0 min left
Sending to a Purchased List - What Is Actually Allowed

Sending to a Purchased List - What Is Actually Allowed

BulkEmailSetup
BulkEmailSetup Team
September 12, 2026
8 min read

Purchased lists are prohibited by the terms of every major sending provider, restricted or unlawful in the EU, UK and Canada, and technically self-defeating regardless of the law. In the US, CAN-SPAM permits mail without prior consent if you honour opt-outs and use accurate headers, so it is not automatically illegal there. Everywhere else, consent rules make it very hard to justify.

This article covers what is actually permitted, what happens technically, and what works instead. It is not a guide to sending purchased lists successfully, because that is not a thing that exists.

What the law says, by market

MarketRuleConsent needed?Penalty exposure
USCAN-SPAMNo, but opt-out must work$53,088 per email
EUGDPR + ePrivacyYes, or narrow legitimate interestUp to 4% global turnover
UKUK GDPR + PECRYes for B2C, softer for B2BUp to £17.5m
CanadaCASLExpress or impliedUp to CAD 10m
AustraliaSpam Act 2003YesUp to AUD 2.2m per day

Two nuances worth knowing. B2B in the UK is genuinely softer: PECR's consent requirement applies to individual subscribers, and mail to a corporate address at a limited company sits under legitimate interest, provided you can show the balancing test and honour objections. That is a real exemption, not a loophole, but it does not cover sole traders or partnerships, and GDPR's transparency duties still apply.

The US is permissive on consent but strict on mechanics. Accurate From and Subject lines, a working unsubscribe honoured within 10 business days, and a valid physical postal address. Purchased lists fail CAN-SPAM most often on the header accuracy and unsubscribe requirements, not the consent one.

None of this is legal advice. If you operate across markets, the strictest applicable rule is the one that governs your risk.

The B2B exemption people misread

The UK's PECR rules are genuinely softer for business-to-business mail, and this is where most of the confusion sits. The consent requirement in PECR applies to "individual subscribers", meaning consumers, sole traders and partnerships. Mail to a named person at a limited company or LLP falls outside that rule, so you can rely on legitimate interest under UK GDPR instead.

That is a real exemption, not a loophole. But it comes with conditions people skip:

  • You must complete and document a legitimate interests assessment, weighing your interest against the recipient's rights.
  • The transparency duties of UK GDPR still apply, so the recipient must be able to find out where you got their data.
  • You must honour objections immediately.
  • It does not cover sole traders, partnerships or personal addresses, even at work.

The ICO's direct marketing guidance sets out the detail. Note that "we bought a list of company addresses" and "we researched relevant companies and can show why each one is relevant" are very different positions under that test, even though both produce a list of B2B addresses.

Why it fails technically, regardless of the law

Even where mailing a purchased list is lawful, the delivery mechanics work against you.

SignalOpt-in listPurchased list
Bounce rateunder 2%15-40%
Complaint rateunder 0.1%often over 0.5%
Spam trapsnonenear certain
Engagement15-30% opens1-5% opens

Bounce rate is the first thing that breaks. Purchased data is stale by definition, and a 20% hard bounce rate tells every receiving network that you did not collect these addresses yourself. Providers suspend on this alone.

Spam traps are the fatal one. These are addresses that exist purely to catch senders mailing lists they did not build. Some are recycled abandoned accounts, some were never real. You cannot detect them by validation, because they accept mail. Hitting one can list your IP and domain at Spamhaus immediately, and that affects all your mail, including invoices and password resets.

Engagement signals finish it. Gmail and Microsoft weight engagement heavily. A list with 2% opens teaches them your mail is unwanted, and that judgment then applies to your legitimate campaigns too.

What a spam trap actually does

Worth understanding properly, because it is the failure mode people do not see coming.

Trap typeWhat it isHow you hit it
Pristineaddress never used by a humanscraped or bought data
Recycledabandoned account reactivated as a trapstale list, no hygiene
Typocommon misspelling of a real domainno validation at signup

Pristine traps are the serious ones. The address has never signed up for anything anywhere, so there is no legitimate way to have it. Mailing one is treated as direct evidence that the list was not collected by you.

You cannot detect traps by validation, because they accept mail. They do not bounce, do not complain, and produce no signal you can see. The first indication is your IP or domain appearing on a blocklist.

Spamhaus operates the most consequential of these, and a listing there affects mail to a large share of the internet at once, including your invoices, password resets and order confirmations. Delisting requires fixing the cause, not merely asking. Our Spamhaus delisting guide covers the process.

What the numbers do to your sender reputation

Google publishes its thresholds openly. Its bulk sender guidelines require a spam complaint rate below 0.3%, with 0.1% as the target, plus SPF, DKIM and DMARC on every sending domain.

A purchased list breaches that immediately, and the damage extends past the campaign:

What happensConsequence
High bounce on first sendprovider flags list provenance
Complaint rate above 0.3%Gmail starts filtering your domain
Spam trap hitblocklisting, all mail affected
Low engagementreceiving networks learn your mail is unwanted

That last row is the one that persists. Gmail and Microsoft score your domain, and that score follows you to any provider you move to. A single purchased-list campaign can cost months of transactional deliverability on a domain that took years to build.

Why dedicated IPs make it worse, not better

This comes up constantly, so it is worth being blunt: moving a purchased list onto dedicated IPs increases your risk.

On a shared pool, your damage is diluted across many senders and the provider suspends you before it gets severe. On dedicated IPs, there is no dilution. The reputation is yours alone, permanently, and a burned IP either takes months of remediation or has to be replaced and re-warmed from zero.

Dedicated infrastructure amplifies whatever your list quality already is. That is exactly why it is the right choice for a clean list and the wrong one for a bought list.

What actually works instead

For B2B outreach, the working model is researched prospecting, not bulk sending. Build the list yourself from public sources, verify each address, personalise genuinely, and send low volumes from dedicated outreach domains kept separate from your main sending domain. This is a different technical setup from bulk marketing, and it is covered in cold email domain setup cost and SMTP for cold email outreach.

For B2C, there is no shortcut. Opt-in acquisition through lead magnets, useful content and clean signup flows. Slower, and the only thing that compounds.

If you have already bought a list, do not mail it. Run it through validation to see the damage, then decide whether any segment has a genuine consent basis. Usually none does. Mailing it to "see what happens" is how a domain that took years to build gets blocklisted in an afternoon.

If you have already bought one

Do not mail it to see what happens. Work through this instead.

1. Do not send anything yet. A single send can list your domain, and that affects mail you cannot afford to lose.

2. Run it through validation. Not to make it safe, which validation cannot do, but to measure the damage. A 20%+ invalid rate confirms what you have.

3. Check for a consent basis segment by segment. Occasionally part of a list has one: customers you already trade with, or B2B contacts at limited companies where you can complete a legitimate interests assessment. Usually none of it does.

4. Isolate anything you do send. If a defensible segment exists, send it from a separate subdomain and separate IPs, never from the domain carrying your transactional mail.

5. Delete the rest. Keeping it "for later" means someone mails it eventually.

6. Ask for the money back. List sellers rarely refund, but the request creates a record of the list's provenance that is worth having.

The one legitimate grey area

Appended data on customers you already have a relationship with is different from a cold purchased list. If someone bought from you and you enriched their record with a corporate email address, you may have a legitimate-interest basis in the UK and EU, and clearly do under CAN-SPAM. Document the basis, honour objections, and keep it separate from your marketing stream. That is a defensible position. "We bought 200,000 addresses" is not.

How BulkEmailSetup helps

We build dedicated SMTP infrastructure for senders with lists they own: your own server, your own IPs, full SPF/DKIM/DMARC/PTR setup, MTA tuning, bounce handling and a warm-up plan. We are direct about the prerequisite, because dedicated IPs punish poor list quality harder than shared pools do.

If your list needs work first, start with email list cleaning and list hygiene. When the list is clean, Basic starts at $549 one-time covering 1 SMTP server, 3 dedicated IPs, 25,000 emails/day and unlimited contacts. See pricing.

Frequently asked questions

Is it legal to send email to a purchased list?

It depends entirely on the market. In the US, CAN-SPAM does not require prior consent, so mailing a purchased list is not automatically illegal provided you honour opt-outs, use accurate headers and include a physical address. In the EU and UK, GDPR and PECR require consent or a narrow legitimate-interest basis that a purchased list almost never satisfies. In Canada, CASL requires express or implied consent and carries penalties up to CAD 10 million.

Will any SMTP provider let me send to a purchased list?

Effectively no reputable one. SendGrid, Mailgun, Amazon SES, Brevo, Klaviyo and Postmark all prohibit purchased lists in their terms, and enforce it through complaint-rate and bounce-rate monitoring rather than by inspecting your list. Providers that openly advertise purchased-list sending tend to have IP ranges that are already blocklisted, so the delivery is poor anyway.

What happens technically when you mail a purchased list?

Bounce rates typically run 15 to 40% against under 2% for an opt-in list, because purchased data is stale. Complaint rates commonly exceed 0.5% against a 0.1% threshold. Purchased lists also carry spam traps, which are addresses that exist only to catch this behaviour, and hitting one can blocklist your IP and domain immediately.

Can a dedicated IP fix purchased-list delivery?

No, and it makes the consequences worse. A dedicated IP means the reputation damage is entirely and permanently yours, with no shared pool to dilute it. A burned dedicated IP takes months to recover or has to be replaced. Dedicated infrastructure amplifies list quality in both directions.

What is the compliant alternative to buying a list?

For B2B outreach, build a researched prospect list yourself from public sources and send genuinely personalised low-volume mail from separate domains, which is a different technical model from bulk sending. For B2C, invest in opt-in acquisition. Both are slower than buying a list and both actually work.

Tags

smtp for purchased listspurchased email listbought email listcan-spam compliancegdpr email marketingemail list qualitycold email
BulkEmailSetup

Written by BulkEmailSetup Team

We help businesses set up their own bulk email infrastructure, dedicated SMTP servers, IP rotation, and full deliverability control. One-time setup, no monthly platform fees.

Ready to set up your email infrastructure?

Get dedicated SMTP servers, IP rotation, and expert support to scale your email sending.

View Pricing