# Address Acquisition Integrity: Legitimate Collection vs. Harvesting

> The acquisition-integrity angle on list building — Spamhaus's confirmed-opt-in baseline, the acquisition metadata every address should carry, and why harvesting software (illegal in AU/NZ/CA and elsewhere) and purchased/appended/co-reg lists are the root cause of poor list quality.

Source: emailmarketing.net — https://emailmarketing.net/learn/list-management/address-acquisition

How an address got onto your list decides, more than anything else, whether its owner will engage with your mail or complain about it. The question here is whether each address was obtained by a method you can stand behind, and whether you can prove it.

That means treating acquisition as a process you document and audit, knowing the illegitimate collection techniques, and knowing why several of them are also unlawful in their own right, harvesting software above all. [Consent Methods and the List-Quality Spectrum](https://emailmarketing.net/learn/list-management/consent-methods) looks at the same addresses from another angle: what kind of permission each one carries. It ranks the eight consent methods by quality and describes their complaint profiles.

## The baseline: confirmed opt-in plus proof

Spamhaus's "Address Acquisition for Mailing Lists: The Basics" sets the minimum for legitimate collection at **confirmed opt-in (COI, also called double opt-in)**. The contact makes a voluntary, active decision to receive mail, and confirms it by clicking a link in an email before the address receives any campaign. Spamhaus attaches these requirements to a signup you can defend:

- **Voluntary, active selection**: no pre-checked boxes. The contact takes the action.
- **Transparent sign-up**: the contact knows who they are subscribing to and what they will receive.
- **Web-form protection**: CAPTCHA or reCAPTCHA on the form, to hold back automated and malicious submissions (the same defense discussed in [Subscription Bombing](https://emailmarketing.net/learn/esp-operations/subscription-bombing)).
- **Active email confirmation**: the COI click, which also stops typos and [spam traps](https://emailmarketing.net/learn/reference/spam-traps), because a trap can never complete the confirmation.

### Acquisition metadata to capture at signup

Legitimacy is useful only if you can **prove** it later. Spamhaus recommends storing at least the following for every address:

| Field | Why it matters |
|---|---|
| **Sign-up date and time in UTC** | Shows when consent was given, and sets the timing for sunset and re-permission |
| **Acquisition channel or source** | Lets you isolate and quarantine a bad source when complaints or trap hits spike |
| **Submitting IP address** | Evidence of a real submission. Separates organic signups from bulk injection |

This record is what you show a **blocklist operator in a delisting dispute**, and what you rely on to answer a **GDPR erasure request or a right-to-object request** (see [Right to Object and Erasure](https://emailmarketing.net/learn/compliance/right-to-object-and-erasure)). No acquisition record means, in practice, no consent you can defend. The [M3AAWG Senders BCP](https://emailmarketing.net/learn/industry-best-practices/m3aawg-senders-bcp) sets out the same record-keeping as proof of consent.

Consent follows the address, not the person. Version 4.0 of that BCP (August 2026) says that when subscribers change the address on file, the new address should be confirmed the same way as a new signup.

## The core principle: consent is not transferable

Every illegitimate method below fails one test: **permission given to one party does not transfer to another.** A contact who agreed to hear from Company A did not, by doing so, agree to hear from Company B, from its "partners", or from whoever bought the file. Spamhaus repeats this ("consent is not transferrable") as the reason why co-registration, renting or buying lists, and appending are all unsafe, however the transaction is documented.

## Illegitimate acquisition techniques

| Technique | What it is | Why it fails |
|---|---|---|
| **Harvesting or scraping** | Software crawls the web and collects anything that looks like an address, or generates addresses by combining names with a domain (a dictionary or directory harvest attack) | There is no path to consent. Spamhaus warns of "serious blocking and delivery issues", lasting harm to reputation, and lower inbox placement. The highest exposure to [pristine traps](https://emailmarketing.net/learn/reference/spam-traps). **Also illegal in its own right** (see below). |
| **Purchased lists** | Addresses bought outright | Consent does not transfer. The result is blocklisting, long-term damage to deliverability, damage to the brand, and legal exposure under GDPR and similar laws. The buyer also drags down the shared reputation of its existing opted-in mail. |
| **Rented lists** | You pay a list owner to send your content to their file, and you never see the addresses | No relationship with the recipients. The owner and the sender share the damage to reputation. |
| **Email appending ("epending")** | You match names or demographic data you hold to email addresses from a vendor, which creates addresses you were never given | It goes against core industry values (Spamhaus endorses the M3AAWG ban on appending). The contact never gave the address to you. |
| **Co-registration or affiliate lists** | An address is captured on Company A's form under wording such as "…and our partners", then passed to Company B | Technically possible, but Spamhaus advises against it: "permission is not transferrable," so it "creates unacceptable risk for campaign damage." |

Almost every ESP's acceptable use policy prohibits harvested, purchased, rented and appended lists, and lists from co-registration or affiliates. Using them is grounds for closing the account, on top of the damage to reputation and the legal risk. This is why acquisition audits are central to [Spam-Trap Incident Response](https://emailmarketing.net/learn/esp-operations/spam-trap-incident-response) and [Customer Vetting](https://emailmarketing.net/learn/esp-operations/customer-vetting).

## Harvesting software is separately illegal

Beyond the harm to reputation, using address-harvesting software, or lists it generated, is a separate offence under the law of several jurisdictions. That makes harvesting the one acquisition method that is not only bad practice but a distinct legal violation, for the sender, for the supplier of the software, and often for the ESP.

- **New Zealand, Unsolicited Electronic Messages Act 2007** (enforced by the Department of Internal Affairs, DIA): businesses must not use "electronic address harvesting software, or lists that have been generated using such software, for the purpose of sending unsolicited commercial electronic messages." The DIA stresses that **buying a database does not make you compliant**. Even when a seller claims "deemed consent" exists, the sender must prove consent when each message is sent, and a breach occurs "regardless of whether they believe consent existed due to the purchase of a database." Deemed consent is narrow. The address must have been **conspicuously published** in a business or official capacity, **without** a statement refusing unsolicited messages, and the message must **relate to the recipient's role or duties**. Enforcement ranges from a formal warning to **High Court action for pecuniary penalties, compensation and damages**. See [APAC Email Laws](https://emailmarketing.net/learn/compliance/apac-email-laws) for the NZ Act's levels of consent and maximum penalties.
- **Australia, Spam Act 2003** ss 20–22: address-harvesting software and lists of harvested addresses must not be **supplied, acquired, or used** in connection with sending that breaks the consent rule. These are three separate contraventions. See [Australia Spam Act](https://emailmarketing.net/learn/compliance/australia-spam-act).
- **Canada, CASL and PIPEDA**, and **US, CAN-SPAM**: harvesting and generating addresses by dictionary attack are named explicitly. Under CAN-SPAM they are an "aggravated violation" (15 U.S.C. 7704). In Canada, the Office of the Privacy Commissioner (OPC) handles them under PIPEDA. Supplying or selecting harvested addresses is a separate ground of liability that can reach the ESP itself. See [Enforcement Cases](https://emailmarketing.net/learn/compliance/enforcement-cases).

In practice, a purchased file, or a "deemed consent" file offered by a broker, should be presumed unsafe and possibly harvested. The burden of proving otherwise is on the sender, and the sender usually cannot meet it.

## Why acquisition method is the root cause

Problems that show up later in list quality, such as spam-trap hits, high complaint rates, spikes in hard bounces and blocklistings, are almost always **acquisition failures that surface late**. A pristine trap appears only in a file that was scraped, generated or bought. A recycled trap appears only in a file that brought old addresses back into use. A spike in complaints after a list swap almost always traces back to appended or transferred addresses whose owners never consented to hear from this sender. Fixing acquisition comes before every remediation procedure, and costs less than any of them:

- The consequence for trap hits, from [Spam Traps](https://emailmarketing.net/learn/reference/spam-traps): "if your list processes allow spamtraps onto the list, it's likely you're also sending mail to actual people who don't want it." Traps are a signal of the acquisition defect, not the defect itself.
- Recovery after an incident ([Reputation Incident Recovery](https://emailmarketing.net/learn/operations/reputation-incident-recovery)) always includes an audit and purge of acquisition sources, because warming up an IP address again on the same contaminated list simply earns the block again.

## Related articles

- [Consent Methods and the List-Quality Spectrum](https://emailmarketing.net/learn/list-management/consent-methods)
- [Spam Traps](https://emailmarketing.net/learn/reference/spam-traps), including pristine, recycled and typo traps
- [List Hygiene and Sunset Policies](https://emailmarketing.net/learn/operations/list-hygiene-and-sunset-policies), including validation at signup
- [Spam-Trap Incident Response](https://emailmarketing.net/learn/esp-operations/spam-trap-incident-response)
- [Customer Vetting](https://emailmarketing.net/learn/esp-operations/customer-vetting), on how ESPs examine a prospect's acquisition practices before onboarding
- [Enforcement Cases](https://emailmarketing.net/learn/compliance/enforcement-cases)
- [Australia Spam Act](https://emailmarketing.net/learn/compliance/australia-spam-act)
- [APAC Email Laws](https://emailmarketing.net/learn/compliance/apac-email-laws)
- [Consent Guidance Updates](https://emailmarketing.net/learn/compliance/consent-guidance-updates), on recent regulator positions on what consent now requires
