Lead Verification: What Each Check Actually Proves
Lead verification covers two different jobs. One asks whether a mailbox will accept mail, the other asks whether the person behind the row is real and lawful to contact.

Lead verification confirms that a lead record is true: the address resolves, the company trades, the person holds the role, the row is not a duplicate, the record fits the agreed criteria, and a lawful basis for contact exists. Address verification answers only the first of those six checks.
Key takeaways
- Two jobs share the name lead verification: address verification for outbound senders, and wider lead validation for teams buying or capturing leads.
- A lead record makes six separate claims, and the address is the cheapest and least informative of them.
- Run the checks cheapest and most decisive first: deduplicate, check the company, apply fit criteria, resolve the identity, then verify the address close to send.
- The UK regulator states that marketing email to individuals needs specific consent, and that the soft opt-in exception does not reach bought-in lists.
Reviewed and updated September 2, 2026
A team buys three hundred leads from a demand generation partner on a Thursday. On Monday a rep works the first forty and reports back: eleven addresses bounced, six people no longer hold the job the record says they hold, two rows are the same person entered twice with different spellings, and one is a competitor who filled in a form to see what the follow up looked like. Nobody was defrauded. Every one of those rows passed whatever check the supplier ran, because the supplier ran a check on something else.
That gap is what lead verification is for, and the reason it is confusing is that the phrase is used for two different jobs by two different buyers.
Two things called lead verification
Search the term and the results split between cold outreach and inbound demand generation, and the two populations barely overlap.
The outbound sender means one thing: will this address accept a message, or will it bounce and cost the sender reputation. That is address verification, it is cheap, it is mature, and the products that do it are compared in email verification tools.
The demand generation buyer means something much wider: is this lead a real person, at a real company, who really did the thing the record says they did, and is there a lawful basis for writing to them. That check has an address component and five other components, and the address component is the least interesting of the six.
- Will this mailbox accept a message
- Answered by syntax, DNS and SMTP checks
- Costs a fraction of a penny per row
- Failure shows up as a bounce, within hours
- Says nothing about who the person is
- Is this a real, reachable, lawfully contactable person who fits
- Answered by six separate checks, only one of which is the address
- Costs more, and part of it cannot be bought
- Failure shows up as a wasted quarter of rep time
- Says nothing about whether they will buy
Both are legitimate. The expensive mistake is buying the first and believing you have bought the second, which is exactly what happened to the team above.
The six checks, and what each one actually proves
A lead record makes six separate claims. Each is checkable, each is checkable by a different method, and each proves a strictly bounded thing.
The address resolves. Syntax is well formed, the domain has mail exchange records, and the mailbox accepts. This proves the message can be delivered. It does not prove the mailbox belongs to the named person, and on a catch all domain it does not even prove the mailbox exists, which is the wall every verifier hits and none of them can climb.
The company exists and is trading. A registry lookup or the company's own live site. This is the cheapest check on the list and the one most often skipped, because a plausible domain name reads as a real company. Records naming companies that dissolved or were acquired are common in files assembled over more than a few months.
The person holds the role. The named human is currently in the named seat. This is the check that decays fastest and the one that decides whether the message is true. A record correct at capture is wrong at a rate that compounds with every month it sits unsent, which is the mechanism described at data decay.
The row is not a duplicate. The same person entered twice under two spellings, or the same company under a legal name and a trading name, is not a data-cleanliness annoyance. It is two reps contacting one buyer, which is the single most damaging thing a supplied file can do to you.
The record matches the profile you agreed. Every field the targeting depends on is present, and reads correctly. A file mixing practitioners and decision makers passes every check above, because each of those rows is accurate.
You may lawfully write to them. The one check the vendors talk about least and the one with the sharpest edge, covered below.
- Step 1Deduplicate
Free, instant, and it shrinks everything downstream. Match on company domain and on person before anything else runs.
- Step 2Check the company
Does the domain resolve to a live business. A dead company invalidates every other field on the row.
- Step 3Check the fit
Apply the criteria you agreed before you bought. This is judgement rather than a lookup, and it removes the rows no verifier can flag.
- Step 4Resolve the identity
Is the named person still in the named seat. Expensive per row, which is why it runs after the free filters.
- Step 5Verify the address
Last, and close to send, because the result has a shelf life measured in weeks.
Running that order backwards is the common mistake, and it is expensive twice over. Verifying addresses first means paying to verify rows you are about to delete for fit, and it means the verification result is stale by the time the file actually sends.
Verification is not qualification, and the two get billed as one

Verification asks whether the record is true. Qualification asks whether the person is worth your time. They are answered by different evidence and they fail in different ways, and a supplier who blurs them is describing a smaller product than you think you are buying.
A row can be perfectly verified and worthless: the address resolves, the person is in seat, the company trades, and they have no budget, no problem you solve and no intention of talking to anyone. Nothing in a verification stack detects that. The distinction between a fit failure and a readiness failure, and why recording them as one flag destroys the feedback, is worked through at unqualified lead.
The reason to keep the boundary sharp is commercial. Where somebody is being paid per lead, the definition of what counts is the whole contract, and a definition that stops at verified is a definition that pays for accurate records rather than for useful ones. What qualified has to mean when money depends on it sets out how that gets settled in writing before anything is bought.
Our own position on the same boundary is narrow and worth stating: meetings are qualified against criteria agreed in writing before launch, and budget, timing and authority are deliberately outside that definition. A standard written afterwards is a standard read off the result.
The consent check, which is the one with legal edges
For leads captured through a form and for leads bought in, the question of whether you may write at all is separate from every check above, and the answer differs by who the recipient is rather than by how good your data is.
The Information Commissioner's Office, the UK regulator, states the rule plainly on its guidance for electronic mail marketing. As published on ico.org.uk and read on 2 September 2026, the guidance says "You must not send marketing emails or texts to individuals without specific consent." It describes a limited exception for a company's own previous customers, and it is explicit about the edge of that exception: the soft opt in "does not apply to prospective customers or new contacts (eg from bought-in lists)".
The line that catches people out is who counts as an individual. The same page states that "Sole traders and some partnerships are treated as individuals", while "You can email or text any corporate body (a company, Scottish partnership, limited liability partnership or government body)." A bought file of small businesses is therefore a mixed population, and the mix is not visible in any field a verifier checks.
The practical consequence for a verification process is one extra column rather than a legal project. Record, per row, what the lawful basis is and where it came from: a corporate body, or a consent captured at a named form on a named date. A supplier who cannot supply that per row is supplying rows you have to treat as unusable for the individual half of the file, and finding that out before the purchase costs one question.
Verifying a supplier rather than a file

The strongest version of this work happens before the file arrives, because verifying a file you already paid for only tells you how much you wasted.
Ask for a sample and run the whole ladder on it, in the order above, and count what survives at each stage. The number that matters is not the pass rate on any single check, it is the share of the sample that clears all six, because that is the only figure that corresponds to rows a rep can work.
Ask for provenance per field rather than a coverage claim. A supplier who can name the source of each field and the date it was last checked is describing a file you can maintain and repair. A supplier who answers with a vendor name and a percentage is describing a purchase. The same question, asked of a lead supplier rather than a data supplier, is the substance of how to test a supplier without committing to volume.
And ask what happens on a failure, in writing, before any money moves. Replacement of rejected rows, the window for rejecting them, and who decides. That clause is worth more than any accuracy percentage on the sales page, because the percentage is measured against the supplier's own definition and the clause is measured against yours. Where the leads are being generated on a platform rather than bought from a list vendor, the same economics and the same definitional argument show up in pay per lead ads.
- Yes: A sample was run through all six checks and the all-six survival rate was counted
- Yes: Provenance and a check date exist per field, not per file
- Yes: The lawful basis is recorded per row, with the form and the date where consent is claimed
- Yes: The rejection window and the replacement terms are written down
- Yes: Duplicates were resolved against your own existing records, not only within the file
- No: The accuracy claim on the sales page was accepted as the acceptance standard
- No: Address verification was treated as evidence the lead is real
What the arithmetic looks like
Take a file of a thousand purchased rows. Every figure in this paragraph is invented for the illustration and describes no real supplier or file. Suppose deduplication removes one row in twelve, the company check removes one in twenty five of what remains, the fit criteria remove a third, identity resolution removes a further tenth, and address verification removes a further eighth.
That chain leaves roughly four hundred and sixty rows a rep can work, from a thousand paid for. The point is not the number, which will be different for every file. It is that the survival rate is a product of five multiplications, so a file that passes each individual check at a respectable rate can still deliver well under half of what was invoiced, and none of the individual pass rates looks alarming on its own.
That is also why the all-six figure is the one to negotiate on. A supplier quoting a single headline accuracy figure is quoting one of the five multiplicands.
What verification cannot do

It cannot tell you the lead is interested, because interest is not a property of a record. It cannot fix a targeting problem, because a file full of accurate wrong people passes every check. It cannot make a stale file fresh, since the result of every check has a shelf life and identity is the shortest of them. And it cannot substitute for the acceptance standard, because a check with no agreed threshold produces a number nobody has to act on.
Where the file is your own rather than bought, the upstream version of this work is building the row correctly in the first place, which is set out at lead list, and the boundary between checking a record and deciding who deserves your time sits at lead qualification.
The short version
Two jobs share the name. Address verification answers whether a mailbox accepts mail and costs almost nothing. Lead validation answers whether a real, reachable, lawfully contactable person who fits your criteria is behind the row, and it is six checks of which the address is one.
Run them cheapest and most decisive first: deduplicate, check the company, apply the fit criteria, resolve the identity, then verify the address close to send. Keep verification and qualification separate, because a verified record can be worthless and a supplier billing on the first while you are buying the second is the most common way this goes wrong. Record the lawful basis per row, since the rules turn on whether the recipient is a corporate body or an individual and no verifier reports that. And do the work on a sample before the purchase, counting the share that clears all six rather than the pass rate on any one.
If the underlying problem is that there are too few conversations rather than too few clean rows, that is the half we run: see what a first campaign produces.
Frequently asked questions.
Frequently asked questions- Is lead verification the same as email verification?
- No. Email verification checks whether a mailbox will accept a message, using syntax, DNS and SMTP tests. Lead verification in the demand generation sense checks six things: the address, the company, the person's current role, duplication, fit against agreed criteria, and the lawful basis for contact. Buying the first while believing you bought the second is the common expensive mistake.
- What order should the checks run in?
- Deduplicate first because it is free and shrinks everything downstream. Then check the company is trading, then apply your fit criteria, then resolve whether the person still holds the role, and verify the address last and close to send. Running address verification first means paying to verify rows you are about to delete, and the result goes stale before the file sends.
- Does verifying a lead mean it is qualified?
- No. Verification asks whether the record is true. Qualification asks whether the person is worth your time. A row can be perfectly accurate and worthless, because nothing in a verification stack detects the absence of a problem you solve. Keeping the two separate matters most where somebody is paid per lead, since a definition that stops at verified pays for accurate records rather than useful ones.
- How do I test a lead supplier before buying?
- Ask for a sample and run all six checks on it in order, counting the share that clears every one rather than the pass rate on any single check. Ask for provenance and a check date per field rather than a coverage percentage. Agree the rejection window and replacement terms in writing before money moves, because that clause is measured against your standard rather than theirs.
About the author.

Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.
Ben Carden · CRO
Connect on LinkedIn →Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
5 ABM Campaign Examples and How Each One Is Built
Five worked account-based campaign examples, each built on the same five fields: account set, tier, plays in order, owner and handoff, and the exit condition.
Two Agencies, One Target List: Who Owns Which Accounts
Two outbound suppliers on one market will contact the same companies unless the buyer splits it first. How to cut the list, run the exclusion feed and check the overlap.
When Outbound Stops Scaling: What Breaks First
Doubling the budget rarely doubles the meetings. The five constraints that bind in order, the signature each one leaves in the numbers, and what actually buys more.
IT Lead Generation: The Buyer Runs Your Playbook
Technology buyers evaluate outbound for a living, and their purchases carry a security review nobody in your meeting owns. Which triggers are real.
Last Outbound Agency Did Not Deliver: Locating the Failure
The leads were bad names a symptom and no stage. Four places an outbound engagement fails, the counts that separate them, and what to change in the next purchase.
HR Lead Generation: The Renewal Clock and Who Signs
An HR buyer who agrees with every word still cannot act outside their own renewal window. Which triggers are observable, and who signs.