Back to blog
Deliverability··10 min read·WillItInbox Team

Bought an Email List? Here's What Happens Next (and How to Recover)

Bought email list? Here's the math on why purchased lists fail, the damage cascade that follows, and how to recover your sender reputation.

bought email listEmail deliverability

A bought email list almost never works. Purchased lists typically produce 5–15% hard bounce rates, near-zero engagement, and spam trap hits that poison your sending domain — often taking your transactional email down with it. If you're considering buying one, the math below will change your mind. If you already sent to one, skip to the damage control section.

I've debugged this exact scenario more times than I can count. A founder buys "10,000 verified B2B leads" for $300, loads them into a sending tool, fires the first campaign, and by Friday their domain is on two blocklists and their password-reset emails are landing in spam. This post covers both audiences: people being pitched a list right now, and people already dealing with the fallout.

What's actually inside a bought email list?

List sellers market these files as "verified," "opt-in," and "fresh." Here's what the data usually contains once you run it through diagnostics:

  • Decayed addresses. B2B email addresses decay at roughly 20–30% per year — people change jobs, companies fold, mailboxes get decommissioned. A list built 18 months ago is already a quarter dead, even if it was "clean" when compiled.
  • Recycled spam traps. Mailbox providers and blocklist operators turn abandoned addresses into traps. Send to one and you get flagged as a sender who doesn't manage list hygiene — because you aren't.
  • Pristine traps seeded by sellers. Some list brokers buy their data from other list brokers, and trap operators deliberately seed addresses into that supply chain. The trap is specifically designed to catch purchased-list senders.
  • Scraped addresses. Addresses harvested from websites, WHOIS records, and LinkedIn. These people never consented to anything and many have never heard of your category, let alone your company.
  • Role accounts and honeypots. info@, sales@, admin@ — low-engagement addresses that drag your metrics down even when they technically deliver.

The common thread: zero consent and zero engagement history. Mailbox providers in 2026 score senders on both. Since Gmail began hard 5xx rejection enforcement in November 2025 (Microsoft followed in May 2025), a list full of dead addresses doesn't just underperform — it gets your mail refused at the connection level.

What happens when you send to a purchased list?

The failure isn't a single event. It's a cascade, and each stage makes the next one worse. Here's the typical timeline I've seen play out:

StageTimelineWhat happens
1. First sendDay 05–15% hard bounce rate, a handful of unsubscribes, almost no replies
2. Trap hitsDay 0–1Spam traps in the list register your send; blocklist operators log it
3. Complaint spikeDay 0–2Spam complaints blow past the 0.1% warning line toward 0.3%+ — people who never opted in hit "Report spam" fast
4. Provider throttlingDay 1–3Gmail/Microsoft start deferring or temp-failing your mail; engagement-based filtering kicks in
5. BlocklistingDay 2–7Your sending IP and/or domain lands on one or more DNSBLs
6. Collateral damageWeek 1–2Your other mail — transactional, invoices, onboarding sequences — starts failing because it shares the domain's reputation

Stage 6 is the part nobody warns you about. Domain reputation in 2026 is not per-campaign. Gmail and Yahoo both moved to domain-reputation-first scoring (Yahoo made it explicit in April 2025). When you torch your domain with a bought email list, the damage applies to everything that domain sends — including the password resets your real customers are waiting for.

Check whether you've been blocklisted: WillItInbox's free blacklist check scans 20+ DNSBLs for your domain and IPs in one pass.

Is buying email lists legal?

Mostly not, depending on where your recipients live. Here's the quick map:

  • CAN-SPAM (US). Technically permits cold B2B email if you honor opt-outs within 10 business days, include a physical postal address, and don't use deceptive headers. Legal-ish, but ISPs don't care about legal — they filter on engagement and complaints.
  • GDPR (EU/UK). Requires a lawful basis for processing personal data, and "I bought it" isn't one. Legitimate interest is a stretch for scraped third-party lists and is very hard to defend if challenged. Fines can reach 4% of global revenue. Regulators have specifically pursued companies using purchased marketing data.
  • CASL (Canada). The strictest of the three. Requires express or valid implied consent, with a private right of action. Purchased lists almost never satisfy it. Penalties up to CAD $10M for organizations.
  • PECR and equivalents. Most EU member states layer additional e-privacy rules on top of GDPR for electronic marketing.

The practical reality: even where it's technically legal (US B2B under CAN-SPAM), the deliverability mechanics make it a losing trade. You're paying money to destroy an asset — your domain reputation — that takes months to rebuild.

"But the seller said the list was verified"

This is the most common objection, and it's based on a misunderstanding of what "verified" means at list-broker scale.

Sellers run one-time SMTP pings: connect to the MX, issue RCPT TO, see if the server says 250. That tells you the mailbox existed at that moment. It tells you nothing about:

  • Consent. The server can't tell you whether the human behind the mailbox wants your email.
  • Engagement. A mailbox that accepts mail but hasn't been opened in three years still returns 250.
  • Trap status. Spam traps are configured to accept mail. Pinging a trap returns success — that's the point of the trap.
  • Catch-all domains. Roughly 10–30% of B2B domains accept everything at the SMTP layer. Every address on those domains "verifies," including the fake ones. Sellers count these as valid.
  • Recency. A ping from six months ago says nothing about today.

So "10k verified leads" really means "10k addresses that answered an SMTP handshake at some point in the past." That is not an asset. It's a liability with a CSV extension.

What's the actual math? Is buying email lists worth it?

Run the numbers on a $300 list of 10,000 addresses versus building the same list:

The bought email list:

  • 10,000 addresses → ~85–92% deliver on day one → ~8,800 inboxes technically reached
  • Typical open rate on cold purchased data: 1–5%. Typical reply rate: under 0.5%. Realistic conversions: single digits, often zero.
  • Cost of failure: domain reputation damage, blocklisting, weeks-to-months of degraded deliverability for all your email, potential ESP account suspension (most ESPs prohibit purchased lists in their ToS and will terminate you).

The built list:

  • 10,000 genuine opt-ins take time — but those subscribers open at 30–45%, reply, buy, and refer.
  • Deliverability compounds: high engagement improves your reputation, which improves inbox placement, which improves engagement.

A 500-person opted-in list will outperform a 10,000-person bought email list on every metric that matters, including revenue. This isn't ideology — it's what the engagement data shows every time.

I already sent to a bought email list. How do I recover?

If the send already happened, speed matters. Reputation damage compounds with every additional send to bad data. Work this checklist in order:

1. Stop sending to the list immediately. Not "pause after this next campaign." Now. Every additional send re-triggers the same filters and resets the recovery clock.

2. Check blocklists and reputation. Run your sending domain and IPs against the major DNSBLs with a blacklist check, and pull your Google Postmaster Tools domain reputation and spam-rate data. You need a baseline to measure recovery against.

3. Suppress permanently. Export every hard bounce, soft bounce that repeats, complaint, and unsubscribe from the campaign. Add them to a permanent suppression list — not a "remove from this campaign" list. Never mail them again, from any list, ever.

4. Validate what's salvageable. If you haven't sent yet, or if you're determining whether any of the data is usable (e.g., a subset that actually opted in through some other channel), run it through real validation — not an SMTP ping. A proper validator checks 12 layers including catch-all detection, disposable domains, spam trap signals, and domain age.

Try it: WillItInbox's email validator — paste addresses or upload a CSV, get confidence scores per address. But be honest: validation tells you which addresses are deliverable, not which people consented. For a bought list, the answer to "should I mail any of these" is usually no.

5. Send nothing promotional until reputation recovers. Keep transactional mail running (your real users need it), but pause all marketing sends for 2–4 weeks minimum. Watch Postmaster Tools. When domain reputation climbs back out of "Bad"/"Low," you can resume — slowly, to your most engaged real subscribers first.

6. Request blocklist delisting. Each DNSBL has its own removal process. Some auto-expire; some require evidence you've fixed the problem. Follow the full process in our blacklist removal playbook.

7. Test before you send again. Before any future campaign, run a real deliverability test — send to a probe address and get your authentication, DNS, and content checked before you risk another live send. Run a free deliverability test — 70+ checks, about 15 seconds, no guessing.

8. Rebuild with opt-in only. Everything from here forward should be confirmed or at least explicit opt-in. More on that below. For the ongoing hygiene practices that prevent this from ever happening again, see list hygiene and sunsetting.

A note on separating transactional and marketing

If you haven't already, this incident is the reason to split your streams: send transactional email from a dedicated subdomain (e.g., mail.example.com) and marketing from another (news.example.com), ideally on separate IPs if volume justifies it. Subdomain reputation is partially independent, so one bad marketing decision can't take down your password resets.

What should you do instead of buying a list?

The legitimate paths to reaching cold audiences exist. They're slower than "buy 10k leads," and they actually work.

Build the list yourself:

  • Lead magnets. A calculator, template, benchmark report, or tool that your exact target customer wants. One good asset can generate hundreds of opted-in subscribers per month.
  • Validate at capture. Verify addresses in real time at the form — catch typos (gmial.com), disposables, and role accounts before they enter your database. This keeps a built list clean from day one instead of needing remediation later.
  • Double opt-in for high-risk segments. It costs you 10–20% of signups and buys you a list with near-zero complaint rates. For B2B cold-adjacent audiences, it's cheap insurance.

Use opt-in data partners correctly:

  • Legitimate partners run campaigns on their infrastructure to their opted-in audience, promoting your content — then hand you the people who explicitly raised their hand for you. You never receive the raw list.
  • If a "partner" offers to sell you the underlying addresses, it's a list broker with better marketing. Walk away.

Outbound that isn't email-blasting:

  • Small-batch, genuinely personalized outreach to researched prospects (50 emails, not 5,000) from a separate sending domain, with proper authentication — SPF, DKIM, and DMARC at enforcement. Our guide to getting SPF, DKIM, and DMARC right covers the setup.

Frequently asked questions

Sources reviewed

Factual review: June 13, 2026 by WillItInbox Editorial.

Keep reading