Skip to content
From the blog

Should you buy lead lists?

No, with one real exception, and the exception is a definition rather than a loophole. One verb covers three different transactions: a marketplace CSV, a licensed database subscription, and a list you sourced yourself. Separate them and the answer stops being an opinion, because the thresholds, the statutes and the enforcement record are all published.

By Kshitij Maheshwari, co-founder · Updated August 2026 · 14 min read

Start here

The short answer, in one table

Three transactions hide behind one verb, and they get three different answers.

What you are buying What you actually get Legal position Deliverability risk Verdict
A marketplace CSV
scraped or resold file
A static file. Nobody in the chain has a relationship with the people in it. No lawful basis you can document. A supplier's contractual promise does not discharge your own duty as controller (CNIL, SAN-2024-003, 31 January 2024). Highest. Seeded spam traps (addresses that catch scrapers), hard bounces, and complaint rates that blow past Google's 0.30% limit and Amazon SES's 0.1%. No
A licensed database
Apollo, ZoomInfo, Cognism and similar
Query access to a maintained dataset, exported record by record under a license. Defensible where the vendor documents its lawful basis and its notification duty, but the vendor's terms put lawful use on you (Apollo Terms of Service, 10 August 2026). Moderate. Stale records still bounce, so the verification step belongs at send time rather than at export. Yes, with conditions
A list you sourced yourself
defined, sourced, enriched, verified
A sourcing record you own, account by account, with a date against every entry. You are the controller of a process you can describe, date and evidence, which is what a regulator asks for. Lowest, and every part of it is yours to control. Yes
Sources

Google's Gmail sender guidelines and Postmaster Tools help, Yahoo's and Microsoft's sender requirements, the Amazon SES Developer Guide, Spamhaus, CNIL deliberation SAN-2024-003, Apollo's Terms of Service and the FTC. All checked August 2026.


The framework

Three purchases, one word

Every argument about buying lists collapses because all three of these get called the same thing.

Definition 1 of 3

A marketplace CSV is a static file you buy once from a broker, a marketplace or a freelancer. The addresses were scraped, harvested or resold, and nobody in the chain has met the people in it.

Definition 2 of 3

A licensed database subscription rents you query access to a maintained dataset. You search, filter and export under license, which is what the licensed databases teams actually subscribe to sell.

Definition 3 of 3

A self-sourced list is one you defined, sourced, enriched and verified. You may have paid for every input, and you still own the record of where each contact came from.

What a seller can hand over
  • A file of addresses that resolve on the day you buy it
  • A description of how they say it was collected
  • A contractual promise about compliance
  • An invoice
What no seller can hand over
  • The record of where each address came from, and when
  • Any agreement from the person to hear from you
  • A file certified free of spam traps, which nobody can do
  • Your own defense, because the duty stays with you

You can buy access to data. You cannot buy permission, and you cannot buy the record of where the data came from.


The worked case

What a bad send does to your domain, hour by hour

The damage arrives in three waves, and only the first one is visible on the day.

An illustrative walkthrough of the mechanism, not a specific client result. We report real numbers only when they are real.

Minutes to hours

The bounces land

  • Hard bounces return almost immediately
  • Every dead address becomes a logged event
  • Amazon SES counts hard bounces to domains you have not verified
  • This is the only part you can see today

The visible damage, and the cheapest

Days 1 to 7

The complaints register

  • Recipients start marking messages as spam
  • Postmaster Tools data typically updates within 24 hours
  • Trap hits are reported as occurrences, never itemised
  • Gmail begins routing more of your mail to spam

The part that decides your next campaign

Week 2 onward

The category moves

  • Domain reputation slides from High toward Medium or Low
  • Google defines every grade as a history, not a snapshot
  • Filtering suppresses the very rate you are watching
  • Deleting the list removes none of the record

Reputation follows the domain, not the campaign

The line nobody quotes

Google's own Postmaster Tools help says it outright: "If Gmail automatically sends a significant number of your messages to spam, the rate shown in the dashboard might seem low, because recipients get fewer of your messages in their Inbox." Your spam rate can fall while you are getting worse (checked August 2026).


The numbers

The thresholds you are actually running into

Every number below is published free by the company that enforces it, with a date attached.

Six published limits
Gmail

Chase the target, not the limit

Google's sender guidelines, whose bulk requirements have been in force since 1 February 2024, tell senders of over 5,000 messages a day to keep the Postmaster Tools spam rate below 0.30%, and separately to stay below 0.10% (checked August 2026).

Yahoo

The clock Yahoo alone keeps

Yahoo's sender requirements, enforced from February 2024, put the spam rate below 0.3% and ask senders to honor unsubscribes within 2 days. That two-day deadline is Yahoo's alone: Google's requirement is one-click unsubscribe.

Outlook

Authenticate or land in junk

Microsoft's rules for domains sending over 5,000 emails a day to Outlook.com, Hotmail.com and Live.com took effect on 5 May 2025: SPF, DKIM and DMARC must pass, and non-compliant mail goes to junk.

Bounces

Review now, a pause later

Amazon SES's own documentation says to keep bounces below 2%; at 5% or greater Amazon SES places the account under review, and at 10% or greater it may pause sending. Vendor documentation, checked August 2026.

Complaints

Fifty times more sensitive

The same Amazon SES page puts complaints under review at 0.1% and a possible sending pause at 0.5%. Bounces buy you five percent of slack. Complaints buy you one tenth of one percent.

Traps

Nobody can sell you removal

Spamhaus, February 2022: seeded traps show a sender is scraping addresses or buying from someone who does, and trap addresses are never revealed by their owners. So no listing can honestly be certified trap-free.


The mechanism

Why the bill arrives on your next campaign

The bought list costs you a bad week. The good list you build afterwards costs you the quarter.

How it actually goes
1
The send

One week of bad numbers

The bought list underperforms, which everyone half expected. Bounces spike, replies do not arrive, the campaign gets written off as a bad list and the file gets deleted. That part is cheap and it is over quickly.

2
The record

Reputation is a history

Google grades domain reputation by history of sending behavior. Bad is a history of sending a high volume of spam regularly; High is a history of very low spam rates. Your bad week joins a running file.

3
The illusion

The rate falls as you sink

Once Gmail routes a chunk of your mail straight to spam, fewer messages reach an inbox to be reported from. Google says the dashboard rate might seem low. Improving numbers can mean worsening delivery.

4
The next one

The good list underperforms too

Six weeks later you build the list properly, verify it and write better copy. It goes out from the same domain, which now carries the record. The obvious conclusion, that outbound does not work here, is wrong.

5
The reason

There is no reset button

Spamhaus put it plainly in March 2026: reputation is built slowly, damaged quickly and constantly recalculated, with no reset button and no appeal process. You cannot buy your way back in.


The law

The legal picture is three pictures

A founder selling into the US, the UK and Germany is under three different regimes at once.

Where Consent before the first email? What actually binds you The receipt
United States No. CAN-SPAM governs how you send, not whether you may start. Accurate headers, a non-deceptive subject, a clear ad disclosure, a valid postal address, an opt-out live 30 days and honored within 10 business days. FTC compliance guide: up to $53,088 per email, and no exception for business-to-business mail.
United Kingdom Not for corporate bodies. Yes for individuals, sole traders and some partnerships. PECR regulation 22. The soft opt-in covers your own past customers and never covers bought-in lists, and personal corporate addresses still carry data-protection duties. ICO, Guide to PECR, electronic mail marketing (checked August 2026).
Germany Yes, business or not. There is no corporate carve-out. Advertising by electronic mail without the addressee's prior express consent is an unreasonable nuisance. The exception is narrow: addresses obtained in connection with a sale. Act Against Unfair Competition, section 7(2) and 7(3).
France Its own B2B conditions, stricter than the UK's and looser than Germany's. The CNIL sets specific conditions for business prospecting and has enforced them against buyers of broker data. Set out in our guide to building a lead list, which carries the French conditions in full.
Why Europe is not one answer

Europe splits because EU law leaves one question, protection for corporate subscribers, to each member state (ePrivacy Directive, Article 13(5)). That is why the UK and Germany land in opposite places.


Stale vs current

The receipts

The scary numbers doing the rounds are stale. The real ones are smaller, and worse.

How the case gets made online

"Buying lists is illegal. It is $43,000 an email under CAN-SPAM, or 20 million euros under GDPR."

  • Quotes CAN-SPAM penalty figures that expired years ago
  • Cites a statutory ceiling nobody has paid for a lead list
  • Usually published by a company selling the alternative
What the published record says

"The current CAN-SPAM maximum is $53,088 an email. The real European enforcement on bought data was 310,000 euros."

  • The FTC's own compliance guide carries the live figure
  • CNIL deliberation SAN-2024-003, 31 January 2024, is a decided case
  • The regulator held that a supplier's contract does not discharge the buyer

The platforms already decided this one. Google says don't purchase email addresses from other companies, Amazon SES says do not buy, rent or share them, and Mailchimp prohibits third-party lists outright.

Want the list built properly instead of bought, by the two of us?

Book a Fit Check

The one question

What to ask a vendor, and what the answers mean

One question separates a licensed dataset from a resold file, and it is not about accuracy.

Don't

Accept the compliance badge

All our data is GDPR compliant, fully opted in, and verified to 95% accuracy.

  • Compliance is not a property of a file
  • Nobody can certify a file trap-free
  • Verified means a mailserver accepted mail
Do

Ask where each record came from

Where was each record collected, on what date, and what notice did the person receive?

  • It is the question a regulator asks first
  • A broker cannot answer it, a database can
  • The answer is the thing you are paying for

Apollo's terms, last updated 10 August 2026, are blunt about this: you are solely responsible for determining the lawfulness of your use, and you may not rely on any compliance assessment Apollo has done.


The alternative

What to do instead

License the data, build the list yourself, verify at send time. Four steps, in order.

  1. 1

    Size the market before you scale it

    Count the accounts that genuinely fit before you decide you need volume. Teams asking for 50,000 contacts often have a few hundred real ones.

    Gotcha

    Wanting to buy a list is usually a symptom. The honest read is that the market feels too small.

  2. 2

    Source it yourself, on licensed data

    Define the ICP, source the accounts, find the people, and keep the record of where each one came from and when.

    Gotcha

    Slower and smaller is the point. The sourcing record is the one asset a broker cannot sell you.

  3. 3

    Enrich provider by provider

    Do not accept one source's coverage as the ceiling. Run providers in sequence until one returns a valid hit, then stop paying.

  4. 4

    Verify immediately before the send

    Verification is a pre-send step, not a purchase-time certificate. A result from six weeks ago tells you about six weeks ago.

    Gotcha

    On a catch-all domain the server accepts everything, so a valid result there is a maybe, not a yes.

Key takeaways
4 points
  • 1 License the data, build the list yourself, verify at send time.
  • 2 You can buy access. You cannot buy permission or provenance.
  • 3 Complaints are far more sensitive than bounces at Amazon SES.
  • 4 Your domain remembers, and there is no appeal process.

Already bought it

How to check a list you already bought

The file is already paid for, so the only question left is how little damage it does.

Before it touches a sequence

7 checks

  • Do not send it yet

    The first send is what writes the record. Everything below happens before it.

  • Dedup against the CRM first

    Customers and open opportunities getting cold outreach is its own kind of damage.

  • Apply every suppression list you hold

    Anyone who opted out anywhere in your stack, plus your own domain and your investors.

  • Strip the role addresses

    info@, sales@ and abuse@ rarely reach a person, and some of them are traps by design.

  • Verify it yourself, at send time

    Whatever the seller stamped on the file, verify immediately before you send.

  • Test a small slice, secondary domain only

    Never the domain your invoices run on. Reputation follows the domain and does not roll back.

  • Watch complaints, not opens

    If the complaint line moves at all, stop. Open rate will not tell you in time.


Failure modes

Where this goes wrong

Four mistakes account for nearly every bought-list disaster, and all four happen before the send.

Treating verified as permission

A verifier tells you a mailserver accepts mail for an address. It does not tell you the person still works there, that they are the right person, or that they want to hear from you.

Sending before the dedup

Cold outreach landing on a current customer or an open opportunity costs more than a bounce, and none of it shows up in the deliverability numbers you are watching.

Buying because the market felt small

If the real market is 900 accounts, 50,000 names does not fix it. More names is the answer to a different problem, and it usually makes this one louder.

Measuring the test on open rate

Open rate is the metric a bought list flatters and the one mailbox providers ignore. Bounces and complaints are what actually get scored against your domain.

!
Caution

Never send a bought list from your primary domain

This is the unwindable one. Reputation follows the domain, and Spamhaus is blunt about the recovery path: there is no reset button and no appeal process. The domain your invoices and customer email run on does not get a second first impression.

Do this instead
Run cold volume from separate sending domains only, and keep the primary clean.

FAQ

Questions founders ask

Is buying email lists illegal?
In the United States, no. CAN-SPAM sets no consent requirement, and the FTC's compliance guide says it makes no exception for business-to-business email. It requires accurate headers, a non-deceptive subject, a clear disclosure that the message is an ad, a valid postal address, and an opt-out live 30 days and honored within 10 business days. Penalties run up to $53,088 per email for knowing violations, current as of August 2026. Buying the list exempts you from none of it.
Is it legal in the EU and the UK?
No single European answer: Article 13(5) of the ePrivacy Directive leaves corporate subscribers to member states. Germany's Act Against Unfair Competition requires the addressee's prior express consent, business or not. The ICO's PECR guidance lets you email a UK corporate body, but sole traders count as individuals and the soft opt-in never covers bought-in lists. Under GDPR, data you did not collect triggers an Article 14 notice within one month.
Will a bought list get my domain blocked?
It is the fastest published route there. Spamhaus says seeded traps show a sender is either scraping addresses or buying from someone who does. Amazon SES's documentation says even a small number of trap hits can badly damage sender reputation. And the damage persists: Google grades domain reputation as a history of sending behavior, and Spamhaus's own line is that reputation has no reset button and no appeal process.
Is an Apollo or ZoomInfo export the same as buying a list?
Not in the sense people usually mean. You are licensing query access to a maintained dataset, not buying a file, and serious vendors document their lawful basis. Apollo's terms, last updated 10 August 2026, make you solely responsible for determining the lawfulness of your use, and say you may not rely on any compliance assessment Apollo has done. Verify at send time, keep a suppression list, and it is defensible.
What bounce rate is too high?
Amazon SES's own documentation has the clearest public numbers: keep bounces below 2%, at 5% or greater the account goes under review, at 10% or greater sending may be paused. Complaints are far more sensitive, under review at 0.1% and a possible pause at 0.5%. Bounces are fixable with a verification step. Complaints are what a bought list generates by construction, because nobody in it agreed to hear from you.
Is there ever a good reason to buy a list?
One. You are testing whether a segment exists at all, the data is licensed rather than scraped, you send from a secondary domain, and you verify immediately before the send. That is a market test, not a pipeline strategy, and it should be sized like one. If the honest reason is that your real market feels too small, more names is not the answer to that question.
Kshitij Maheshwari, co-founder of Real Good GTM
About the author
Kshitij Maheshwari

Co-founder of Real Good GTM. He has been the first business hire and Chief of Staff at seed-stage B2B startups, building outbound pipeline before any playbook existed. This post comes from sourcing and verifying lists for live outbound campaigns, and from checking every threshold and statute here against the source that publishes it.

Connect on LinkedIn

Keep going

Build the list instead

How much coverage is worth paying for, how enrichment actually works, and what it looks like done for you.

Tempted to buy a list? Talk to us first.

Book a fit check. We'll look at how big your market actually is, where the data should come from, and tell you straight if outbound is not the right motion for you yet.

Book a Fit Check

No hard sell. No fake numbers. Real good work speaks for itself.