Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

Email List Audit Checklist: Review Your List Before Sending

On this page

Why Audit Before Sending

An extracted email list is a raw output. It contains every email address found in your source files, including addresses that should not be contacted: unsubscribed recipients, invalid addresses, system mailboxes, spam traps and contacts who never agreed to hear from you.

Sending to an unaudited list damages your sender reputation, increases bounces, triggers spam complaints and can violate compliance requirements. An audit is the step between extraction and sending that catches these problems.

The Checklist

1. Source review

Do you know where every address came from?

If you downloaded results as CSV with sources from Email Extractor, the source column tells you which file each address was found in. Review this column and ask:

  • Are all source files legitimate? A contract, a CRM export and your own correspondence are reliable sources. A file of unknown origin is a risk.
  • Are the source files current? Addresses from files more than a year old carry a higher risk of being invalid or recycled into spam traps. See Email list decay explained.
  • Did any addresses come from purchased or shared lists? These carry the highest risk of spam traps and compliance issues.

Action: Flag any addresses from unknown or high-risk sources for extra scrutiny or removal.

2. Suppression list check

Have you checked the list against your suppression list?

A suppression list contains addresses of people who have unsubscribed, complained, requested deletion, or repeatedly bounced. Every new list must be checked against it before sending.

If you do not have a suppression list, create one before this audit. At minimum, it should contain:

  • Addresses that have previously unsubscribed from your communications.
  • Addresses that have complained (marked your messages as spam).
  • Addresses that have hard bounced in past sends.
  • Addresses where the person requested data deletion (under GDPR, CCPA or other privacy laws).

Action: Remove every address that appears on your suppression list.

3. Role-based address review

Does the list contain role-based addresses?

Role-based addresses (info@, support@, sales@, admin@, webmaster@, billing@, contact@) go to shared inboxes rather than individual people. They tend to produce higher complaint rates because the person checking the inbox may not know why the address is receiving your message.

See Role-based email addresses explained.

Action: Remove role-based addresses unless you have a specific reason to contact that functional inbox.

4. Disposable address check

Does the list contain disposable or temporary email addresses?

Addresses at disposable providers (Guerrilla Mail, Temp Mail, Mailinator and similar services) are created for one-time use and typically expire within hours or days. Sending to them is wasted effort and inflates bounce rates.

See Disposable email addresses explained.

Action: Remove addresses at known disposable providers.

5. Obvious invalid addresses

Are there addresses that are clearly not contactable?

Scan for:

  • noreply@ and no-reply@ addresses.
  • mailer-daemon@ and postmaster@ addresses.
  • Addresses at your own domain that belong to system accounts.
  • Addresses that look like Message-IDs rather than mailboxes (unusually long random strings followed by @). These can appear in extractions from EML files. See Email header fields explained.
  • Test addresses (test@example.com, test@yourcompany.com).

Action: Remove obviously invalid or non-contactable addresses.

6. Domain check

Do the domains look legitimate?

Spot-check the domains in your list:

  • Are there addresses at domains that do not exist? A quick check for common typo domains (gmial.com, yaho.com, hotmal.com) catches typo traps and data entry errors.
  • Are there addresses at domains you do not recognise? These may be legitimate or may be signs of data quality issues.

Action: Remove addresses at known typo domains. Flag unfamiliar domains for validation.

7. Email validation

Have you validated the addresses?

Email Extractor identifies email addresses in your files. It does not check whether those addresses are currently active, deliverable or safe to send to. Validation is a separate step performed by a dedicated email validation service.

Validation checks:

  • Whether the domain has MX records (can receive email).
  • Whether the specific mailbox exists and can accept messages.
  • Whether the address is a known spam trap.
  • Whether the domain is a known disposable provider.

Action: Run the entire list through an email validation service. Remove addresses marked as invalid, risky or undeliverable.

8. Compliance review

Are you allowed to email these people?

  • CAN-SPAM (US): Commercial messages must include an unsubscribe mechanism and your physical address. Having someone's email address does not grant permission to email them, but CAN-SPAM does not require prior consent for commercial email, only that you honour opt-outs. See CAN-SPAM and extracted email lists.
  • GDPR (EU/EEA): Requires a legal basis for processing personal data, which may mean prior consent for marketing. See GDPR and email extraction.
  • CCPA (California): Gives California residents the right to know what data you have, request deletion and opt out of sale or sharing. See CCPA and email extraction.

Action: Confirm you have a legal basis for contacting the people on your list under all applicable laws. Remove anyone you cannot lawfully contact.

9. Volume and sending plan

Are you ready to send responsibly?

  • If your sending address or domain is new or has low volume, do you have a warm-up plan?
  • Is the list size appropriate for your current sending reputation?
  • Do you have SPF, DKIM and DMARC configured for your sending domain?

Action: Plan your send volume and ensure your email authentication is in place.

10. Format check

Is the list formatted correctly for your platform?

Each email marketing platform or CRM expects data in a specific format (column names, file encoding, file type). Importing a misformatted file can cause errors or data loss.

See How to format your email list for a CRM.

Action: Format the final list to match your platform's import requirements before uploading.

Quick Reference

Check Question Action
Source review Do you know where each address came from? Flag or remove unknown sources
Suppression list Checked against unsubscribes, bounces, complaints? Remove matches
Role-based Any info@, support@, admin@? Remove unless needed
Disposable Any temporary email addresses? Remove
Invalid Any noreply@, mailer-daemon@, test@? Remove
Domains Any typo domains or non-existent domains? Remove typos, flag unknowns
Validation Run through a validation service? Remove invalid results
Compliance Legal basis for contacting? Remove where no basis
Sending plan Warm-up and authentication ready? Plan before sending
Format Matches your platform's requirements? Reformat if needed

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)