verification step belongs at send time rather than at export. | Yes, with conditions |
| A list you sourced yourself defined, sourced, enriched, verified |
A sourcing record you own, account by account, with a date against every entry. | You are the controller of a process you can describe, date and evidence, which is what a regulator asks for. | Lowest, and every part of it is yours to control. | Yes |
Google's Gmail sender guidelines and Postmaster Tools help, Yahoo's and Microsoft's sender requirements, the Amazon SES Developer Guide, Spamhaus, CNIL deliberation SAN-2024-003, Apollo's Terms of Service and the FTC. All checked August 2026.
Three purchases, one word
Every argument about buying lists collapses because all three of these get called the same thing.
A marketplace CSV is a static file you buy once from a broker, a marketplace or a freelancer. The addresses were scraped, harvested or resold, and nobody in the chain has met the people in it.
A licensed database subscription rents you query access to a maintained dataset. You search, filter and export under license, which is what the licensed databases teams actually subscribe to sell.
A self-sourced list is one you defined, sourced, enriched and verified. You may have paid for every input, and you still own the record of where each contact came from.
- •A file of addresses that resolve on the day you buy it
- •A description of how they say it was collected
- •A contractual promise about compliance
- •An invoice
- •The record of where each address came from, and when
- •Any agreement from the person to hear from you
- •A file certified free of spam traps, which nobody can do
- •Your own defense, because the duty stays with you
You can buy access to data. You cannot buy permission, and you cannot buy the record of where the data came from.
What a bad send does to your domain, hour by hour
The damage arrives in three waves, and only the first one is visible on the day.
An illustrative walkthrough of the mechanism, not a specific client result. We report real numbers only when they are real.
The bounces land
- Hard bounces return almost immediately
- Every dead address becomes a logged event
- Amazon SES counts hard bounces to domains you have not verified
- This is the only part you can see today
The visible damage, and the cheapest
The complaints register
- Recipients start marking messages as spam
- Postmaster Tools data typically updates within 24 hours
- Trap hits are reported as occurrences, never itemised
- Gmail begins routing more of your mail to spam
The part that decides your next campaign
The category moves
- Domain reputation slides from High toward Medium or Low
- Google defines every grade as a history, not a snapshot
- Filtering suppresses the very rate you are watching
- Deleting the list removes none of the record
Reputation follows the domain, not the campaign
Google's own Postmaster Tools help says it outright: "If Gmail automatically sends a significant number of your messages to spam, the rate shown in the dashboard might seem low, because recipients get fewer of your messages in their Inbox." Your spam rate can fall while you are getting worse (checked August 2026).
The thresholds you are actually running into
Every number below is published free by the company that enforces it, with a date attached.
Chase the target, not the limit
Google's sender guidelines, whose bulk requirements have been in force since 1 February 2024, tell senders of over 5,000 messages a day to keep the Postmaster Tools spam rate below 0.30%, and separately to stay below 0.10% (checked August 2026).
The clock Yahoo alone keeps
Yahoo's sender requirements, enforced from February 2024, put the spam rate below 0.3% and ask senders to honor unsubscribes within 2 days. That two-day deadline is Yahoo's alone: Google's requirement is one-click unsubscribe.
Authenticate or land in junk
Microsoft's rules for domains sending over 5,000 emails a day to Outlook.com, Hotmail.com and Live.com took effect on 5 May 2025: SPF, DKIM and DMARC must pass, and non-compliant mail goes to junk.
Review now, a pause later
Amazon SES's own documentation says to keep bounces below 2%; at 5% or greater Amazon SES places the account under review, and at 10% or greater it may pause sending. Vendor documentation, checked August 2026.
Fifty times more sensitive
The same Amazon SES page puts complaints under review at 0.1% and a possible sending pause at 0.5%. Bounces buy you five percent of slack. Complaints buy you one tenth of one percent.
Nobody can sell you removal
Spamhaus, February 2022: seeded traps show a sender is scraping addresses or buying from someone who does, and trap addresses are never revealed by their owners. So no listing can honestly be certified trap-free.
Why the bill arrives on your next campaign
The bought list costs you a bad week. The good list you build afterwards costs you the quarter.
One week of bad numbers
The bought list underperforms, which everyone half expected. Bounces spike, replies do not arrive, the campaign gets written off as a bad list and the file gets deleted. That part is cheap and it is over quickly.
Reputation is a history
Google grades domain reputation by history of sending behavior. Bad is a history of sending a high volume of spam regularly; High is a history of very low spam rates. Your bad week joins a running file.
The rate falls as you sink
Once Gmail routes a chunk of your mail straight to spam, fewer messages reach an inbox to be reported from. Google says the dashboard rate might seem low. Improving numbers can mean worsening delivery.
The good list underperforms too
Six weeks later you build the list properly, verify it and write better copy. It goes out from the same domain, which now carries the record. The obvious conclusion, that outbound does not work here, is wrong.
There is no reset button
Spamhaus put it plainly in March 2026: reputation is built slowly, damaged quickly and constantly recalculated, with no reset button and no appeal process. You cannot buy your way back in.
The legal picture is three pictures
A founder selling into the US, the UK and Germany is under three different regimes at once.
| Where | Consent before the first email? | What actually binds you | The receipt |
|---|---|---|---|
| United States | No. CAN-SPAM governs how you send, not whether you may start. | Accurate headers, a non-deceptive subject, a clear ad disclosure, a valid postal address, an opt-out live 30 days and honored within 10 business days. | FTC compliance guide: up to $53,088 per email, and no exception for business-to-business mail. |
| United Kingdom | Not for corporate bodies. Yes for individuals, sole traders and some partnerships. | PECR regulation 22. The soft opt-in covers your own past customers and never covers bought-in lists, and personal corporate addresses still carry data-protection duties. | ICO, Guide to PECR, electronic mail marketing (checked August 2026). |
| Germany | Yes, business or not. There is no corporate carve-out. | Advertising by electronic mail without the addressee's prior express consent is an unreasonable nuisance. The exception is narrow: addresses obtained in connection with a sale. | Act Against Unfair Competition, section 7(2) and 7(3). |
| France | Its own B2B conditions, stricter than the UK's and looser than Germany's. | The CNIL sets specific conditions for business prospecting and has enforced them against buyers of broker data. | Set out in our guide to building a lead list, which carries the French conditions in full. |
Europe splits because EU law leaves one question, protection for corporate subscribers, to each member state (ePrivacy Directive, Article 13(5)). That is why the UK and Germany land in opposite places.
The receipts
The scary numbers doing the rounds are stale. The real ones are smaller, and worse.
"Buying lists is illegal. It is $43,000 an email under CAN-SPAM, or 20 million euros under GDPR."
- ✕Quotes CAN-SPAM penalty figures that expired years ago
- ✕Cites a statutory ceiling nobody has paid for a lead list
- ✕Usually published by a company selling the alternative
"The current CAN-SPAM maximum is $53,088 an email. The real European enforcement on bought data was 310,000 euros."
- ✓The FTC's own compliance guide carries the live figure
- ✓CNIL deliberation SAN-2024-003, 31 January 2024, is a decided case
- ✓The regulator held that a supplier's contract does not discharge the buyer
The platforms already decided this one. Google says don't purchase email addresses from other companies, Amazon SES says do not buy, rent or share them, and Mailchimp prohibits third-party lists outright.
Want the list built properly instead of bought, by the two of us?
Book a Fit CheckWhat to ask a vendor, and what the answers mean
One question separates a licensed dataset from a resold file, and it is not about accuracy.
Accept the compliance badge
All our data is GDPR compliant, fully opted in, and verified to 95% accuracy.
- ✕Compliance is not a property of a file
- ✕Nobody can certify a file trap-free
- ✕Verified means a mailserver accepted mail
Ask where each record came from
Where was each record collected, on what date, and what notice did the person receive?
- ✓It is the question a regulator asks first
- ✓A broker cannot answer it, a database can
- ✓The answer is the thing you are paying for
Apollo's terms, last updated 10 August 2026, are blunt about this: you are solely responsible for determining the lawfulness of your use, and you may not rely on any compliance assessment Apollo has done.
What to do instead
License the data, build the list yourself, verify at send time. Four steps, in order.
-
1
Size the market before you scale it
Count the accounts that genuinely fit before you decide you need volume. Teams asking for 50,000 contacts often have a few hundred real ones.
Gotcha
Wanting to buy a list is usually a symptom. The honest read is that the market feels too small.
-
2
Source it yourself, on licensed data
Define the ICP, source the accounts, find the people, and keep the record of where each one came from and when.
Gotcha
Slower and smaller is the point. The sourcing record is the one asset a broker cannot sell you.
-
3
Enrich provider by provider
Do not accept one source's coverage as the ceiling. Run providers in sequence until one returns a valid hit, then stop paying.
-
4
Verify immediately before the send
Verification is a pre-send step, not a purchase-time certificate. A result from six weeks ago tells you about six weeks ago.
Gotcha
On a catch-all domain the server accepts everything, so a valid result there is a maybe, not a yes.
- 1 License the data, build the list yourself, verify at send time.
- 2 You can buy access. You cannot buy permission or provenance.
- 3 Complaints are far more sensitive than bounces at Amazon SES.
- 4 Your domain remembers, and there is no appeal process.
How to check a list you already bought
The file is already paid for, so the only question left is how little damage it does.
Before it touches a sequence
7 checks
-
Do not send it yet
The first send is what writes the record. Everything below happens before it.
-
Dedup against the CRM first
Customers and open opportunities getting cold outreach is its own kind of damage.
-
Apply every suppression list you hold
Anyone who opted out anywhere in your stack, plus your own domain and your investors.
-
Strip the role addresses
info@, sales@ and abuse@ rarely reach a person, and some of them are traps by design.
-
Verify it yourself, at send time
Whatever the seller stamped on the file, verify immediately before you send.
-
Test a small slice, secondary domain only
Never the domain your invoices run on. Reputation follows the domain and does not roll back.
-
Watch complaints, not opens
If the complaint line moves at all, stop. Open rate will not tell you in time.
Where this goes wrong
Four mistakes account for nearly every bought-list disaster, and all four happen before the send.
A verifier tells you a mailserver accepts mail for an address. It does not tell you the person still works there, that they are the right person, or that they want to hear from you.
Cold outreach landing on a current customer or an open opportunity costs more than a bounce, and none of it shows up in the deliverability numbers you are watching.
If the real market is 900 accounts, 50,000 names does not fix it. More names is the answer to a different problem, and it usually makes this one louder.
Open rate is the metric a bought list flatters and the one mailbox providers ignore. Bounces and complaints are what actually get scored against your domain.
Never send a bought list from your primary domain
This is the unwindable one. Reputation follows the domain, and Spamhaus is blunt about the recovery path: there is no reset button and no appeal process. The domain your invoices and customer email run on does not get a second first impression.
Questions founders ask
Is buying email lists illegal?
Is it legal in the EU and the UK?
Will a bought list get my domain blocked?
Is an Apollo or ZoomInfo export the same as buying a list?
What bounce rate is too high?
Is there ever a good reason to buy a list?
Co-founder of Real Good GTM. He has been the first business hire and Chief of Staff at seed-stage B2B startups, building outbound pipeline before any playbook existed. This post comes from sourcing and verifying lists for live outbound campaigns, and from checking every threshold and statute here against the source that publishes it.
Connect on LinkedInBuild the list instead
How much coverage is worth paying for, how enrichment actually works, and what it looks like done for you.
How many data providers do you need?
Where the curve flattens, and the point at which a fourth provider stops earning its credits.
Read the postThe data enrichment guide
Turning a name into a record you can act on, and knowing which fields are worth paying for.
Read the guideTAM enrichment
The version where we build and maintain the living list for you, and keep it fresh.
See the add-onTempted to buy a list? Talk to us first.
Book a fit check. We'll look at how big your market actually is, where the data should come from, and tell you straight if outbound is not the right motion for you yet.
Book a Fit CheckNo hard sell. No fake numbers. Real good work speaks for itself.