emailmarketing.net

Address Acquisition Integrity: Legitimate Collection vs. Harvesting

The acquisition-integrity angle on list building — Spamhaus's confirmed-opt-in baseline, the acquisition metadata every address should carry, and why harvesting software (illegal in AU/NZ/CA and elsewhere) and purchased/appended/co-reg lists are the root cause of poor list quality.

Operational6 min read

Who it is for Senders, ESP operators

Applies to senders on any platform

How an address got onto your list decides, more than anything else, whether its owner will engage with your mail or complain about it. The question here is whether each address was obtained by a method you can stand behind, and whether you can prove it.

That means treating acquisition as a process you document and audit, knowing the illegitimate collection techniques, and knowing why several of them are also unlawful in their own right, harvesting software above all. Consent Methods and the List-Quality Spectrum looks at the same addresses from another angle: what kind of permission each one carries. It ranks the eight consent methods by quality and describes their complaint profiles.

The baseline: confirmed opt-in plus proof

Spamhaus's "Address Acquisition for Mailing Lists: The Basics" sets the minimum for legitimate collection at confirmed opt-in (COI, also called double opt-in). The contact makes a voluntary, active decision to receive mail, and confirms it by clicking a link in an email before the address receives any campaign. Spamhaus attaches these requirements to a signup you can defend:

  • Voluntary, active selection: no pre-checked boxes. The contact takes the action.
  • Transparent sign-up: the contact knows who they are subscribing to and what they will receive.
  • Web-form protection: CAPTCHA or reCAPTCHA on the form, to hold back automated and malicious submissions (the same defense discussed in Subscription Bombing).
  • Active email confirmation: the COI click, which also stops typos and spam traps, because a trap can never complete the confirmation.

Acquisition metadata to capture at signup

Legitimacy is useful only if you can prove it later. Spamhaus recommends storing at least the following for every address:

Field Why it matters
Sign-up date and time in UTC Shows when consent was given, and sets the timing for sunset and re-permission
Acquisition channel or source Lets you isolate and quarantine a bad source when complaints or trap hits spike
Submitting IP address Evidence of a real submission. Separates organic signups from bulk injection

This record is what you show a blocklist operator in a delisting dispute, and what you rely on to answer a GDPR erasure request or a right-to-object request (see Right to Object and Erasure). No acquisition record means, in practice, no consent you can defend. The M3AAWG Senders BCP sets out the same record-keeping as proof of consent.

Consent follows the address, not the person. Version 4.0 of that BCP (August 2026) says that when subscribers change the address on file, the new address should be confirmed the same way as a new signup.

Every illegitimate method below fails one test: permission given to one party does not transfer to another. A contact who agreed to hear from Company A did not, by doing so, agree to hear from Company B, from its "partners", or from whoever bought the file. Spamhaus repeats this ("consent is not transferrable") as the reason why co-registration, renting or buying lists, and appending are all unsafe, however the transaction is documented.

Illegitimate acquisition techniques

Technique What it is Why it fails
Harvesting or scraping Software crawls the web and collects anything that looks like an address, or generates addresses by combining names with a domain (a dictionary or directory harvest attack) There is no path to consent. Spamhaus warns of "serious blocking and delivery issues", lasting harm to reputation, and lower inbox placement. The highest exposure to pristine traps. Also illegal in its own right (see below).
Purchased lists Addresses bought outright Consent does not transfer. The result is blocklisting, long-term damage to deliverability, damage to the brand, and legal exposure under GDPR and similar laws. The buyer also drags down the shared reputation of its existing opted-in mail.
Rented lists You pay a list owner to send your content to their file, and you never see the addresses No relationship with the recipients. The owner and the sender share the damage to reputation.
Email appending ("epending") You match names or demographic data you hold to email addresses from a vendor, which creates addresses you were never given It goes against core industry values (Spamhaus endorses the M3AAWG ban on appending). The contact never gave the address to you.
Co-registration or affiliate lists An address is captured on Company A's form under wording such as "…and our partners", then passed to Company B Technically possible, but Spamhaus advises against it: "permission is not transferrable," so it "creates unacceptable risk for campaign damage."

Almost every ESP's acceptable use policy prohibits harvested, purchased, rented and appended lists, and lists from co-registration or affiliates. Using them is grounds for closing the account, on top of the damage to reputation and the legal risk. This is why acquisition audits are central to Spam-Trap Incident Response and Customer Vetting.

Harvesting software is separately illegal

Beyond the harm to reputation, using address-harvesting software, or lists it generated, is a separate offence under the law of several jurisdictions. That makes harvesting the one acquisition method that is not only bad practice but a distinct legal violation, for the sender, for the supplier of the software, and often for the ESP.

  • New Zealand, Unsolicited Electronic Messages Act 2007 (enforced by the Department of Internal Affairs, DIA): businesses must not use "electronic address harvesting software, or lists that have been generated using such software, for the purpose of sending unsolicited commercial electronic messages." The DIA stresses that buying a database does not make you compliant. Even when a seller claims "deemed consent" exists, the sender must prove consent when each message is sent, and a breach occurs "regardless of whether they believe consent existed due to the purchase of a database." Deemed consent is narrow. The address must have been conspicuously published in a business or official capacity, without a statement refusing unsolicited messages, and the message must relate to the recipient's role or duties. Enforcement ranges from a formal warning to High Court action for pecuniary penalties, compensation and damages. See APAC Email Laws for the NZ Act's levels of consent and maximum penalties.
  • Australia, Spam Act 2003 ss 20–22: address-harvesting software and lists of harvested addresses must not be supplied, acquired, or used in connection with sending that breaks the consent rule. These are three separate contraventions. See Australia Spam Act.
  • Canada, CASL and PIPEDA, and US, CAN-SPAM: harvesting and generating addresses by dictionary attack are named explicitly. Under CAN-SPAM they are an "aggravated violation" (15 U.S.C. 7704). In Canada, the Office of the Privacy Commissioner (OPC) handles them under PIPEDA. Supplying or selecting harvested addresses is a separate ground of liability that can reach the ESP itself. See Enforcement Cases.

In practice, a purchased file, or a "deemed consent" file offered by a broker, should be presumed unsafe and possibly harvested. The burden of proving otherwise is on the sender, and the sender usually cannot meet it.

Why acquisition method is the root cause

Problems that show up later in list quality, such as spam-trap hits, high complaint rates, spikes in hard bounces and blocklistings, are almost always acquisition failures that surface late. A pristine trap appears only in a file that was scraped, generated or bought. A recycled trap appears only in a file that brought old addresses back into use. A spike in complaints after a list swap almost always traces back to appended or transferred addresses whose owners never consented to hear from this sender. Fixing acquisition comes before every remediation procedure, and costs less than any of them:

  • The consequence for trap hits, from Spam Traps: "if your list processes allow spamtraps onto the list, it's likely you're also sending mail to actual people who don't want it." Traps are a signal of the acquisition defect, not the defect itself.
  • Recovery after an incident (Reputation Incident Recovery) always includes an audit and purge of acquisition sources, because warming up an IP address again on the same contaminated list simply earns the block again.