Guide

Is buying an email list legal?

nodilist2026-10-0314 min read

In the United States, buying a list of business email addresses is generally legal, and so is emailing the people on it without their prior consent. The federal law for commercial email, the CAN-SPAM Act, works on an opt-out basis: it sets rules for each message you send, including a working unsubscribe, rather than requiring permission first (15 U.S.C. 7704). The FTC says the law "makes no exception for business-to-business email" (FTC compliance guide). What the law regulates is each email you send, and how the list was collected can add risk on top.

Other laws also apply. Privacy and data broker laws apply to the list seller and to data about individuals. Phone rules apply if you call or text. Mailbox providers such as Gmail and Yahoo have their own sender requirements, and in practice those decide whether your email arrives. Each is covered below.

Key facts

  • CAN-SPAM covers all commercial email, including business-to-business (FTC).
  • Each email that violates CAN-SPAM can carry a civil penalty of up to $53,088. The FTC set that figure in its January 2025 adjustment and said on 15 September 2026 that its penalty amounts stay unchanged for 2026 (FTC 2025 adjustment; FTC 2026 notice).
  • Unsubscribe requests must be honored within 10 business days (15 U.S.C. 7704(a)(4)).
  • Sending to harvested or machine-generated addresses turns an ordinary violation into an aggravated one (15 U.S.C. 7704(b)).
  • Since February 2024, Gmail and Yahoo require sender authentication and a spam complaint rate below 0.3% (Google; Yahoo).

What does CAN-SPAM require?

CAN-SPAM requires seven things of every commercial email, according to the FTC's compliance guide (FTC):

  1. Accurate header information. The "From," "To," "Reply-To" and routing information must be accurate and identify who sent the message.
  2. A subject line that isn't deceptive. It must reflect what the message is about.
  3. Identification as an ad. You must disclose clearly and conspicuously that the message is an advertisement.
  4. Your physical postal address. This can be your street address, a post office box registered with the Postal Service, or a private mailbox registered with a commercial mail receiving agency (FTC; 16 CFR Part 316).
  5. A clear way to opt out. The mechanism must keep working for at least 30 days after you send (15 U.S.C. 7704(a)(3)). You may not charge a fee or ask for any personal information beyond an email address, and opting out can't take more than a reply email or a visit to a single web page (FTC).
  6. Honor opt-outs within 10 business days. After someone opts out, you can't sell or transfer their address to anyone, except a company helping you comply (FTC; 15 U.S.C. 7704(a)(4)).
  7. Watch what others do on your behalf. If you hire an agency or a sending service, you remain legally responsible. The FTC says you "can't contract away your legal responsibility" (FTC).

These rules apply to messages whose primary purpose is commercial. Messages that only complete or confirm a transaction the recipient already agreed to, such as a receipt, are "transactional or relationship" messages and are mostly exempt (16 CFR Part 316). A cold sales email to a list you bought is commercial.

What are aggravated violations, and why does list sourcing matter?

An aggravated violation is a CAN-SPAM violation made worse by how the addresses were obtained. The statute names two methods (15 U.S.C. 7704(b)(1)):

  • Address harvesting: collecting addresses with automated tools from a website or online service whose operator posts a notice that it won't give, sell or transfer addresses.
  • Dictionary attacks: generating possible addresses by combining names, letters or numbers into many permutations.

The aggravation attaches to a message that already breaks the basic rules in section 7704(a). It reaches the sender and also anyone who helps "through the provision or selection of addresses," if they knew or should have known how the addresses were obtained (15 U.S.C. 7704(b)(1)). In lawsuits by state attorneys general or internet access providers, a court can increase damages up to three times for aggravated violations (15 U.S.C. 7706).

This is why our lists will contain only emails published on a public web page or in an official register. A website email will come with the URL of the page where we found it. An email taken from an official register will be labelled with the register and its file date. We don't guess addresses from name patterns (for example first.last@practice.com), because that is close to what the statute calls a dictionary attack. You will be able to open any source URL in your file and see the address where it was published, or look the record up in the named register.

A labelled source doesn't make a campaign legal on its own. Your messages still need to meet the seven rules above.

What are the penalties?

Each email that violates CAN-SPAM can carry a civil penalty of up to $53,088 in an FTC action (FTC compliance guide). That is the inflation-adjusted amount from the FTC's January 2025 adjustment (Federal Register, 17 Jan 2025). On 15 September 2026 the FTC published a notice that, following guidance from the Office of Management and Budget, its penalty amounts stay unchanged during 2026 (Federal Register, 15 Sep 2026).

Other enforcers have their own damages (15 U.S.C. 7706):

Who suesDamages per messageCapUp to three times for aggravated or willful violations?
State attorney generalUp to $250$2,000,000Yes
Internet access providerUp to $100 for false-header violations, $25 for others (15 U.S.C. 7706(g)(3))$1,000,000Yes

The caps don't apply to violations of the false-header rule in section 7704(a)(1). CAN-SPAM gives individual recipients no right to sue (15 U.S.C. 7706). Criminal penalties exist for fraud-type conduct, such as sending through someone else's computer without permission or falsifying header information (18 U.S.C. 1037).

What doesn't CAN-SPAM cover?

CAN-SPAM covers the emails you send. It doesn't cover everything around a list purchase.

State email laws. CAN-SPAM overrides state laws that expressly regulate commercial email, except where they prohibit falsity or deception (15 U.S.C. 7707(b)). California's anti-deception email law is one that remains. It covers falsified headers, using a third party's domain without permission and misleading subject lines, and a recipient can sue for liquidated damages of $1,000 per email (Cal. Bus. & Prof. Code 17529.5).

Privacy laws (CCPA). California's privacy law protects California residents as natural persons, at home and at work (Cal. Civ. Code 1798.140). Its temporary exemption for personal information in business-to-business communications and transactions expired on 31 December 2022, according to the California Attorney General (California AG). So a named contact at a business, or a sole practitioner, can have privacy rights even when you only email them about work. The law applies to for-profit businesses that meet one of three tests: more than $25 million in annual revenue (adjusted for inflation), buying, selling or sharing the personal information of 100,000 or more California consumers or households a year, or getting 50% or more of revenue from selling or sharing personal information (1798.140(d)).

Data broker laws. California's Delete Act defines a data broker as a business that knowingly collects and sells to third parties the personal information of consumers it has no direct relationship with (Cal. Civ. Code 1798.99.80). Since 1 August 2026, data brokers must check the state's deletion platform (DROP) at least once every 45 days and delete the data of people who asked (Cal. Civ. Code 1798.99.86). These duties fall on the seller. Before you buy from anyone, ask how they handle deletion requests. Our guide to the California Delete Act and B2B data has the full rules and a list of questions for vendors.

Businesses and people. Each row of our lists will be one office or organization. The dentist list will carry the emails offices publish on their own websites: shared inboxes such as office@ and, where a practice publishes one, a named inbox at the practice's own domain. There will be no column for a person's name, and every email will carry the URL of the page where it was published. A named inbox, or a solo practice whose name and NPI are the dentist's own, is still data about a person, so privacy laws can apply to those rows. Anyone can ask us to remove their data through data removal.

What a provider register shows about businesses and people

Most of the records behind a healthcare list describe people, not companies. In the CMS NPPES file of 2026-09-14, active dental registrations included ~273,000 individual registrations, each belonging to a dentist, and ~137,000 organization registrations for practices and groups. The exact figures are in dentists-register-2026-10.csv, and the dentist email list page explains how the list will be built from them.

What these numbers don't show. A registration isn't a row on our list, and one practice can hold several registrations. The split shows why "B2B" data about small practices so often turns out to be data about individuals.

Can you call or text the numbers on a list?

Calling a business to sell to that business is largely outside the federal Do Not Call rules. The FTC says "most phone calls to a business made with the intent to solicit sales from that business are exempt" from the Telemarketing Sales Rule's Do Not Call provisions (FTC). Mobile numbers are different:

  • Autodialed or prerecorded calls to a mobile number need the called party's prior express consent, and prior express written consent when the call is telemarketing (47 CFR 64.1200(a)(1)-(2)).
  • What counts as an autodialer is narrow. The Supreme Court held in 2021 that the device must be able to store or produce telephone numbers using a random or sequential number generator (Facebook v. Duguid). Prerecorded and artificial-voice calls are covered either way.
  • The National Do Not Call Registry protects residential subscribers, and the FCC applies those rules to telemarketing calls and text messages to wireless numbers as well (47 CFR 64.1200(c), (e)). A sole practitioner's personal mobile, listed as a practice number, can fall under it.
  • States have their own telemarketing and texting laws, some stricter than federal law. Check the states you call into.

Our files will list the phone number each office publishes. We don't promise a line type for any list, so check whether a number is a mobile before any automated call or text. Our acceptable use terms prohibit autodialed, prerecorded or artificial-voice calls and texts to mobile numbers without the consent the law requires.

What about contacts outside the US?

Our lists cover US businesses only. If you email people in other countries, different rules apply, and many are stricter than CAN-SPAM. In the UK, for example, the ICO says you can email any corporate body, but sole traders and some partnerships are treated as individuals, so you need their consent or an earlier customer relationship (ICO). Canada and the EU have their own consent rules. Check them with a local adviser before you send.

Will email to a bought list reach the inbox?

That depends on mailbox providers such as Gmail and Yahoo. Their sender rules are stricter than CAN-SPAM, and they can reject mail that breaks them.

Since 1 February 2024, Gmail has required every sender to personal Gmail accounts to authenticate with SPF or DKIM, send over TLS, and keep the spam rate reported in Postmaster Tools below 0.3%. Google asks senders to stay below 0.10% (Google). A sender of close to 5,000 or more messages a day to personal Gmail accounts is a bulk sender, permanently. Bulk senders also need SPF, DKIM, DMARC and one-click unsubscribe, and Google recommends handling unsubscribe requests within 48 hours. Since November 2025 Gmail has been rejecting non-compliant messages temporarily or permanently. These requirements apply to mail sent to personal Gmail accounts, not to Google Workspace business domains (Google FAQ).

Yahoo's rules, enforced from February 2024, are similar: SPF or DKIM for every sender, both plus a DMARC policy for bulk senders, unsubscribes honored within 2 days, and a spam rate below 0.3%. Yahoo's own recommendations also say "Don't purchase mailing lists" (Yahoo).

For a bought list, this means:

  • Keep complaints low. A 0.3% spam rate is 3 complaints per 1,000 delivered emails. Relevant, low-volume, clearly identified messages keep it down.
  • Bounces still count. High bounce rates damage your sender reputation. Check each email's status before sending, and see our bounce-rate benchmarks. Catch-all addresses can't be confirmed as deliverable, so send to them in smaller batches.
  • Consider a separate sending domain. Sending cold outreach from a separate domain or subdomain keeps complaints away from your main company domain.

A checklist before you send

  1. Know where each address came from. Ask the seller for a source per email. Avoid lists built by guessing name patterns.
  2. Keep only relevant contacts. Email people about their work, in their role. Relevance lowers complaints and, outside the US, is often a legal condition.
  3. Write an honest message. Use accurate From and Reply-To details, a subject line that matches the body, and say it's an advertisement.
  4. Add your postal address and a working unsubscribe link or reply-to-unsubscribe instruction to every email.
  5. Honor opt-outs fast. The law allows 10 business days. Gmail recommends 48 hours and Yahoo expects 2 days. Keep a suppression list and never resell or share opted-out addresses.
  6. Set up SPF, DKIM and DMARC on your sending domain and add one-click unsubscribe headers.
  7. Watch your complaint rate in Google Postmaster Tools. Stay under 0.1% and stop well before 0.3%.
  8. Check your vendors. If an agency sends for you, you are still responsible.
  9. Separate mobiles from landlines. Don't autodial, robocall or text mobile numbers without consent, and check state telemarketing rules.
  10. Respect deletion requests from contacts, and tell the seller when someone asks to be removed from their data.
  11. Read the seller's terms. Ours are in the acceptable use policy.
  12. Ask a lawyer if you email outside the US, work in a regulated industry, or plan a large campaign.

What this guide can't tell you

  • Whether a particular campaign is legal. That depends on your message, your audience, where they are and how you send.
  • State telemarketing and texting rules, which differ from state to state and change often.
  • Rules outside the US beyond the short note above.

Laws change and your facts matter. If you are unsure about a campaign, ask a lawyer who handles marketing law. This is general information, not legal advice.

Frequently asked questions

Can you legally buy an email list in the US?

Yes, in general. No federal law bans buying or selling business email addresses. What you do with the list is regulated: every commercial email must meet CAN-SPAM's rules (FTC). The seller has its own duties under privacy and data broker laws (Cal. Civ. Code 1798.99.80).

Is cold emailing legal?

In the US, generally yes. CAN-SPAM doesn't require prior consent. It requires honest headers and subject lines, identification as an ad, a postal address and a working opt-out (15 U.S.C. 7704). Other countries, such as the UK, have stricter rules.

Does CAN-SPAM apply to B2B email?

Yes. The FTC says the law "makes no exception for business-to-business email" (FTC).

What is the fine for a CAN-SPAM violation?

Up to $53,088 per violating email in an FTC action, the amount set in January 2025 and unchanged for 2026 (Federal Register, 15 Sep 2026). State attorneys general and internet access providers can seek separate damages (15 U.S.C. 7706).

Do I need consent to email a business contact?

Not under CAN-SPAM. You need a clear opt-out and must honor it within 10 business days (15 U.S.C. 7704(a)(4)). Consent does matter for autodialed and prerecorded calls to mobile numbers (47 CFR 64.1200) and under some foreign laws.

Will a bought list hurt my deliverability?

It can, if many addresses bounce or recipients mark you as spam. Gmail and Yahoo require a spam rate below 0.3% (Google; Yahoo). Send relevant messages in small batches, and check each email's verification status first.

Are you responsible if your email agency breaks the rules?

Yes. The FTC says both the company whose product is promoted and the company that sends the message may be held legally responsible (FTC).

Sources

  1. FTC, CAN-SPAM Act: A Compliance Guide for Business, accessed 2026-10-03
  2. 15 U.S.C. 7704, Other protections for users of commercial electronic mail, accessed 2026-10-03
  3. 15 U.S.C. 7706, Enforcement generally, accessed 2026-10-03
  4. 15 U.S.C. 7707, Effect on other laws (preemption), accessed 2026-10-03
  5. 18 U.S.C. 1037, Fraud and related activity in connection with electronic mail, accessed 2026-10-03
  6. eCFR, 16 CFR Part 316 (CAN-SPAM Rule), accessed 2026-10-03
  7. FTC, Adjustments to Civil Penalty Amounts, Federal Register, 17 Jan 2025, accessed 2026-10-03
  8. FTC, Civil Penalty Inflation Adjustments (amounts unchanged for 2026), Federal Register, 15 Sep 2026, accessed 2026-10-03
  9. California Bus. & Prof. Code 17529.5, accessed 2026-10-03
  10. California Attorney General, California Consumer Privacy Act (CCPA), accessed 2026-10-03
  11. California Civil Code 1798.140 (CCPA definitions), accessed 2026-10-03
  12. California Civil Code 1798.99.80 (Delete Act definitions), accessed 2026-10-03
  13. California Civil Code 1798.99.86 (DROP deletion obligations), accessed 2026-10-03
  14. eCFR, 47 CFR 64.1200 (TCPA rules), accessed 2026-10-03
  15. FTC, Q&A for Telemarketers and Sellers About DNC Provisions in the TSR, accessed 2026-10-03
  16. Facebook, Inc. v. Duguid, 592 U.S. 395 (2021), accessed 2026-10-03
  17. Google, Email sender guidelines, accessed 2026-10-03
  18. Google, Email sender guidelines FAQ, accessed 2026-10-03
  19. Yahoo, Sender best practices, accessed 2026-10-03
  20. ICO, Electronic mail marketing (PECR), accessed 2026-10-03
  21. CMS NPPES Data Dissemination V.2, file dated 14 Sep 2026 (register counts in /data/dentists-register-2026-10.csv), accessed 2026-10-03