Most verdicts on this site come with nuance. This one doesn’t.
Why this is a no, always
Consent doesn’t transfer. Valid permission means the recipient clearly and knowingly agreed to receive your mail—freely given, specific, informed. A list assembled by someone else fails every part of that definition. If a pre-checked box or a terms-of-service clause doesn’t count as consent (and it doesn’t), an address purchased from a broker counts even less.
The mechanics destroy you quickly. Purchased lists are a package of everything inbox providers punish:
- Stale addresses—bounce rates spike, and past a few percent, providers read you as a spammer. (Above 4% is the classic danger line.)
- Spam traps—addresses that exist solely to catch senders who mail without permission. Hitting them can land your domain on blocklists like Spamhaus.
- Recipients who never asked—which means complaint rates far above the 0.3% ceiling Gmail and Yahoo enforce, from people encountering your brand for the first time as an intruder in their inbox.
Your ESP will act before the providers do. Sending to purchased lists violates essentially every email platform’s acceptable use policy. High bounces and complaints from a bought list get accounts paused or terminated—the platform is protecting its shared infrastructure from you.
And the damage lands on your domain, which follows you to any provider you flee to afterward.
What to do instead
Grow the boring way, which is also the only way that works: consent at the point of signup (an unchecked, specific checkbox), double opt-in to prove it, content worth subscribing to. A thousand people who asked for your email outperform a hundred thousand who didn’t—in revenue, not just in deliverability metrics.
If a vendor promises “verified, opted-in leads,” ask: opted in to whom? Not to you. That’s the entire problem.