A good lead list is not "1,000 emails". It is a small set of people who match your ideal
customer, whose address is real, and whose first line you did not copy-paste. Bad lists do
not just waste money — they burn your sending domain. Here is the process I use.
Define the ICP before you touch a tool
Write three sentences: who exactly (role + company size + industry), what pain, what trigger
means they are in-market now (funding, hiring, product launch, tech change). If you cannot
name the trigger, you are about to buy a random list.
Sourcing that does not poison the data
- Prefer primary sources. Company websites, careers pages, GitHub orgs, conference speaker lists. These are more accurate than scraped aggregators and less likely to contain traps.
- Check the domain before the mailbox. Does the site resolve, load, and match the company name? Typo-domains and parked domains are how bounce rates explode.
- One source per fact. Record where each field came from. If you cannot cite it, delete it.
Verify before you write
-
Syntax basics (
name@domain.tld) are cheap — reject the obvious. - Domain/MX check. No MX record means no mailbox, no exceptions.
-
Role addresses are not leads.
info@,sales@,noreply@go in a separate bucket, never your main sequence. - Catch-all domains are not "verified". Mark them as risky. A "verified" badge you cannot defend is worse than an honest "unverified".
Do not trust a single checker. Run two and keep only the intersection.
Deliverability hygiene
This is where most freelancers cost their clients real money:
- Warm the domain. A brand-new domain sending 500 cold emails on day one is a one-way trip to spam.
- Use a custom subdomain for outreach so your main domain is insulated.
- Keep bounce rate under 2%. Above it, pause and clean.
- Include a real postal address and one-click unsubscribe — required in most jurisdictions.
- Never buy a list and blast it. That is the definition of spam.
The opener that works
Personalization is not "Hi {FirstName}". It is one specific, verifiable line that proves you
looked:
Saw you're hiring two SREs and just moved to Kubernetes — most teams hit the same
observability gap at that stage.
That sentence comes from the trigger you defined earlier. If you cannot write one for a lead,
the lead is not qualified.
Compliance is not optional
- EU/UK: GDPR/UK-GDPR — you need a lawful basis (usually legitimate interest for B2B) and a clear opt-out. Document it.
- US: CAN-SPAM — real address, honest subject, working unsubscribe.
- Canada: CASL — stricter; consent-based for many cases. Check before sending.
This is not legal advice; it is why a clean, consent-aware list beats a giant one.
A workable workflow
- Write the ICP + trigger.
- Pull 200–300 candidates from primary sources.
- Check domain + MX; drop failures.
- Verify emails with two checkers; keep the intersection.
- Deduplicate by person and by company.
- Write one personalized opener per lead — or drop the lead.
- Send in small batches; watch bounce and reply; pause if bounce > 2%.
- Log source and result for every field so the next list is better.
A verified list of 50 with real openers will outperform 2,000 scraped addresses every single
time — and it will not cost you your domain.
I build verified B2B lead lists with per-lead openers and deliverability checks. Details in
my portfolio.
Top comments (0)