ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

Which comes first, verification or validation?

Back to InsightsWhich comes first, verification or validation?

Which comes first, verification or validation?

Key Facts

  • Dormant email lists with 6+ months of inactivity contain 15–30% invalid or inactive addresses, according to MailTester's list-hygiene research.
  • SMTP-level email validation achieves 98.9% accuracy, but it's deliverability hygiene — not proof of consent, per MailTester.
  • Bounce rates above 0.5% raise red flags with email service providers, MailTester reports.
  • Past-customer status is not blanket permission to message through any channel, operational guidance warns.
  • CAN-SPAM allows 10 business days to honor opt-outs, but the FCC's 2024 order permits only a single non-marketing confirmation text after revocation, per compliance guidance.
  • Good list hygiene can improve inbox placement by up to 20%, citing Return Path research.
  • No regulatory text formally defines or sequences verification versus validation in consent workflows — the order of operations matters more than the terminology, per practitioner guidance.

Why the Question Trips Up Service Businesses Reactivating Old Lists

Ask three compliance officers what "verification" means for a customer list, and you'll likely get three different answers — one about email deliverability, one about identity checks, one about consent. That ambiguity is exactly what trips up service businesses trying to reactivate dormant customers.

The terms carry distinct meanings depending on who's using them. In email deliverability, "validation" is an SMTP-level check that a mailbox actually exists — a technical hygiene practice, not a compliance step. In KYC and identity work, "verification" means confirming who someone is, with vendors like Ondato describing a defined sequence of initial verification followed by periodic reverification. In marketing compliance, neither term is formally defined or sequenced by any authority. No regulatory text or compliance framework tells you whether verification or validation comes first in a consent workflow.

That gap creates real risk for businesses texting or calling old customers. The most direct operational guidance available — practitioner guidance on database reactivation — is blunt about it: past-customer status is not a blanket permission to send any message through any channel. Consent must be checked per channel before anything is queued. The same source warns businesses not to infer consent from a completed job alone, especially for automated texts and calls.

The technical side has its own stakes. Dormant lists — contacts with six or more months of no engagement — typically contain 15–30% invalid or inactive email addresses, according to MailTester's list-hygiene research. Bounce rates above 0.5% raise red flags with email service providers, which is why validation is treated as a critical pre-send step. But cleaning addresses is deliverability work, not consent work — a technically valid email can still belong to someone who opted out months ago.

For a business planning outreach, the practical sequence looks like this:

  • Check consent and opt-out status per channel — call, text, email — before building any campaign
  • Confirm the contact is eligible for the chosen channel, not just that the contact exists
  • Run technical validation (email deliverability, number formatting) only on consented contacts
  • Preserve evidence of consent and honor opt-outs immediately — CAN-SPAM allows 10 business days, but faster is safer

This is why CallMyCustomers starts every engagement with a list review rather than a send button: eligibility per channel gets settled before a single message is drafted, and opt-outs are honored immediately once campaigns run. The FCC's 2024 consent-revocation order, as summarized in the same guidance, permits only a single non-marketing confirmation text after someone revokes — a narrow margin that punishes sloppy sequencing. The order of operations matters more than the terminology: confirm permission first, then worry about whether the address or number works.

The distinction between verification and validation in consent workflows isn't just semantic — it determines whether your outreach complies with regulations or risks costly penalties. For CallMyCustomers, this sequence directly impacts how we protect client relationships while reactivating dormant lists. Getting this order wrong wastes effort and introduces avoidable legal exposure.

Verification confirms whether valid consent exists for a specific channel — essentially asking, "Do we have permission to call, text, or email this contact?" This step must happen first. As operational guidance states, "Channel eligibility: The consent and opt-out state for email, text, or calls" is a "minimum required field before building any campaign" and requires immediate suppression on opt-out. Skipping this check means contacting someone who has already revoked permission, violating TCPA and CAN-SPAM rules that mandate honoring opt-outs within 10 business days.

Validation, by contrast, assesses technical deliverability — for example, whether an email address is syntactically correct and linked to an active mailbox. While important for inbox placement (with dormant lists containing 15–30% invalid addresses), performing validation on non-consented contacts is wasted effort. It consumes resources on contacts you cannot legally message and creates a false sense of readiness. Email validation achieves 98.9% accuracy but serves only as hygiene for consented lists, not a compliance gate.

Therefore, the correct sequence is clear: verify consent eligibility per channel before any outreach, then validate technical deliverability only for contacts who passed verification. This approach aligns with CallMyCustomers' practice of immediate opt-out suppression and explicit consent collection during booking. It ensures every message sent rests on a foundation of verified permission, transforming list hygiene from a compliance afterthought into the cornerstone of permission-based reactivation.

What Validation Actually Buys You: Deliverability, Not Permission

Consent verification and email validation serve fundamentally different purposes in a reactivation workflow. While verification confirms whether a customer has given permission to be contacted, validation ensures that contact information can actually be delivered. This distinction is critical: a validated email address is not the same as a permitted one, and confusing the two risks both compliance failures and wasted effort.

For dormant lists—those with six or more months of no engagement—research shows that 15–30% of addresses are invalid or inactive. SMTP validation achieves 98.9% accuracy in identifying these problematic entries, allowing teams to remove dead weight before sending. Keeping bounce rates below the 0.5% ESP red-flag threshold through this hygiene step can improve inbox placement by up to 20%, directly boosting the chances that a message reaches the intended recipient.

These are deliverability wins, not permission grants. Validation tells you whether an email can land in an inbox; verification tells you whether you’re allowed to send it there in the first place. CallMyCustomers treats them as separate steps: first confirming consent eligibility per channel, then applying technical validation only to contacts who have already cleared that gate. This sequence protects sender reputation while honoring the legal and ethical requirement that outreach begins only with permission.

Consent workflows require a deliberate sequence to ensure compliance and effectiveness. Before any outreach begins, businesses must first confirm that a customer has not opted out of communication through their preferred channel. This verification step is non-negotiable, as past-customer status alone does not grant blanket permission for messaging across email, text, or call channels. According to operational guidance, confirming eligibility before sending and preserving evidence of consent are foundational practices for regulated outreach.

Once consent is verified per channel, the next step involves technical validation of the contact information itself. For email campaigns targeting dormant lists, this means running SMTP-level validation to identify invalid or inactive addresses — a process that achieves 98.9% accuracy and can uncover 15–30% unusable entries in lists with six or more months of no engagement. This technical hygiene is distinct from consent verification; it ensures deliverability but does not address whether the recipient has agreed to receive messages. Only after both steps are complete should campaign eligibility rules — such as seasonal relevance, offer approval, or business logic filters — be applied to determine who receives outreach.

The workflow continues with execution, followed by strict opt-out processing that honors requests immediately and adheres to regulatory timelines. CAN-SPAM requires opt-outs to be honored within 10 business days, while the FCC’s 2024 consent-revocation order limits any final confirmation text to a single message without marketing content. Throughout this sequence, every action — from verification to opt-out handling — must be logged in an audit trail that preserves evidence of consent, including timestamps, channel, and source. For contacts dormant 12 months or longer, a low-friction reconfirmation (e.g., a simple “Reply YES” text) is warranted before full outreach, mirroring the risk-tiered reverification patterns used in KYC frameworks to address consent staleness proactively. Engageware’s model for regulated industries demonstrates how embedding these steps into a unified workflow ensures compliance, traceability, and operational resilience.

How a Done-For-You Partner Handles This For You

When you hand off reactivation to a done-for-you partner, the sequence stops being theoretical and starts being operational. The free list review that CallMyCustomers runs before any fee is exactly where consent verification happens first: every contact is segmented by recency — 30 days, six months, 12-plus months — and by channel consent state, so nothing is queued until eligibility is confirmed. Industry guidance makes this explicit: channel eligibility for email, text, or calls is a minimum required field before building any campaign, and past-customer status is not a blanket permission to send through any channel.

  • List review segments by recency and consent state at zero cost
  • Every script, offer, and message is owner-approved before send
  • Opt-outs are honored immediately across all channels
  • Clinic clients run under BAA/HIPAA, TCPA, and A2P 10DLC practice

Technical list hygiene runs in parallel but stays distinct. Email validation cleans dormant lists where 15–30% of addresses can be invalid or inactive, using SMTP checks with 98.9% accuracy to keep bounce rates below the 0.5% ESP threshold — but this is deliverability work, not consent verification. The consent gate stays first: verify opt-in status per channel, then validate technical deliverability for the consented subset only. Audit trails capture the verification result, the consent source, and any suppression action, creating the evidence trail that regulators and carrier registrations require.

Classification edge cases — message type, technology, consent record, jurisdiction — should go to qualified counsel before launch. Operational guidance is clear on this: review the live campaign with qualified counsel when the classification is uncertain. If you want to see what a compliant reactivation could produce from your list, start with a free list review and get the segmentation, the rate, and the setup before you spend a dollar.

Frequently Asked Questions

Should I verify consent or validate email addresses first when reactivating a dormant customer list?
You should verify consent eligibility per channel before any outreach, as past-customer status alone does not grant permission to message. Technical email validation (deliverability checks) should only run on contacts who have already cleared the consent gate, since it serves as hygiene, not compliance.
What percentage of email addresses in dormant lists are typically invalid or inactive, and why does that matter for reactivation?
Dormant lists with six or more months of no engagement typically contain 15–30% invalid or inactive email addresses, which can trigger ESP red flags if bounce rates exceed 0.5%. Cleaning these improves inbox placement but does not replace the need for consent verification.
Does a validated email address mean I have permission to send marketing messages to that contact?
No, email validation only confirms technical deliverability—whether an address can receive mail—not whether the recipient has given consent. A validated address may still belong to someone who opted out, so consent must be verified first.
How soon must I honor an opt-out request under CAN-SPAM, and what does the FCC’s 2024 consent-revocation order allow after revocation?
CAN-SPAM requires honoring opt-outs within 10 business days, while the FCC’s 2024 order permits only a single non-marketing confirmation text after consent is revoked—no further promotional messages.
For customers dormant 12 months or longer, what step should I take before launching a full reactivation campaign?
For contacts dormant 12+ months, implement a low-friction reconfirmation (e.g., 'Reply YES to continue') before full outreach, as long-dormant consent carries higher staleness risk and benefits from proactive reverification.
Why is it risky to run email validation on a list before checking consent status?
Validating emails before consent verification wastes resources on contacts you cannot legally message and creates a false sense of readiness, since technical deliverability does not equate to permission to send.

Permission Before Precision: The Sequence That Protects Your Reactivation

The distinction between verification and validation isn't semantic — it's the difference between compliant outreach and costly exposure. Verification confirms you have permission to contact someone through a specific channel; validation only confirms the address or number technically works. Dormant lists carry 15–30% invalid emails, making validation essential for deliverability, but running it before consent verification wastes resources on contacts you can't legally message. The FCC's 2024 consent-revocation order leaves no room for sequencing errors: one non-marketing confirmation text after opt-out, then silence. CallMyCustomers builds every reactivation on this order — consent eligibility per channel first, technical hygiene second, owner-approved messaging third. The free list review surfaces exactly where each contact stands before any spend. If you're sitting on a list of past customers, old quotes, or lapsed members, start with a free review to see the segmentation, the rate, and the compliant path to booked work — no software to buy, no surprise line items.

Stay in the Loop