A Technically Valid Email Address Can Still Be Dangerous
An email address can exist, accept mail and pass every ordinary technical validation check.
It can still have no business being on your campaign.
That distinction matters because email validation is often treated as a permission slip. The address receives a green tick, the list is declared clean, and the campaign moves towards the send button.
But technical validation answers only one question:
Does this address appear capable of receiving email?
It does not answer:
- Where did the address come from?
- Why does the business hold it?
- Is there suitable evidence for the intended marketing?
- Has the recipient previously unsubscribed or objected?
- Is the contact a company, employee, sole trader or individual subscriber?
- Is the address appropriate for this particular campaign?
- What risk could sending to it create for the sender?
A green tick is useful.
It is not a small electronic blessing from the email gods.
What technical validation can tell you
Technical validation is an important part of responsible email operations.
It may identify malformed addresses, missing domains, domains without functioning mail records and mailboxes that appear unable to accept email. It can help prevent avoidable bounces and remove obvious mistakes before they reach a live campaign.
ASI treats validation seriously because repeatedly sending to addresses that cannot receive mail is wasteful and potentially damaging.
The problem begins when technical validity is treated as the whole decision.
An address may be technically functional while belonging to someone who never asked to hear from you. It may have been collected years ago, purchased from an uncertain source, scraped from a public website or imported without the evidence that explains why it is there.
It may also belong to someone who has already unsubscribed.
The mailbox still works. The marketing eligibility does not.
Source evidence matters
Two identical email addresses can carry completely different levels of operational confidence depending on how they entered the system.
One may have been submitted directly through a clearly worded form.
Another may have arrived inside an inherited spreadsheet called final_contacts_REAL_v7.xlsx, which is rarely the beginning of a peaceful afternoon.
The address itself cannot explain the difference.
A responsible sending system needs to know more than whether the mailbox exists. It needs enough source information to understand how the contact was acquired, what the person was told, which organisation collected the information and what type of communication was expected.
This matters because business-to-business marketing is not one single bucket. The ICO’s guidance on business-to-business marketing explains that the PECR rule on direct marketing by electronic mail does not apply to corporate subscribers in the same way, but UK GDPR can still apply where personal data is used for direct marketing in a business context.
That distinction is important.
It does not mean every B2B email requires identical consent evidence.
It means “B2B” is not a magic word that removes the need to understand the record.
A limited company’s general business address, a named employee’s corporate address and a sole trader’s address may appear together in the same imported file. They do not necessarily carry the same legal or operational considerations.
ASI therefore treats B2B status as something that needs evidence and confidence, not something that should be guessed from the presence of a company name.
Consent is not contained inside the address
An email address does not carry its collection history with it.
It cannot tell the receiving platform:
- who collected it;
- when it was collected;
- what wording was shown;
- whether consent was requested;
- whether another lawful basis was considered;
- whether the person expected marketing;
- whether permission covered the organisation now intending to send.
That evidence must come from somewhere else.
This is particularly important when lists are transferred between systems or supplied by another party. A file may contain technically excellent addresses while providing almost no defensible explanation of why those people should receive the proposed campaign.
Technical cleanliness does not repair weak acquisition.
ASI does not present itself as legal advice, and it does not pretend that every marketing situation has one universal answer. The client remains responsible as the data controller for understanding the lawful basis and purpose of its marketing.
What ASI can do is refuse to treat missing evidence as positive evidence.
When the source, consent position or B2B classification is unclear, holding the record for review is safer than quietly allowing an assumption to board the send rail.
Suppression must outrank validation
An unsubscribed address may remain technically valid for years.
The mailbox may accept mail perfectly. The domain may be healthy. The owner may still use the address every day.
None of that cancels the unsubscribe.
This is why suppression cannot be treated as another optional list filter. It must sit above campaign selection and technical validation.
The ICO’s direct marketing guidance says that when someone no longer wants their information used for direct marketing, organisations should place their details on a suppression or “do not contact” list instead of simply deleting them. That allows future marketing lists to be checked so the same person is not contacted again by mistake. See the ICO guidance on respecting people’s preferences.
In practical terms, the suppression decision must win every time.
It should not matter whether the address arrived through:
- a new subscriber form;
- an integration;
- a CSV import;
- an external customer system;
- a previous campaign list;
- a manually created record.
If the recipient has exercised an applicable opt-out or objection, a later import must not quietly revive them.
A technically valid suppressed address is still suppressed.
Valid addresses can still reveal poor data practices
Some addresses are specifically used to identify poor acquisition or list-management behaviour.
Spamhaus explains that spam traps are used to identify email marketers with poor permission and list-management practices. Its guidance on spam traps also makes the larger point that senders should fix the underlying data problem rather than simply trying to find and remove the individual trap.
This illustrates the wider issue.
A mailbox accepting the message does not prove that sending the message was sensible.
Mailbox providers and anti-abuse systems observe behaviour. They see complaints, repeated unwanted mail, low-quality acquisition patterns, inactive data and sending histories that suggest the audience was not expecting the campaign.
Google’s email sender guidelines also advise senders to monitor server responses, spam rate and domain reputation, and to reduce sending volume if messages start bouncing or being deferred.
By the time those patterns become a visible reputation problem, the sender may already be dealing with throttling, reduced placement or a lengthy recovery process.
Validation can reduce technical failure.
It cannot turn an inappropriate audience into an appropriate one.
The better operating principle
A contact should reach the send rail only when several questions have been answered.
Is the address technically usable?
Is there enough source evidence?
Is the contact suitable for this type of marketing?
Is the intended use consistent with the available consent or other applicable basis?
Is the recipient free from suppression?
Is the address appropriate for this campaign and this sending environment?
These are different questions.
Combining them into one “valid” status gives the operator a comforting answer while hiding the decisions that matter.
ASI separates technical validation from send eligibility because they perform different jobs.
Validation examines the address.
Eligibility examines whether the address should be included in the proposed send.
How ASI approaches the problem
ASI is designed around a simple principle:
Protect the Sender.
That means the platform may hold or exclude an address even when the address is technically capable of receiving mail.
Before a contact reaches the protected send rail, ASI can consider the available validation result, source evidence, consent position, B2B confidence, suppression status and campaign eligibility.
It does not need to accuse the record of being unlawful or permanently bad.
It only needs to recognise that the evidence is not currently strong enough for automatic release.
That distinction protects everyone involved.
The recipient is less likely to receive marketing they did not expect.
The operator is less likely to make a reasonable-looking mistake.
The client retains clearer evidence about why a record was included, held or excluded.
The sender’s domain and IP are protected from unnecessary exposure.
The important decision is no longer:
Can this mailbox receive an email?
It becomes:
Do we have enough evidence to justify putting this recipient on this send?
That is a more demanding question.
It is also the question serious email operations should have been asking all along.
Validation is the beginning of the decision
Email validation remains essential.
Without it, campaigns carry avoidable bounce risk, poor data consumes infrastructure and operators begin with an audience that may not even exist.
But validation should be the first gate, not the final approval.
A technically valid address may still be unsupported by source evidence, unsuitable for the intended marketing, covered by a previous objection or dangerous to the sender’s reputation.
The platform should be capable of recognising that before the campaign leaves the station.
A green tick should mean: We have established one useful fact.
It should never mean: Send it and hope the rest is probably fine.


