Purchased List

A contact list bought or rented, not built through opt-in.

Nobody agreed to hear from you, hence the outsized spam-trap risk.

Definition

A purchased list is a contact list bought or rented from a third party rather than built through opt-in. Because nobody on it agreed to hear from you specifically, it carries disproportionate spam-trap and complaint risk: broker-compiled data accumulates dead, recycled, and trap addresses that a sender has no way to spot before mailing them.

We see purchased lists come through verification constantly, usually inherited from a conference sponsorship, a data-broker deal, or an old acquisition someone is trying to make use of. The list looks complete: names, titles, company domains, sometimes a job function. What it does not have is a single person on it who ever agreed to hear from the sender. That gap, between “we have their address” and “they opted in to hear from us,” is where nearly every problem below starts.

What a purchased list is

A purchased list is a set of contact records bought outright or rented for a single use from a third party, rather than collected through your own signup form, checkout flow, or lead magnet. “Rented” lists are common in B2B: a broker lets you mail their list once, through their infrastructure or yours, without ever handing over the underlying records. Either way, the defining trait is the same: no one on it took an action directed at you.

These datasets get compiled in a handful of overlapping ways. Some are scraped from public web pages, directories, and social profiles. Others are aggregated from public records, old event badge scans, or defunct companies’ databases sold off as an asset. A single record often gets resold many times over, passing through a chain of brokers who each add a few fields and drop a few rows, with no one in the chain running the equivalent of ongoing list hygiene on it.

Why these lists carry outsized spam-trap risk

Spam traps come in two flavors, and purchased lists tend to accumulate both. Pristine traps are addresses that never belonged to a real person. They are seeded specifically in places scrapers are likely to find them, which means a list built by scraping the open web can contain some from the moment it is assembled.

Recycled traps are the slower-building problem. A mailbox provider will eventually convert a long-abandoned real address back into a trap, but a broker’s dataset from two or three years ago has no way of knowing that happened. Because list brokers rarely run a bounce-processing loop of their own, these traps simply sit in the data, get resold as if still current, and land in a buyer’s inbox with no warning attached.

The legal landscape is genuinely split, which is part of why purchased lists persist. In the US, CAN-SPAM does not require prior consent: it is possible to comply with the letter of the law while mailing a purchased list, as long as you disclose the sender, avoid deceptive headers, and honor opt-outs promptly.

GDPR, UK GDPR, and Canada’s CASL take the opposite starting point: commercial email generally needs an existing relationship or documented consent, which a purchased list cannot provide for the individuals on it. Where your recipients live determines which regime applies, so a list that is technically mailable in one jurisdiction can be a compliance problem in another.

Why purchased-list sending almost always backfires

Even setting the legal question aside, mailbox providers act as a second enforcement layer that does not care what the law permits. A purchased list starts a sending relationship with zero engagement history: recipients have never opened, clicked, or replied to you, so opens and clicks read near zero from the very first message rather than declining gradually over time.

That flat-zero engagement, combined with a trickle of trap hits and a spike in spam complaints from recipients who do not recognize the sender, is exactly the pattern mailbox providers use to identify low-quality senders. The damage rarely stays contained to one campaign: reputation is tracked at the domain or IP level, so a single purchased-list send can drag down deliverability for properly opted-in mail sent from the same infrastructure afterward.

What to do if you already have one

Going forward, the reliable path is building a list through genuine opt-in: signup forms, gated content someone chose to download, or a checkout flow, so every address on it belongs to someone who took an action pointed at your brand.

If a purchased list already exists in your database, treat it as high-risk data rather than a normal contact list:

  • Run it through verification first, to strip invalid, disposable, and trap-flagged addresses before it ever reaches a send.
  • Segment it away from your opt-in contacts entirely, so a reputation hit from the purchased segment cannot spread to addresses you know are engaged.
  • Warm it slowly with a small, pre-verified subset rather than mailing the full list at once, and watch complaint and bounce rates closely on that first send.
  • Consider a re-permission campaign, explicitly asking recipients to opt in, instead of treating the purchased data as sendable on its own.

None of this makes a purchased list equivalent to one you built yourself, but it is the difference between an isolated, contained risk and one that quietly erodes the sender reputation your legitimate mail depends on.

Explore more from Verifox

A purchased list sits at the center of a wider set of list-quality and risk concepts. These are the terms most worth understanding next.

  1. List Hygiene

  2. Zombie Email

  3. Spam Trap

Common questions

Purchased lists, answered

A purchased list looks like a shortcut and behaves like a liability. Here’s what actually happens to your sender reputation the moment you mail one.

Is buying an email list illegal?

It depends on where your recipients live. In the US, CAN-SPAM does not require prior consent, so mailing a purchased list is technically permitted as long as you disclose who is sending, avoid false headers, and honor opt-outs.

Under GDPR, UK GDPR, and CASL, though, commercial email generally needs an existing relationship or consent you cannot get from a broker, which makes purchased-list mailing effectively prohibited for recipients in those regions regardless of what the list vendor promises.

Can I verify a purchased list before sending to make it safe?

Verification makes it safer, not safe. Running a list through email verification removes syntax errors, dead domains, and known spam traps before you send, which meaningfully cuts your bounce and trap-hit rate.

What verification cannot fix is consent. Every address can pass a technical check and still belong to someone who never agreed to hear from you, so engagement and complaint risk stay elevated even on a fully verified purchased list.

Why do purchased lists have so many spam traps?

Two reasons compound. Pristine traps are seeded specifically where scrapers and harvesters will find them, so any dataset built by scraping the web is likely to contain some from the start.

Recycled traps add up over time: mailbox providers convert long-abandoned real addresses into traps, but a broker’s dataset from three years ago has no way of knowing that, so every resale carries a growing number of dormant addresses that have quietly turned toxic.

What’s the difference between a purchased list and a co-registration list?

A co-registration list comes from someone checking a box on another company’s signup form to also hear from partners, so there is at least a thin, indirect layer of consent. A purchased list usually has none: it is compiled or scraped and sold with no opt-in step at all.

Co-reg leads still perform worse than a list someone opted into directly with you, but a purchased list is riskier still, since the person on it never agreed to anything related to your brand or category.

Will my ESP let me upload a purchased list?

Most reputable ESPs prohibit it outright in their acceptable-use policy, and many actively screen new lists for the signatures of purchased data: uniform formatting, no opt-in timestamp, and engagement that stays near zero from the first send.

Getting flagged can mean a suspended account, not just a rejected campaign, so it is worth reading your ESP’s policy before you ever upload a list you did not build through your own opt-in forms.

What should I do if I already sent to a purchased list and got blocklisted?

Stop sending to that list immediately and run it through the free email checker or bulk verification to strip invalid, disposable, and trap-flagged addresses before you touch it again.

Then work your sending domain’s delisting process with the specific blocklist that flagged you, and rebuild volume slowly on a separate, opt-in-only segment so your recovering reputation is not exposed to the same list again.

Are purchased lists ever worth it?

Rarely, once you count the real cost: degraded sender reputation on every domain that sends the campaign, ESP or blocklist exposure, and a conversion rate far below what the row count suggests, since most of it is unreachable or uninterested from day one.

Building a smaller list through genuine opt-in almost always outperforms a larger purchased one, because every address on it actually chose to hear from you.