Definition
A purchased or scraped email list is a collection of email addresses obtained from a third-party vendor, broker, or automated scraping tool rather than through organic opt-in processes. Despite persistent myths to the contrary, purchased lists are universally harmful to email marketing programmes. Under CAN-SPAM, purchased lists are not explicitly illegal — the law does not require prior consent — but sending to purchased lists violates best practices and invites complaints that damage sender reputation. Under GDPR, the situation is clearer: purchased lists are almost always illegal because they lack the specific, informed, unambiguous consent that GDPR requires. A third party cannot give valid consent on a data subject's behalf, and the individuals on purchased lists have not agreed to receive communications from the purchasing brand.
The most insidious danger of purchased lists is spam trap seeding. Internet service providers, mailbox providers, and anti-spam organisations seed lists with email addresses specifically designed to catch spammers. These addresses are never used for legitimate subscriptions. When a purchased list contains spam traps, sending to them triggers immediate reputation damage. A single campaign hitting multiple spam traps can reduce deliverability from 98% to 20% in a matter of hours, and recovering from a spam trap hit can take months of carefully managed sending. Pristine lists and recycled traps — addresses that were once valid but have been dormant for extended periods — are the two main categories, and both appear frequently in purchased lists.
Reputation damage from purchased lists extends beyond the direct impact of spam traps and complaints. Mailbox providers evaluate sender reputation holistically, considering complaint rates, bounce rates, engagement patterns, and authentication practices. A purchased list sends high volumes to unengaged recipients who will mark emails as spam, creating a complaint rate spike that degrades reputation for the sending domain and IP address. Recovering from purchased-list damage requires migrating to a new domain or IP, warming the new sending infrastructure, and rebuilding the list organically — a process that typically takes three to six months and costs significantly more than building a legitimate list from scratch. The premise that purchased lists work long-term is fundamentally flawed because the metrics that matter for deliverability — engagement, consent, and relevance — are entirely absent from purchased list data.
Best Practices
Never purchase or scrape email lists under any circumstances. There is no legitimate use case for sending marketing emails to addresses obtained without explicit, informed consent from the recipient.
Verify the provenance of any third-party data before integrating it with your email programme. If a partner provides email addresses as part of a joint marketing arrangement, audit their consent collection process and verify that each address has given explicit consent to receive communications from your brand.
Implement list acquisition protocols that require proof of consent for any email address entering the marketing database. This policy should apply to all sources — partner lists, event signups, in-store collections, and offline data imports.
If you have inherited a purchased list from a previous team or acquisition, suppress all addresses from that list immediately. Do not attempt to mail them even once. The reputational risk far exceeds any potential short-term revenue.
Warm new IP addresses and domains with a slow, deliberate ramp-up using only confirmed opt-in subscribers. Sending volume should increase gradually over four to eight weeks, with careful monitoring of bounce, complaint, and engagement rates at each step.
Monitor your sender reputation using tools such as Google Postmaster Tools, Microsoft SNDS, and deliverability monitoring platforms. A sudden drop in reputation metrics should trigger an immediate investigation into whether purchased addresses have entered your list.
Related Glossary Terms
Bounce Classification
Bounce classification uses SMTP codes (550, 551, 552, 553, 554, 450, 451, 452) and enhanced status codes to categorise permanent and transient delivery failures.
DMARC Alignment
DMARC identifier alignment determines whether the domain in the From header matches the domains used in SPF and DKIM authentication. Strict or relaxed.
Email Active Subscriber
An active email subscriber has opened or clicked an email within a defined recency period, typically 30-90 days by industry. Active subscriber rate of 40-60% is typical for healthy email lists.
Australia Spam Act
Australia's Spam Act 2003 regulates commercial electronic messages including email. It requires consent, functional unsubscribe mechanisms within 5 working days, and sender identification. Penalties reach AUD $2.22 million per day.
Email Authentication Failure
Email authentication failures occur when SPF, DKIM, or DMARC checks fail, causing messages to be rejected, spammed, or quarantined by receiving mailbox providers.
Email B2B Consent
The legal requirements for B2B email marketing consent, covering GDPR legitimate interest, CASL implied consent, CAN-SPAM exemptions, and jurisdiction-specific best practices.
Frequently Asked Questions
Under GDPR, buying an email list is almost always illegal because the individuals on the list have not given consent to receive communications from your brand. Under CAN-SPAM, it is not explicitly illegal but violates best practices and carries significant practical risks. Under CASL, sending to a purchased list is a violation of the consent requirement.
Spam traps are deliberately planted by mailbox providers and anti-spam organisations on websites and lists that are known to be harvested by unscrupulous list sellers. When a purchased list is compiled through scraping or from a seller who acquires addresses through dubious means, spam traps are inevitable.
Recovery is possible but slow and expensive. It typically involves stopping all mail to the purchased addresses, moving to a new sending domain or IP, warming up the new infrastructure carefully, rebuilding the list through legitimate opt-in methods, and gradually improving reputation over three to six months.
Ask for proof of consent for every address on the list. A legitimate list provider will have documentation of when, where, and how each subscriber opted in. If the provider cannot supply this documentation or becomes evasive, the list is likely purchased or scraped.
The appeal is speed and volume — a purchased list promises immediate access to a large audience without the time investment of organic list building. In reality, the deliverability damage makes the list worthless or worse, and the cost of recovery typically exceeds the cost of building the same audience organically. ## Related Terms - email-b2b-consent - can-spam - deliverability - double-opt-in