Brand Logo

The Outbound Data Stack Checklist: 7 Steps From Raw List to Booked Meeting

2026-09-24 · Erin Watanabe

In March 2024, a client called me at 7:40 in the morning — ten days out from the end of Q1. Their SDR team had pushed 4,200 cold emails the week before on a list they'd bought from a data marketplace. Bounce rate came back at 31%. Google had started throttling their primary sending domain. They were three meetings short of quota and had just set fire to their best sending asset.

We spent the next 72 hours rebuilding their outbound data stack from the ground up. What follows is the checklist we ran, in order. It's the same seven steps I walk teams through when they're starting from scratch — the emergency version just compresses the timeline.

It's written for B2B sales teams, RevOps leads, and outbound agencies running cold email and cold calls into a defined ICP. If you're running pure inbound or PLG motions, roughly half of it won't apply to you. Seven steps. Here they are.

Step 1: Define "qualified" before you buy a single record

This is the step everyone skips because it doesn't feel like work. It is work. Before you open a data vendor's site, write down three things on one page: the firmographic filter (headcount, revenue band, region), the role filter (title, function, seniority), and the trigger you're looking for (a funding round, a hiring spike, a tech stack change).

It's tempting to think richer data is the problem and a bigger budget fixes it. But a $40K enrichment subscription pointed at the wrong ICP just produces faster wrong answers. I've watched two teams this year blow six figures on data contracts while their ICP definition was still "mid-market B2B, kind of."

Checkpoint: If you can't defend why a specific 200-person SaaS company in Austin is in your list and a 200-person fintech in Denver is not, your filter isn't done yet.

Step 2: Get honest about what a data enrichment API is — and when you actually need one

This is the question I get most from teams under 20 people, so let's answer it directly. A data enrichment API is a programmatic endpoint you send a partial record to — an email address, a domain, a LinkedIn URL — and it returns the fields you asked for: job title, company size, tech stack, recent funding, location, and so on. You call it from your CRM, your sequencing tool, or a script. It runs at list scale, not one row at a time.

When should a B2B sales team use one? Three situations, roughly:

  • You have 500+ existing CRM records with systematic gaps (bad titles, missing domains, dead emails) and no headcount to clean them by hand.
  • You're ingesting leads from multiple sources — webinar registrations, content downloads, event scans — and the fields arrive in inconsistent formats.
  • You want to route records automatically based on enrichment output (enterprise AE vs. SMB AE vs. nurture sequence).

When you should not use one: when you have 40 records and a spare afternoon. When the enrichment output isn't wired to any downstream decision. And when you're using it as a substitute for Step 1 — an API will happily enrich a bad list into a bigger bad list.

One more thing. Single-source enrichment misses a lot. Waterfall enrichment — querying multiple providers in sequence and taking the first solid hit — closes a meaningful chunk of that gap, which is why most modern stacks run it that way rather than betting on one vendor.

Step 3: Layer intent data on top, not underneath

Intent data is a ranking signal, not a qualification signal. It tells you which of your already-qualified accounts are showing buying behavior this week. It does not tell you whether an account was ever a good fit.

I don't have hard data on the exact reply-rate lift from intent alone — I wish I'd tracked it more carefully across the last two years. What I can say anecdotally is that intent changes sequencing priority more than it changes outcome. Teams that treat it as a tiebreaker between two qualified accounts get value. Teams that use it to skip qualification end up calling the wrong people with more confidence.

Practical order: enrich → filter by ICP → overlay intent → sequence the top tier first.

Step 4: Verify emails, then verify your sending domain — this is the step most teams skip

Everyone verifies emails. Almost nobody checks the domain that's actually sending them.

Email verification tells you whether an address is deliverable today. Deliverability is a different problem: it's whether Gmail, Microsoft, and Yahoo will let you into the inbox when you press send. You can have a 98% verified list and still get throttled, because deliverability is about your sending reputation, not the list's cleanliness.

The mechanics matter here. Gmail's bulk sender requirements, which took effect in February 2024, apply to anyone sending 5,000+ messages a day to Gmail addresses. The big four — authenticate with SPF, DKIM, and DMARC; keep your spam rate below 0.3% in Postmaster Tools; support one-click unsubscribe; and don't send to addresses that hard-bounced before.

Authentication standards in play: SPF (RFC 7208), DKIM (RFC 6376), DMARC (RFC 7489). DMARC alignment, not just presence, is what most filters check for.

The "buy a big list, filter it later" mentality comes from an era when filtering was the hard part. That's changed. Today the hard part is keeping your domain healthy while you send, and the filtering has been largely commoditized. Treat your sending domain as a piece of infrastructure, not a byproduct.

Checkpoint: Run your primary domain through a free DMARC checker. If you don't have a policy of at least p=none with alignment, fix that before your next campaign launches.

Step 5: Fill the direct dials gap — and decide who's allowed to use them

Direct dials are the most over-sold and under-managed record type in the stack. They're also the only signal that reliably converts to a live conversation when email is cold.

Two things I've learned the hard way. First, direct dial coverage varies wildly by industry and company size — SaaS and tech hover high; manufacturing, healthcare, and anything regulated run much lower. If your enrichment vendor claims uniform coverage, ask them to show it broken out by vertical.

Second, and this is the one teams ignore: decide who on your team is allowed to dial. I've watched an AE burn an account's goodwill by cold-calling a CISO on a personal mobile because the number was sitting in the CRM with no gating. Direct dials are a privilege, not a default field. Put them behind a role permission and a stated use policy, or don't pull them at all.

My experience here is based on roughly 60 mid-market B2B stacks in North America and Western Europe. If you're selling into APAC or heavily regulated verticals like finance and healthcare, your coverage numbers and consent rules will look different.

Step 6: Keep a human in the loop on the first touch

Full automation on the first reply is the fastest way to sound like everyone else. The first touch — the first sentence, the first call opener — is where the deal lives or dies, and it's also where generic sequencing gets exposed.

This is the gap that agent-native prospecting tools like okki-go's Agent-native workflow are designed for, and it's also where the human-in-the-loop model earns its place. The agent handles what humans are bad at: waterfall enrichment, deduplication, CRM hygiene, sequencing timing, mailbox rotation, and the fifty small data reconciliations between systems. The human handles what agents are still bad at: reading the reply, adjusting the angle, deciding whether to push or back off.

If you're running an okki-go AI BDR alongside human SDRs, the split I'd suggest is roughly 80/20 — 80% of the pipeline mechanics in the agent, 20% of the actual communication with the prospect in a human. Anything more aggressive usually reads as more aggressive to the prospect, and not in a good way.

What you should not expect: any tool being a full replacement for a RevOps team or an SDR bench. That framing sells software and loses deals.

Step 7: Measure against a metric that isn't reply rate

Reply rate is broken as a KPI. A domain getting throttled to spam folders can post an above-average reply rate because the only people who see it are the ones who opened it. Bounce rate doesn't tell you whether anyone read anything.

The metrics that actually move:

  • Positive reply rate — replies that ask a question, request a meeting, or forward to a colleague. Everything else is noise.
  • Meetings booked per 100 contacts — the only number an AE actually cares about.
  • Spam rate in Postmaster Tools — the leading indicator of a domain on its way to the penalty box.
  • Hard bounce rate — keep it under 2% or stop the campaign and re-verify.

Run these weekly. Monthly is too late.

Where this usually goes wrong

Every failed rebuild I've been called into shares at least two of these failure modes:

  1. Buying data before defining ICP. The list is a solution to a problem you haven't stated yet.
  2. Treating verification as the finish line. Email verification is table stakes. Domain health is the fight.
  3. Running intent data under the qualification layer. It ranks, it doesn't qualify.
  4. Opening the direct dials floodgates. No policy means no dignity, and dignity converts.
  5. Automating the first human moment. The agent should feed the human, not replace them at the exact point prospects are deciding whether you're a person or a script.

The fundamentals of outbound haven't changed since I started doing this — find the right person, say something true, follow up without being weird. The execution has transformed, and most of what was best practice in 2020 is now a way to get filtered. Build the stack in the order above and the fundamentals have a chance to breathe.