Home/Blog/Your Prospect List Is Quietly Rotting: A Working Guide to B2B Data Decay

Your Prospect List Is Quietly Rotting: A Working Guide to B2B Data Decay

Open filing drawer representing an ageing contact database

There is a specific kind of bad week in outbound where nothing has changed except the results. Same list, same sequence, same sender, and suddenly the bounce rate has tripled and replies have stopped. Nobody touched anything. That is what makes it confusing.

Usually nobody did touch anything. That is the problem. The list sat still while the world underneath it moved.

Contact data has a shelf life, and most small teams treat it as though it does not. A list built in February is worked again in August as if the two are the same asset. They are not. Somewhere between a fifth and a third of it is now wrong, and the wrong parts are actively damaging the parts that are still right.

This is a maintenance article. It covers how fast B2B data actually goes off, which fields go first, what stale data costs beyond the obvious, and a routine small teams can realistically keep.

How fast data decays, and what the numbers actually mean

The most commonly cited figure in this area comes from HubSpot's database decay work, drawing on MarketingSherpa research, which puts B2B contact database decay at roughly 2.1 per cent per month, compounding to about 22.5 per cent a year. That number has been repeated so many times it has become the industry default.

It is a reasonable baseline, but it is worth being clear about what it does and does not tell you. It is an aggregate across all fields and all industries. Your list is not average. If you sell into technology companies, where tenure is short and reorganisations are frequent, decay runs faster. If you sell into local government or manufacturing, it runs slower.

More importantly, decay is not evenly spread across the record. Treating a contact as a single object that is either fresh or stale hides where the damage actually is.

Job titles move fastest, because people are promoted, restructured or given a broader remit without anything else about them changing. The email still works. The person still exists. But the personalisation you built on their title is now describing a job they no longer do, which is worse than no personalisation at all, because it signals clearly that you are working from an old list.

Phone numbers decay quickly too, and the reasons are structural rather than personal. Direct dials tied to office extensions were undermined by the shift to distributed work, and many of those numbers now ring in empty rooms or route to a switchboard that has no record of the person. Various data vendors put phone decay well above email decay, though the specific figures they publish should be read with the knowledge that they are selling phone data.

Email addresses sit in the middle. They fail hard and visibly, which is at least honest. When someone leaves, the mailbox is usually deactivated within a few months and you get a bounce that tells you plainly the record is dead. The dangerous cases are the ones that fail quietly: the address that still accepts mail but goes to nobody, or the catch-all domain that accepts everything and delivers none of it.

Company-level data decays more slowly but more expensively. Acquisitions, rebrands, domain changes and office closures are less frequent than job moves, but a single missed acquisition can invalidate every contact at that company at once, and it tends to happen right as those accounts become most interesting.

The single biggest driver behind all of this is simply that people change jobs, and they do it at a pace that has not slowed. Average tenure in many professional roles now sits under three years, which means that in any given twelve-month window a meaningful slice of your list has moved somewhere else.

The costs that do not appear on the invoice

The obvious cost of decayed data is wasted send volume, and that is the least important one.

The real damage is what it does to deliverability. Mailbox providers judge a sending domain on how recipients and their servers respond to it, and a high proportion of messages to non-existent addresses is one of the clearest negative signals available. Once your reputation slips, the consequence is not that bad addresses bounce, which they were going to do anyway. The consequence is that good addresses start landing in spam.

This is what makes data decay a compounding problem rather than a linear one. The damage does not stay contained to the dead records. It leaks into the live ones, and it does so invisibly, because a message delivered to a spam folder looks exactly like a message delivered to an inbox from the sender's side. You do not get a bounce. You get silence, and silence is easy to misread as a messaging problem.

Teams then respond to the silence by rewriting their copy. The copy was fine. The list was killing the domain.

There is a second cost that lands on the person doing the work. Reps who work a bad list spend a large share of their day discovering that records are wrong, and that is demoralising in a way that failing to close deals is not. Failing to close a deal is the job. Sending forty messages and getting eleven bounces is admin dressed up as selling.

The third cost is analytical. Reply rates calculated across a list that is a quarter dead are not measuring what you think they are. If you are trying to work out whether a new message performs better than an old one, and the denominator includes a large block of addresses that never received anything, you will draw the wrong conclusion, and you will draw it confidently.

Putting a number on it for your own business

Abstract decay percentages are easy to nod at and ignore. It helps to run the arithmetic against your own list, because the output is usually more alarming than the percentage suggested.

Take a list of three thousand contacts, built over the last eighteen months, with no systematic re-verification. Apply a conservative twenty per cent annual decay and the compounding is not kind: after eighteen months, something in the order of seven hundred to nine hundred of those records are wrong in some material way. Not all of them will bounce. A large share will be people who have moved on but whose mailboxes are still catching mail, or people still at the company in a different role.

Now consider what that does to a send. If you mail all three thousand and two hundred and fifty bounce, that is an eight per cent hard bounce rate. Most deliverability guidance treats anything above about two per cent as a warning sign, and sustained rates above five per cent as the point where mailbox providers begin throttling or filtering a sender. You have not just wasted the two hundred and fifty. You have put the remaining two thousand seven hundred at risk, along with every send you make for the next several weeks while the reputation recovers.

The recovery period is the part that surprises people. Sending reputation is built on rolling behaviour, so a single bad send does not clear the moment you stop. Teams that burn a domain typically spend four to eight weeks sending reduced volume to their most engaged contacts before performance returns to where it was, assuming they diagnose the cause at all.

There is a rough way to value the maintenance work against that. If a quarterly re-verification pass on your priority accounts takes four hours and costs a modest amount in credits, compare it against the cost of a month of degraded deliverability across your whole sending operation. For most small teams the comparison is not close, which is why the practice survives despite being tedious.

A note on the compliance layer

Data hygiene and compliance overlap more than most outbound teams assume, and in Australia the overlap is legislated.

The Spam Act 2003 governs commercial electronic messages sent to Australian addresses, and it requires consent, accurate sender identification and a functional unsubscribe mechanism. Consent can be inferred in business-to-business contexts in some circumstances, particularly where a work address is published in a business capacity and the message relates to that person's role. That inference is doing a lot of work, and it gets weaker as your data gets older, because a role-relevance argument depends on the role being current.

This is a practical reason to re-verify rather than a legal argument, and it is worth stating plainly: none of this is legal advice, and if your outbound operates at scale into regulated industries it is worth getting proper advice on your specific approach. But the direction is clear enough. A message sent to someone whose title you last confirmed two years ago is harder to defend as relevant to their current role than one sent to a record checked last quarter.

The Australian Privacy Principles add a further point that is easy to miss: organisations covered by the Privacy Act are expected to take reasonable steps to ensure the personal information they hold is accurate, up to date and complete. Holding a large volume of stale contact data is not just commercially wasteful. It sits awkwardly against that expectation.

The practical takeaway is that the hygiene routine below serves two purposes at once. It protects deliverability, and it keeps the basis on which you are contacting people defensible.

Verification, enrichment and re-verification are three different things

These get used interchangeably and they do quite different jobs.

Verification asks whether an address is currently deliverable. It is a technical check against the receiving mail server and it is cheap, fast, and worth doing before every significant send. It tells you nothing about whether the person still works there or whether the title is right.

Enrichment fills gaps. You have a name and a company and you want an email, a title, a company size. It is what most people mean when they say data provider, and it is the step most teams do exactly once, at the point the record enters the system.

Re-verification is the one that gets skipped. It is going back to records you already have and checking whether the underlying facts are still true. Not whether the mailbox accepts mail, but whether this person is still in this role at this company. It is more expensive than verification and less exciting than enrichment, and it is where most of the actual value sits, because it is the only one of the three that addresses decay rather than just detecting its symptoms.

A useful mental model is that verification is a smoke alarm, enrichment is furnishing the room, and re-verification is checking whether anyone still lives there.

A maintenance routine that a small team can actually keep

The failure mode of every data hygiene article is that it describes a process requiring a dedicated operations person. Here is a version scaled to a team that does not have one.

Before every send: verify. Run the target segment through an email verification step immediately before the send, not as part of a monthly batch. This is cheap, takes minutes, and catches the records that died since you last looked. Remove anything that fails outright and anything flagged as risky or catch-all if your domain reputation is already fragile.

Every quarter: re-verify the top decile. You do not need to re-verify the whole database, and you should not try, because attempting it is how the task never gets done. Take the accounts that matter most, whether that is open opportunities, target accounts or anyone contacted in the last six months who engaged, and check whether those people are still in those roles. This is a few hundred records for most small teams, not tens of thousands.

Every six months: suppress the dormant tail. Any record that has been contacted three or more times across a long period with no engagement of any kind should be moved out of the active list. Not deleted, suppressed. It costs nothing to keep and it costs deliverability to keep mailing.

Continuously: capture the change signals you already receive. This is the free one and nobody does it. Out-of-office replies frequently name a replacement and a new contact. Bounce messages sometimes include a forwarding note. A rep hears on a call that someone has moved teams. All of this is high-quality, current data arriving for free, and in most small teams it is read once and discarded. Building even a rough habit of updating the record when this information arrives will outperform an expensive quarterly refresh.

Once a year: audit the company layer. Check your top accounts for acquisitions, domain changes and rebrands. This is a short exercise and it prevents the specific embarrassment of a personalised message addressed to a company that no longer exists under that name.

Deciding what to keep and what to let go

There is a hoarding instinct in sales databases that is worth naming. Records feel like assets, and deleting them feels like destroying value, so lists grow monotonically and never shrink.

A more useful frame is that an unverified record is a liability with an option attached. It might be worth something. It is definitely costing you sending reputation if you mail it. The question is not whether the record could theoretically be valuable, it is whether it is worth the deliverability risk of finding out.

Practically, this means being willing to suppress large blocks of the list without ceremony. A list of eight hundred verified, current contacts in your ideal customer profile will outperform a list of nine thousand accumulated records on every metric that matters, including total meetings booked, and it will do so while keeping your domain healthy enough to keep working next quarter.

The same logic applies to buying data. A smaller, more current dataset is worth more than a larger, older one, and the price per record is close to irrelevant next to the accuracy rate. Any provider unwilling to tell you how recently a record was verified is telling you something about how recently it was verified.

The signals your own system is already generating

Before buying anything, it is worth cataloguing the decay information your business already receives and throws away. In most small teams this list is longer than expected.

Out-of-office replies are the richest source. A well-configured one names a colleague, gives their address, and states whether the absence is temporary or permanent. A departure auto-reply is a complete data update delivered to you for free, and in most teams it is treated as noise to be filtered out of the reply inbox.

Soft bounces that repeat are a second source. A single soft bounce means very little. The same address soft bouncing across three separate sends over two months usually means the mailbox is full because nobody is reading it, which in practice means the person has gone even though the address technically still exists.

Website and product analytics give you a third. If a known contact from an account stops appearing entirely while other people from the same domain start showing up, something has changed on their side.

Then there are the human sources. A rep hears on a call that the person they have been chasing has moved to a different division. Someone mentions in a meeting that a target company has been acquired. Support gets a ticket from a new name at an existing account. All of this is current, accurate and specific, and it evaporates unless there is somewhere obvious to put it.

The habit worth building is not complicated. Whoever encounters the information updates the record then, in the same few minutes, rather than intending to do it later. The barrier is almost always that updating the record takes more clicks than it should, so the fix is usually to make that path shorter rather than to remind people harder.

What to look for in a data provider

If you do buy data, the questions worth asking are narrower than most vendor conversations suggest.

Ask when each record was last verified, and whether that date is exposed per record or only as a claim about the database average. An average is close to meaningless, because a provider can maintain a strong average by frequently re-checking a popular core while a long tail rots.

Ask what happens when a record is found to be wrong. Some providers refund or replace credits for hard bounces. Some do not. The policy tells you how confident they are.

Ask how they handle role changes specifically, since that is the fastest-moving field and the one least likely to produce a bounce. A provider that only tests deliverability is not detecting the majority of your decay.

Ask about coverage in your actual market rather than in aggregate. Global datasets are frequently thin on Australian and New Zealand mid-market companies while being excellent on North American technology firms, and a headline record count tells you nothing about the segment you sell into.

Finally, run a paid sample before committing to an annual contract. Take two hundred records in your core segment, verify them independently, and calculate the real accuracy rate. It is a small cost and it settles the question in a way that no vendor benchmark can.

Where tooling fits

Most of the routine above can be automated to some degree, and the parts worth automating are the repetitive lookups rather than the decisions.

The build-versus-buy question for small teams usually comes down to how often your list turns over. If you are working a stable set of target accounts, manual re-verification of a few hundred records each quarter is entirely feasible and costs only time. If you are continuously generating new prospect lists, doing it by hand stops being realistic quickly, and the enrichment and verification steps need to sit inside whatever tool is generating the list rather than being a separate manual stage afterwards.

Empiraa Signal handles this by putting enrichment in line with prospect discovery, so records are built current rather than assembled from a static file and cleaned later. The general principle holds regardless of tooling, though: data quality maintained at the point of entry is far cheaper than data quality restored after the fact.

The short version

Contact data goes off at somewhere around twenty per cent a year as a baseline, faster in high-turnover industries, and unevenly across fields, with titles and phone numbers ageing quickest.

The real cost is not the wasted sends. It is the damage to sending reputation, which quietly degrades the performance of the records that are still good, and which is usually misdiagnosed as a copy problem.

Verify before every send. Re-verify the accounts that matter every quarter. Suppress the dormant tail twice a year. Capture the change information already arriving in your inbox. And be willing to run a much smaller list than instinct suggests.

None of this is interesting work. It is the reason some teams' outbound keeps functioning in month nine while others are rebuilding their domain reputation from scratch.

Ash Brown

Ash Brown

Founder & CEO of Empiraa

Published 28 August 2026

Ready to fix the part of your business that feels messy?

Whether you're trying to execute strategy, grow pipeline, or connect the way your team works, Empiraa gives you a clearer system to run from.

GPS for strategy execution. Signal for sales growth.