Decay University · Part 4: Sending well: lists, content, practice

Lesson 30 of 64

List hygiene: the list is the reputation

Your list is your reputation. Consent, bounce types, spam traps, sunset policies, and why bought lists end sending careers.

Last updated 19 July 2026

Mailbox providers don't grade your emails. They grade how the people you mail react to them: opened, replied to, ignored, deleted unread, reported as spam. That means the list itself, who is on it and how they got there, is the largest single input to the sender reputation you met in the last module. Perfect authentication on unwanted mail is just well-identified spam. This lesson covers the whole life of a list: who gets on and who comes off, and what a list does when you leave it alone.

Consent comes first

Consent means the person asked for this mail, from you, recently enough to remember doing it. A whitepaper download from three years ago is a lead. A badge scanned at a conference is a lead. Neither is consent to a weekly newsletter.

Filters can't see consent directly. What they see is its shadow: consented mail gets opened, clicked, replied to, and moved out of spam when it lands there. Unconsented mail gets deleted unread or reported. (A "complaint" in deliverability language is one specific act: a recipient pressing the report-spam button. Every mailbox provider counts them.) Everything else in this lesson is a technique for keeping the shadow looking right, and none of it works for long if the consent underneath is fake.

Single or double opt-in

Single opt-in: someone types an address into your form and they're on the list. Double opt-in: after the form, you send a confirmation email, and they're only on the list once they click it.

The tradeoff is real on both sides, so let me state it honestly. Single opt-in grows a list faster and captures everyone who was willing to type an address. It also captures typos, bots filling forms, spite sign-ups, and plain carelessness with other people's addresses. Those addresses turn into hard bounces and complaints from strangers, and occasionally into spam traps. Double opt-in verifies that every address is real and its owner wanted this. The cost: some genuinely interested people never click the confirmation, sometimes because the confirmation email itself landed in spam, which is an irony this whole course exists to reduce.

My position, since a course should have one: default to double opt-in and treat single as the option that needs justifying. Double opt-in also protects you from being weaponized. Bots stuffing a signup form with victims' addresses (it happens, and the form owner takes the reputation damage) can't get past a confirmation click.

Hard bounces, soft bounces

A bounce is mail coming back. A hard bounce is a permanent rejection: the address doesn't exist, or the domain doesn't exist. A soft bounce is a temporary one: a full mailbox, or a receiving server having a bad day. The mechanics of how these come back to you are the subject of the bounces and feedback loops lesson; here the question is what they mean for the list.

A hard-bounced address is dead. Remove it and never send again. This matters beyond tidiness, because repeatedly sending to nonexistent addresses is itself a signal receivers watch. Legitimate senders stop mailing dead addresses because their software listens to the answer. A sender who keeps hammering mailboxes that don't exist looks like software that doesn't listen, and mail aimed scattershot at dead addresses is exactly how mail from an old scraped list behaves. Receivers notice the ratio.

Soft bounces get retried automatically and most resolve. An address that soft-bounces month after month is worth treating as dead too; a mailbox that has been full for a year has been abandoned.

Spam traps

A spam trap is an address whose only job is to identify senders who should never have had it. Nobody reads trap mail. Blocklist operators and mailbox providers run networks of them, Spamhaus among the best known. Two kinds matter, and they accuse you of different crimes.

A pristine trap never belonged to a human being. It was created as a trap, seeded in places only a scraping program would find, and waited. If you mail one, there is no innocent explanation: that address entered your list through scraping or through buying from someone who scraped. Operators treat pristine hits accordingly, and a listing can follow.

A recycled trap used to be a real person's address. The provider closed the abandoned account, hard-bounced all mail to it for an extended period, and then quietly turned the address back on as a trap. Think about what that sequence filters for. Everyone who processes bounces stopped mailing the address during the bouncing period. Whoever is still sending when it reactivates has ignored the return channel for a long time. A recycled hit signals negligence rather than theft, but it damages reputation all the same.

There's a cousin worth knowing: typo domains like gmial.com, registered by trap operators to catch mail meant for the real thing. Double opt-in filters these out on its own, since no confirmation click ever comes back from a trap.

Lists rot while you do nothing

Here is the part that surprises people. A list that was one hundred percent genuine on the day it was collected is a different list two years later, without a single bad signup. People change jobs and their work addresses die with them. Personal accounts get abandoned. Interests move on, and the subscriber who loved you in 2024 deletes you unread in 2026. Some slice of any list goes dead every year, silently.

This is the decay thesis of this course in miniature: nothing you did was wrong, and the asset degraded anyway. The classic visible symptom, and a pattern behind sudden blocklistings we see, is the big send to a list that sat cold for a year. The list aged in storage; the send finds out all at once.

I'll also make an admission here. Inbox Decay cannot see your list. We read DNS and message headers, so we'll catch your broken SPF record before you feel it, but no outside tool can tell you that a third of your subscribers stopped existing. Your ESP's bounce and engagement data is the only window into list health, and only you can look through it.

Sunset the disengaged

A sunset policy is a standing rule that stops mailing people who have stopped reading: for example, anyone with no clicks or replies across a set number of months and campaigns gets moved out of regular sends. The exact thresholds matter less than having the rule and running it on a schedule instead of "when we get around to it".

One honest caveat: opens are a weak signal for this. Apple Mail's privacy features fetch images whether or not a human looked, so open rates overcount. Lean on clicks and replies where you can.

The instinct that a bigger list is a bigger asset dies hard. It's backwards. Filters read your engagement rates across everything you send, so every disengaged address on the list lowers the average and taxes delivery to the people who do read you. Cutting ten thousand dead addresses usually improves revenue, because the mail to the living starts landing.

Re-engagement, done honestly

Before sunsetting someone, one honest attempt is fair: a single email that says you've noticed they've stopped reading and asks whether they want to stay, with a real choice and a real goodbye. Silence is an answer. Respect it.

The dishonest version is a months-long "we miss you" campaign to the dormant segment. That's how senders manufacture their own complaint spikes: a person who forgot you exist is the person most likely to press report-spam instead of hunting for the unsubscribe link.

Bought lists end careers

Now assemble the whole lesson and point it at one object: the purchased list. It has no consent, so it generates complaints. It has unknown age, so it's salted with hard bounces and recycled traps. It was built by scraping or by merging other bought lists, so pristine traps ride along. Every failure mode above, in one CSV.

Then add the arithmetic that changed in 2024. Gmail and Yahoo now hold bulk senders to a spam complaint threshold, covered in the bulk sender rules lesson: Google's sender guidelines say to keep the rate under 0.1% and never let it reach 0.3%, measured in Postmaster Tools. That ceiling is three complaints per thousand delivered messages. An opted-in list rarely brushes it. Mail a thousand strangers who never heard of you and three annoyed people is an optimistic outcome. One purchased list can push a domain over the line in a single send, and the damage attaches to the domain, following you across every IP and tool you switch to afterwards.

The fix is unglamorous and there is no clever alternative: ask permission and mail the people who gave it. Remove the ones who take it back. While you work on that half, the technical half takes a minute to verify: run the free health check and make sure the mail you send to a clean list is authenticated well enough to deserve it.

A clean list is the foundation, and the law has opinions about how you built it: consent and the law is next. The message on top comes after: content and design sorts the structural choices that genuinely move placement from the spam-word rules that stopped mattering decades ago.

Terms from this lesson

  • consent - the recipient asked for this mail, from you, recently enough to remember doing it. The foundation every other list practice builds on.
  • single opt-in - a signup form adds the address to the list immediately, with no verification step.
  • double opt-in - the address only joins the list after its owner clicks a link in a confirmation email, proving the address is real and wanted.
  • hard bounce - a permanent delivery failure, typically a nonexistent address or domain. Remove the address and never send again.
  • soft bounce - a temporary delivery failure, such as a full mailbox or a busy server. Retried automatically; chronic soft bouncers should be treated as dead.
  • pristine spam trap - a trap address that never belonged to a person, seeded where only scrapers look. Hitting one proves a list was scraped or bought.
  • recycled spam trap - a once-real address that bounced for an extended period and was then reactivated as a trap. Hitting one proves bounces were ignored.
  • sunset policy - a standing rule that stops regular mail to subscribers who show no engagement over a defined window.
  • complaint rate - the share of delivered mail that recipients report as spam. Gmail and Yahoo enforce thresholds on it for bulk senders.

Check yourself

1. What does repeatedly sending to addresses that hard-bounce signal to mailbox providers?

2. You mail an address that turns out to be a pristine spam trap. What does that prove about your list?

3. What is the honest cost of double opt-in?

4. Why can one purchased list end a domain's sending career under the 2024 rules?