Bad Ideas: Why Giving Your Email List to a Third Party Is Just Dumb


A story recently broke on 404 Media that made deliverability experts everywhere cry a little inside: YouTube channel Channel 5 admitted to handing a CSV file of its email subscribers over to a third party so that person could market a new product to them.

Putting aside the specific names and political figures involved (which are irrelevant to the underlying email mechanics) this incident serves as a prime example of what never to do with your email list.

If you own an email list, hand-delivering a .csv file of your subscribers' contact information to a third party is fundamentally, egregiously stupid. It harms deliverability, breaks the law, betrays subscriber trust, and destroys the value of your own audience.

On the one hand, I'm surprised that this needs to be said. On the other hand, I need to recognize that not everybody has a history and understanding of email marketing best practices. Of what the rules are when it comes to mailbox providers and spam filters. Of what's commonly allowed and what's not. Some (annoying) people intentionally share data and send spam today. They don't all get caught. You can potentially look at that and assume that it must be okay, because they're doing it. But, it's not okay, and lots of folks DO get into trouble for it.

So, let me explain: Here is why sharing or handing off your email list is bad idea that leads you toward a deliverability and operational nightmare.

Consent Is Not Transferable

The cardinal rule of email marketing is permission. Subscribers gave you permission to send them your content. Permission is not a generic asset that can be packaged, transferred, or loaned out to a friend, partner, or third party. Just because someone signed up for your YouTube channel's newsletter or bought your merchandise does not mean they consented to receive emails about someone else's product, crypto token, or business venture. When a third party sends mail to a list they didn't build, that mail is Unsolicited Bulk Email (UBE). By definition, that is spam.

That's what Spamhaus is looking to block. That's what mailbox providers, the hosters of email inboxes like Google, Microsoft, Yahoo, Apple, etc., are looking to block. They know it's unwanted. They know it makes their users unhappy.

Inbox Pain in 3 … 2 … 1

What happens when a user receives an email from an unfamiliar sender promoting something they never asked for? They don't buy the product. Instead, they click the "report spam" button.

With major inbox providers like Gmail and Yahoo enforcing strict spam complaint thresholds (often requiring complaint rates to stay below 0.1% to 0.3%), it takes only a handful of annoyed recipients to completely wreck a sender's reputation.

If a third party blasts a list of people who never opted into their emails, pam complaint rates will skyrocket instantly. The sender's domain and IP address will get blacklisted. Mail from that sender will go straight to the spam folder, or even end up blocked.

Legal & Regulatory Pain, Too

The legal end of this isn't my area of expertise, especially internationally. But I did stay at a Holiday Inn Express last night.

Let's talk about CAN-SPAM & US Law: Under US law, CAN-SPAM has an affirmative consent permission standard, which this violates. Also, CAN-SPAM explicitly protects mailbox providers (ISPs and anti-spam services) when they block unsolicited email in good faith. Anyone receiving and sending to a third-party list is setting themselves up for massive blocking pain, and mailbox providers are legally shielded when they shut those messages down.

GDPR & International Laws: In Europe, the General Data Protection Regulation (GDPR) strictly prohibits sharing personal data (like an email address) with third parties for direct marketing without explicit, informed consent. If European residents are on that subscriber list, sharing that CSV file is a direct, fineable violation of privacy laws. Oof.

Privacy Policy Breaches: Most websites have a privacy policy promising users that their data will not be sold or shared with third parties for direct marketing. In many jurisdictions (such as under California's CCPA), violating your own stated privacy policy probably brings legal liability.

But again, I'm not a lawyer and this is not legal advice.

You'll Open The Portal to Heck

Subscribers trust you with their email address expecting you to protect it. The moment you export a .csv file and send it out into the wild, you lose all control over that data. That file can now be copied, backed up, stored on unsecured drives, forwarded, leaked, re-sold, or even buried in soft peat for three months and recycled as firelighters. You have turned your loyal subscribers' inboxes into a free-for-all target for unwanted spam. Once a subscriber realizes that you were the leak, your brand's reputation and audience trust are permanently destroyed.

You'll Break the Inbox

Inbox space is not an infinite resource. By handing your subscriber list over to third parties, you create an anti-spam version of a "tragedy of the commons," right in your own audience's email account. You are now directly competing with those third parties for your subscribers' limited attention. If those third parties burn out the inbox with spam, your subscribers will either stop opening emails altogether, unsubscribe from everyone, or abandon the inbox entirely. You are literally diluting and destroying the value of your own asset.

Inbox burn out is real. People switch email accounts, abandoning ones overrun with spam.

What You Should Do Instead

If you have a friend, partner, or sponsor whose product you genuinely want to endorse to your audience, you do not give them your list. Instead, you send the email yourself. The email must originate from your infrastructure, sent by you, to the subscribers who opted into your email list or newsletter.. Write a section in that newsletter (or maybe even send a dedicated email) saying: "Hey, I want to share this cool thing from a partner I respect. Check them out here." And if you want to give your readers a chance to sign up for future emails from the partner, include a clear link that says, "Click here if you want to sign up for their emails."

If subscribers click that link voluntarily and sign-up for the other email list, that's permission.

(Note: If you are being paid to promote a product or service, always ensure you follow local advertising regulations, such as FTC disclosure rules for sponsored/affiliate content.)

Never Forget

An email list is a permission-based relationship between you and your subscribers. It is not a commodity to be handed around. The moment you give a CSV file of your subscribers to a third party, you aren't helping them "expand their audience.” You're facilitating spam. You're risking legal problems. You're engaging in the opposite of the things needed to maximize deliverability and inbox placement success.