Email validation is the least interesting step in any outbound build and one of the easiest to get wrong. Not wrong as in “picked the wrong vendor.” Wrong as in “put it in the wrong place.”
Most teams validate early. They pull a list, clean it, and feel good about starting from verified data. It seems careful. It is actually the expensive version, and it does not protect the thing that matters.
Why the end and not the beginning
Two reasons, and the second one matters more.
You pay for contacts you never email. A raw list gets cut down constantly. Companies fail the fit screen. Duplicates collapse. People turn out to be the wrong role, the wrong seniority, the wrong country. Validating at the start means paying to verify every one of those before you know they are going anywhere. On a list of any size that is most of your spend on records that get deleted the same week.
Verification goes stale. This is the real argument. People change jobs constantly. An address that verified clean in March may belong to nobody by August. If you validate in March, sit on the list, and send in August, you validated a fact that is no longer true and you will find out through your bounce rate.
So the position is simple. Validation is the last gate before send, not the first step after sourcing. If a long time passes between validating and sending, validate again. It is cheap. Bounces are not.
What you are actually protecting
It helps to be clear about the stakes, because “keep the list clean” undersells it.
A cold email program runs on sending domains and mailboxes that took weeks to warm up. That warmup is an investment in reputation: mailbox providers slowly decide you are a legitimate sender. Bounces attack that directly. Send to enough dead addresses and providers stop trusting the domain, your inbox placement drops, and the fix is not a setting. The fix is new domains and another month of warmup.
A high bounce rate does not just hurt the campaign it happened on. It damages the sending reputation behind every campaign on that domain, including the ones that were working. The cost of skipping validation is never contained to the list that caused it.
So the question is not “is validation worth the cost per address.” It is “is validation worth less than rebuilding sending infrastructure.” Framed that way it stops being a close call.
Only “safe to send” is a pass
Every validator returns more than a yes or a no. You will see categories like valid, invalid, catch-all or accept-all, unknown, disposable, and role-based.
The mistake is treating anything that is not an outright “invalid” as a green light. Catch-all means the domain accepts everything at the front door and decides later, so you really do not know. Unknown means the check did not conclude. Neither is evidence the address is real.
On a well-built list from a real ICP, expect roughly three quarters to come back safe to send. If your pass rate is dramatically higher than that, be suspicious of your validator. If it is dramatically lower, the problem is upstream in how the list was sourced, and no amount of validating fixes a badly built list.
Send the data, do not upload the file
One practical point that gets skipped for convenience.
Most validators offer two paths: upload a file of addresses, or call an API address by address. The upload is easier. It is also the one where a file of real people’s contact details sits on someone else’s storage waiting to be processed, and in some setups needs to be publicly reachable for the vendor to fetch it.
Calling the API means the data moves, gets checked, and does not sit anywhere. It costs a little more effort to wire up once. For anything involving other people’s personal data, that is the correct trade, and it is the kind of choice that is invisible until the day it is not.
Where this fits
Validation is the last thing that happens to a contact before it becomes a lead in a campaign. Source, screen for fit, enrich, dedupe against what you already have, then validate, then send. Nothing between validation and send.
That is why it goes last, and why it is not optional. It is unglamorous, it is cheap, and skipping it is one of the few mistakes in outbound that you cannot undo by fixing your copy.
Validate immediately before you send, accept only confirmed addresses, and treat catch-all and unknown as unanswered. You are not protecting a spreadsheet, you are protecting domains that took a month to warm.