List Quality Audit: Find Bad Data Before Campaigns
Run a list quality audit to catch invalid, risky, role-based, and stale contacts before campaigns so you reduce bounces without cutting reach.

A list quality audit helps you find bad contact data before it turns into bounces, spam complaints, and weak campaign results. You review each record for accuracy, consent, recency, and deliverability risk, then decide what to keep, verify, suppress, or remove.
What Is a List Quality Audit?
A list quality audit is a structured review of your contact records before you send.
You check four things:
- Accuracy: Is the email address valid and formatted correctly?
- Recency: Is the contact still active, current, and relevant?
- Consent: Do you have permission or a legitimate basis to contact them?
- Deliverability risk: Is the address likely to bounce, complain, or hurt sender reputation?
That makes it narrower than a full deliverability audit.
A deliverability audit looks at your whole sending system. It may cover SPF, DKIM, DMARC, IP reputation, domain reputation, content, complaint rates, mailbox placement, throttling, and sending patterns.
A list quality audit focuses on the data you plan to send to.
It is also different from one-time list cleaning. Cleaning often means removing invalid email addresses from a file. A proper contact data audit goes deeper. It reviews source quality, consent status, engagement, duplicates, stale records, role-based contacts, and risky email addresses.
Run one before:
- A product launch.
- A seasonal campaign.
- A large newsletter send.
- A CRM or ESP migration.
- A cold outreach push.
- A reactivation campaign.
- A send to any segment that has not been mailed recently.
Audit the segment you plan to send, not only the full database. A “healthy” master list can still contain a risky campaign segment.
The Data to Collect Before You Audit
You need enough fields to judge whether each contact is valid, current, permitted, and worth sending to.
Start with the core identity and lifecycle fields:
| Field | Why it matters |
|---|---|
| Email address | Needed for syntax checks, domain checks, and mailbox verification. |
| Source | Tells you how the contact entered your system. |
| Signup or created date | Helps identify stale records and old imports. |
| Last engagement date | Shows whether the contact still responds to email. |
| Consent status | Confirms whether you can send marketing or sales email. |
| CRM owner | Helps route exceptions and high-value account review. |
Then collect sending history fields:
- Last email sent date.
- Bounce history.
- Complaint history.
- Unsubscribe status.
- Suppression status.
- Previous verification result, if available.
- Campaign or list membership.
- Account status, if the contact is tied to a customer or opportunity.
This data gives you context. An address that looks risky but belongs to an active customer may need a different action than a risky cold prospect from a scraped import.
Missing data is also a signal.
If a record has no source, no timestamp, and no consent status, you cannot explain why it is in your CRM. That does not always mean you must delete it. But it does mean you should treat it as higher risk.
Common high-risk patterns include:
- Imported contacts with no source.
- Contacts created before your current consent process existed.
- Records with no engagement history.
- Contacts owned by inactive users.
- Old event lists with no follow-up record.
- Leads from forms that did not use email verification.
Good CRM data quality starts with knowing where records came from and when they became marketable.
Checks That Reveal Bad or Risky Contacts
The fastest way to improve email list quality is to identify contacts that are invalid, stale, risky, duplicated, or low value.
Address-level checks
Check each email address for basic validity first:
- Invalid syntax: Missing
@, spaces, illegal characters, broken domains. - Typo domains:
gmial.com,hotnail.com,yaho.com. - Disposable domains: Burner inboxes used for one-time signups.
- Undeliverable mailboxes: Addresses that the receiving server rejects.
- Catch-all domains: Domains that appear to accept any local part.
Syntax checks catch obvious errors. They do not prove that a mailbox exists.
Domain checks tell you whether the domain can receive mail. They do not always prove that the specific address works.
SMTP mailbox checks can go further, but results vary. Some domains block probes. Some accept all mail at the edge and filter later. That is why you need verdicts and risk levels, not just “valid” or “invalid.”
Risk and value checks
Not every deliverable address is a good campaign target.
Flag these contact types:
- Role-based contacts such as
info@,support@,sales@, andadmin@. - Shared inboxes used by teams instead of individuals.
- Free-mail domains such as Gmail, Yahoo, Outlook, and similar providers.
- Risky email addresses with uncertain mailbox results.
- Catch-all addresses where the domain accepts unknown users.
- Disposable addresses from temporary inbox providers.
Role-based contacts are not always bad. A support inbox at a target account may be useful for transactional or operational mail. It is usually weak for lifecycle marketing or sales outreach because you do not know who receives it.
Free-mail domains are also not automatically bad. They are normal for consumers, creators, small businesses, and early-stage buyers. But in B2B, a free-mail domain may be lower value than a verified corporate address.
Record-level checks
Email verification catches address risk. Your CRM still needs record quality checks.
Look for:
- Duplicate contacts with the same email.
- Duplicate leads under different casing, such as
Alex@Example.comandalex@example.com. - Contacts with no name, company, source, or owner.
- Contacts with no engagement history.
- Contacts not updated in 12, 18, or 24 months.
- Contacts tied to closed-lost, churned, or disqualified accounts.
- Contacts who unsubscribed but still appear in active campaign lists.
Duplicates cause reporting errors and poor routing. Stale records increase bounce risk. Suppressed contacts in active sends create compliance and trust problems.
How to Segment Audit Results
Segment audit results into action groups so your team knows what to do next.
Use five practical groups:
| Segment | What it means | Typical action |
|---|---|---|
| Keep | Valid, consented, recent, and engaged or strategically relevant. | Send as planned. |
| Verify | Missing or old verification data, but record may still be useful. | Re-check before sending. |
| Re-permission | Address may be valid, but consent or engagement is weak. | Send a permission pass if allowed. |
| Suppress | High risk, unsubscribed, complained, invalid, or not sendable. | Exclude from campaigns. |
| Delete | No value, no consent, invalid, duplicated, or unexplainable. | Remove under your data policy. |
Do not treat every risky contact the same way.
Separate high-value risky contacts from low-value risky contacts.
A high-value risky contact might be:
- A decision-maker at an active opportunity.
- A customer admin on a strategic account.
- A recent demo requester with a catch-all corporate domain.
- A known buyer whose company mail server blocks verification probes.
A low-value risky contact might be:
- An old cold prospect with no engagement.
- A disposable signup.
- A role account from a purchased list.
- A record with no source, no consent, and no owner.
For high-value risky contacts, you may route the record to the owner, confirm the address manually, find a better contact, or use a lower-risk channel first.
For low-value risky contacts, suppress them from bulk campaigns.
Avoid over-cleaning. Verification is a signal, not the whole decision. Use engagement, consent, account status, and business context before deleting records.
List Quality Benchmarks to Watch
Track list quality benchmarks over time so you can spot data decay before it hurts campaigns.
Useful metrics include:
- Invalid rate: Share of addresses that are clearly undeliverable.
- Risky rate: Share of addresses with uncertain or high-risk results.
- Catch-all rate: Share of addresses on domains that accept all mail.
- Role-account share: Share of records using shared or function-based inboxes.
- Stale-contact share: Share of contacts with no recent update or engagement.
- Duplicate rate: Share of records with repeated emails or likely duplicate identities.
- Missing-source rate: Share of contacts without a reliable acquisition source.
- Suppression conflict rate: Share of suppressed or unsubscribed contacts still present in send segments.
Bounce rate deserves special attention.
Many teams use 2% as a practical warning threshold. If a campaign segment is likely to exceed that, review the list before sending. A much higher bounce rate can damage trust with mailbox providers, especially if it happens repeatedly or appears on a newly warmed domain.
Benchmarks vary by list type:
| List type | Expected quality pattern | What to watch |
|---|---|---|
| Signup list | Usually fresh, but may contain typos and disposable emails. | Typo domains, burner domains, fake signups. |
| Customer list | Usually higher value, but may include stale employees. | Departed users, role accounts, old admins. |
| Newsletter list | Quality depends on age and engagement. | Long-term inactives, old imports, consent gaps. |
| Cold prospect list | Often highest risk. | Invalid emails, missing source, role accounts, catch-all domains. |
| Event list | Mixed quality. | Shared badges, old exports, unclear consent. |
For bounce prevention, watch trends more than single snapshots.
If your invalid rate rises after one lead source goes live, fix the source. If your stale-contact share grows each quarter, tighten lifecycle rules. If catch-all rates are high in cold outreach, reduce volume and prioritize higher-intent accounts.
A Practical List Quality Audit Workflow
A good list quality audit should be repeatable. You want a process your team can run before every major send.
1. Export the campaign segment
Export only the contacts you plan to mail.
Include:
- Email.
- Contact ID.
- Account ID.
- Source.
- Created date.
- Last modified date.
- Last engagement date.
- Consent status.
- Unsubscribe and suppression status.
- CRM owner.
- Lifecycle stage.
- Last bounce or complaint date.
Keep stable IDs in the export. You need them when you write results back to the CRM.
2. Normalize the data
Clean the obvious formatting problems before verification.
Do this first:
- Trim spaces.
- Lowercase domains.
- Remove duplicate exact emails.
- Normalize common field values.
- Standardize dates.
- Split obviously malformed rows into a review file.
Do not “fix” domains by guessing at scale unless you can preserve the original value. A typo suggestion is useful, but you still want an audit trail.
3. Verify and enrich records with risk signals
Run email verification on the address column.
You want results such as:
{
"email": "alex@gmial.com",
"verdict": "undeliverable",
"reason": "typo_domain",
"suggestion": "alex@gmail.com",
"is_disposable": false,
"is_role": false,
"is_catch_all": false,
"risk": "high"
}
Useful verification outputs include:
- Deliverability verdict.
- Risk score or risk category.
- Syntax status.
- Domain status.
- Mailbox status.
- Disposable domain flag.
- Role-account flag.
- Catch-all flag.
- Typo suggestion.
4. Apply suppression rules
Create clear rules before reviewing edge cases.
For example:
- Suppress invalid and undeliverable addresses.
- Suppress known complainers.
- Suppress unsubscribed contacts from marketing sends.
- Suppress disposable addresses from lifecycle campaigns.
- Review catch-all addresses by value tier.
- Review role-based contacts by campaign type.
- Re-permission stale contacts only when policy and law allow it.
Your rules should differ by send type. Product notifications, customer admin emails, newsletters, and cold outreach do not carry the same consent and risk profile.
5. QA a sample
Sample each action group before you commit changes.
Check:
- Are important customer contacts being suppressed unexpectedly?
- Are unsubscribed contacts still marked sendable?
- Are role accounts handled correctly for the campaign type?
- Are typo corrections reasonable?
- Are duplicates merged or suppressed in a predictable way?
- Are high-value risky contacts routed for manual review?
QA prevents silent damage. It also helps sales, marketing, and ops trust the process.
6. Document the decision logic
Write down the rules you used.
Include:
- Audit date.
- Segment name.
- Data fields reviewed.
- Verification provider or method.
- Suppression criteria.
- Re-permission criteria.
- Exception handling.
- Owner for follow-up work.
This turns email list hygiene into an operating process, not a one-off cleanup project.
How Bounceable Fits Into the Audit
Bounceable fits into the verification step of your list quality audit.
You can use bulk-style workflows or API-based checks before a campaign, at signup, or during CRM cleanup. The goal is simple: identify bad and risky addresses before they receive mail.
Bounceable checks for signals that matter in a pre-send audit:
- Deliverable, risky, undeliverable, or unknown verdicts.
- Disposable and burner domains.
- Typo suggestions, such as
gmial.comtogmail.com. - Role-based contacts.
- Catch-all domains.
- Mailbox-level SMTP signals where available.
- Free provider detection.
- Bounce risk scoring.
A developer might call verification during signup. RevOps might verify newly imported leads before they enter sequences. Lifecycle teams might run checks before reactivating an old segment.
Use the results to automate sane CRM actions:
- Mark invalid email addresses as suppressed.
- Route risky email addresses to owners for review.
- Block disposable emails on high-value forms.
- Store typo suggestions for correction flows.
- Exclude role-based contacts from person-based nurture campaigns.
- Re-check stale records before large sends.
That protects sender reputation and keeps campaign reporting cleaner. Your open rate, reply rate, and conversion rate mean more when obvious bad data is out of the send.


