Address Acquisition Integrity: Legitimate Collection vs. Harvesting
The acquisition-integrity angle on list building — Spamhaus's confirmed-opt-in baseline, the acquisition metadata every address should carry, and why harvesting software (illegal in AU/NZ/CA and elsewhere) and purchased/appended/co-reg lists are the root cause of poor list quality.
How an address entered the list is the single largest determinant of whether it will engage or complain (see Consent Methods and the List-Quality Spectrum for the eight-method quality ranking and complaint profiles). This article takes the complementary acquisition-integrity view: it treats acquisition as a process to be documented and audited, catalogs the illegitimate collection techniques (not just their place on the spectrum), and records why several of them are separately unlawful — harvesting software most of all. Where consent-methods.md asks "what kind of permission does this address carry?", this article asks "was the address obtained by a method a sender can stand behind, and can they prove it?"
The baseline: confirmed opt-in plus proof
Spamhaus's "Address Acquisition for Mailing Lists: The Basics" sets the legitimate floor at confirmed opt-in (COI / double opt-in): a voluntary, active decision by the contact to receive mail, confirmed by clicking a link in an email before the address is ever mailed a campaign. Requirements Spamhaus attaches to a defensible signup:
- Voluntary, active selection — no pre-checked boxes; the contact takes the affirmative action.
- Transparent sign-up — the contact knows who they are subscribing to and what they will receive.
- Web-form protection — CAPTCHA/reCAPTCHA on the form to blunt automated and malicious submissions (the same defense discussed in Subscription Bombing).
- Active email confirmation — the COI click, which also blocks typos and spam traps (a trap can never complete confirmation).
Acquisition metadata to capture at signup
Legitimacy is only useful if it can be proven later. Spamhaus recommends storing, for every address, at minimum:
| Field | Why it matters |
|---|---|
| Sign-up date/time in UTC | Establishes when consent was given; anchors sunset/re-permission timing |
| Acquisition channel/source | Lets you isolate and quarantine a bad source when complaints or trap hits spike |
| Submitting IP address | Evidence of a real submission; distinguishes organic signups from bulk injection |
This record is what you produce to a blocklist during a delisting dispute and what you rely on to answer a GDPR/erasure or right-to-object request (see Right to Object and Erasure). No acquisition record ≈ no defensible consent. The M3AAWG Senders BCP formalizes the same proof-of-consent record-keeping.
The core principle: consent is not transferable
Every illegitimate method below fails one test: permission acquired by one party does not transfer to another. A contact who agreed to hear from Company A never thereby agreed to hear from Company B, its "partners," or whoever bought the file. Spamhaus repeats this ("consent is not transferrable") as the reason co-registration, list rental/purchase, and appending are all unsafe regardless of how the transaction is papered.
Illegitimate acquisition techniques
| Technique | What it is | Why it fails |
|---|---|---|
| Harvesting / scraping | Software crawls the web collecting anything shaped like an address, or generates addresses by permuting names against a domain (dictionary/directory-harvest attack) | Zero consent path. Spamhaus: "serious blocking and delivery issues," long-lasting reputation harm, reduced inbox placement. Maximal pristine-trap exposure. Separately illegal — see below. |
| Purchased lists | Addresses bought outright | Consent not transferable; blocklisting, long-term deliverability degradation, brand damage, and legal exposure under GDPR and equivalents. The buyer also drags down shared reputation for its existing opted-in mail. |
| Rented lists | Pay a list owner to mail your content to their file; you never see the addresses | No relationship with recipients; reputation damage is shared between owner and sender. |
| Email appending ("epending") | Match names/demographic data you hold to email addresses sourced from a vendor, manufacturing addresses you were never given | Violates core industry values (Spamhaus endorses the M3AAWG prohibition on append); the contact never gave you the address. |
| Co-registration / affiliate | Address captured on Company A's form under "…and our partners" language, then passed to Company B | Technically possible but Spamhaus advises against: "permission is not transferrable," so it "creates unacceptable risk for campaign damage." |
Practically every ESP acceptable-use policy prohibits harvested, purchased, rented, appended, and co-reg/affiliate lists; using them is grounds for account termination on top of the reputation and legal damage. This is why acquisition audits are central to Spam-Trap Incident Response and Customer Vetting.
Harvesting software is separately illegal
Beyond reputation harm, using address-harvesting software — or lists generated by it — is an independent statutory offence in multiple regimes. This makes harvesting the one acquisition method that is not merely a bad practice but a distinct legal violation for the sender, the supplier of the software, and often the ESP.
- New Zealand — Unsolicited Electronic Messages Act 2007 (enforced by the Department of Internal Affairs): businesses must not use "electronic address harvesting software, or lists that have been generated using such software, for the purpose of sending unsolicited commercial electronic messages." The DIA stresses that buying a database does not confer compliance: even where a seller claims "deemed consent" exists, the sender bears the burden of proving consent when each message is sent, and a breach occurs "regardless of whether they believe consent existed due to the purchase of a database." Deemed consent is narrow — the address must have been conspicuously published in a business/official capacity, without an accompanying "no unsolicited messages" statement, and the message must relate to the recipient's role/duties. Enforcement ranges from a formal warning to High Court action for pecuniary penalties, compensation and damages. (See APAC Email Laws for the NZ Act's consent tiers and penalty maxima.)
- Australia — Spam Act 2003 ss 20–22: address-harvesting software and harvested-address lists must not be supplied, acquired, or used in connection with sending in breach of the consent rule — three separate contraventions. (See Australia Spam Act.)
- Canada — CASL / PIPEDA and US — CAN-SPAM: harvesting and dictionary-attack address generation are called out explicitly — an "aggravated violation" under CAN-SPAM (15 U.S.C. 7704), and handled by the OPC under PIPEDA in Canada. Supplying or selecting harvested addresses is an independent hook that can reach the ESP itself. (See Enforcement Cases.)
The operational takeaway: a purchased or "deemed-consent" file offered by a broker is presumptively unsafe and potentially harvested; the burden to prove otherwise sits with the sender, and it usually cannot be discharged.
Why acquisition method is the root cause
Downstream list-quality symptoms — spam-trap hits, high complaint rates, hard-bounce spikes, blocklistings — are almost always acquisition failures surfacing late. A pristine trap only appears in a file that was scraped, generated, or bought; a recycled trap only appears in a file that reactivated stale addresses; a complaint spike after a list swap almost always traces to appended or transferred addresses whose owners never consented to this sender. Fixing acquisition is therefore upstream of, and cheaper than, every remediation runbook:
- The trap-hit corollary from Spam Traps: "if your list processes allow spamtraps onto the list, it's likely you're also sending mail to actual people who don't want it." Traps are a signal of the acquisition defect, not the defect itself.
- Post-incident recovery (Reputation Incident Recovery) always includes an acquisition audit and purge, because re-warming an IP over the same contaminated list simply re-earns the block.
Related
- Consent Methods and the List-Quality Spectrum — the eight-method quality ranking and complaint-risk profiles (the permission-quality view)
- Spam Traps — pristine/recycled/typo traps as the late signal of an acquisition defect
- List Hygiene and Sunset Policies — signup-time validation and the post-acquisition lifecycle
- Spam-Trap Incident Response — working a trap hit, including the acquisition audit
- Customer Vetting — how ESPs interrogate a prospect's acquisition practices before onboarding
- Enforcement Cases · Australia Spam Act · APAC Email Laws — the statutory harvesting prohibitions
- Consent Guidance Updates — recent regulator positions on what consent now requires