Lead generation

B2B Lead Generation: A Practical Guide

How to build a B2B lead list that actually converts — where the data comes from, which sources are worth your time, how to verify it, and what to do with it once you have it.

Most guides on this subject describe a funnel and stop. This one describes the plumbing: where B2B contact data actually comes from, what each source is good for, why so much of it is wrong, and how to end up with a list you can send to without burning your domain.

It is written from the inside. We build a tool that does this, so we know exactly where the process breaks — including the parts that no tool can fix.

What "lead generation" actually means

The phrase covers two very different jobs that get muddled constantly:

Demand generation is making people want what you sell — content, ads, SEO, events. It is slow, compounding, and expensive to start.

Outbound prospecting is finding people who fit your customer profile and contacting them first. It is fast, controllable, and completely dependent on data quality.

This guide is about the second one. If you have no customers yet, outbound is usually the only lever that moves in week one, because it does not require anyone to have heard of you.

Step one: define the profile before you collect anything

The single biggest waste in outbound is collecting 5,000 contacts and then deciding who to sell to. Do it the other way round.

A usable profile has four parts:

Part Example Why it matters
Business type Dental clinics Determines which source has them
Geography Miami, Fort Lauderdale, Orlando Determines volume and language
Size signal Independent, 1–3 locations Determines whether your pitch lands
Buying trigger Recently opened, hiring, running ads Determines reply rate

The first two are easy to search on. The third and fourth usually have to be inferred or filtered after collection — and they are where most of the reply-rate difference lives. A generic message to a perfect-fit business beats a clever message to a bad-fit one, every time.

Write the profile down as a sentence: "Independent dental clinics with one or two locations in South Florida that have a website but no online booking." Now every collection decision has an answer.

Step two: pick sources that match the profile

There is no single database of businesses. Different kinds of company are visible in different places, and picking the wrong source is why lists come back half-empty.

Google Maps is the default for anything with a physical location — clinics, restaurants, trades, retail, gyms, law firms, garages. Almost every local business has a listing, and each listing links to a website. It has no email field, so the email has to come from the website behind it. That path is covered in detail in how to find business emails from Google Maps.

Web search catches businesses that have a website but no map presence — agencies, consultancies, SaaS, e-commerce, anything remote-first.

LinkedIn is where you find people rather than companies: a role, at a company, right now. It is the only mainstream source where "Head of Growth at a 40-person agency" is a searchable thing. See finding B2B leads on LinkedIn without Sales Navigator.

Instagram, TikTok and YouTube are where you find creators, studios, boutiques and personal brands — businesses that never built a proper website because their profile is the website. Different game, different tactics: see finding creators and influencers by niche.

Yelp, Facebook Pages and Shopify fill specific gaps — hospitality, community businesses, and online stores respectively.

Directories and association member lists are underrated. A trade association's member directory is a pre-qualified list of exactly one kind of business, usually with contact details already published.

The practical answer is to run several at once and de-duplicate, because coverage overlaps unpredictably. A dental clinic might be on Maps but not Yelp; the next one is on both; the third has only an Instagram.

Step three: get from "a business exists" to "here is an address"

This is the step everyone underestimates.

A source gives you a name, a category, sometimes a phone number, and — if you are lucky — a website. It does not give you an email. The email is on the business's own website, usually on a contact page, an about page, or a legal imprint page. Getting it means visiting the site and reading it.

At small volumes you do that by hand: two to three minutes each, so 200 businesses is a full working day and the last hour of it is riddled with mistakes. At any real volume you automate it, which means dealing with the reasons naive automation fails:

  • Obfuscation. A meaningful share of sites hide their address from exactly this kind of collection — rendering it as an image, splitting it across HTML elements, or using Cloudflare's email protection. It looks normal to a human and is invisible to a naive scraper.
  • The wrong page. The address is rarely on the homepage. It is behind /contact, /about, /impressum, /kontakt, or in the footer of every page.
  • The wrong address. Sites are littered with example@ placeholders, the web developer's own address, and image-hosting noise that pattern-matches as an email.
  • Role accounts. info@, contact@ and hello@ are real and reachable but land in a shared inbox. They convert worse than a named address and better than nothing.

Expect a contactable address for roughly one third to two thirds of what a search finds, depending on the industry and the country. Anyone promising more than that is either counting guesses as data or selling you a stale database.

Step four: verify before you send, not after

An unverified list is a domain-reputation liability. Mailbox providers treat a high bounce rate as the clearest signal that a sender is working from purchased or scraped data, and the penalty lands on your sending domain — not on the list.

Verification has three levels, each stricter than the last:

  1. Syntax — is it a structurally valid address, and is the domain a real domain rather than a typo?
  2. MX record — does the domain publish a mail server at all? A domain with no MX cannot receive mail, full stop.
  3. SMTP probe — does the mail server acknowledge that specific mailbox, without a message being sent?

The third is where "valid", "risky" and "invalid" come from, and where the nuance lives. Plenty of servers accept every address you ask about (a catch-all) which is why "risky" exists as a category and why treating it as either valid or invalid is wrong. The whole mechanism is unpacked in email verification explained.

Delete the invalids. Send to the valids. Decide deliberately about the risky ones — usually by sending to them separately, from a different domain, so a bad batch cannot damage your main one.

Step five: send in a way that survives

A perfect list still fails if the sending setup is wrong. In short:

  • Authenticate the domain with SPF, DKIM and DMARC before the first send.
  • Send from a domain you are willing to lose — not your primary company domain.
  • Warm it up over weeks, not days.
  • Keep daily volume low per mailbox and add mailboxes rather than raising volume.
  • Make it trivially easy to opt out, and honour it instantly.

Each of those has failure modes worth understanding properly, and they are covered in the cold email deliverability guide. The message itself — what actually earns a reply — is in cold email templates that get replies.

What good looks like, numerically

Rough shape of a healthy outbound motion, for calibration rather than as a promise:

  • Bounce rate under 2%. Above 5% and you are damaging your domain with every batch.
  • Open rates are unreliable now that Apple Mail Privacy Protection pre-fetches images. Stop optimising for them.
  • Reply rate is the real metric. A well-targeted list with a relevant, short message lands in low single-digit percentages. Anything dramatically higher usually means a very narrow, very well-chosen list.
  • Positive reply rate — replies that are not "no" — is what actually predicts revenue.

If your reply rate is near zero, the problem is almost always targeting, not copy. Rewrite the profile before you rewrite the email.

The mistakes that cost the most

Buying a static database. It was collected once, by someone else, for everyone. B2B contact data decays fast — people change jobs, businesses close, domains lapse. You are buying a snapshot of an unknown age, and so is everyone else who emailed that list last month.

Collecting before defining. Covered above, and it is still the most common one.

Treating every source the same. Running a LinkedIn-shaped search on Google Maps returns nothing useful, and the conclusion people draw is that the tool is broken.

Sending to role accounts and named addresses identically. info@ needs a different opening line than a named person, because a different person reads it.

Optimising the email before fixing the list. Copy is a multiplier on targeting. Multiplying zero does nothing.

FAQ

Collecting publicly published business contact details is generally lawful in most jurisdictions, and contacting a business about something relevant to its business is treated differently from contacting a private individual. The rules that matter in practice are the ones about sending: identifying yourself honestly, providing a working opt-out, and honouring it. In the EU and UK, GDPR and PECR add requirements around legitimate interest and record-keeping. This is not legal advice — if you are operating at scale, get a lawyer to look at your specific setup.

How many leads do I need to start?

Fewer than you think. A list of 200 genuinely well-matched businesses will teach you more in a week than 5,000 loosely-matched ones, because you can read every reply and adjust. Scale the volume only once the message is earning replies.

Why do so many businesses have no email address?

Because they never published one. Some businesses deliberately route everything through a contact form or a phone number, and a form has no address behind it that anyone outside the company can see. No tool can produce an address that does not exist publicly — the honest ceiling on any collection method is "what the business chose to publish".

Should I use role addresses like info@ or contact@?

Yes, but treat them as a separate segment. They are real, monitored inboxes at small businesses, and at a two-person clinic the info@ address is the owner. At a larger company it is a reception queue. Write to them as a shared inbox — say who you want to reach and why — rather than pretending you know who is reading.

How often should I rebuild the list?

Re-collect rather than re-use anything older than about three months for local businesses, and sooner in high-churn sectors like hospitality and agencies. The cost of re-running a search is far lower than the cost of a bounce spike.

Keep reading