Browse templates

Email hygiene is not a cleanup you run after a bad campaign: it is a routine with a fixed schedule.

Last checked Oct 1, 202624 min readProvider rules cited below

Definition

Email hygiene is the standing practice of keeping a sending list free of addresses that should not receive mail: dead ones, mistyped ones, shared mailboxes, and addresses belonging to people who stopped engaging.

It is not a cleanup you run after a bad campaign. It is three habits that run on their own clock: a check at the point of capture, a suppression step after every send, and a review of the rest of the email list on a fixed schedule.

The reason it matters is that mailbox providers grade you on the result. Google, Yahoo and Microsoft each publish sender guidance, and all three ask for the same two things in different words: send only to people who asked for your emails, and remove the addresses that fail.

This entry covers the whole routine at overview depth. Bounce codes, catch-all domains and the way contact records go stale each have their own entry, linked where they come up, so this page stays on what to remove, when, and why.

Email hygiene, list hygiene, and the words around them

List hygiene is the name used inside many marketing teams. Email hygiene is the name used in deliverability. They describe the same work, and the difference only matters when a vendor uses one word to sell a narrower service than you think you are buying.

TermHow this page uses itWhat it does not cover
Email hygieneThe whole practice: capture checks, suppression, scheduled reviewNothing, when used properly
List hygieneThe same practice, named from the list sideNothing, when used properly
List cleaningOne pass over an existing list to remove bad recordsThe rules that stop bad records arriving
List scrubbingOften the same as cleaning, sometimes just removing unengaged subscribersBounce and complaint handling
VerificationA technical check that an address can receive mailWhether the person wants your mail
SuppressionThe standing record of who must never be mailedRecords that are simply stale
Sunset policyThe written rule for retiring an unengaged contactInvalid or bouncing addresses

The definitions in this table are this page's working vocabulary, not an industry standard. Treat the first two as interchangeable and the rest as parts of them. A vendor selling verification is selling one of seven jobs on this page, which is worth knowing before you conclude your hygiene problem is solved.

What Google, Yahoo and Microsoft actually ask for

This is the least speculative part of email marketing, because the companies deciding where your emails land wrote their rules down. The table below is drawn only from the sender guidance each one publishes, read on Oct 1, 2026.

TopicGoogle (Gmail)YahooMicrosoft (Outlook.com)
Mail coveredMail sent to personal Gmail accounts, not Google Workspace accountsMail to Yahoo domainsOutlook.com consumer addresses: hotmail.com, live.com, outlook.com
Bulk thresholdMore than 5,000 messages a day, counted across the same primary domainNo volume threshold specifiedDomains sending more than 5,000 emails a day
Spam complaintsBelow 0.3% for all senders; advised below 0.10% and never 0.30% or higherKeep your spam rate below 0.3%Names spam complaints as a reason to remove invalid addresses
BouncesAutomatically unsubscribe recipients who have multiple bounced messagesMonitor hard and soft bounces, remove invalid recipients promptlyRemove invalid addresses regularly
Unengaged peopleConsider unsubscribing recipients who do not open or read your messagesMonitor inactive recipients, consider a periodic reconfirmation emailRemove inactive or invalid addresses monthly or quarterly
Confirming sign-upsConfirm each recipient's address before subscribing themUse double or confirmed opt-in; no pre-checked opt-in boxesEnsure recipients have consented to receive your messages
Bought addressesDo not purchase email addresses from other companiesDo not purchase mailing listsNot addressed directly
UnsubscribeOne-click for bulk marketing mail; its FAQ lists requests not honored within 48 hours as a failureOne-click for bulk senders, requests honored within 2 daysFunctional, clearly visible unsubscribe links

Google's FAQ adds that a sender who crosses the bulk line once is classified as a bulk sender permanently. Yahoo's FAQ says only that a bulk sender sends a significant volume of mail, and that it will not specify a threshold, so do not plan around a number for Yahoo.

Microsoft is the plainest of the three. Its announcement for high-volume senders carries a section headed Additional Email Hygiene Recommendations, and the bullet inside it says to remove invalid addresses regularly to reduce spam complaints, bounces, and wasted messages.

Read the complaint thresholds as instructions about your list rather than about your sending setup. A spam rate is the share of recipients who decided your mail was unwanted, and Google notes that recipients who want your messages are less likely to report them as spam.

Cleaning, deliverability and sender reputation

Email hygiene is one input to email deliverability, not the whole of it. Cleaning an email list removes the failures that damage sender reputation, and it cannot rescue emails that people never wanted or a sending domain that is not authenticated.

  • What cleaning fixes: bounces, complaints from subscribers who forgot they signed up, and the wasted volume that distorts every rate you report.
  • What it does not fix: missing SPF, DKIM or DMARC records, a blocked sending IP, or email content the recipient did not ask for.
  • What it supports: a reputation built on emails people want. Yahoo says sending to users who are not reading your mail, or who report it as spam, will harm your delivery metrics and reputation.
  • How fast it works: Google notes that it can take time for improvements in spam rate to reflect positively on spam classification, so give a cleanup several sends before judging it.

Order matters when something goes wrong. Authenticate first, then clean the list, then look at content and sending frequency. The next section explains why the first step has nothing to do with the list itself.

Authentication and DMARC: what hygiene cannot fix

A clean list does not pass authentication for you. Yahoo requires SPF or DKIM from all senders, and SPF, DKIM and a DMARC policy of at least p=none from bulk senders. Microsoft's announcement asks the same of domains sending more than 5,000 emails a day to Outlook.com.

Both providers state what happens when you fall short. Yahoo's FAQ says mail that does not meet its requirements may be sent to the spam folder or rejected. Microsoft's updated announcement says high-volume mail that fails its authentication requirements is rejected with a 550 5.7.515 response.

DMARC under RFC 9989

DMARC is now defined by RFC 9989, published in May 2026, which obsoletes RFC 7489. A DMARC pass needs an SPF or DKIM pass, and the domain behind that pass must be aligned with the From: domain, in relaxed or strict mode.

  • The pct tag is retired. RFC 9989 removes the old sampling percentage and introduces a t tag for testing: with t=y, a receiver applies a policy one level below the published one.
  • Monitoring mode has a name. The RFC calls p=none with aggregate reports turned on monitoring mode, which is the minimum Yahoo and Microsoft accept from bulk senders.
  • A pass is not a verdict. RFC 9989 warns that a DMARC pass by itself does not guarantee that delivery to the inbox would be safe or desirable.

That last point is where hygiene comes back in. Authentication tells a receiver the mail really came from you. Whether it reaches the inbox still depends on how recipients react to it, and that depends on who is on the list.

When to run an email hygiene check

The routine on this page runs on a calendar, but some events call for an extra pass outside it. Each of these is a moment when bad records either arrive in bulk or start showing up in your numbers.

TriggerWhy it calls for a checkWhat to run
Switching sending platform or CRMOld records get a second life on a new system, sometimes without the old suppression listMerge suppression, then full verification
A large import or event listRecords arrive in bulk from a source you have not testedVerification and role checks before the first send
A jump in hard bouncesInvalid addresses are reaching audiences from somewhereBounce rate by source, then fix the source
A jump in spam complaintsPeople who did not expect your mail are receiving itReview consent, frequency and the newest sources
Form sign-ups that look automatedUnprotected forms collect fake or malicious entriesConfirmed opt-in and form validation
Falling clicks and repliesThe engaged share of the list is shrinkingSunset review and re-permission
Reviving a file nobody has mailedOld records collect dead addresses and trap candidatesVerification, then a small staged send

The table is this page's checklist, not a provider rule. The common thread is that each trigger points at a source. Fix the source as well as the records, or the same check comes due again next quarter.

Clean at capture: confirmed opt-in, forms and expectations

The cheapest record to clean is the one that never enters the database. Every provider rule above about confirming sign-ups is really a rule about email list building, which is where, in this page's view, many hygiene problems start.

  • Confirm the address. Google says to confirm each recipient's address before subscribing them. Yahoo says to send a message asking people to click to confirm their opt-in.
  • Keep robots out. Yahoo says confirmed opt-in keeps a list free of uninterested people, fake email addresses and most robots, and protects people who might be signed up maliciously.
  • No pre-checked boxes. Yahoo tells senders not to subscribe users through an opt-in checkbox that is automatically checked.
  • Catch typos. Spamhaus describes typo domain traps at lookalike domains and calls confirmed opt-in at collection a perfect way to avoid them.

Set expectations and honor the list's intent

Yahoo asks senders to tell new subscribers what mail to expect, how often it will arrive and what it will look like. It also says to honor the frequency of the list's intent: do not start sending daily emails to people who signed up for a weekly or monthly one.

Google suggests letting recipients review the individual mailing lists they are subscribed to and unsubscribe from each one or from all of them. A preference page like that turns some would-be complaints into a smaller subscription, which is the cheapest hygiene there is.

What to remove from a B2B list, and when

Many hygiene arguments are really scheduling arguments. The table below separates the two questions: what qualifies a record for removal, and how quickly the removal has to happen. The timings are this page's recommendations except where a deadline is named.

RecordHow you knowActionWhen
Hard bounceThe receiving server says the address does not existSuppress permanentlyFirst occurrence
Repeated soft bounceTemporary failures across several consecutive sendsSuppressAfter the number of sends your rule names
UnsubscribeOne-click header or the link in the bodySuppress permanentlyImmediately, and inside the deadlines below
Spam complaintA feedback loop reportSuppress permanentlyOn receipt
Role addressThe local part is info, sales, admin, postmasterExclude from marketing audiencesAt import
Invalid syntax or dead domainVerification at the formReject before the record existsAt capture
Disposable domainVerification flagReject, or keep out of nurtureAt capture
DuplicateSame address after normalizing case and spacingMerge into one recordAt import and at the scheduled review
Unengaged contactNo click or reply across your defined windowRe-permission, then suppressAt the sunset review
Never-mailed importLoaded months ago and never sent toVerify before it enters any audienceBefore the first send
Person left the companyAn auto-reply, a bounce, or enrichmentRetire the address, keep the company recordOn the signal

Three deadlines are not yours to choose. Yahoo asks bulk senders to honor unsubscribes within 2 days, and Google's FAQ lists requests not honored within 48 hours as a failure. The FTC says CAN-SPAM opt-outs must be honored within 10 business days, with the mechanism working for at least 30 days after sending.

The provider windows are much shorter than the legal one, so build your process around the shortest. An unsubscribe that waits for a weekly batch job can be legal under CAN-SPAM and still break Google's and Yahoo's rules.

Bounce handling, the part that is not optional

Bounces are the clearest hygiene signal you get, because the receiving server is telling you in writing that the address failed. The mistake is treating every failure the same way. The email bounces entry covers the reply codes in detail.

Hard bounces, soft bounces and blocks

  • Hard bounce: a permanent failure. RFC 5321 says a server returns a 550 reply when a recipient is known not to be a deliverable address. Suppress on the first occurrence and store the response you received.
  • Soft bounce: a temporary failure such as a full mailbox or a server asking you to try later. Retry, and suppress only after a defined run of failures.
  • Block: the reply names a policy or reputation reason rather than an unknown mailbox. Treat it as a sending problem; removing that one address will not fix it.
  • Auto-reply: not a bounce, but sometimes the best signal you will get. A message saying someone has left the company retires that address.

Google lists automatically unsubscribing recipients who have multiple bounced messages among the unsubscribe options a sender can offer. Yahoo asks senders to monitor hard and soft bounces as well as inactive recipients, and to remove invalid recipients from the list promptly.

Google also says that if messages start bouncing or being deferred, you should reduce sending volume until the error rate falls, then increase slowly again. A bounce spike is a reason to slow down while you find the source, not to push the rest of the send through.

Write the soft bounce rule down before you need it. A number chosen in a calm week, applied automatically, beats a judgment call made the morning after a campaign went badly.

Role addresses and shared mailboxes

A role address belongs to a function rather than a person: info, sales, support, admin, billing, careers, postmaster, abuse, no-reply. RFC 2142 lists names such as info, marketing, sales and support as standard business mailboxes. Where a domain supports them they accept mail, so verification calls them valid.

  • Nobody consented. A shared mailbox cannot opt in, and whoever reads it today did not choose your newsletter.
  • Complaints are likely. In this page's view, a person reading a shared inbox has little reason to keep mail they never asked for, and the spam button is the fastest way to clear it.
  • Some are trap-adjacent. Spamhaus describes registration and role addresses published in whois records as a special type of live trap, and says they should almost never be on a marketing mailing list.
  • B2B files collect them. Some smaller companies publish an info address as their only contact, so scraped and enriched files can fill up with them.

Keep the distinction between marketing and prospecting clear. Writing one researched message to an info address at a small company is a cold email decision. Adding that address to a nurture audience is a hygiene failure that can show up later as a complaint.

Spam traps, and why hunting them is the wrong move

A spam trap is an address used to expose senders who add people to lists without permission. Spamhaus says trap owners never reveal them, and it urges senders to view traps as proof of a data collection or hygiene issue rather than hunting for them.

Type (Spamhaus)What it isWhat hitting it says about you
Classic or pristineAn address never given to a user or published, sometimes at a domain that accepts any addressYou acquired addresses you were never given
SeededAn address deliberately scattered online, for example in page sourceYou are scraping, or buying from someone who scrapes
Typo domainAn address at a lookalike of a common domainYou accept form entries without confirming them
Dead addressA once-valid mailbox switched off, then silently reopened as a trapYou ignored hard bounces for a long time
Dead domainAn expired domain bought by a trap ownerYour list has records nobody has checked in years
LiveA real person's mailbox, used to judge unsolicited mailYou mailed someone who never asked
Registration and roleAddresses published in whois records, such as postmaster and abuseYou harvested contact pages or whois data

The right-hand column is this page's reading of Spamhaus's descriptions. Notice that every row points back at a habit, not at a record, which is why Spamhaus says hunting traps only treats the symptom.

Dead address traps are the ones a cleaning routine removes by itself. Spamhaus says these addresses reject mail with a hard bounce for a period, often 12 months or more, before being turned back on. A sender who suppresses hard bounces on sight never reaches that second stage.

Unengaged contacts, and how to define inactive

Dead addresses are easy. The harder half of email hygiene is the contact whose mailbox works perfectly and who has ignored you for a year. Those records add complaint risk and flatter the reporting on every email blast you send.

Google suggests considering unsubscribing recipients who do not open or read your messages. Yahoo asks senders to monitor inactive recipients and to consider sending a reconfirmation email to them periodically. Neither names an inactivity window, and in this page's view the right window depends on how often you send.

Do not define inactive on opens

Google states that it does not track open rates, that it cannot verify open rates reported by third parties, and that low open rates are not necessarily an accurate indicator of deliverability. Apple says Mail Privacy Protection prevents senders from seeing whether a message was opened.

Write the rule on clicks and replies, and count it in sends rather than months, so it survives a change of cadence. A monthly sender and a weekly sender both counting twelve campaigns without a click are applying the same standard to very different calendars.

  • Count clicks and replies. Both are actions the recipient chose to take, and neither is inferred from a tracking pixel.
  • Count purchases and meetings. A customer who never clicks a newsletter is not unengaged in any sense that matters.
  • Exclude recent arrivals. Someone who signed up last week has had no chance to click anything.
  • Segment before you cut. Check whether one source or one form supplies most of the unengaged subscribers.
  • Send less before you send nothing. Moving a fading segment to a lower frequency is a step between full engagement and suppression.

Re-permission before removal

Suppressing an unengaged contact without asking wastes a record that might still be worth something. One direct message separates the people who forgot about you from the people who are gone. Yahoo suggests reconfirmation emails, and Google suggests periodically confirming that recipients want to stay subscribed.

Keep it plain, make staying and leaving equally easy, and do not run it as a discount campaign. Give it a deadline and honor it: if the rule says non-responders are suppressed after the third message, suppress them, or the exercise only postpones the decision.

Verification: what it checks and when to run it

Verification is the technical half of hygiene. It tells you whether an address can receive mail, which is a different question from whether the person wants your emails. Both questions have to be answered, and only one of them has a tool.

CheckWhat it catchesBest moment to run it
SyntaxMalformed addresses and stray charactersIn the form, as the person types
Domain and MX recordsDomains that cannot receive mail at allOn form submission
Mailbox acceptanceAddresses the server rejects as unknownOn submission, and before a first send
Disposable domainsThrowaway addresses used to grab a downloadOn submission
Role detectionShared mailboxes such as info and supportAt import
Catch-all detectionDomains that accept everything, so nothing is provenAt import, flagged as unknown

What a mailbox check can and cannot prove

Mailbox checks lean on how SMTP servers answer, and RFC 5321 limits what those answers mean. Sites may disable the VRFY command for security reasons, and when they do, the server must return a 252 reply rather than anything that looks like success or failure.

  • 252 is not a yes. RFC 5321 uses 252 for an address that cannot be verified in real time, where the server will still accept the message and attempt delivery.
  • Acceptance is not delivery. A server that accepts a message takes on responsibility for delivering it or reporting failure, so a later bounce can still arrive after a clean check.
  • Some domains accept everything. On a catch-all email domain, every address looks deliverable at the RCPT stage, so the result is unknown.

Treat catch-all and unknown results as unproven rather than clean. In this page's view, sending to a large block of them at once is the fastest way to turn a quiet list into a bounce spike, so stage them into small sends and watch what comes back.

Three moments deserve a verification pass: at capture, before the first send to any list you did not collect yourself, and before a migration between sending platforms. Skipping the last one is how old records get a second life on a new sending domain.

Verification is not consent

A verified address is one that exists. It says nothing about whether the person agreed to hear from you, and it does not turn a purchased file into a mailable list. Google tells senders not to purchase email addresses from other companies, and Yahoo says not to purchase mailing lists.

Suppression, the list that outranks every tool

Suppression is the output of hygiene: the set of addresses that must never receive marketing mail, checked against every audience before every send. Unsubscribes, complaints, hard bounces, competitor domains and sales do-not-contact requests all belong on it.

The structural rule is that suppression has to sit above your sending tools rather than inside one of them. If unsubscribes live only in the current platform, the first campaign sent from a new one mails every person who already said no. The email marketing database entry covers how that record is stored.

The FTC adds a rule worth repeating: once people have told you they do not want more messages, you cannot sell or transfer their email addresses, even as a mailing list. The only exception is a company you have hired to help you comply with CAN-SPAM.

Delete or suppress the record

SituationDo thisReason
Unsubscribe or complaintSuppress, keep the recordDeleting it means a re-import can mail them again
Hard bounceSuppress the address, keep the person and companyThe person may reappear at a new address
Unengaged after re-permissionSuppress, keep the historyYou may want the account context later
Invalid at captureNever create the recordNothing of value is lost
Erasure requestFollow the request and your legal advice on what may be keptThe request is about the person, not the mailbox

The default on this page is suppress, not delete. A deleted record has no memory, so the same address can walk back in through the next import and undo a decision someone already made about you. Nothing in this table is legal advice.

A cleaning schedule for a B2B list

A schedule beats good intentions, because hygiene competes with campaign work and tends to lose when it is optional. The flow below is the shape this page recommends for a B2B program; adjust the cadence to how often you send.

At captureverify and normalize
After each sendbounces and complaints
Monthlyduplicates and role checks
Quarterlysunset review
Before a migrationfull re-verification
Form ownerAutomationOpsMarketingOps
CadenceWhat happensWhy it sits here
At captureSyntax, domain, MX, disposable and role checks, plus normalizationThe cheapest place to stop a bad record is before it exists
After every sendHard bounces suppressed, complaints suppressed, soft bounce counters updatedThe signals arrive with the send, so the handling belongs there
MonthlyDuplicate merge, role address sweep, review of bounce rate by sourceSource-level problems only show up when you group by source
QuarterlySunset review, re-permission campaign, suppression of non-respondersEngagement needs several sends before it means anything
Before any migrationFull re-verification of the list you are movingA new sending setup should start on proven records, which is what email warm up assumes
Before reactivating an old fileVerification, then a small staged sendOld records accumulate dead addresses and trap candidates

The monthly and quarterly rows match the only cadence a provider has published: Microsoft's FAQ for high-volume senders tells them to aim to remove inactive or invalid addresses regularly, monthly or quarterly. Google and Yahoo say periodically and promptly without naming an interval.

No benchmarks here

Vendors publish list decay percentages and average bounce rates measured on their own customers. None of the provider pages cited here sets a bounce rate threshold, so those figures are not targets for your list. Compare your bounce rate per source against your own last quarter instead.

The repeatable cleaning routine

Run the steps in this order. Each one narrows the list, so doing them out of sequence means paying to verify records you were about to suppress anyway.

  1. Freeze and back up

    Export the current list before you change anything. A hygiene pass is destructive by design, and you want a copy of what existed before it ran.

  2. Apply suppression first

    Remove everyone already on the suppression list: unsubscribes, complaints, prior hard bounces, do-not-contact accounts. This costs nothing and shrinks everything that follows.

  3. Normalize and deduplicate

    Trim whitespace, compare addresses without regard to case, fix obvious typos in common domains, then merge duplicate records so a person cannot receive the same campaign twice.

  4. Strip role addresses

    Flag shared mailboxes and move them out of marketing audiences. Keep them on the company record if sales uses them, marked as not mailable by marketing.

  5. Verify what is left

    Run verification on the remaining addresses. Delete invalid ones, keep unknown catch-all results in a separate group, and note which sources produced the failures.

  6. Split by engagement

    Separate active contacts, recent arrivals who have had no chance to engage, and the unengaged group that your written rule defines. Only the third group needs a decision.

  7. Re-permission, then retire

    Send one direct message to the unengaged group asking whether to continue. Suppress the people who do not respond rather than deleting their history.

  8. Record what you found

    Write down the failure rate by source and by form. That number is the only way the next quarter's capture rules get better instead of repeating the same cleanup.

A note on step three. RFC 5321 says the local part of an address, before the @, must be treated as case sensitive in transport, though it discourages relying on that; domains are not case sensitive. Match duplicates without regard to case, but keep the address as the person typed it.

Why B2B addresses stop working

A work address is issued by an employer, and the employer decides what happens to it when the person leaves. That single fact drives much of what is different about B2B hygiene, and the data decay entry covers how the wider contact record goes stale.

  • Job changes retire addresses. When a contact leaves, the mailbox may be closed, forwarded or left running, and your record can become a hard bounce waiting to happen.
  • Companies change domains. Rebrands, acquisitions and consolidations can retire whole domains at once, taking every contact at that company with them.
  • Catch-all servers hide the damage. Verification returns unknown, so a dead address at an accepting domain looks fine until you send to it.
  • Role addresses arrive in bulk. Enriched and scraped B2B data can be full of info and sales mailboxes that no person signed up with.
  • Free domains can signal a weak record. A personal address on a free email domain in a B2B list can mean the form was filled in to get a download.

This page's view is that a B2B list deserves re-verification on a fixed cadence even when nothing looks wrong, and that company-level records should outlive contact-level ones. When a person leaves, you lose an address, not an account.

Tool categories that do the work

No rankings and no prices here, because the category you need depends on where your records come from. These are the kinds of tools a hygiene routine uses, and what each one can and cannot tell you.

VerificationIs this address real

Syntax, domain, MX and mailbox checks, plus role, disposable and catch-all flags. Runs at capture through an API, or in bulk on an existing file, within the SMTP limits described above.

Sending platformWhat happened to the send

Bounce classification, complaint feedback, unsubscribe handling and per-campaign engagement. The source of many of your hygiene signals.

Postmaster and reputationHow providers see you

Spam rate, domain and IP reputation, authentication results. Google points senders to Postmaster Tools for spam rate; Yahoo offers a Complaint Feedback Loop.

CRM and enrichmentIs this person still there

Job change signals, company status and refreshed contact fields, covered in lead enrichment. Useful for repairing records rather than deleting them.

One warning about verification services specifically. Uploading your contact list to a third party is a data processing decision, not just a purchasing one, so check what the provider retains and where before the file leaves your system.

Measuring whether email hygiene worked

The point of a cleaning routine is not a smaller list. It is a list where the numbers below move in the right direction and stay there through the next few campaigns.

Hard bounce rate per sendWhether invalid addresses are still entering audiences
Bounce rate by sourceWhich form, import or vendor supplies the bad records
Spam complaint rateThe number providers grade you on, watched in postmaster tools
Unsubscribe rateWhether the mail matches what people signed up for
Click and reply rateWhether the remaining audience is genuinely engaged
Share of records unmailed this quarterHow much of the list is dead weight in reporting
Verification failure rate at captureWhether the front door is doing its job
CompareEach number against your own previous quarter, per source

Bounce rate by source is the one people skip and the one that pays. An overall rate tells you there is a problem, while the same rate split by intake route tells you which form or import to fix.

What a clean email list does to your numbers

Cleaning an email list makes it smaller, and every engagement rate you report is a fraction with the list size underneath it. Removing unengaged subscribers raises click rate and reply rate without a single word of the email changing.

  • Click rate rises at once. The denominator lost the subscribers who were not clicking, so the same clicks are divided among fewer contacts.
  • Bounce rate falls at once. The invalid email addresses that produced the bounces are no longer in the audience.
  • Complaint rate should fall over time. Google says people who want your messages are less likely to report them as spam, so a list of people who want them should complain less.
  • List growth looks worse. Net growth hides the records you removed, so report additions and removals as separate numbers.
  • Revenue per send should hold. If it drops, you removed customers who were buying without clicking, and the inactivity rule needs work.

Write down what each cleaning pass removed and why. Comparing engagement across quarters is meaningless when nobody remembers that a large block of unengaged subscribers left the email list in between.

Common email hygiene mistakes

  • Cleaning after a bad campaign instead of on a schedule, so the routine only ever runs under pressure.
  • Defining inactive on opens, which Google says it does not track and Apple's Mail Privacy Protection hides.
  • Verifying a purchased file and concluding it is now mailable. Valid is not the same as permitted.
  • Leaving suppression inside one sending platform, so a migration mails everyone who unsubscribed.
  • Deleting unsubscribes to tidy the database, which lets the next import bring them straight back.
  • Processing unsubscribes on the 10 business day legal clock when Google and Yahoo expect 48 hours or 2 days.
  • Treating catch-all unknown results as valid and sending to a large block of them at once.
  • Reading a 252 reply or an accepted RCPT as proof that a mailbox exists.
  • Hunting for spam traps rather than fixing the collection habit that put them on the list.
  • Mailing role addresses because verification said they accept mail.
  • Expecting a clean list to fix missing SPF, DKIM or DMARC, or a DMARC pass to guarantee the inbox.
  • Running one giant cleanup before a migration and never touching the capture rules that caused it.

In a sequence

Hygiene produces one message worth writing by hand. When a contact at a target account hard bounces, the account is still real and someone else there does the job. This example was written for this page.

Address check after a hard bounce at a target account
Subject: Wrong address for {{formerContactName}}?

Hi {{firstName}},

My email to {{formerContactName}} came back as undeliverable, so I am guessing {{pronoun}} has moved on from {{companyName}}.

Two quick questions, and no reply is a fine answer to both:

Who owns {{topic}} there now?
Should I take that address off our list entirely?

Either way I will stop sending to the old one today.

{{senderName}}
{{companyName}}, {{postalAddress}}
Backfires when

You send it to a role mailbox, or to someone who never agreed to hear from you in the first place.

Then a housekeeping note reads as an excuse to start a conversation, and the shared mailbox marks it as spam.

Send it only to a named person who already has a relationship with your company.

Frequently asked questions

What is email hygiene?

Email hygiene is the standing practice of keeping a sending list free of addresses that should not receive mail. It covers verification at the point of capture, suppression of bounces and complaints after every send, and a scheduled review of unengaged contacts.

What is the difference between email hygiene and list hygiene?

There is none in practice. List hygiene is the name used inside many marketing teams and email hygiene is the name used in deliverability. Both cover capture checks, bounce and complaint suppression, and the scheduled review of everything else.

What should I remove from my email list?

Hard bounces on the first occurrence, repeated soft bounces, unsubscribes, spam complaints, role addresses, invalid and disposable addresses, duplicates, and contacts who have not clicked or replied across the window your written rule defines.

How often should I clean my email list?

Verify at capture and suppress bounces and complaints after every send. Microsoft advises high-volume senders to remove inactive or invalid addresses monthly or quarterly. This page suggests a monthly duplicate and source review, a quarterly sunset review, and full re-verification before any migration.

What is the difference between a hard bounce and a soft bounce?

A hard bounce is permanent: RFC 5321 says a server returns 550 when a recipient is known not to be deliverable, so suppress it on the first occurrence. A soft bounce is temporary, such as a full mailbox, so retry and suppress only after a defined run of failures.

What are role addresses and should I email them?

Role addresses belong to a function rather than a person: info, sales, support, admin, postmaster. Keep them out of marketing audiences. Spamhaus describes registration and role addresses as a type of live trap that should almost never be on a marketing list.

What is a spam trap?

An address used to expose senders who add people to lists without permission. Spamhaus lists classic, seeded, typo domain, dead address, dead domain, live and registration traps. Owners never reveal them, so you avoid them by fixing collection and removing dead records.

How do I avoid spam traps?

By fixing collection rather than hunting addresses. Spamhaus urges senders to treat traps as proof of a data or hygiene problem. Confirm sign-ups, validate at the form, suppress hard bounces immediately, and never mail a purchased or scraped file.

How do I define an unengaged contact?

On clicks and replies, counted in sends rather than months, and excluding people who signed up too recently to have acted. Google says it does not track open rates, and Apple says Mail Privacy Protection stops senders from seeing whether a message was opened.

Does email verification make a purchased list safe to send?

No. Verification proves an address exists, not that the person agreed to hear from you. Google tells senders not to purchase email addresses from other companies, and Yahoo says not to purchase mailing lists or use pre-checked opt-in boxes.

Can email verification prove a mailbox exists?

Not always. Under RFC 5321 a server may disable VRFY and answer 252, which means it will accept and try to deliver without confirming the address. Catch-all domains accept every address, and a message accepted at first can still bounce later.

What is a suppression list?

The set of addresses that must never receive marketing mail, checked against every audience before every send. It holds unsubscribes, complaints, hard bounces, competitor domains and do-not-contact requests, and it has to sit above your sending tools rather than inside one.

How fast do I have to process an unsubscribe?

Yahoo asks bulk senders to honor unsubscribes within 2 days, and Google's FAQ lists requests not honored within 48 hours as a failure. The FTC says CAN-SPAM opt-outs must be honored within 10 business days, and the mechanism must work for at least 30 days after sending.

Does poor email hygiene hurt deliverability?

Yes. Google requires a spam rate below 0.3% and advises staying below 0.10%, and Yahoo requires below 0.3%. Yahoo says mailing people who are not reading, or who report you as spam, harms delivery metrics and reputation.

Sources and reading
  1. Google, Gmail Help, Email sender guidelines, for the personal Gmail scope, the more than 5,000 messages a day bulk requirements, the 0.3% limit for all senders and the advice to stay below 0.10% and never reach 0.30%, one-click unsubscribe, confirming and periodically reconfirming subscribers, unsubscribing after multiple bounces, reducing volume when messages bounce, the rule against purchased addresses and open rates, checked Oct 1, 2026.
  2. Google Workspace Admin Help, Email sender guidelines FAQ, for the rule that the guidelines apply only to mail sent to personal Gmail accounts, counting by primary domain, permanent bulk sender status, the DMARC p=none minimum and unsubscribe requests not honored within 48 hours, checked Oct 1, 2026.
  3. Yahoo Sender Hub, Sender Requirements and Recommendations, for authentication for all and bulk senders, the 0.3% spam rate, one-click unsubscribe and the 2 day deadline, confirmed opt-in, setting expectations, the frequency of the list's intent, pre-checked boxes, purchased lists, bounces, inactive recipients, reconfirmation email and the Complaint Feedback Loop, checked Oct 1, 2026.
  4. Yahoo Sender Hub, FAQs, for Yahoo not specifying a bulk volume threshold and for mail that fails its requirements being sent to spam or rejected, checked Oct 1, 2026.
  5. Microsoft Defender for Office 365 Blog, Strengthening Email Ecosystem: Outlook's New Requirements for High-Volume Senders, Microsoft's own announcement for the Outlook.com scope, the more than 5,000 a day threshold, the SPF, DKIM and DMARC rules, the Additional Email Hygiene Recommendations section, the 550 5.7.515 rejection and the monthly or quarterly list cleaning answer in its FAQ, checked Oct 1, 2026.
  6. RFC 9989, Domain-Based Message Authentication, Reporting, and Conformance (DMARC), for its May 2026 replacement of RFC 7489, the pass and alignment rule, monitoring mode, the removal of the pct tag, the t tag and the note that a DMARC pass does not guarantee inbox delivery, checked Oct 1, 2026.
  7. RFC 5321, Simple Mail Transfer Protocol, sections 2.1, 2.4, 3.3, 3.5.3, 6.1 and 7.3, for the 550 reply for an undeliverable recipient, case sensitivity of the local part, the 252 reply, disabling VRFY, and responsibility for delivery or failure notices after acceptance, checked Oct 1, 2026.
  8. RFC 2142, Mailbox Names for Common Services, Roles and Functions, for info, marketing, sales and support as business mailbox names, checked Oct 1, 2026.
  9. Spamhaus, Spamtraps: fix the problem, not the symptom, for the spam trap types, wildcard domains, the dead trap hard bounce period, confirmed opt-in against typo traps, and the position that traps are evidence of a collection or hygiene problem rather than something to hunt, checked Oct 1, 2026.
  10. Federal Trade Commission, CAN-SPAM Act: A Compliance Guide for Business, for the 10 business day opt-out deadline, the 30 day minimum life of an opt-out mechanism and the rule against selling or transferring opted-out addresses, checked Oct 1, 2026.
  11. Apple Support, Use Mail Privacy Protection on iPhone, for the statement that it prevents senders from seeing whether a message was opened, checked Oct 1, 2026.
  12. Jeluvi entries this term builds on: email bounces, catch-all email, data decay, email deliverability, email marketing database, email warm up, email blast, B2B data, lead enrichment.
  13. No list decay percentages or bounce rate benchmarks are quoted, because none of the provider pages cited here sets one. No vendor is ranked and no prices are given. Nothing on this page is legal advice.
  14. The address-check email on this page was written for this page. It is not copied from any company's mail.
Take the sequence with you

The 10-day cadence, five templates, one email.

Five touches across email, LinkedIn and phone, five templates with placeholders marked, and the first-30-days checklist. One email.

Build a LinkedIn or outreach tool? Jeluvi is read by the people who use them. See how partners appear on Jeluvi.