Verified merchant email data · 50 states + DC · CSV, API, or direct CRM delivery
MCA Email Leads Merchant data · MCA Book a call
Data & compliance

Where the data
comes from

Data quality and compliance are the two things that quietly decide whether an outbound program lasts a quarter or a year. Here is how we handle both.

Sourcing

Records are compiled from public business filings and registrations, licensing and permit records, self-reported business directory submissions, partner intent networks, and merchant-permissioned inquiry data.

Every record is business contact data, not consumer data. We do not compile personal consumer profiles, and we do not sell anything intended for consumer marketing.

Verification pipeline

Pass 01
Syntax and formatting validation, role-account and disposable-domain screening
Pass 02
Domain and MX record validation, catch-all detection and flagging
Pass 03
Mailbox-level verification, with failures removed rather than counted against your order
Ongoing
Rolling re-verification on held inventory; anything older than 30 days is re-checked before release

Suppression

  • Global opt-out list applied permanently across every account and campaign
  • Client CRM suppression on request, so you never pay for a contact you already own
  • Litigator and complaint-flag suppression maintained continuously
  • Client-supplied do-not-contact lists honored on every subsequent pull

CAN-SPAM in practice

Every managed campaign we run uses accurate sender identity and headers, non-deceptive subject lines, a valid physical postal address, and a working one-click opt-out processed immediately and globally. When you send data yourself, those obligations are yours — and hiring a vendor does not transfer them. We build to the standard and expect clients to send responsibly.

Several states impose additional requirements, and Canada CASL and EU GDPR are materially stricter, being consent-based rather than opt-out-based. None of this page is legal advice. Confirm your specific program with your own counsel.

Compliance questions

Is cold email to businesses legal?
Business-to-business email in the United States is governed primarily by CAN-SPAM, which permits cold outreach provided headers and sender identity are accurate, the subject line is not deceptive, a valid physical postal address appears, and a working opt-out is honored promptly. Several states and other countries impose stricter rules. We build to CAN-SPAM and expect clients to send responsibly, but we are not a law firm — confirm your own program with counsel.
Can you suppress against my existing CRM?
Yes. Upload your current contacts or connect your CRM and we dedupe against it before delivery, so you are not paying for records already sitting in your pipeline. Opt-out and do-not-contact lists are suppressed globally and permanently.
Will this hurt my domain reputation?
It can, if you send cold volume from your primary domain — which is why we do not recommend it. Our infrastructure service builds a separate sending estate with its own domains, authentication, and warmup so your main email stays clean. On managed campaigns, sending happens on our estate, not yours.
How are the email addresses verified?
Records run through syntax and domain checks, MX validation, and mailbox-level verification before delivery, with a rolling re-verification pass on anything held in inventory. Any record that fails verification is removed before the file reaches you rather than counted against your order.

Talk to us

Step 1 of 2

You will pick a time on the next screen. No spam, no resale of your information — see our privacy policy.

Next step

Get counts against your lender box

Bring your criteria to the call and we will scope a test pull, confirm coverage, and price it.