B2B Sales Strategy

    Where Did You Get My Email Address: The Answer Lives on the Row

    A prospect replying to ask where their address came from is not the phone objection it resembles. The answer is recorded at list build or it does not exist.

    Editorial illustration for Where Did You Get My Email Address
    August 29, 2026Updated August 29, 20269 min read
    Share:
    The short answer

    Answer with the specific surface the record came from, the reason that person was written to, and confirmation they have been removed, in fewer words than the question. The tool name is not an answer. Record the collection surface and date on every row at build time, because it cannot be reconstructed once the reply arrives.

    Key takeaways

    • On a call the question is a reflex that arrives before anything is explained, so deflecting it is reasonable; a written reply cost the sender more effort than deleting the message and deserves a real answer.
    • The answer is a property of the row rather than of the reply, which means it has to be recorded at collection: the specific surface and the date, not the name of the tool the record was exported from.
    • UK regulator guidance lists the source of the personal data among the privacy information owed when data was obtained from somewhere other than the person, and states that a publicly accessible source does not remove the obligation.
    • Suppress at programme level before replying, and read the frequency of these replies as a finding about the premise rather than about the recipients.

    Reviewed and updated August 29, 2026

    A campaign sends on Tuesday morning. On Wednesday a single reply arrives, and it has nothing to say about the offer. The person wants to know where their address came from. Somebody opens the sending platform, finds the row, and discovers that the only provenance attached to it is the name of the company that sold the record.

    That gap is the whole problem, and it is not a writing problem. The question has one honest answer, the answer lives on the row rather than in the reply, and a programme that cannot produce it has learned something about its own list rather than about the person who asked.

    The same words mean different things on the phone and in writing

    Sales teams already have a settled position on this question, and it was formed on the telephone, where it is correct.

    On a call the question arrives seconds into an interruption, before the caller has explained anything. It carries no information about the person's situation, which is what makes it a reflex rather than a position, and arguing with a reflex means arguing against a view nobody has formed yet. The standard advice follows from that reading: acknowledge it briefly, do not litigate it, and get back to whether there is a reason to keep talking. The taxonomy behind that reading, and why most objection libraries are full of rebuttals to statements containing nothing to rebut, is set out in which objection handlers earn their place.

    A written reply behaves differently, and the difference is effort. The recipient read the message, decided the offer was not what they wanted to discuss, and then composed and sent something anyway. Deleting the mail was available and cheaper. Whatever else the reply is, it is evidence that the provenance mattered to that person more than the offer did.

    Two consequences follow immediately. The phone move of acknowledging and pivoting answers a question they did not ask, which reads as evasion in a medium where they can see the whole exchange. And the reply is worth more as information than as an objection, because it is the one moment a stranger tells you exactly what they noticed about your outreach.

    On a callA reflex
    • Arrives before the caller has explained anything
    • Costs the person nothing to say
    • Contains no fact about their situation
    • Deflecting briefly and moving on is the standard advice
    • The conversation can still be recovered in the same minute
    In a written replyA deliberate act
    • Arrives after the whole message has been read
    • Cost the person more effort than deleting it
    • States what they noticed and what they care about
    • Deflecting is visible in the thread and reads as evasion
    • The answer is owed in writing and can be checked later
    The same seven words, arriving through two channels. Only one of them was worth the sender's effort to produce, which is what changes the right response.

    The answer is a property of the row, not of the reply

    Section illustration: The answer is a property of the row, not of

    There is exactly one way to answer this question well, and it is decided long before anyone replies: somebody recorded, at the moment the record was collected, which surface it came from.

    The surfaces are ordinary and they are specific. A company's own team page. A published speaker roster or a conference programme. A professional profile the person maintains themselves. A regulatory register. A licence directory. An index assembled by a data vendor from some combination of the above. Each of those is a different sentence to write back, and each of them is checkable by the person receiving it.

    Where that was never recorded, what the row carries instead is the name of the tool it was exported from, and that is not an answer to the question that was asked. A data vendor is a conduit, and naming it tells the person which company to complain to rather than where their details actually came from. It also invites them to go and read that vendor's own removal page instead of yours, which moves the conversation somewhere you cannot see it and leaves your own record untouched.

    Provenance decays as well, which is the second reason to store it per row rather than reconstruct it later. The surface that held a person's details eighteen months ago frequently no longer does, and the general problem of a verified record quietly ceasing to be verified is covered in data decay. A note saying where a row came from and when it was collected survives that decay; a memory of the build does not.

    Can you answer the provenance question for this row?
    • Yes: The specific surface the record came from, named as a page rather than as a category
    • Yes: The date it was collected
    • Yes: The premise that put this person on this campaign, in one sentence
    • Yes: A privacy notice that loads, reachable from the message itself
    • Yes: A one step route to stop, honoured across every campaign
    • No: The name of the tool the row was exported from
    • No: A general statement that the information was publicly available
    What a row has to carry for this question to be answerable in a day. The bottom two are what most lists carry instead, and neither one answers what was asked.

    The row-level discipline behind this is the same discipline that separates a usable lead list from an export of names, and it is worth noticing that the fields are identical. A list built so that every row can justify its own presence is a list that can answer this question, and the two properties arrive together because they have the same cause.

    You already owed them the answer

    The reply is usually read as an unexpected demand. It is closer to a request for something the first message should have carried.

    The UK regulator publishes a checklist of the privacy information a company has to provide, and it distinguishes between data collected from the person and data obtained from somewhere else. On the second list, alongside the identity of the organisation and the lawful basis, sits "The source of the personal data (if the personal data is not obtained from the individual it relates to)". The same guidance addresses the objection senders reach for first, stating of publicly accessible sources that "You still have to provide people with privacy information", and it sets the deadline at "no later than one month", or at the point of first communication where the data is being used to communicate with the person.

    Cold outbound is data obtained from somewhere else, used to communicate with the person, which puts it inside both of those sentences by construction. What the full obligation looks like for a European or UK recipient, including the lawful-basis work that sits underneath it and the separate national sending rules, is worked through in GDPR for B2B outbound, and the parallel US and Canadian regimes are in whether cold email is legal.

    The practical reading matters more here than the legal one. A programme that can answer the question inside a day was already carrying the disclosure it owed. A programme that cannot has two gaps at once, a data gap and a disclosure gap, and only the first one is visible from the inside.

    What an honest reply contains

    Section illustration: What an honest reply contains

    Four parts, and the discipline is mostly in what is left out.

    The surface, named specifically. A team page, a speaker roster, a public register, a trade directory. Where a data vendor supplied the row, say so and say what that vendor indexes, rather than offering the brand name as though it settled anything.

    Why this person, in one sentence. The premise that put them on the campaign. This is the part that separates an answer from a form letter, and it is only available if the campaign had a premise in the first place.

    The stop, in one step. Not an invitation to reply again. A statement that they are being removed, followed by actually removing them.

    Nothing else. No second pitch, no attachment, no question designed to reopen the thread. A reply that answers the question and then asks for fifteen minutes has told the person that the answer was a device.

    Length is part of the message. An answer longer than the question reads as a defence, and the shortest version of this reply is usually the most convincing one, because a sender with a real answer does not need paragraphs to give it.

    Three answers that are not answers

    "It is publicly available." This is the most common reply and it fails twice. It names a category rather than a surface, so the person still does not know where to look, and the guidance quoted above says of personal data taken from publicly accessible sources that "You still have to provide people with privacy information".

    The vendor's name, on its own. It answers a question about your supply chain instead of the one asked, and it hands the person a removal process that lives somewhere other than your own systems.

    "You must have signed up for something." Usually false, and it is the version most likely to convert a mild question into a spam complaint, because it tells somebody who knows they did not sign up that you are guessing.

    Treat the reply as closer to a stop than to interest

    Section illustration: Treat the reply as closer to a stop than to

    The default disposition is to answer, then remove the person, unless they say something that indicates otherwise.

    That is not caution for its own sake. Somebody who wanted the offer would have replied about the offer. A reply that goes to the provenance instead is the strongest available evidence that the approach itself was unwelcome, and continuing to send after it converts a person who asked a reasonable question into a person who reports you.

    The removal has to be programme-wide rather than campaign-wide, which is the distinction that makes a suppression list worth maintaining as an asset rather than as a per-campaign filter. An entry that stops one campaign and not the next produces exactly the same outcome as no entry at all, arriving later.

    Our own outbound sends one message per campaign, with no thread replies and no scheduled second attempt, which changes the shape of this particular moment: there is no sequence still queued behind the reply, so the whole of the action is the answer and the suppression. The operating model that rule forces, and why the reply handling carries more weight when the sending carries less, is in the outbound sales playbook.

    1. Step 1Find the row

      Pull the record, its collection surface and its date, and the premise the campaign was built on.

    2. Step 2Suppress first

      Enter the address at programme level, across every campaign and every sending domain, before anything is sent back.

    3. Step 3Answer plainly

      The surface, the reason they were written to, and the confirmation that they have been removed. Nothing further.

    4. Step 4Read the frequency

      One of these is ordinary. A steady stream of them is a finding about the premise rather than about the recipients.

    What happens when the question arrives. The suppression step comes before the reply is written, because a message that promises removal and precedes it is a promise nobody has kept yet.

    What a run of them says about the list

    The individual reply is a row-level event with a row-level answer. The rate at which they arrive is a different signal entirely, and it is the more useful of the two.

    A message built on something the company itself published invites a different question. A prospect who reads a sentence referring to their own careers page, their own conference session or their own product announcement has been given the provenance inside the message, and the reply that comes back tends to be about the substance rather than about the sourcing. A message built on an inferred attribute, a database segment or a purchased signal has nothing in it that the reader recognises as being about them, which is what makes the address feel unaccounted for.

    That distinction between a published event and an inferred state is the same one that decides whether a campaign has a reason to exist at all, and it is worked through in the difference between a filter and a signal. The relevant half here is the rule it lands on: let unpublished signals decide timing, and let published ones appear in the copy. A premise the recipient can verify for themselves is a premise that answers the provenance question before it is asked.

    So a programme seeing this reply regularly should read it upstream. The people asking are describing a message that arrived from nowhere, and no improvement to the reply template changes what produced it.

    The short version

    Section illustration: The short version

    On the phone this question is a reflex and deflecting it is reasonable. In a written reply it is a deliberate act that cost the sender more than deleting the message would have, and it deserves a real answer.

    The answer is a property of the row rather than of the reply. Record the specific surface a record came from and the date it was collected, at collection, because it cannot be reconstructed afterwards and the name of the tool does not substitute for it.

    The disclosure was already owed. The UK regulator lists among the privacy information you must provide, where the data came from somewhere other than the person, "The source of the personal data (if the personal data is not obtained from the individual it relates to)", and it puts the deadline at first communication where the data is used to make contact.

    Answer with the surface, the premise and the removal, in fewer words than the question. Suppress at programme level before replying. Then read how often it happens, because a steady stream of these is a finding about the premise rather than about the people sending them.

    RevenueFlow runs cold email and LinkedIn campaigns for B2B teams, one message per campaign, and is paid on attended meetings that meet criteria agreed in writing before launch. You can see what a campaign would look like for your market.

    Regulator guidance verified against the Information Commissioner's Office right to be informed guidance as fetched on 29 August 2026, with a dated snapshot retained. Confirm current text before relying on it.

    Questions

    Frequently asked questions.

    Frequently asked questions
    Do I have to tell a prospect where I got their email address?
    Where the data came from somewhere other than the person, the UK regulator's checklist of privacy information includes the source of the personal data, and its stated deadline is a reasonable period and no later than one month, or first contact where the data is used to communicate. Cold outbound sits inside both conditions, so the disclosure was owed before anyone asked for it.
    Is publicly available an acceptable answer?
    It fails on two counts. It names a category rather than a surface, so the person still cannot check it, and the same regulator guidance states plainly that a publicly accessible source does not remove the obligation to provide privacy information. Name the page, the roster or the register instead, which takes the same number of words and is verifiable.
    Should we keep sending to someone after they ask this?
    Treat it as closer to a stop than to interest and remove them unless they say otherwise. Somebody who wanted the offer would have replied about the offer. The removal belongs at programme level across every campaign and sending domain, because an entry that stops one campaign and not the next produces the same outcome as no entry, arriving later.
    What should we record at list build so this is answerable?
    Two fields per row and one sentence per campaign. The specific surface the record came from, named as a page rather than a category, and the date it was collected. Then the premise that put that person on that campaign. Those three things compose the entire reply, and none of them can be reconstructed reliably after the fact.
    cold emailoutboundobjection handlinglist buildingcompliance
    Byline

    About the author.

    RevenueFlow Team

    B2B cold email experts helping companies generate qualified leads through done-for-you outreach campaigns.

    RevenueFlow Team

    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.

    B2B Sales Strategy

    Finding and Reaching Decision Makers in Outbound: When You Cannot Ask

    In cold outbound the title on the record is the only evidence you have, and it is weak. How to select on accountability instead, and where coverage ends.

    7 min readRead →
    B2B Sales Strategy

    Outbound Is Sending and Not Booking: Which Number to Read First

    A short meeting count is produced by four multiplied stages, so the cause can sit anywhere and the symptom looks the same. Here is the order to read them in.

    8 min readRead →
    B2B Sales Strategy

    Pay Per Meeting Pricing When the Deal Is Small: Where the Model Breaks

    Pay per meeting is decided by your deal economics before it is decided by the vendor. The arithmetic that settles it, and what to buy when it does not clear.

    7 min readRead →
    B2B Sales Strategy

    AI Cold Calling: What a Per-Minute Price Buys and Where It Breaks

    Retell lists AI voice agents at $0.07 to $0.31 a minute. JustCall lists $0.99. The fourteen-fold gap is the most instructive thing about the category.

    8 min readRead →
    B2B Sales Strategy

    Meetings Are Landing and Nothing Is Closing: Reading the Failure in Order

    A full calendar and a flat revenue line is a different problem from a quiet calendar. How to read it in order, and why buying more meetings makes it worse.

    8 min readRead →
    B2B Sales Strategy

    Quality or Quantity in Outbound: The Two Decisions People Merge Into One

    Quality and quantity are not two ends of one dial. Selection decides who is on the list, measurement decides what you divide by, and merging them is why nobody wins.

    8 min readRead →