We bought the same "verified" lead list three times

August 2026. The numbers below are from full runs on the delivered files, except where I say sample. I've left the sellers unnamed, since this isn't about them.

What I did

I wrote one requirement in plain English and sent the identical text to three sources:

US e-commerce / Shopify agencies, 11–50 people. Founder, CEO or Owner only. Fields: name, title, company, website, verified work email (not info@), LinkedIn.

Then I bought it three times: $27 from a marketplace freelancer, $40 from another, and $99 from a self-serve list platform that publishes an accuracy guarantee.

Every row that got delivered went through the same checks: syntax, duplicates, role addresses, free-mail domains, mail server lookups, and full mailbox verification through a commercial service. Those ran on every row, not a sample. Then I hand-checked 15 random rows per list against company sites and public profiles.

What arrived

The $27 seller never delivered. Before the deadline he asked to cancel, saying he could only get Shopify stores, not agencies. His listing said lead generation "for any industries."

The $40 seller delivered 111 rows with all eight fields filled in.

The $99 platform exported 300 rows on demand.

The numbers

$40 seller$99 platform
Rows delivered111300
Confirmed deliverable43 (38.7%)151 (50.3%)
Hard bounces found00
Catch-all (unknowable)62 (55.9%)72 (24.0%)
Other / unknown677
Cost per confirmed address$0.94$0.66

Neither list is a scam, and both are also less than half usable.

Zero bounces isn't good news

That row of zeros is the interesting one. I'd assumed a clean list would show a few dead addresses — every real list does. Zero means something else happened.

Zero means the file went through a bounce scrubber before it reached me, and scrubbing only deletes the addresses that are provably dead. It doesn't tell you the survivors are alive. What you're left with is some confirmed-working addresses, plus a big pile sitting on servers that accept anything you throw at them. Those are the catch-alls, and they tell you nothing either way.

So "verified" here means scrubbed. On the $40 list, more than half the rows are in that fog. They might work, but there's no way to find out except by sending, which is the exact question I paid someone else to answer.

Where the $40 list came from

I didn't expect to be able to work this out, and it turned out to be the most useful part.

Some of the company names had search keywords jammed into them: Brand Name | Web Design Company NYC. No business registers itself that way, but owners do write their map listings that way, because it helps them show up in local search.

Three things lined up:

First, those exact pipe-form names show up word for word on four different sites that mirror public map listings. The same companies appear on industry directories under normal names. So the name column came off a map, not a directory.

Second, one of the website fields still had the tracking suffix owners paste into a map listing's website box. That string doesn't come from anywhere else.

Third, map listings don't publish email addresses at all. And 100 of the 111 emails in this file follow a name pattern like firstname@domain, first.last@domain. When your source has no emails in it, you generate them from names and hope.

So: scrape a public map by category, guess the emails, scrub the bounces, deliver. That also explains the odd entries. The file included plain web-design shops, which live in the map's "web design" category but would never turn up in a Shopify partner directory.

The people were real. They were just the wrong people.

I hand-checked 15 rows from each file.

On the $40 list, all 15 companies were real and trading, and 14 of the 15 people verifiably work there in the role given. One contact left no public trace at that company, while the public org chart named someone else in that job.

Then I checked them against what I'd actually asked for:

The $99 platform had better people data. All 15 person-and-title links checked out, several matching public profiles word for word, which makes me think it's recycled from a big directory. But 3 of the 15 companies were dead: one domain refusing connections, one 404 with its locations closed, one no longer resolving. Call it a third of the sample stale or gone. Maybe 5 of 15 were plausibly e-commerce; the others included an electrical contractor, a lighting showroom, a powder-metal manufacturer and a denture clinic. One row was a New Zealand domain inside a US-only export.

Here's the part I keep coming back to. The identity fields are accurate, and that's exactly why the file feels trustworthy when you open it. Real names, real companies, real titles. Nothing was invented, and what nobody did was check whether the rows match what you asked for, whether the companies are still alive, or whether the addresses actually receive mail, and those are the three things you can't see by looking at the spreadsheet.

What it actually costs

The purchase price is the small number. What you're really putting at risk is your sending domain.

Push a few hundred messages into a file where half the addresses are unknown and you're running an experiment on your own reputation using someone else's data. Domain reputation takes a long time to build back once it goes.

Next to that, $27 versus $99 isn't really the question.

How to check a list yourself, in about 20 minutes

You don't need anyone for this.

  1. Count the rows against what you were promised. It's free and takes a minute.
  2. Run it through any mailbox verification service. If invalid comes back at exactly zero, it was scrubbed, so treat "valid" as your real count and everything else as unknown.
  3. Count the catch-alls. That's your fog, so don't put it in the win column.
  4. Take 20 rows and look at the email format. How many are firstname@domain or first.last@domain? Over 80% and they were generated from names, not collected.
  5. Read the company names. Pipes, dashes and city names inside a company name mean someone scraped a listing title.
  6. Sort the title column and read it. It takes two minutes and it's the check people skip most.
  7. Open five of the websites at random. Dead ones tell you how old the underlying database is.

Steps 1, 4, 5, 6 and 7 don't need any tools.

What I didn't test

Why I bothered

I check delivered work for a living, so I bought some work to check. I don't sell lists, I don't clean lists, and I don't fix anything I audit, which is the only reason these numbers are worth anything to you. If I had something to sell you afterwards, I'd have a reason to make the findings look bigger.

The checklist above is the whole method. Use it before your next purchase.