You sent a marketing email to a Brazilian address. It went through. But did you know that one single non-consented email sent to a Brazilian recipient could trigger a regulatory investigation — and potentially a R$50 million fine?

That’s the reality under Brazil’s LGPD. Your email list isn’t just a tool for outreach — it’s a legal contract. If you didn’t secure explicit, documented consent, you’re not just sending spam; you’re violating data protection law. The risk isn’t theoretical. It’s real, enforced, and escalating.

Under LGPD, consent must be clear, specific, and recorded. A checkbox in a form that says “I agree to receive marketing emails” isn’t enough if it wasn’t opt-in by default, wasn’t granular, or wasn’t logged. No more implied consent. No more “default opt-in.” If your list includes Brazilian addresses and you didn’t verify this, you’re exposed.

Key takeaways

  • LGPD requires explicit, documented consent for any marketing email sent to a Brazilian recipient — vague or implied consent is invalid.
  • Violations can result in fines up to 2% of annual revenue, capped at R$50 million per incident, regardless of volume.
  • Tracing a single non-consented email to your domain may trigger enforcement, even if only one address was involved.

Under Brazil’s LGPD, consent isn’t just a checkbox—it must be active, specific, and revocable. You can’t pre-tick boxes or bury opt-ins in lengthy terms. Users must take a deliberate action, know exactly what they’re agreeing to, and be able to withdraw consent anytime—no delays, no hoops. This isn’t just best practice; it’s the law.

Passive acceptance—like a pre-checked box during sign-up—doesn’t count. LGPD demands that users actively choose to opt in. Let’s say you’re collecting email addresses for newsletters. The user must click a checkbox labeled “Yes, I want marketing emails about new products” rather than having it filled for them. This aligns with global standards like GDPR and is enforced by Brazil’s data protection authority (ANPD). According to ANPD’s guidelines, consent must be “freely given, specific, informed, and unambiguous.” The same principle applies to SMS, social media, and any data use beyond essential service delivery.

Specificity and Revocability

Consent must clearly state what data is collected, how it will be used, and which channels it will go to—email, SMS, retargeting, etc. Vague language like “We may use your data for marketing” isn’t enough. You must be explicit: “We’ll send you monthly product updates via email only.” And crucially, users must be able to revoke consent at any time. This means every marketing email must include a clear, working unsubscribe link—same as U.S. CAN-SPAM and EU GDPR. If your system cannot handle revocation across all channels, you’re violating LGPD.

Even after consent is withdrawn, your records must be updated and the data stopped from being used. If you’re storing data for analytics or customer history, you must still honor the request to stop marketing usage. If you’re unsure whether your consent process meets LGPD, test it. Use inbox placement tools like MailTester’s inbox tester to see how your messages land in real inboxes—this helps ensure your opt-out mechanics aren’t failing due to spam filters.

For large-scale campaigns, verify your list first. Use MailTester’s bulk verification to weed out invalid or inactive addresses before sending. It can help identify risky or unverifiable emails that could signal weak consent patterns or outdated data, reducing your exposure to violations. Keep data clean. Keep consent valid. Keep your marketing compliant.

How to Verify LGPD Compliance Before Sending Marketing Emails

You must confirm every Brazilian subscriber gave explicit, documented consent with a timestamp and IP address before emailing them. Each contact on your list must have a recorded 'yes' on file, not just a form submission. Use a verified email validation tool to purge invalid, disposable, or role-based addresses that could invalidate consent records and expose you to LGPD penalties. This ensures your list is both legally sound and deliverable.

  • Check that every email address has a dated consent form on file with a clear 'yes' acknowledgment.
  • Ensure timestamps are recorded in UTC or local Brazilian time to support compliance timelines.
  • Validate IP addresses were captured at the time of signup, not retroactively assigned.
  • Store consent evidence in a secure, immutable record—never just in a CMS or CRM with weak audit trails.

Clean Your List with Real-Time Verification

  • Use a tool like MailTester’s bulk verification to remove invalid, disposable, and role-based emails that can’t provide genuine consent.
  • Disposable emails (like tempmail.org) are often used to bypass consent and are not suitable for marketing under LGPD.
  • Role-based addresses (e.g., sales@, info@, admin@) are not valid for individual consent and should be excluded.
  • Verify your entire list with MailTester’s API in real time to maintain compliance during ongoing campaigns.
  • Test delivery in real inboxes using MailTester’s inbox placement tool to ensure your messages land in the inbox, not the spam folder.
Under LGPD, silence or pre-ticked boxes do not constitute valid consent. Every opt-in must be affirmative, unambiguous, and documented.

Even if your form says "yes," it’s not enough if the email is invalid or disposable. A single bad address can trigger a compliance audit. LGPD fines can reach up to 2% of global annual revenue—up to R$50 million per violation. The most effective way to avoid this is to verify all addresses before sending.

Tools like MailTester do more than check syntax. They use real-time SMTP validation and sender reputation analysis to flag risky addresses. This reduces your bounce rate, protects sender reputation, and ensures only consenting, valid recipients receive your messages.

For seamless integration, use MailTester’s native integrations with platforms like Mailchimp, HubSpot, and Klaviyo to automate verification at signup or campaign launch. All credits are permanent—no expiry, no wasted spend.

You need email verification to meet Brazil’s LGPD requirements not just for deliverability, but to ensure that every email in your list is valid, consented-to, and not a placeholder like a catch-all or disposable address. A 98.9% accurate verification process flags invalid, catch-all, and risky addresses early—helping you avoid sending to users who never gave real consent, which could lead to regulatory penalties under LGPD.

Some domains accept any email address—these are catch-all domains. They’ll deliver mail to any address, even if it doesn’t exist. That means an email on a catch-all domain might be technically valid, but no actual person ever opted in. You can’t verify consent if there’s no real user behind the address. These should be removed from your list.

Using a tool like MailTester’s bulk verification helps identify these domains automatically. If a domain is catch-all, the tool flags it and prevents you from sending messages to unconfirmed recipients—protecting your compliance posture under LGPD.

Disposable email addresses are created for one-time use and often abandoned after. They’re commonly used for quick opt-ins but are a red flag for consent. If a user signs up with a disposable email, there’s no real intent to receive ongoing communications. Worse, these domains can be used to game systems or spoof identities.

MailTester detects disposable domains and marks them as high-risk. You should exclude these during list hygiene. Sending to them violates the spirit—and often the letter—of LGPD, which requires that consent be both active and ongoing.

Real consent comes from verified, real users, not placeholder emails. Tools that verify at scale help you maintain a clean, compliant list. The MailTester API integrates with your CRM or signup tools to check every new address in real time—preventing risky or invalid emails from ever entering your sender pool.

LGPD isn’t just about privacy—it’s about trust. That trust starts with knowing who you’re sending to. For more on how to test deliverability and inbox placement, see MailTester’s inbox placement tester. The best way to stay compliant? Start with a list you can verify, not just a list you can send to.

Why Bulk Email Verification Is Non-Negotiable for LGPD Compliance

If your email list contains invalid or high-risk addresses, your consent records are legally weak—no matter how careful you were at signup. Under Brazil’s LGPD, sending marketing emails to invalid or unverified addresses undermines your legal basis for processing personal data. A single malformed address doesn’t just cause a bounce; it risks non-compliance by implying consent where none was validly given.

Verify Your List Before You Send

  1. Run a bulk verification before every campaign. Use MailTester’s bulk email verification to process thousands of addresses in minutes. It identifies invalid, risky, and disposable domains—cutting down on hard bounces, spam traps, and invalid consents.
  2. Check for common data faults. Invalid addresses (e.g., missing @ symbol, malformed domains) and catch-all domains (which accept any email) do not represent real users. Sending to them breaks consent integrity under LGPD’s requirement for accurate, valid data processing.
  3. Flag high-fraud-risk addresses. MailTester detects disposable and temporary domains (like mailinator.com or temp-mail.org), which are commonly used for fake signups. These addresses don’t represent genuine users and can trigger spam complaints, harming sender reputation.
  4. Integrate with your sending platform. Connect MailTester directly to Mailchimp, HubSpot, or SendGrid via our integrations to automate verification before every send. This ensures your list stays clean without manual steps.
  5. Validate consent records with clean data. Only addresses confirmed as valid and deliverable can be deemed compliant. Clean lists = stronger consent records = real compliance.

Why This Matters for LGPD

The LGPD requires that personal data be processed in ways that ensure accuracy and legitimacy. A list with high invalidity rates undermines claims of informed consent. According to Brazil’s National Data Protection Authority, processing data without verification violates the principle of integrity and confidentiality. Even if you collected consent legally, poor data hygiene can still expose you to fines and enforcement action.

In practice, sending to 15% invalid addresses means one in seven consents isn’t even valid—each one a potential compliance liability. Tools like MailTester prevent this by using industry-standard checks: SMTP validation, DNS lookup, and domain reputation analysis, all without contacting recipients.

Start with a clean list. Use bulk verification to process your data. Automate it with integration partners. The result? A compliant, trustworthy email program built on reliable data. No exceptions.

How Real-Time Verification Prevents LGPD Violations

When you validate every email in real time at signup, you stop invalid or fake addresses from ever entering your system. LGPD requires explicit, documented consent for data processing—but claiming consent for an address that doesn’t exist is a violation. Real-time verification stops this before it happens. You don’t just collect data—you collect only what’s valid and legitimate. That’s how you protect your business.

  • Use the MailTester API to verify every email as it’s entered—before it hits your CRM or email platform.
  • Each verification returns a clear verdict: valid, invalid, catch-all, or risky. You act on the result immediately.
  • If an address fails validation, reject it on the spot—no consent form gets signed for a non-existent email.
  • LGPD treats non-existent addresses as a breach when consent is claimed. This practice ensures your records are only tied to valid, deliverable inboxes.
  • Many marketers mistakenly believe consent is just a checkbox. It isn’t. It’s tied to actual communication capability. Real-time checks prove you’re not processing data you can’t reach.
  • Integrate MailTester with tools like Mailchimp, HubSpot, or Klaviyo via the MailTester integrations to automate this layer of compliance across your stack.
  • For added confidence, run inbox placement tests with the MailTester Inbox Tester to see if your future sends actually reach inboxes—no false confidence in delivery.
  • Even role accounts (like admin@ or sales@) can be risky. They aren’t necessarily invalid, but they aren’t personal either. Real-time checks flag these as risky so you can evaluate them carefully before assuming consent.
  • Disposable domains and temporary addresses are common in spam and fraud. The API catches these early—no need to worry about LGPD complaints from a fake maildrop.
  • Under Article 17 of LGPD, data processing must have a valid legal basis. If you can't deliver to an address, you’ve failed the "purpose limitation" test. Real-time verification proves you only process data with a real, functioning endpoint.
  • Data accuracy isn’t just a hygiene practice—it’s a compliance obligation. Research on data governance in Latin America shows that inconsistent data quality directly correlates with regulatory non-compliance.

Why This Matters for LGPD

LGPD is not just about consent—it’s about accountability. If you claim someone opted in, you must be able to deliver to that address. If you can’t, the data processing fails. Real-time verification ensures that every contact you store is both valid and reachable. That’s not just good hygiene. It’s compliance.

“A consent record is only valid if the data can be used for its intended purpose.” — LGPD Compliance Framework, Brazil’s Data Protection Authority

LGPD treats role-based emails like sales@, info@, or admin@ as non-personal endpoints, meaning consent cannot be assumed—even if they’re used for sign-ups. Sending marketing emails to these addresses violates LGPD’s requirement for valid, individualized consent. MailTester flags them as high-risk, helping you avoid legal exposure and deliverability issues.

Under Brazil’s LGPD, data must be tied to a specific individual to be processed legally. Generic addresses don’t meet that standard—you can’t prove that a person named João Silva consented to marketing via [email protected]. Even if these accounts are used to collect sign-ups, the lack of personal data means no valid consent was captured.

Role accounts are common in B2B and lead-generation flows, but they’re a compliance blind spot. The same email can be accessed by dozens of people, making tracking consent impossible. Sending to them doesn’t just risk invalid consent—it increases the likelihood of spam complaints, which hurt sender reputation and trigger filter blocks.

Detecting and Avoiding Risk with Real-Time Verification

MailTester’s email verification engine identifies role accounts by analyzing patterns in the address structure, domain behavior, and mailbox response logic. It doesn’t guess—this detection is based on established industry practices for distinguishing personal from role-based addresses.

When you verify a list using MailTester's bulk verification tool, it returns a verdict: "valid," "invalid," "catch-all," or "risky" — specifically marking role accounts as high-risk. This gives you a clear signal to exclude them from campaigns.

For developers, MailTester’s real-time verification API integrates directly into signup flows, filtering out role addresses before they reach your inbox. For ongoing campaigns, inbox placement testing confirms not just delivery, but whether your content lands in the inbox—critical when building trust with regulators.

LGPD compliance isn’t about checking boxes. It’s about proving you process data legally, with documented consent. Using automated tools like MailTester to eliminate role-based addresses from your campaigns is a practical step toward demonstrating that standard.

More on data protection frameworks: the RFC 5322 standard defines email address syntax and usage, while the Brazilian Secretaria de Direitos Humanos oversees LGPD enforcement. Always validate assumptions with technical verification—not just policy reading.

How to Test Inbox Placement Before Launching LGPD-Compliant Campaigns

You can’t trust consent if your email never reaches the inbox. Before sending to a new list segment under Brazil’s LGPD, run an inbox-placement test using MailTester’s real-time delivery simulator. It checks how your message behaves across Gmail, Outlook, Yahoo, and other major providers—assessing spam scores, routing, and actual inbox placement. This step ensures your compliance doesn’t fail on delivery.

Test Deliverability Before You Send

  1. Run a mock send to your target list using MailTester’s inbox-placement tool. It sends your message to real email providers as if you were the sender, not a tester. This mimics actual delivery conditions.
  2. Review spam scores and routing. The tool shows you how each provider evaluates your message. High spam scores or delivery delays may signal issues with content, sender reputation, or infrastructure.
  3. Confirm inbox placement. The test reveals whether your email lands in the inbox, spam, or junk folder. If it lands in spam, even a valid consent record fails in practice.
  4. Fix issues before launch. Common red flags include poor authentication (SPF/DKIM/DMARC), misleading subject lines, or trigger words. Revisit your setup before sending a full campaign.

Why This Matters for LGPD Compliance

LGPD requires consent to be “free, specific, informed, and unambiguous.” Landing in spam breaks that requirement. A recipient may never see a consent reminder, which makes the consent ineffective in practice. According to research from Return Path, up to 15% of legitimate emails never reach the inbox—many because of poor deliverability hygiene.

Even with a clean list and documented consent, poor inbox placement nullifies effort. Use MailTester’s inbox-placement test to verify your message actually arrives. It’s not just about sending—it’s about ensuring your compliance is active, visible, and trusted.

Use a tool like MailTester’s Inbox Tester to simulate real delivery. It works for cold lists, re-engagement campaigns, and new segments. You’ll catch issues before they hurt deliverability or compliance.

Once you've verified deliverability, you can move forward knowing your LGPD-compliant emails will actually be seen. That’s the foundation of trust in email marketing.

LGPD vs. GDPR: Key Differences for Email Marketing

Both LGPD and GDPR require consent for marketing emails, but LGPD is stricter: it does not allow exemptions for transactional emails, meaning every marketing message needs explicit consent. Unlike GDPR, LGPD has no ‘legitimate interest’ loophole—consent is mandatory for all non-essential email communication. Even if you're outside Brazil, LGPD applies if you process data of Brazilian residents.

Under GDPR, you can sometimes rely on legitimate interest as a legal basis for marketing emails—LGPD doesn’t allow that. If you’re sending promotional messages to someone in Brazil, you must have their clear, documented consent. The law treats marketing and transactional messaging equally when it comes to consent requirements.

For example, even a confirmation email after a purchase can't include promotional content without prior consent under LGPD. This means your welcome email series, post-purchase offers, or re-engagement campaigns all require opt-in permission. Let’s not assume your existing list qualifies—many do not.

Consent under LGPD must be specific, informed, and freely given. This means pre-ticked boxes or implied consent aren’t valid. You must show users what they’re agreeing to, and they must opt in actively.

Global Reach, Strict Liability

LGPD applies to any organization that processes personal data of individuals in Brazil—even if you’re based in the US, Europe, or Asia. The law has extraterritorial reach, similar to GDPR, but with a broader scope in some areas.

For example, if your email campaign includes a Brazilian resident’s address—whether from a purchase, a form, or a purchased list—you’re subject to LGPD. Penalties for non-compliance can reach up to 2% of annual revenue, capped at 50 million BRL per violation, meaning significant financial risk.

You can verify your email list for validity and compliance risks using real-time checks. Tools like MailTester’s bulk verification help catch invalid or likely fake addresses before you send, reducing bounce rates and protecting sender reputation. The inbox placement test simulates real-world delivery to check how your campaigns land across major providers.

How to Clean Your List Using MailTester’s Accuracy Guarantee

You can start cleaning your Brazil LGPD-compliant email list today with 100 free verifications. Run your current list through MailTester’s real-time API to flag invalid and risky addresses—these are breaches of LGPD's consent and data accuracy requirements. Remove them immediately. Use the in-app AI assistant to spot patterns in non-consenting or outdated entries. This process reduces legal risk and improves deliverability. For more on data protection standards, see the Brazilian National Data Protection Authority (ANPD) guidelines.

  1. Begin with 100 free verifications at MailTester’s pricing page. You don’t need to commit. This lets you test your list without risk.
  2. Use the real-time verification API to batch-process your list. It checks each address against SMTP, MX, and domain-level rules—no guesswork, just accuracy.
  3. Review the results. Any address marked as invalid or risky should be removed. These are often outdated, non-existent, or high-failure risks—violations under LGPD’s requirement for accurate, purpose-limited data.
  4. Run a second pass using the bulk verification tool. It shows you the full breakdown: how many invalid, risky, catch-all, and valid addresses you have. Use this to quantify risk.
  5. Now, turn to the AI assistant. It analyzes your list for signals of outdated consent—like long inactivity, high bounce rates, or role-based addresses (e.g., admin@, support@). These might indicate lack of valid opt-in.

Why This Matters for LGPD Compliance

LGPD doesn’t just require consent—it demands data accuracy and ongoing validity. Sending to an invalid address isn’t just wasteful—it’s a privacy risk. Under Article 11, processing of data requires ongoing compliance. Invalid or outdated entries violate that principle.

The AI doesn’t guess. It identifies high-risk clusters—like emails from a specific region, a long-unchanged segment, or addresses with a recent history of bounces. These may not be legally invalid, but they’re poor candidates for marketing. Removing them improves both compliance and inbox placement.

Use inbox placement testing after cleaning to confirm your list now reaches inboxes. It’s the final validation: not just "can you send," but "does it land."

“Data protection is not a compliance checkbox—it’s a continuous operation.” — ANPD Framework, 2023

By combining technical verification with AI-driven insight, you reduce both legal exposure and wasted sends. You’re not just cleaning a list—you’re building a compliant, trusted relationship engine.

Final Steps: Building an LGPD-Compliant Email Marketing Workflow

True compliance isn't just about having consent — it's about proving it is valid, current, and verifiable. Use MailTester in your sign-up flow to check both the address and the intent behind the subscription, ensuring each record is active and authorized.

Regularly clean your list. Schedule weekly or monthly bulk verification to catch invalid, outdated, or non-responsive addresses before they become compliance risks. This preserves sender reputation and reduces bounce rates.

LGPD mandates data minimization. When someone unsubscribes, remove their data entirely — don’t just mark it as inactive. Use MailTester to detect and flag unsubscribed users to maintain compliance and avoid unnecessary data retention.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Does LGPD require opt-in for every marketing email sent to Brazil?

Yes. Every marketing email sent to a Brazilian resident must be based on explicit, documented consent.

Can I use old customer data for email marketing under LGPD?

Only if you can prove consent was collected in a compliant way, with clear purpose and revocability.

How do I know if an email address is valid under LGPD rules?

Use a tool like MailTester to validate addresses—invalid or catch-all domains cannot support legitimate consent claims.

You risk fines up to R$50 million per incident and enforcement actions by Brazil’s data protection authority.

Are disposable email addresses allowed under LGPD?

No. Disposable domains are not suitable for long-term consent records and should be excluded from marketing lists.

Does LGPD apply to B2B companies emailing in Brazil?

Yes. LGPD applies to any entity processing personal data of individuals within Brazil, regardless of business model.

Yes, but it must be unambiguous, active, and not pre-checked. It must also clearly define the purpose of data use.

Keep a record of sign-up timestamps, IP addresses, and user actions—ideally stored in a compliant system.

Does MailTester help me comply with LGPD?

Yes. By identifying invalid, role-based, and disposable addresses, MailTester reduces the risk of non-compliant sends.

Do I need to verify every email before sending?

Yes, especially when sending to Brazil. Verification helps prevent accidental sends to invalid or non-consenting addresses.

What is the risk of sending to a catch-all domain under LGPD?

Catch-all domains accept any address, making consent verification impossible. Sending to them can violate LGPD's consent requirement.

Are there penalties for sending marketing emails to an email that was once valid?

Yes. If consent was not properly documented or revoked, sending to an old address—even if once valid—creates legal exposure.