How-to

How to import an email list into new software

Last reviewed 21 September 2026

Importing a list is seven steps: establish that the people on it agreed to hear from you, export it and read what is actually in the file, strip the rows that cost more than they are worth, carry your suppression list across before any subscriber, re-permission anything you cannot account for, ramp the first sends instead of mailing everyone at once, and import the consent evidence, not only the addresses. A list you cannot account for is not imported; it is re-asked.

Consent belongs to the relationship between you and a person, not to the software that happened to be holding the address, so moving a list between tools does not by itself make the mail unlawful or unwelcome. What changes on the day of a move is the risk: a list that has been sitting still for a year contains addresses that have been abandoned, recycled into spam traps, or forgotten by their owners, and the first send after an import is the one that arrives as a surprise to the largest number of people at once. Everything below is about surviving that first send.

Establish that you may mail these people at all

The question is not whether the export is yours. It is whether each person in it did something that counts as agreeing to hear from you, and whether you can still show what that was. Under the GDPR that is Article 7(1): where processing rests on consent, you have to be able to demonstrate that the person consented. Under CAN-SPAM the standard is different and lower — commercial mail may be sent without prior consent provided the header information is accurate, the message is identifiable, a postal address is present and an opt-out is honoured — so the same file can be lawful to send in one jurisdiction and not in another, and the safe reading is the strictest one that applies to anybody on the list.

Sort the file by where each row came from rather than by how old it is. Addresses that filled in your own form, with a date and a page recorded, are the strongest case. Addresses from a checkout, a booking or an event you ran are usually defensible and are exactly what the soft opt-in in national ePrivacy law was written for, within the narrow limits the ICO reads into it. Addresses somebody gave you at a conference, addresses a partner shared, addresses scraped from a directory and addresses bought from anybody are a different category entirely, and no amount of careful sending rescues them.

Write down the answer per source before you upload anything, because the decision is much harder to make afterwards, when the rows have lost their provenance and become one undifferentiated list in a new tool. None of this is legal advice; it is the shape of the questions, with the articles named so you can check them.

Export the file and read what is actually in it

Export to CSV and open it, rather than moving it through an integration that promises to do the transfer for you. An integration migrates what the old tool considered a subscriber, which is a category that quietly includes people who unsubscribed and were kept for reporting, people who hard bounced and were kept for history, and people who never confirmed and were kept because the old tool did not enforce confirmation on every route in.

Read the column headings first. A useful export has an address column, a status column, a created-at timestamp, the source or form name, and often the IP and timestamp of a confirmation click. Those last two are the consent record, and they are the part most often lost in a migration, because the importer on the other side only asks for an address and a name. An export with no dates and no status column is not a list you can account for, whatever it says at the top of the file.

Count the rows by status before you do anything else. The number that matters is not how many addresses the file contains but how many of them are confirmed, currently subscribed, and were active in the last few months, because that is the list you are actually moving. It is normal for that figure to be a fraction of the headline one, and much better to learn it now than after a send.

Strip the rows that cost more than they are worth

Every address in the file has an expected value and an expected cost, and for a surprising number of them the cost is higher. A hard bounce costs a delivery attempt against a domain that has just started sending. A spam trap costs a listing. A role address costs a complaint from somebody who never signed up personally. None of these is worth keeping in exchange for a slightly larger number on a dashboard.

The rule of thumb is that an address earns its place by having done something, recently, that a machine can see. Opened is no longer such a thing — open tracking stopped being reliable evidence in 2021 — so the signals left are clicks, replies, purchases and logins. An address with none of those in the last year is not a subscriber; it is a line in a spreadsheet, and it is the line most likely to have become a trap.

What an export usually contains, why each kind of row is a risk, and what to do
Kind of rowWhy it is a riskWhat to do with it
Addresses that unsubscribed or complainedMailing one again is the single fastest way to earn a complaint and, under CAN-SPAM, the clearest violationMove them to the suppression list, never to the subscriber list
Addresses that hard bouncedThe mailbox does not exist; repeated attempts are read as a sender who does not clean a listSuppress permanently and do not retry on the new platform
Role addresses: info@, sales@, support@, admin@Nobody at a shared mailbox agreed personally, and several well-known spam traps are role addressesDrop them, or send them a confirmation message and keep only the ones somebody clicks
Addresses with no date, no source and no statusYou cannot demonstrate consent for a row that records none, which is what Art. 7(1) asks forRe-permission them or delete them; importing them silently is the decision to have no record
Addresses collected for something unrelatedConsent under the GDPR has to be specific, so a booking form is not agreement to a courseAsk again, naming what you will send this time
Addresses bought, scraped, rented or inherited with an acquisitionPurchased data is dense with traps and complaints, and it damages the domain rather than the listDo not import it at all; there is no safe volume
Addresses with no click, reply or purchase in a year or moreAbandoned mailboxes are recycled into traps, and silence is the best available predictor of a complaintRe-permission as a separate, small, slow send, or retire them

Carry the suppression list across before any subscriber

The suppression list is the most valuable thing you own and the thing most often lost in a move, because importers ask for subscribers and nothing asks for the people you must never contact. Upload it first, on its own, and confirm it is in place before a single subscriber row goes anywhere near the new tool. A platform that offers no way to import suppressions is a platform that is about to let you mail everybody who ever left.

This is also the step that most often resurrects somebody. The classic sequence is an old export taken before a person unsubscribed, imported later into somewhere that has no record of the unsubscribe, and that person receives a message they explicitly refused — which under CAN-SPAM is a violation regardless of intent, and under Article 21(3) of the GDPR is processing after an objection. The export is not wrong. The order of the two imports is.

If your suppression list holds hashes rather than addresses, hash the incoming file the same way and compare before importing, rather than after. The comparison has to happen on the way in; a check that runs at send time is one configuration change away from not running.

Re-permission everything you cannot account for

A re-permission campaign is one message to an existing list asking the people on it to confirm they still want the mail, after which everyone who did not answer is suppressed rather than mailed again. It is what you run for the rows that survived the previous two steps but still have no record behind them, and it is the only mechanism that turns a list you cannot account for into one you can.

The message has to stand on its own, because most of the people receiving it do not remember you. Name the thing they signed up for, say when and where if you know, say plainly what happens if they do nothing, and ask for exactly one click. Do not attach an offer to it; a re-permission message that is also a promotion is a promotion sent to people who have not agreed to receive one. Do not send a reminder to the people who ignored it either — the ignoring was the answer.

Expect the list to come back smaller, and treat that as the point rather than the cost. The addresses that do not answer were not going to open, click or buy; they were going to sit in the denominator making every rate look worse and occasionally reporting you. What you have afterwards is a list you can describe to a regulator and a complaint rate you can predict.

Ramp the first sends instead of mailing everyone at once

The largest, least engaged, most surprising send you will ever make is the first one after an import, and sending it to the whole list on day one is how a domain gets its reputation set by its worst possible audience. Split the import into batches ordered by how recently each person did something, send to the most recent batch first, and wait long enough between batches to see the result of the one before.

What you are watching for is the spam complaint rate, which Google asks bulk senders to keep below 0.3% and which is worth aiming a long way under, around 0.1%. A batch that comes in over the ceiling is not a batch to push past; it is information about every batch below it, which is by definition less engaged. Stop, and go back to the re-permission step for the remainder.

A course has an advantage here that a newsletter does not, and it is worth using deliberately. A course sends one message per subscriber per day counted from the day that person confirmed, so importing a list into a course staggers itself: nobody is mailed on a schedule shared with anybody else, and the volume spreads across the days on which people happened to click rather than landing in one hour.

Import the evidence, not only the addresses

Finish by moving the part of the old system that was never on the subscriber row: what each person was shown when they agreed, when they submitted the form, when they clicked the confirmation link and from where, and what they were told they would receive. Article 7(1) puts the burden of proof on you and does not care which vendor you were using when the consent was given.

Where the old tool recorded a consent sentence, store it as text rather than as a link to the page it used to live on, because the page will be edited and the record will silently become a description of your current copy instead of what that person actually read. Where the old tool recorded nothing, record that too — a row marked as imported without evidence, with the date it arrived and the source it came from, is a far better artefact than a row that looks identical to one collected through a form.

Then write two lines somewhere durable: where this list came from, and what you did to it on the way in. In two years that note is the difference between answering a complaint in a paragraph and reconstructing a migration from memory.

Common questions

Is it legal to import an email list into new software?

Moving addresses between tools is not itself the problem; consent attaches to the relationship rather than to the platform. What matters is whether each person agreed to hear from you and whether you can still demonstrate it, which is what Article 7(1) of the GDPR requires. CAN-SPAM sets a lower bar — accurate headers, a postal address, a working opt-out — so one file can be lawful to mail in one jurisdiction and not another. Rows with no record behind them should be re-permissioned rather than imported.

What should I remove from a list before importing it?

Everyone who unsubscribed or complained, every hard bounce, every role address of the info@ or support@ kind, anything bought, scraped or rented, anything collected for an unrelated purpose, and anything with no click, reply or purchase in the last year. The last group is the one people keep and should not: abandoned mailboxes get recycled into spam traps, and silence is the best available predictor of a complaint.

How do I email a list I have not contacted in a long time?

Send one re-permission message rather than resuming where you left off. Name what they signed up for, say when and where if you know, say what happens if they do nothing, ask for a single click, and attach no offer to it. Everyone who does not answer goes to the suppression list. Send it in small batches ordered by how recently each person did anything, and stop if the complaint rate rises rather than working through the rest.

Can I buy an email list if I only mail it carefully?

No. Purchased and scraped data is dense with recycled addresses and spam traps, the people in it never agreed to anything so complaints arrive at a rate no ramp survives, and under the GDPR there is no consent to demonstrate. The damage lands on the sending domain rather than on the list, which means it follows you to the next list you build honestly. There is no volume at which this becomes safe.

The short version: sort by source before you sort by date, carry suppressions first, drop role addresses and anything bought, re-permission whatever has no record behind it, and let the first sends go out in batches ordered by recency rather than all at once. A list that survives that process is smaller than the one you exported and is worth more, because every address left on it belongs to somebody who acted recently and can be shown to have agreed. The sources below are the texts the rules in this guide come from.

Sources

  1. Regulation (EU) 2016/679, the GDPR, Articles 7, 13, 14 and 21 on EUR-Lex
  2. The ICO’s guidance on direct marketing and PECR
  3. FTC: CAN-SPAM Act compliance guide for business
  4. Google’s email sender guidelines, which state the complaint-rate thresholds
  5. Yahoo’s sender requirements and best practices

Read next

This page is part of Email deliverability for small senders: what decides it, which is the complete guide to the subject.

These guides are about the format rather than about any particular tool. What this site itself does is on the home page, and the rest of the set is on the guides index .

Elsewhere on this site

The rest of this site comes at the same subject from other directions: guides on the format itself, a tool for one job each, a page for each kind of work, what to check when choosing software, a course written out in full, the courses people have actually published here, and one definition or figure at a time.

Thinking of writing one of these?

5dayemail hosts a five-to-ten day email course: you write it once, and everyone who joins your list gets one email a day, in order, starting from the day they confirm.

Accounts are opened a few at a time rather than by signing up. Leave your address and you will be written to when the next ones open.

One message, when there is room. No course emails, no newsletter, and the address is not passed on. Ask and it is deleted; what is kept, and for how long, is in the privacy policy.