Someone on your team just found a vendor selling "50,000 verified marketing emails, opt-in guaranteed." It's tempting. It's also almost always a mistake, and the reasons go way beyond "it feels spammy."
Let's separate the legal question from the practical one, because they have different answers.
Is it actually illegal?
In the US, buying a list isn't automatically a CAN-SPAM violation. CAN-SPAM regulates how you send, not where you got the address — it never required opt-in consent to begin with, only an opt-out mechanism, accurate headers, and a physical address in the footer.
So a purchased list, by itself, doesn't break US federal law. But two things make this technically-legal loophole nearly worthless in practice.
First, most purchased lists were never legitimately collected in the first place — scraped, harvested, or bought from a broker who bought them from someone else, three degrees removed from actual consent. Second, the moment you email outside the US, the calculus flips entirely.
Where it becomes flatly illegal
GDPR (the EU's privacy law) and Canada's CASL (Canada's Anti-Spam Legislation) both require opt-in consent before you send, not after. A purchased list can't carry that consent forward — the person on the list consented to something, from someone else, not to hearing from your brand.
Email even one EU resident from a purchased list and you're in GDPR territory, where fines run up to 4% of global annual revenue. CASL penalties can reach CAD $10 million per violation for an organization.
- US (CAN-SPAM): opt-out based, purchased lists are a gray area, not a bright-line violation
- EU (GDPR): opt-in required, purchased lists are a violation the moment you hit send
- Canada (CASL): opt-in required, among the strictest and most aggressively enforced anti-spam regimes globally
That gray area in the US is shrinking fast anyway. Read on for why.
The real cost isn't the fine, it's your domain
Here's the part vendors don't mention: CAN-SPAM's actual maximum civil penalty is $53,088 per individual email, set by the FTC's most recent inflation adjustment effective January 2025. Not per campaign. Per email.
But most companies buying lists never see an FTC complaint at all — they get hurt faster and quieter than that. Spam-trap hits (dead addresses ISPs seed specifically to catch purchased-list senders) and mass unsubscribe/spam-report rates get your sending domain and IP blocklisted by Gmail, Outlook, and Yahoo within days.
Once blocklisted, every email you send — including to your real, opted-in customers — lands in spam or gets silently dropped. Rebuilding sender reputation after a blocklisting event routinely takes months, and some domains never fully recover.
What "co-registration" doesn't fix
Co-registration lists (where someone checked a box on Site A agreeing to hear from "partners") feel safer because there's technically a checkbox involved. They aren't safer.
Courts and regulators increasingly treat buried, pre-checked, or vague "partners" consent as no consent at all — this is exactly the theory driving recent state privacy enforcement. The person never agreed to hear from you, specifically, and a rented "partner" checkbox from six months ago won't hold up as proof of active interest.
If the consent doesn't name your brand, don't treat it as consent to your brand.
Recent enforcement makes the risk concrete
Regulators went from theoretical to painful quickly. In 2024, the FTC fined smart-camera company Verkada $2.95 million, its largest CAN-SPAM penalty ever, for blasting prospects with commercial emails that had no unsubscribe link, no honored opt-outs, and no physical address. None of that required proving the list was purchased, sloppy sending mechanics alone were enough.
State law raised the stakes further. In April 2025, the Washington Supreme Court ruled in Brown v. Old Navy that the state's Commercial Electronic Mail Act imposes a $500 penalty on every email with any false or misleading subject line, not just ones that mislead about the email's actual purpose. Plaintiffs argued this exposed retailers to trillions in theoretical liability, which pushed the Washington legislature to pass a 2026 amendment cutting the penalty to $100 per email and requiring proof the sender knew the subject line was false.
The lesson holds either way: state anti-spam law can create per-email liability the FTC's federal ceiling never reaches. A purchased list, with its higher bounce and complaint rates, is far more likely to draw the scrutiny that surfaces these violations in the first place.
Common mistakes teams make with 'safer' alternatives
- Assuming a confirmation email retroactively legalizes a cold list. Sending a second, opt-in-style message to a purchased address is still an unsolicited commercial email under CASL and GDPR, the recipient never consented to receiving it in the first place.
- Assuming CASL doesn't apply to non-Canadian companies. CASL applies whenever a commercial message is accessed by a computer system located in Canada, not based on where the sender is headquartered.
- Confusing 'verified' with 'consented.' A vendor verifying that an email address is deliverable says nothing about whether that person ever agreed to hear from your brand.
- Ignoring state-level anti-spam law because CAN-SPAM feels permissive. Washington's CEMA and similar state statutes can impose per-email penalties federal law doesn't touch.
What actually works instead
Building your own list is slower and that's the whole point — every subscriber chose you specifically.
- Lead magnets and gated content: trade something valuable for a real opt-in
- Double opt-in: confirms the address is real and the person meant to subscribe, which also protects your sender reputation
- On-site and event capture: people who already know your brand convert into subscribers who actually open
- Paid ads to a landing page: costs money, but every resulting subscriber is unambiguously consented
A smaller list of people who chose you will always outperform a bigger list of people who didn't — in opens, in revenue, and in staying off blocklists.
A single spam-trap hit from a purchased list can tank deliverability for your entire domain, including transactional emails like password resets and receipts. The blast radius is bigger than the campaign that caused it.