How to Clean an Email List Before a Cold Email Campaign

Cold email lives or dies on list quality. A campaign with a 6% bounce rate can damage a sending domain in a single send, and it takes weeks of careful sending to recover. For agencies it's worse: it's the client's domain on the line.

Here's the process we recommend before any cold campaign goes out.

Step 1: Deduplicate and normalise

Before paying to verify anything:

  • Trim whitespace and lowercase the domain part.
  • Remove exact duplicates, including duplicates that differ only in case.
  • Remove obviously broken rows: no @, spaces inside, placeholder values like n/a.
  • Remove addresses on your suppression list (previous bounces, unsubscribes, complaints) and your client's.

This alone often removes 5 to 10% of a purchased or merged list, at zero cost.

Step 2: Verify every address

Run the whole list through verification. In the MailRambo dashboard, upload the CSV; with the API, send batches of up to 200:

start = session.post(
    "https://www.mailrambo.com/v1/verify/batch",
    json={"emails": chunk, "name": "Client X - Q4 outreach"},
    headers={"Idempotency-Key": f"client-x-q4-{i}"},  # safe to retry
).json()

Every address comes back with deliverable: true or false and a reason. Only true goes into the send list by default.

Step 3: Decide on the grey areas

Result Recommendation for cold email
mailbox_exists Send
role_account (info@, sales@) Usually exclude; low reply rates, more complaints
catch_all Exclude, or send later in a small separate batch
unverifiable Exclude
disposable, spamtrap, mailbox_not_found Never send

Catch-all addresses are the biggest trap. They look fine at verification time and bounce later. If the segment is too valuable to drop, send to it separately at low volume, from a secondary domain, and stop at the first sign of bounces. More detail: what a catch-all email is.

Step 4: Prioritise by lead quality

Not every deliverable address is worth the same. Domain signals tell you a lot about the company behind an address:

  • Mail provider: Google Workspace or Microsoft 365 usually means an established business.
  • Security gateway: Mimecast or Proofpoint in the MX records means stricter filtering, so write plainer copy and avoid links in the first email.
  • DMARC at reject and 2048-bit DKIM: a mature IT setup.
  • No MX, or a parked domain: remove.

MailRambo's dashboard grades each lead A to F using these signals, and the API returns them with ?detail=full. You can check a single domain for free with the domain health checker.

Step 5: Check your own sending domain

The cleanest list in the world won't help if your sending domain is broken:

  • SPF includes your sending tool, stays under 10 lookups, and there's only one SPF record.
  • DKIM is set up for the sending tool with a 2048-bit key.
  • DMARC exists; p=none is fine to start.
  • The domain is warmed up: start at 20 to 30 emails a day per inbox and increase gradually.

Use a separate domain for cold outreach (for example getacme.com rather than acme.com), so the main domain's reputation is never at risk.

Step 6: Send carefully and watch the numbers

  • Send in batches across several days, not all at once.
  • Stop and investigate if bounces go above 2% or spam complaints above 0.1%.
  • Remove bounces immediately and sync them to the CRM.
  • Re-verify anything older than 90 days before the next sequence.

A quick checklist

  • [ ] Deduplicated and normalised
  • [ ] Suppression lists applied
  • [ ] Every address verified; only deliverable: true kept
  • [ ] Role and catch-all addresses decided deliberately
  • [ ] Leads prioritised by domain quality
  • [ ] Sending domain authenticated and warmed up
  • [ ] Batch sending with bounce and complaint monitoring

For agencies, the verification report doubles as a deliverable: showing a client how many dead or risky addresses were removed before launch is an easy way to show value.

Start with the free email verifier, or create a free account to clean full lists.

Run these checks from your code

Verify addresses at signup, clean lists and read SPF/DKIM/DMARC with one API call. 100 free verifications a month, test keys that cost nothing, and the API on every plan.