Email List Compliance Audit: How to Check Your List Meets Legal Requirements
By Email ExtractorPublished 9 min read
On this page
Why Compliance Audits Matter
An email list compliance audit checks whether your email contact data meets legal requirements for the jurisdictions you operate in. Violations can result in significant fines, domain blacklisting and reputational damage:
Consent was not a condition of service (unless necessary)
Third-party data has consent
Purchased or partner lists have verifiable consent for your emails
Data provider can demonstrate consent records
Consent is current
Consent has not expired or been withdrawn
Re-consent campaigns run for stale contacts
2. Suppression and opt-out audit
Check
What to verify
Pass criteria
Unsubscribe mechanism works
Every marketing email includes a working unsubscribe link
Test unsubscribe from recent campaigns; confirm it works
One-click unsubscribe
List-Unsubscribe header is implemented for bulk senders
Email headers include List-Unsubscribe and List-Unsubscribe-Post
Unsubscribe is honoured within 10 days
CAN-SPAM requires 10 business days; GDPR effectively requires faster
Check processing time from unsubscribe to suppression
Global suppression list exists
A master suppression list prevents re-adding unsubscribed contacts
Suppression list is maintained and applied to all sends
Suppression list is applied before every send
New imports and campaign sends check against suppression
Test by adding a suppressed address to a new import; confirm it is blocked
Hard bounces are suppressed
Invalid addresses are not re-mailed
Hard bounces automatically added to suppression
Complaint addresses are suppressed
Spam complaints trigger suppression
Feedback loops (FBLs) are configured; complaints trigger suppression
Previous opt-outs are preserved during migrations
CRM or platform migrations do not lose suppression data
Migration plan includes suppression list transfer
3. Data source audit
Check
What to verify
Pass criteria
Source of every contact is recorded
Each contact has a documented acquisition source
Source field is populated for every record
Date of acquisition is recorded
Each contact has a date stamp
Date field is populated
No scraped data without legal basis
Contacts obtained through scraping have appropriate legal basis
Review scraping practices against applicable law
Purchased lists have documentation
Data purchase agreements include consent warranties
Contracts with data providers are on file
Co-registration sources are documented
Contacts from co-registration have proper consent
Co-registration consent language is on file
Event and conference lists have consent
In-person collection included consent notice
Registration forms or badge-scan agreements include consent
Website forms collect consent
Online forms include consent checkbox or notice
Review form designs and consent language
4. Data quality audit
Check
What to verify
Pass criteria
Email syntax is valid
All addresses follow valid email format
No malformed addresses in the list
Domains have valid MX records
Email domains can receive email
MX lookup confirms deliverability
Duplicate addresses are identified
No address appears more than once
Deduplication has been run
Role-based addresses are flagged
info@, admin@, support@ addresses are identified
Role-based addresses are segmented or removed from marketing
Disposable addresses are flagged
Temporary email domains are identified
Known disposable domains are filtered
Spam traps are absent
No known spam trap addresses exist in the list
Email verification service has checked for spam traps
Bounce rate is acceptable
Historical bounce rate is within tolerance
Under 2% hard bounce rate
Complaint rate is acceptable
Spam complaint rate is within tolerance
Under 0.1% complaint rate (Google postmaster threshold: 0.3%)
5. Data retention and minimisation audit
Check
What to verify
Pass criteria
Retention policy exists
A documented policy defines how long contact data is kept
Written retention policy is on file
Retention policy is enforced
Contacts older than retention period are reviewed or removed
Automated or manual cleanup runs on schedule
Inactive contacts are managed
A sunset policy addresses contacts who have not engaged
Contacts with no engagement in 6-12 months are reviewed
Unnecessary data is not collected
Only data needed for the stated purpose is collected
Forms do not collect fields that are never used
Data deletion requests are honoured
GDPR and CCPA deletion requests are processed
Deletion process is documented and tested
6. Security and access audit
Check
What to verify
Pass criteria
Access is restricted
Only authorised personnel can access email lists
Access controls and permissions are in place
Data is encrypted at rest
Email databases are encrypted
Encryption is enabled on storage systems
Data is encrypted in transit
Email data transfers use encryption (TLS/SSL)
API calls and file transfers use HTTPS/SFTP
Export controls exist
List exports are logged and restricted
Export activity is auditable
Third-party processors are vetted
ESP and CRM providers meet compliance requirements
Data processing agreements (DPAs) are signed
Breach notification plan exists
Process for reporting data breaches is documented
Breach response plan is on file and tested
Conducting the Audit
Step-by-step process
Step
Action
Tools needed
1
Export current email list from all sending platforms
CRM, ESP, marketing automation platform
2
Consolidate and deduplicate across sources
Email extraction and dedup tool
3
Map each contact to its source and consent record
CRM data, source fields, consent logs
4
Run email verification to check validity
Email verification service
5
Cross-reference against suppression lists
Master suppression list
6
Identify contacts without documented consent
Query contacts with empty source or consent fields
7
Flag contacts in regulated jurisdictions
Map contacts by geography (GDPR, CASL, CCPA)
8
Review data retention compliance
Check age of contacts against retention policy
9
Document findings and remediation steps
Audit report
10
Implement fixes and re-audit
Follow-up audit in 30-90 days
Regulation-Specific Requirements
CAN-SPAM (United States)
Requirement
What it means for your list
No false or misleading headers
Sender name and email must be accurate
Subject lines must not be deceptive
Subject must relate to email content
Must identify message as advertisement
Commercial email must be identifiable as such
Must include physical address
Every email includes your valid postal address
Must include opt-out mechanism
Working unsubscribe in every commercial email
Must honour opt-outs within 10 business days
Suppression processing must complete within 10 days
Cannot require fee or personal info to opt out
Unsubscribe must be simple and free
Note: CAN-SPAM does not require prior opt-in
But ISPs and ESPs have stricter requirements
GDPR (European Union / EEA)
Requirement
What it means for your list
Lawful basis required
Consent, legitimate interest, or contractual necessity
Consent must be freely given, specific, informed, unambiguous
No pre-checked boxes; clear consent language
Right to withdraw consent
Easy unsubscribe; must be as easy as giving consent
Right to erasure
Must delete data on request
Right to data portability
Must provide data in machine-readable format on request
Records of processing
Document what data you hold, why, and how it is processed
Data protection impact assessment
Required for high-risk processing
Data breach notification
Notify authority within 72 hours; notify individuals if high risk
Data processing agreements
Required with all third-party processors (ESP, CRM, etc.)
CASL (Canada)
Requirement
What it means for your list
Express consent required for commercial electronic messages
Must have opt-in consent (not just opt-out)
Implied consent has time limits
2 years from purchase; 6 months from enquiry
Must identify sender and include contact information
Sender name, address, phone or email in every message
Must include unsubscribe mechanism
Working unsubscribe; must be processed within 10 business days
Consent records must be maintained
Keep records of how and when consent was obtained
Installation of software requires consent
Relevant if emails contain software downloads
Remediation Steps
For contacts without documented consent
Situation
Remediation
Source is known but consent is not documented
Send a re-consent email; suppress those who do not re-consent
Source is unknown
Remove from active lists; do not email until consent is obtained
Purchased list with unclear consent
Quarantine; contact data provider for consent documentation
Contacts from before compliance programme existed
Run re-permission campaign; suppress non-responders
Contacts in GDPR jurisdictions without consent
Remove immediately unless legitimate interest can be documented
For data quality issues
Issue
Remediation
High bounce rate
Run email verification; remove invalid addresses
Duplicate addresses
Deduplicate; merge records where possible
Role-based addresses
Segment out of marketing sends; use for transactional only
Spam trap addresses
Remove immediately; investigate how they entered the list
Inactive contacts
Run re-engagement campaign; sunset those who remain inactive
Preparing for the Audit
When consolidating email lists from multiple platforms (CRM exports, ESP exports, spreadsheets, legacy databases) for a compliance audit, upload the files to Email Extractor to extract and deduplicate email addresses across all sources. This creates a single unified list for the audit, making it easier to identify duplicates, check for suppressed addresses and verify that every contact has a documented source.