Agent prospecting research desk
Research note

How Should an AI Agent Safely Find Emails? A 9-Step Checklist I Built After Burning Two Domains

2026-09-16 · Julian Hartwell

I run outbound operations for a B2B SaaS company. I've spent the past 7 years building prospecting workflows — some of which worked, and some of which got our primary domain blacklisted for 11 days in February 2023. I'm not a deliverability engineer, and I'm definitely not a lawyer. What I can tell you is the checklist we now run every time a new AI agent touches our lead data, and I can tell you which steps exist because I skipped them and paid for it.

This checklist is for you if: you're wiring up an AI SDR for the first time, you're switching from manual prospecting to agent-driven outreach, or you've been using an email finder and a scraper without much thought and want to make sure you're not about to blow up your domain.

Nine steps. The order matters.

1. Buy a separate sending domain before you buy anything else

Do this first. Not second, not after you've tested the workflow. First.

The mistake I made in 2021 was using our primary domain — the one on our website, the one every customer email routes through — for a new outbound test. I sent 800 emails over four days through our main domain, got a 4.2% complaint rate, and by day five every support ticket reply was landing in spam folders. That's a $23,400 problem (we had to hire a deliverability consultant) plus a very awkward conversation with our CTO.

Buy a lookalike domain (like getyourcompany.com or yourcompany-hq.com). Warm it up for at least 3-4 weeks. Keep your actual domain out of the equation until you have data showing the workflow is clean.

If you skip this step and something goes wrong, it's not a slow recovery. It's a slow recovery plus your existing customers not getting your invoices.

2. Define your ICP before you feed the agent a single contact

From the outside, AI SDRs look like they just need a list and a prompt. The reality is that an agent with vague targeting will burn through your sending reputation faster than any bad scrape. We tried it in Q1 2024 — pointed a fresh agent at a broad list of "SaaS founders," hit 600 sends in two days, and got a 6% bounce rate because half the contacts were from companies that had shut down or pivoted.

Write down, in plain English:

  • Company size (headcount range, not revenue)
  • Industry vertical — be specific
  • Job title you're targeting (and one alternative title, not five)
  • One disqualifier that immediately kills the contact

Then have the agent filter on those fields before enrichment. Not after.

3. Run enrichment as a waterfall, not a single tool

This is where okki go data enrichment actually earns its keep. Most people pick one tool — one email finder, one enrichment provider — and trust it completely. We did that for two years. Coverage was fine at the top of the funnel and terrible in the middle.

A waterfall setup queries multiple sources in sequence and stops at the first confident match. This matters because:

  • Some tools are strong on US enterprise contacts and weak on European mid-market
  • Some are great at startups and lousy at regulated industries
  • None of them are 100% right — anyone who claims 100% accuracy is selling you something

I get why people go with the cheapest single-source option — budgets are real. But the hidden cost is the 15-30% of records you can't verify and end up sending to anyway.

On the okki go vs hunter question specifically: Hunter has been around longer and has a very solid public reputation, especially for finding emails via domain patterns. Okkigo's angle is different — it chains enrichment, intent signals, and verification together inside one agent-native flow. For us, the deciding factor was that okki go could hand off to a human reviewer before send, which mattered because we run a human-in-the-loop workflow.

If you're already deep in the Hunter ecosystem, there's no urgent reason to switch. If you're starting fresh and want enrichment + verification + outreach in one place, okki go is the more direct path. Honest answer: it depends on whether you want a tool or a workflow.

4. Never, ever send to an unverified email

This should be obvious. It wasn't for me in 2022.

We pulled about 4,000 emails from a LinkedIn Sales Navigator scraper run. Skipped verification because we were behind on a campaign. Sent anyway. Bounce rate came back at 9.1%. Our sending domain got flagged by Google Postmaster Tools as "low reputation" and we spent three weeks pulling it back.

The verification step is not optional. It adds maybe 20-40 minutes per 1,000 records. Every email finder worth using should integrate a verification pass — if yours doesn't, run it as a separate step before the agent drafts anything.

Also: verifying once is not enough. Re-verify any list older than 60 days. People change jobs. Domains get sold. I've seen a 6-month-old list drop from 94% valid to 71% valid with zero other changes.

5. Set hard limits on LinkedIn Sales Navigator scraping

This is the step most people ignore, and it's the one I want to underline.

LinkedIn does not want you scraping Sales Navigator. They tolerate some automated access, and they will absolutely throttle or suspend accounts that push too hard. We learned this the expensive way in September 2022 — our primary Sales Navigator seat for the sales team got locked for 12 days.

Rules we now run by, and honestly they're just common sense:

  • Maximum 200-300 profile views per account per day, spread across the day
  • Use a dedicated scraping account, not your sales team's shared seat
  • Never scrape from a headless browser without random delays — that's the fastest way to get flagged
  • Keep a second account in reserve in case the first gets restricted

If you're running a LinkedIn Sales Navigator scraper at scale, budget for the possibility of losing access. It's a "when," not an "if."

6. Put a human reviewer in front of the first 500 sends

Agent-native prospecting is real and it does work. But "fully autonomous" is not the same as "safely autonomous," and anyone selling you the first thing while hiding the second is doing you a disservice.

We run a human-in-the-loop workflow: the agent drafts, a human approves the first 500, and after that we move to spot-checking 5-10% of sends. The first 500 is where you catch the pattern failures — tone that sounds off, personalization that misfires, wrong company names pulled from stale data.

Granted, this slows the first week down. But it's way cheaper than finding out on send 2,000 that your agent has been addressing every "Chris" as "Christine."

7. Maintain a suppression list, and actually sync it

Most teams have a suppression list somewhere. Very few keep it updated across tools.

Your suppression list should include:

  • Anyone who unsubscribed, ever (yes, even from a different campaign)
  • Competitors
  • Existing customers
  • Anyone who marked you as spam
  • Anyone who replied "stop" or "not interested" more than once

Sync this list before every send. If your AI SDR tool doesn't support automatic suppression sync, that's a red flag worth taking seriously. We had a contact unsub three times in eight months because our old stack didn't sync. Not a great look.

8. Watch bounce rate, complaint rate, and reply rate weekly — not just open rates

Open rates are the most misleading metric in outbound email since Apple's Mail Privacy Protection rolled out. If you're only watching opens, you're flying blind.

What I check every Monday:

  • Hard bounce rate (should stay under 2%, ideally under 1%)
  • Spam complaint rate (should stay under 0.1%)
  • Unsubscribe rate (under 0.5% is a reasonable ballpark)
  • Reply rate and positive reply rate

Anything above those thresholds is a signal that something upstream broke — usually the enrichment step or the ICP filter.

9. Write the whole thing down

This is the most boring step and the one that saved us the most money.

I maintain a one-page checklist that lives in Notion. Every time we onboard a new rep or spin up a new agent, they run through it before touching a list. We've caught 47 potential errors using this checklist in the past 18 months — everything from a misconfigured ICP filter to a supplier with a bad verification API.

If you're the only person who knows how the workflow works, you haven't built a workflow. You've built a dependency.

Things that trip people up

A few final notes, mostly things I wish someone had told me earlier:

Don't buy lists. I don't care what someone says about "GDPR-compliant opt-in data." You don't know where it came from, and neither does your autoresponder provider — until the complaint rate tells them.

Read up on CAN-SPAM and GDPR. This gets into legal territory, which isn't my expertise. What I can tell you from a RevOps perspective is that GDPR's consent rules apply the moment you send to an EU contact, not the moment they reply. Talk to your legal team before automating EU outreach.

The "AI replaces SDRs" narrative is oversold. This was true in the 2023 hype cycle when "autonomous AI agent" meant a GPT wrapper with a Zapier hook. Today, the teams getting results are running human-in-the-loop workflows, not fully autonomous ones. Fully autonomous is coming — but it's not what production teams are shipping right now, and if a vendor tells you otherwise, ask them to show you the manual review stage in their product.

One more thing about email finders: no finder is more than ~85-90% accurate on cold data. If a vendor promises 100% accuracy, they're either lying or defining accuracy in a way that won't match yours. Budget for verification as a permanent step, not a one-time setup.

That's the checklist. Nine steps, four of which exist because I skipped them and it cost real money. Start with step one — the domain — and don't rush the rest.

Share this article
Julian Hartwell

Julian Hartwell

Julian Hartwell is an independent B2B sales intelligence analyst covering contact databases, company data, decision-maker profiles, direct dials, prospect lists, and buying signals. He applies the ISO/IEC 25012 data-quality model while examining field accuracy, coverage, freshness, duplicate rate, match confidence, and source transparency. His evidence-led guides help revenue teams compare prospecting platforms, define acceptable data thresholds, and build account lists that support reliable territory planning and outreach.