How to Build an Email List of Local Businesses: A Measured Funnel
To build an email list of local businesses, collect businesses with websites from a source you may use, take published addresses from each site, check each domain's mail server, then verify every address. When we ran 337 trades businesses through that funnel on 1 October 2026, 156 published an address, and most could only be classed as risky.
Most guides describe this process as if every step works. This one measures what is left after each step, because the losses are what determine how many businesses you need to start with and how carefully you need to send.
The funnel at a glance
| Step | Businesses left | What was lost |
|---|---|---|
| Businesses with a website in the source | 337 | — |
| Website loaded | 302 | 35 sites down, blocking us, or timing out |
| At least one address published | 156 | 146 sites with no address on the pages we checked |
| Address on the business's own domain | 111 | 23 used free webmail, 25 used another domain |
| Mail server gave a definite answer to our probe | 66 | 44 refused our test network, 1 unclear |
| Server rejects unknown addresses, so an address can be confirmed | 23 | 43 domains accept any address (catch-all) |
The rest of the post explains each step and how to do it properly.
How we measured
Sample: businesses tagged as roofers, plumbers, HVAC firms or electricians, with a website, in OpenStreetMap, inside boxes around 11 US metro areas: Austin, Dallas, Denver, Phoenix, Atlanta, Tampa, Chicago, Columbus, Minneapolis, Seattle and Portland. We removed links to social and directory sites and de-duplicated by domain: 337 domains.
Steps, run on 1 October 2026:
- Fetched each homepage and up to two pages whose link contained "contact", and extracted email addresses.
- Looked up MX records with
digand classed the mail provider by the primary MX host. - Opened an SMTP connection to the primary mail server and asked it to accept mail for a random, certainly non-existent address. No message was sent.
Limits: this is a convenience sample of businesses someone mapped, not all US trades. Our test network address was listed on Spamhaus blocklists at the time, so Microsoft 365 and most security gateways refused to answer it. The raw data is in our research folder.
Step 1: source businesses you are allowed to use
Start from a list of businesses with websites, from a source whose terms allow you to keep the data. This is where many list-building tutorials quietly break rules.
The usual source is Google Maps. Two facts to know:
- Maps has no email field. It gives you a website and phone number at best. The email comes from the website.
- The Maps Platform terms restrict copying. Section 3.2.3(a) of the Google Maps Platform Terms of Service says customers "will not export, extract, or otherwise scrape Google Maps Content for use outside the Services", and gives as an example: "copy and save business names, addresses, or user reviews". If you build on the Places API, that applies to you.
Alternatives that you can keep:
| Source | What you get | Terms |
|---|---|---|
| State licensing boards | Licensed contractors, often with owner names | Public records; varies by state |
| OpenStreetMap | Businesses with tags, sometimes a website | ODbL: credit OSM; share-alike if you distribute a database built on it |
| Trade association member directories | Members by area | Check each site's terms |
| Your own manual research on Maps | One business at a time | Visiting a website you found is ordinary browsing |
OpenStreetMap is genuinely open, but thin for this purpose. Our 11 metro boxes returned only a few hundred tagged trades businesses with websites, far fewer than exist. Use it to supplement, not as a sole source. Licensing data is usually richer for trades: we cover it, along with how to find owner names, in cold email to local service businesses.
Step 2: take addresses from the website
About half of the sites published an address at all. Of 302 sites that loaded, 156 (52%) showed at least one email on the homepage or contact pages. The other half rely on phone numbers and contact forms.
Of the 156 that did publish:
| What they published | Sites |
|---|---|
| An address on their own domain | 111 |
| — of which a role address (info@, office@, service@ and so on) | 96 |
| — of which at least one named person's address | 19 |
| A free webmail address (Gmail, Yahoo and others) | 23 |
| Only addresses on some other domain | 25 |
Three practical lessons:
Role addresses are the norm, and that is fine. At a five-person roofing company, office@ is often read by the owner or the person who books the work. Treat named addresses as a bonus, not the target. Whether to send to role addresses at all is a judgement we cover in role-based email addresses.
Free webmail is common at the smallest firms. 23 sites listed a Gmail or similar address. These are real inboxes, but verification of consumer mailboxes has its own quirks.
Check that the address domain matches. We found three sites whose published address would not deliver as written: two on misspellings of the company's own domain (a missing letter in each, with no DNS records at all), and one on a parked domain. Copying addresses from websites faithfully copies their typos too.
Step 3: check the mail server
Before verifying addresses, check that the domain can receive mail at all. 42 of the 337 website domains, about 12%, could not: 41 had no MX record, and one published a "null MX" (a single MX of .), which RFC 7505 defines as a declaration that the domain accepts no mail. The business receives email somewhere else, often a free webmail address or a different domain, so a guessed address on the website domain will almost certainly fail. (Strictly, RFC 5321 lets senders fall back to a domain's A record when it has no MX, but a website's server rarely accepts mail.)
By primary MX host, the providers were:
| Mail provider (by MX) | Domains |
|---|---|
| Google Workspace | 113 |
| Microsoft 365 | 100 |
| Other host | 45 |
| Security gateway (Proofpoint, Mimecast and similar) | 29 |
| GoDaddy | 6 |
| Zoho | 3 |
You can look up any domain's mail server with our MX lookup tool.
Step 4: verify, and expect a lot of catch-all
On small business domains, catch-all is the common case, not the exception. We asked each mail server whether it would accept a random, made-up address:
| Server response | Domains |
|---|---|
| Accepted the made-up address (catch-all) | 93 |
| Rejected it (verification can confirm or rule out addresses) | 52 |
| Refused our test network on reputation grounds | 138 |
| No MX record | 42 |
| No clear answer | 12 |
Of the 145 servers that gave a definite answer, 93 (64%) accepted a made-up address. On Google Workspace, 75 of 113 did. We re-tested a subset with a second random address and got identical answers.
What that means for your list:
- On those 93 domains, a verifier cannot tell
info@fromnobody@. The honest result is risky, whatever the address. Here is why. - A published address on a catch-all domain is still a reasonable send, because a person put it there. A guessed owner address on a catch-all domain is a coin flip.
- 99 of the 100 Microsoft 365 domains refused to talk to our network at all. That is about our network, not the addresses, and it is exactly why verification needs clean infrastructure. A verifier on a well-configured network gets answers there.
Step 5: segment and send
Split the list by what you actually know about each address.
| Segment | Example | How to send |
|---|---|---|
| Published, verified valid | office@ on a domain that rejects unknowns |
Main sends |
| Published, risky (catch-all) | info@ on a catch-all domain |
Small batches, watch bounces |
| Guessed, verified valid | Owner's first@ confirmed by the server |
Main sends |
| Guessed, risky | Owner's first@ on a catch-all domain |
Smallest batches, or skip |
| Invalid or no MX | Typo domains, parked domains | Remove |
Keep the source and date of every address. You will need it if anyone asks where you got their details, which in the UK and EU you are obliged to tell them; see the legal side of collecting business emails.
The takeaway
Plan for heavy losses. From 337 local businesses with websites, about half published an address, a third had an address on their own domain, and where the mail server gave us a definite answer, about two in three of those domains could not confirm any specific mailbox. Source from data you are allowed to keep, take addresses from websites rather than guessing, check the mail server before the mailbox, and send catch-all addresses separately. Run a few addresses through the free email verifier before you build the whole list, to see which segment your market falls into.
Common questions
How do I build an email list of local businesses?
Start from a list of businesses with websites, from licensing boards, open map data or manual map searches. Visit each website for a published address, look up the domain's mail server, and verify every address before sending. Expect to lose a large share at each step: in our test, about half of the sites published no address at all.
Can I scrape business emails from Google Maps?
Google Maps does not show email addresses, and Google's Maps Platform terms bar API customers from copying and saving business names, addresses or reviews outside its services. Use Maps to discover businesses by hand if you like, but take contact details from each business's own website or an openly licensed source.
What percentage of small business websites list an email address?
In our check of 302 US trades business websites on 1 October 2026, 156, or 52%, published at least one address on the homepage or up to two contact pages. Most of those were role addresses like info@ or office@ rather than a named person's address.
Why do so many local business emails come back as risky?
Because many small business domains accept mail for any address. In our test, 93 of the 145 mail servers that gave a definite answer accepted a made-up address, so no address at those domains can be confirmed by a verifier. That is a property of the domain, not a fault in the address.
Verify unlimited addresses for $29.99/month
Real SMTP mailbox checks. No credits, no per-email fees.
Get Started