You found a contact’s email on a company website. It’s public. You think, “This is fair game.” But in 2026, that assumption could land you in regulatory trouble.

Under the UK’s Privacy and Electronic Communications Regulations (PECR), scraping public B2B contacts isn’t a legal loophole. It’s a minefield. Just because an email is visible doesn’t mean you can use it to send marketing messages without permission.

You’re not breaking the law by collecting the data—but you are if you use it without a lawful basis. PECR doesn’t care how you got the email. It only cares how you use it.

Key takeaways

  • Scraping B2B emails in the UK is not automatically legal—even when the data is publicly listed.
  • PECR requires a legitimate basis for contacting someone, and scraping alone does not provide that basis.
  • Even with a public email, sending marketing messages without consent risks fines and reputational damage under UK law.

What Does PECR Say About B2B Marketing Emails in 2026?

PECR allows direct marketing to businesses in the UK, but only if it’s not unsolicited and based on a legitimate interest. You must have a fair reason to contact the company—such as a prior business relationship or a clear, relevant service offer—and you can’t override any individual privacy rights, even within a corporate email address. Every email must include your sender identity and a working unsubscribe link, or you risk enforcement from the ICO.

Legitimate Interest Is Valid—But Restricted

Let’s be clear: you can use legitimate interest to send B2B emails, but only if you're contacting a business entity, not an individual. If the email address belongs to someone like [email protected], and you’re certain it’s a business account, you may rely on this legal basis. But you can’t assume this applies just because the domain looks corporate or has a role-based name. The ICO’s guidance emphasizes that this justification fails if recipients have opted out or if the contact is irrelevant or overly intrusive.

For example, if your software helps with logistics, you can send information about your service to [email protected] if there’s a clear connection. But if you’re selling office snacks to an HR manager at a finance firm, that’s a harder case—and more easily challenged. PECR is strict on relevance and intent, and enforcement isn’t limited to complaints: the ICO can investigate based on patterns, like high bounce rates or spam complaints.

Unsubscribe and Identity Must Be Clear

Every email must clearly show who you are and how to opt out. This isn’t optional, even for B2B. Your return path must be valid, and the unsubscribe mechanism must work immediately—not just after a delay or confirmation. The ICO considers this a fundamental rule, and failure can result in fines or reputational damage.

Even if you’re using an aggregator or third-party tool, the responsibility stays with your organization. That’s why verifying your list beforehand makes sense. You can use a service like bulk verification to catch invalid, role-based, or likely non-responsive addresses before sending. This helps ensure your list is accurate and compliant, reducing bounce rates and the risk of being flagged.

For real-time checks, you can integrate directly with our API to confirm validity and detect disposable or suspicious domains on the fly. This is especially useful if you’re growing your list via forms, outreach, or tools like email finder. And if you send campaigns via platforms like Mailchimp or Klaviyo, our integrations help keep your data clean and compliant from inside the workflow.

Ultimately, PECR in 2026 doesn’t change the core rules: relevance, consent, and transparency still matter. The law doesn’t care about your tech stack—it cares about what you send, to whom, and whether you’re respecting boundaries. The best defense is a clean list, real verification, and clear sender identity. For that, tools like inbox placement testing help you check deliverability and avoid blacklists. And yes, even with a “valid” B2B sender, your reputation still affects delivery. It’s not just about law—it’s about trust. For more on how to stay compliant, explore our pricing and free trial. You can verify 100 emails for free, and credits never expire.

What Defines a 'Scraped' Contact Under PECR?

A 'scraped' contact under PECR is any email address collected from public sources—like LinkedIn profiles, company websites, or public directories—without explicit, active consent. Even if the contact is a professional in a legitimate role, using it for marketing without a valid legal basis counts as a PECR breach. The UK’s Information Commissioner’s Office (ICO) treats such data as inherently high-risk unless rigorously verified and cleaned for compliance.

Why Public Sources Aren’t a Free Pass

Just because an email is publicly listed doesn’t mean it’s fair game for marketing. PECR's core rule is that you can’t send marketing emails without either prior consent or a valid “legitimate interest” justification. Scraping a name and email from a company’s “Contact Us” page doesn’t count as consent. It’s not enough that the person works at a business or is visible on a public platform. If you’re not on a known relationship path, that’s a scraped contact.

Let’s be clear: a professional role doesn’t grant permission to market. A CEO’s email isn’t immune just because they’re in a leadership position. The ICO has made it clear that unverified outreach via scraped data is a red flag in enforcement actions. In 2023, they cited companies for using leads from public directories without consent—this isn't rare, it happens regularly.

How to Reduce Risk When Using B2B Lists

You can still use public data, but only if it’s verified and cleansed. The key is confirming that the address is valid, active, and belongs to a real person—no point sending to a non-existent or defunct email. More importantly, you must ensure the contact isn’t on a suppression list, doesn’t trigger spam traps, and isn’t associated with a role account or disposable domain.

Using a tool like bulk verification helps remove invalid, risky, and high-fraud signals. It checks for catch-all domains, role accounts (like info@ or sales@), and disposable emails—common red flags in scraped lists. It also flags emails that bounce or are known to be spam traps.

For more precision, you can test your sender reputation and inbox placement with inbox placement testing, which simulates how your email lands in inboxes across providers like Gmail, Outlook, and Yahoo. This helps you assess deliverability before you send.

Ultimately, the difference between compliant and non-compliant isn’t just about source—it’s about process. The ICO isn’t interested in where your list came from. It’s focused on whether you had a lawful basis to send. So, if you scraped it, you need to verify it. And you need to know that your verification service checks for the real compliance risks—not just syntax.

How Does PECR Apply to B2B Email Lists Built from Public Sources?

You can use B2B email addresses found on public websites—like a company’s contact page—if the email is directly tied to business operations and you’re sending non-promotional messages. Sending marketing content, however, requires a clear legal basis such as prior business interaction or explicit consent. Even if the data is publicly available, PECR’s rules on unsolicited communications still apply. Always verify that your list meets current standards before sending.

Public Data Is Fair Game—But With Limits

PECR doesn’t prohibit using business emails found on a company’s official site—like sales@ or info@ listed on a homepage. If the email is clearly associated with business functions, it’s considered fair game for outreach. The key is that the message must be relevant to the role the email represents. This includes requests for partnerships, service inquiries, or support. You’re not breaking the law by reaching out with a functional, non-marketing purpose.

But let’s be clear: a “contact” email doesn’t automatically mean you can send promotional material. PECR’s core principle is that you can’t bombard someone with marketing unless you have a legal basis to do so. That means unless you've had prior contact or the recipient has given consent, even a valid email from a public source can’t be used for marketing.

If you’re sending promotional content—like product updates, discounts, or event invites—you must have either a prior business relationship or clear consent. If you’ve never communicated with the sender before, you can't rely on public availability alone. For example, using the same info@ address to invite someone to a sales webinar without prior contact crosses into violation territory.

That’s where email verification tools come in. They don’t just eliminate invalid addresses—they help you confirm if an email is still active, properly formatted, and not a catch-all. This protects you from unintended violations. A tool like bulk verification can help you clean your list before you send, reducing the chance of sending to inactive, risky, or non-compliant addresses.

You can’t safely send B2B emails to scraped contacts without verifying them first. Many scraped emails are outdated, invalid, or assigned to non-existent users. Sending to these addresses risks triggering spam traps, damaging your sender reputation, and violating UK data laws like the UK GDPR and PECR. Even one flagged email can lead to penalties from the ICO or blacklisting by major providers. Verification isn’t a nice-to-have—it's how you maintain compliance and avoid legal exposure.

Scraped data is rarely reliable

Most B2B leads pulled from public websites aren’t current. Staff leave, roles change, and domains get retired. Without verification, you’re sending to addresses that may never have been active, or that are now dormant or assigned to different roles. This is a common flaw in cold outreach: the data seems usable, but the actual user isn’t there. According to research by Return Path, over 30% of email addresses in a standard list are inactive or invalid. That’s not a risk you can ignore.

Invalid emails harm sender reputation

Spam filters track bounce rates and user engagement. Sending to invalid or non-existent addresses increases your bounce rate. High bounce rates signal poor data hygiene. If an ISP detects this, they may start filtering your emails into spam folders or block them entirely. Worse, some of these invalid addresses are legacy spam traps—carefully maintained to catch unsolicited senders. If you send to one, your domain can be marked as malicious. Tools like MxToolbox and Spamhaus maintain public blocklists that track known source domains.

The UK Information Commissioner’s Office (ICO) takes data quality seriously. Under PECR, you must have a lawful basis for sending marketing emails. Sending to unverified contacts puts you at risk of enforcement. The ICO has warned that sending to incorrect or outdated addresses violates the principle of “data minimisation” and undermines consent. A verified list reduces the chance of complaints, investigations, or enforcement action.

Let’s be clear: verification isn’t just about delivery. It’s about legality. Tools like bulk verification or the real-time API help you filter out dead, risky, or disposable emails before sending. You’re not just cleaning data — you’re protecting your brand, reputation, and compliance standing. If you’re relying on scraped contacts, verification isn’t a step — it’s your first line of defence.

How Email Verification Reduces Compliance Risk in 2026

Using email verification tools like Emaillistchecker.io reduces PECR compliance risk in 2026 by ensuring you only send to valid, active B2B contacts. It filters out invalid, catch-all, or risky emails that could trigger bounces, abuse reports, or complaints — all of which undermine a 'legitimate interest' defense. This step proves due diligence, a key requirement under UK privacy law.

Validating B2B Contacts to Avoid PECR Violations

When you scrape or collect B2B emails, you risk including outdated, incorrect, or non-existent addresses. Each bounce or complaint can be flagged by mailbox providers and forwarded to regulators. Tools like Emaillistchecker.io use real-time checks against SMTP, DNS, and domain reputation systems to separate valid from invalid emails — reducing your bounce rate before the first send.

For instance, an email that appears syntactically correct might still point to a catch-all server, where all messages are accepted — even if the person doesn't exist. These addresses can’t be traced back to a specific user and are often flagged as spam traps by providers. Emaillistchecker.io identifies these risks in advance, so you don’t accidentally send to them.

Demonstrating Due Diligence Under PECR

If you're ever challenged by the ICO or a customer over a marketing email, the burden shifts to you to show you took reasonable steps to ensure compliance. Sending to invalid or high-risk addresses weakens that position. By using a tool that validates each email before delivery, you’re showing a clear process — one that aligns with industry best practices.

Under PECR, you can rely on 'legitimate interest' only if you’ve minimized harm and acted responsibly. A verified list demonstrates that you didn’t blindly send to unconfirmed addresses — a key distinction in enforcement cases. The Information Commissioner’s Office has emphasized that technical measures to prevent abuse are part of that responsibility.

Tools like Emaillistchecker.io offer bulk verification via their bulk verification service, making it easy to clean and validate large lists at scale. You can also use their API for real-time validation during lead capture, ensuring every new contact is checked at point of entry. Integration with platforms like HubSpot or Klaviyo via native integrations keeps your data clean without extra work.

Ultimately, verification isn’t just about deliverability — it’s about reducing legal risk. In 2026, as enforcement intensifies, maintaining a clean, validated B2B list isn’t optional. It’s how you prove you’re acting responsibly under UK law.

The Role of Bounce Rates in PECR Compliance

High bounce rates are a red flag under PECR: they signal poor list hygiene and can suggest your B2B outreach is untargeted or careless. The Information Commissioner’s Office (ICO) views consistently high bounce rates as evidence of ineffective consent management. Keeping your bounce rate below 5% — a commonly recognized threshold in industry standards — helps demonstrate responsible data handling and reduces the risk of enforcement action.

Bounce Rates and the ICO’s Expectations

You don’t need to be perfect, but you do need to be disciplined. The ICO doesn’t specify a single threshold for what counts as "too high," but consistent rates above 5% are widely seen as concerning in email deliverability circles. This isn’t just about deliverability — it’s about proving you’re actively managing the data you’re using to contact people.

When your list includes invalid, outdated, or non-existent addresses, the natural result is hard bounces. These aren’t just technical failures; they’re signs of poor data quality. The ICO expects organizations to demonstrate that they don’t treat email lists as disposable. High bounce rates suggest you’re not doing the basic work of validating or cleaning data before sending.

Verification as a Compliance Tool

Let’s be clear: verification isn’t optional — it’s part of maintaining PECR compliance. By catching invalid emails, catch-alls, and disposable domains before sending, you proactively reduce bounce rates. A clean list isn’t just better for deliverability; it shows your team is taking data responsibility seriously.

Using real-time verification tools cuts bounce rates before they happen. For instance, running your list through bulk verification software like EmailListChecker’s bulk verification tool identifies and removes problematic addresses. This doesn’t eliminate all risk, but it makes a measurable difference in your compliance posture.

Even if your outreach is otherwise legitimate, consistent sending to non-existent addresses can trigger scrutiny. The ICO considers low bounce rates a proxy for ongoing data stewardship. By integrating verification at scale and using tools like our API for automated validation, you build a documented trail of diligence.

And if your list is sourced from scraping, verification becomes non-negotiable. No amount of permission claims outweigh the risk of sending to addresses you didn’t confirm are active. Tools like the email finder can help you build lists from known domains, reducing reliance on unverified sources.

A low bounce rate isn’t just a deliverability win — it’s evidence that your business treats personal data with care. That’s what the ICO looks for.

Use Case: Validating a B2B Contact List from a Public Directory

You can legally use scraped B2B emails from public directories under UK GDPR and PECR—provided you validate them first, confirm no opt-outs apply, and use only 'valid' addresses in a permission-based campaign. This process ensures compliance while minimizing bounce rates and protecting sender reputation. Skipping verification risks enforcement actions and damaged deliverability.

Step-by-Step Validation Process

  1. Extract emails from public sources like company websites, LinkedIn profiles, or industry directories. These sources are generally lawful under PECR for B2B outreach, but they often include invalid, outdated, or non-existent addresses. Always ensure the data isn’t obtained from private databases or through automated scraping of login-protected pages.
  2. Upload your list to Emaillistchecker.io and run a bulk verification. This checks for syntax errors, domain validity, MX record presence, and real inbox responsiveness. The tool also detects catch-all domains and disposable email addresses—common red flags in raw scraped data. You can upload up to 100 emails for free at bulk verification.
  3. Review the results and filter out non-qualified addresses. Remove anything flagged as ‘invalid’, ‘catch-all’, ‘disposable’, or ‘risky’. Catch-alls can accept any address, so sending to them harms deliverability. Disposable emails often signal low intent. Only proceed with ‘valid’ addresses—these are confirmed to exist and accept mail.
  4. Send only to valid addresses via a permission-based flow. Even if PECR allows non-consensual B2B emails, you must offer a clear opt-out. Use campaigns that include a working unsubscribe link and respect user preferences. This reduces the risk of spam complaints and ISP blocklists.
  5. Maintain logs of verification and usage for audit readiness. Keep records of what data you collected, when, from where, and how it was verified. This includes timestamped reports from Emaillistchecker.io and evidence of opt-out mechanisms. The Information Commissioner’s Office (ICO) may request these under Article 30 of GDPR. A solid audit trail helps prove due diligence.

Compliance and Deliverability Considerations

Even if you’re allowed to use public data under PECR, sending to invalid or risky addresses damages sender reputation. ISPs like Gmail, Outlook, and Apple monitor bounce rates, complaint ratios, and engagement. High bounce rates—especially from catch-alls or disposable domains—trigger spam filters.

Regular verification reduces these risks. Tools like Emaillistchecker.io use real-time SMTP checks and domain analysis, aligning with industry best practices for deliverability. For ongoing campaigns, integrate with tools like Mailchimp or HubSpot via our integrations to automate verification before sending.

Common Mistakes with B2B Scraped Lists Under PECR

You're not safe just because a contact is publicly listed. PECR requires clear, lawful grounds for sending marketing emails — and scraping a list from LinkedIn or a company site doesn’t grant consent. You must verify each address, filter out role accounts, and prove you have a valid legal basis. Skipping these steps risks enforcement action from the ICO and damaged sender reputation. Let’s break down the most common errors.

  • Assuming a public website or LinkedIn profile means someone agrees to receive your email is a fundamental error. PECR doesn’t treat public presence as implied consent — it’s not a green light to send marketing content.
  • Just because an email is listed doesn’t mean it’s active or receptive. Many B2B contacts are outdated, role-based (e.g. info@, sales@), or not personally responsible for email engagement.
  • Before sending, verify every address. Tools like bulk verification help flag invalid, catch-all, or risky emails before you waste sends.

Ignoring Contact Quality and Legality

  • Don’t send to every scraped email. Role accounts like info@, support@, or contact@ typically aren’t valid recipients for targeted outreach and often trigger spam filters.
  • Outdated or non-existent addresses don’t just bounce — they hurt your sender reputation. ISPs track bounce rates and will block you if you repeatedly send to dead mailboxes.
  • Always include a working, one-click unsubscribe link. Without it, your email violates both PECR and GDPR. You must honor opt-outs within 24 hours.
  • Never assume you can ‘justify’ a list by reference to industry norms or past use. PECR requires documented legal basis — usually, a legitimate interest assessment for B2B, or clear consent.
  • Keep records showing why each contact qualifies. If the ICO audits you, you’ll need proof you had a valid reason to contact them, not just a scraped list.
Under PECR, “consent” isn’t a single checkbox — it’s a continuous obligation to justify every message sent, even to B2B prospects.

PECR vs GDPR: How They Apply to B2B Scraped Contacts

You can’t legally send B2B marketing emails to scraped contacts under UK law, even if you have a valid business interest. PECR governs exactly how you can contact someone via email, phone, or other electronic means, and it overrides GDPR for direct marketing use. GDPR sets the broader rules for lawful data processing, but PECR adds strict requirements on consent and opt-out mechanisms for electronic marketing — especially when you’re using data you didn’t collect directly.

PECR’s Role in Marketing Contacts

PECR requires that any electronic marketing to a UK-based business must follow specific rules: you need either prior consent or a valid, documented legitimate interest — and even then, you must provide a clear, easy way for recipients to opt out. If you've scraped a list, you’ve already failed the consent requirement, and proving legitimate interest is extremely difficult. You can’t assume that B2B contacts have an implied interest in your product just because they work for a company in your industry.

GDPR’s Broader Foundation

GDPR doesn’t ban the use of scraped data outright — it mandates that processing must have a lawful basis, such as consent or legitimate interest, and that you must be able to prove it. However, for scraped data, consent is impossible to obtain, and demonstrating legitimate interest requires showing a direct, reasonable connection between your communication and the recipient’s potential interest. Courts and the ICO have ruled that mass scraping and marketing to unknown recipients rarely meet this threshold.

For example, even if your list is sourced from a company website, you still need to verify each email is active and that the recipient has not opted out. Using an invalid list increases your risk of being flagged by ISPs like Gmail or Hotmail — and could land you on blocklists. Citizen Advice notes that businesses face enforcement action if they send unsolicited marketing, especially when using third-party data.

Let’s be clear: if you’re using a scraped list, you’re likely violating PECR. No amount of GDPR compliance fixes that. You need to verify each email, confirm opt-out status, and ensure your sender reputation isn’t compromised. That’s where tools like bulk verification come in — they check for validity, catch-all domains, and disposable addresses, reducing the risk of sending to non-existent or invalid inboxes.

Even better: use tools like email finder to locate accurate, verifiable contacts through official channels — not scrapers. And always test deliverability with inbox placement checks before sending. You’re not just improving deliverability; you’re staying compliant.

Don’t assume that just because you’re targeting businesses, you can ignore the rules. The ICO has fined companies for B2B campaigns based on scraped data, even when the target was a company. PECR applies with equal force to B2B — no exceptions.

How Emaillistchecker.io Supports PECR-Compliant B2B Outreach

PECR requires that B2B email outreach be based on lawful bases, including a pre-existing relationship or explicit consent. Scraping contacts without confirmation violates this. Emaillistchecker.io helps organizations meet these requirements by validating lists before outreach.

Bulk verification removes invalid, disposable, and catch-all emails—common in scraped data—reducing the risk of sending to non-existent or non-responsive addresses. The real-time API ensures new leads are validated at capture, preventing non-compliant data entry. The email finder provides accurate, up-to-date contact details without scraping, supporting lawful acquisition from public sources.

Verified lists deliver better inbox placement and lower bounce rates, which helps maintain sender reputation and defend against compliance challenges. The in-app AI assistant interprets verification results, flags potentially risky entries, and supports informed decisions during manual review.

Sources

Keep reading

Ready to put this into practice? Emaillistchecker.io verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Can I use scraped B2B emails for cold outreach in the UK?

Yes, but only if you have a legitimate basis like a previous business relationship, and only after verifying the emails for accuracy and compliance.

Does PECR allow scraping company emails for marketing?

Scraping public data is not illegal, but using it for marketing requires a legal basis such as legitimate interest or consent.

What happens if I send to an invalid email under PECR?

Invalid emails increase bounce rates, which may trigger spam filter flags and lead to penalties from the ICO.

How can I prove I’m compliant with PECR?

Maintain a clean, verified list, record your legal basis, include unsubscribe links, and avoid scraping without verification.

Is a catch-all email address compliant to send to?

No — catch-all addresses accept all emails and are often used by spam bots. Sending to them increases reputation risk.

Does Emaillistchecker.io support bulk B2B list verification?

Yes — it handles large B2B lists with 98.9% accuracy, filtering out invalid, disposable, and risky addresses.

Can a high bounce rate violate PECR?

Yes — high bounce rates signal poor list hygiene and may indicate unsolicited or untargeted outreach, raising compliance concerns.

Not always — but you must have a valid legal basis like legitimate interest or prior engagement, not just a scraped email.

Is using an email finder compliant with PECR?

Yes — email finders like Emaillistchecker.io source contact data ethically and verify it, reducing compliance risk.

What should I do with role accounts like info@ or sales@?

Avoid sending direct marketing to role accounts. They are often catch-alls or shared inboxes, not individuals.

How often should I clean my B2B list?

At least quarterly, or after major campaigns — regular cleaning prevents high bounce rates and maintains PECR compliance.

Do I need to remove contacts from my list if they unsubscribe?

Yes — PECR requires immediate removal upon opt-out. Failing to do so is a direct violation.