Where to find B2B leads (the best sources in 2026)
Rank lead sources by provenance, not by volume. Where each one legally stands, how fast it decays, and a 200-row test before you buy.
Rank B2B lead sources by where the data came from, not by how many rows it contains. Every lead has one of four provenances: you observed it, someone handed it to you, a vendor sold it, or a machine collected it. That single fact determines the legal footing, how fast the record decays, how much verification you owe it, and how a recipient will react when you contact them. Volume rankings put databases at the top and referrals at the bottom, which is exactly backwards for anyone measuring revenue rather than sends.
The four provenances every B2B lead has
Sort your sources into these four buckets before you compare anything else about them.
- First-party observed. Form fills, booking-page reservations, webinar registrations, product signups, inbound replies, event badge scans you actually ran. You hold a record of how the data reached you.
- Introduced. Referrals from customers, warm intros from investors or partners, and named recommendations. The provenance is a person who will vouch for you.
- Licensed. A contact database you pay for. The vendor collected it, and your rights to use it are whatever the contract says, subject to the law where the person lives.
- Collected. Scraped, crawled, inferred from patterns, or assembled from public filings and directories. You did the collecting, so the compliance and accuracy burden is entirely yours.
Provenance predicts the two things that actually matter operationally. Freshness falls as you move down the list, because observed data was true at the moment you observed it and licensed data was true whenever the vendor last checked. Verification burden rises for the same reason. A first-party address that just submitted a form needs almost no verification; a licensed row needs all of it.
There is a third property that gets ignored: explainability. If someone asks how you got their details, the first two buckets have an answer that ends the conversation. The last two frequently do not, and a supervisory authority asking the same question is a slower conversation.
First-party is the source almost everyone under-mines
Before buying anything, count what you already hold. Most teams under twenty people are sitting on several hundred usable records they have never systematically worked.
Places to look, in the order they usually pay off:
- Booking-page no-shows and cancellations. Someone picked a slot. That is stronger intent than anything a database will sell you, and the record is already yours.
- Trial and free-plan signups that never activated. They told you their problem by signing up. Nothing about that expires quickly.
- Inbound replies that were never followed up. Every "not right now" from six months ago is a dated record of interest with an implicit re-contact date attached.
- Support and contact-form conversations. People describing a problem in their own words are the best copy source you will ever have, quite apart from being leads.
- Website visitors who identified themselves in any way at all — a newsletter, a calculator, a download.
The reason this bucket gets skipped is that it feels too small to matter. Run the arithmetic before you accept that. A team with 300 unworked first-party records and a 4% meeting rate gets 12 meetings — *an illustrative figure, not a benchmark* — for the cost of an afternoon's segmentation. The same 12 meetings from a licensed list would need thousands of sends and a month of sending reputation to build. Booking pages, with Google and Outlook calendar sync and video links, are on Autocloz's free plan with no per-seat fee, which is what keeps this bucket filling in the first place; how to organise what you already have is covered in segmenting your CRM and lists.
Introduced leads convert best and scale worst — build the ask into a process
Referrals are the highest-converting source in almost every B2B business, and almost nobody runs them as a system. The failure is not that people dislike asking. It is that asking has no trigger, so it never happens.
Give it triggers. Three that work without being awkward:
- The moment a customer says something positive in writing. A reply, a support message, a renewal confirmation. Ask then, in that thread, naming one specific type of company you would like to meet.
- Thirty days after successful onboarding. Early enough that the effort of switching is fresh, late enough that they have a result.
- When a champion changes jobs. They now need to solve the same problem at a new company, and they already know your product. This is the single most underused trigger in B2B and it is publicly visible on their profile.
Name the target precisely when you ask. "Do you know anyone who might need this" produces nothing; "we are trying to meet heads of finance at 50-to-200-person logistics companies — does anyone come to mind?" produces names, because you have made recall easy rather than open-ended.
Licensed databases: what you are buying, and how to test one for nothing
A contact database sells you three separate things and prices them as one: coverage of your segment, accuracy of the fields, and rights to use the data. Vendors compete loudly on the first and quietly on the other two.
Coverage claims are near-useless in the abstract. A database with 200 million contacts and thin coverage of 30-to-80-person manufacturers in Maharashtra is worse for you than a smaller one with deep coverage there. Test coverage *in your segment*, never in total — which means writing the segment down in filterable terms first, and the ICP generator is a faster way to get to that than a whiteboard.
Here is the test to run before any purchase. It costs nothing but time and it has settled more procurement arguments than any demo.
- Write down 25 companies you already know fit, chosen without reference to the vendor. Include a few you know are awkward — recently renamed, recently acquired, non-English trading name.
- Ask the vendor to return the matching contacts for those 25 during the trial. Count how many companies they find at all, and how many produce a person in the right function.
- Take 200 rows from a live search in your real segment and verify every address. Record the split of deliverable, risky, undeliverable and unknown.
- Send to 50 of them from a warmed mailbox and count hard bounces plus "no longer with the company" replies within a week.
- Compute cost per usable contact, not cost per row. Divide the annual price by the rows that survived steps 3 and 4.
Step 5 is the number. Two vendors quoting the same price per thousand rows routinely differ by three or four times on cost per usable contact, and no marketing page tells you which is which. If you want a starting reference for what a genuinely usable row looks like before you buy, Autocloz's shared lead database lets you search without metering and counts only the rows you take out — 500 rows a day on the free plan, 5,000 on Growth, 25,000 on Pro and 100,000 on Scale — which is a structure designed so the test above is cheap to run.
Autocloz's free plan covers 5 users and 10 mailboxes, includes 1,000 email verifications a day, and runs all five channels with per-channel daily caps — start free and run the 200-row test on your own segment before you sign anything.
What hiQ v. LinkedIn actually decided about collecting your own data
Scraping is discussed as though one court settled it. Two things were decided and they point in different directions, so it is worth being precise.
On the criminal-statute question, the Ninth Circuit affirmed in April 2022 that the Computer Fraud and Abuse Act's "without authorization" provision does not apply to data on public web pages that require no login — and that violating a website's user agreement alone does not trigger CFAA liability. That is the holding people cite.
On the contract question, the district court granted LinkedIn summary judgment on breach of contract, finding that hiQ's scraping and its use of fake profiles violated LinkedIn's user agreements. The litigation ended in December 2022 with a stipulated consent judgment that included $500,000 against hiQ, liability under California common-law trespass to chattels and misappropriation, and injunctive relief restricting further scraping.
The practical reading: public scraping is not a federal computer-crime problem in that circuit, and it remains a contract and tort problem. LinkedIn's User Agreement is explicit — section 8.2.2 prohibits developing or using "software, devices, scripts, robots or any other means or processes (such as crawlers, browser plugins and add-ons or any other technology) to scrape or copy the Services", section 8.2.13 prohibits bots and unauthorised automated methods, and 8.2.1 prohibits false identities. A tool that logs into your account and clicks for you is squarely inside 8.2.13, and the account bearing the consequence is yours.
Public filings and directories are the underrated collected source
Not all collected data comes from scraping a platform that forbids it. A large amount of genuinely public, genuinely structured B2B signal is published by governments and is free to use.
- SEC EDGAR (United States). Form D is the notice of an exempt securities offering, and the SEC requires a company to "file this notice within 15 days after the first sale of securities in the offering". It names the issuer, the officers and the amount. If newly funded companies are a trigger for you, this is the primary source that the funding-news sites are themselves reading.
- Companies House (United Kingdom) publishes incorporations, filings, officer appointments and registered addresses as open data.
- India's MCA registry publishes company master data, incorporation dates and director details.
- Job boards are a public statement of what a company is investing in. Ten open sales roles is a different signal from ten open support roles, and both are readable without any vendor.
These sources share a useful property: because they are filings rather than profiles, they are timestamped. You know when the fact became true, which is what makes a trigger usable. The tactics for acting on that timing are in prospecting techniques that still work.
The notice obligation nobody attaches to a purchased list
This is the part of buying data that gets skipped, and it is not optional in Europe.
The GDPR distinguishes data collected from the person from data collected about them elsewhere. Article 14 governs the second case, and Article 14(3)(a) sets the timing: the information must be provided "within a reasonable period after obtaining the personal data, but at the latest within one month". Article 14(5)(b) offers an exemption where provision "proves impossible or would involve a disproportionate effort", but the text frames that around archiving in the public interest, scientific or historical research and statistical purposes — it is not a general convenience carve-out for outbound sales.
India works differently again. The Digital Personal Data Protection Act, 2023 requires a lawful ground that is either consent or one of the "certain legitimate uses" enumerated in Section 7, and it does not include a general legitimate-interests ground equivalent to the GDPR's Article 6(1)(f). For anyone running outbound into India, that absence is the material difference, not the notice mechanics.
In the United States, CAN-SPAM regulates the message rather than the list: no deceptive subject lines, a valid physical postal address in the message, a working opt-out, and — in the FTC's words — "you must honor a recipient's opt-out request within 10 business days", with each violating email exposed to penalties of up to $53,088.
None of this is legal advice, and the right move for a company sending at volume across jurisdictions is to get an opinion on its own facts. The point here is narrower: the compliance burden attaches to the *provenance*, so it belongs in the source-selection decision rather than being discovered afterwards.
Combining sources without double-contacting the same person
Two sources will hand you the same human twice, and the person receiving two different first touches from your company in one week will remember it.
Deduplicate on identity, not on strings. An email address is the strongest key you have, but the same person appears as r.sharma@ at one source and rahul.sharma@ at another, so email alone under-merges. Name plus company domain over-merges in the other direction, because two people share a name more often than you expect and a blank domain collides with every other blank. Use email first, fall back to normalised name plus domain, and treat the fallback as a suggestion a person confirms rather than an automatic merge.
Then verify, because a merged record inherits the worse address as often as the better one. Every deliverability problem downstream starts here, and the mechanics of cleaning before you send are covered in how to clean an email list. The free email checker is enough for a spot check on a single address; a full list needs the bulk path.
For the broader question of which sources fit which motion — and where paid databases sit against building your own — the Autocloz and ZoomInfo comparison lays out the tradeoff between renting coverage and owning provenance.
What Autocloz's lead sourcing does not do
Some plain limits, because a source page that only lists strengths is not useful for a purchase decision.
The built-in verifier cannot confirm that a specific mailbox exists. It runs syntax checks, a typo guard over the most common domains, a disposable-provider list, role-address detection and a DNS/MX lookup, and it deliberately opens no SMTP connection. That means an address clearing every layer is reported as risky and unconfirmable rather than deliverable — which is honest, because nothing in that pipeline can prove a mailbox is real. A deliverable verdict is written only when a real delivery is accepted or an external oracle confirms it.
It does not tell you whether you have a lawful basis to contact a row. No software can, because the answer depends on your jurisdiction, your relationship and your purpose.
It does not scrape LinkedIn for you, and it will not make an action taken through your own LinkedIn account safe. Platform limits and platform terms apply to your account regardless of what tool performs the click.
It does not replace judgement about fit. A filter matches fields; it cannot tell you that a company matching every field on paper has just signed a three-year contract with your competitor. That is what a discovery call is for, and how to build a targeted lead list covers the field-level work that has to happen before any of it.
Frequently asked
What is the best source of B2B leads?
There is no single best source, and the ranking depends on what you are optimising. Ranked by conversion, referrals and inbound win. Ranked by coverage, a purchased database wins. Ranked by legal simplicity, first-party data you observed yourself wins by a wide margin. Most teams that outperform run two or three sources at once and verify everything before the first send, because the failure modes of the sources are different and do not overlap.
Is scraping LinkedIn to find leads legal?
The answer separates into two different questions with two different answers. In hiQ Labs v. LinkedIn the Ninth Circuit held in April 2022 that scraping data from public web pages does not violate the Computer Fraud and Abuse Act's "without authorization" provision. Separately, the district court granted LinkedIn summary judgment on breach of contract, and the case ended in December 2022 with a stipulated judgment against hiQ including $500,000 and injunctive relief. LinkedIn's User Agreement prohibits scraping at section 8.2.2 and automated access at 8.2.13, so contract and tort exposure survives even where the criminal statute does not apply.
Do I have to tell people I bought their contact details?
Under the EU General Data Protection Regulation, yes. Article 14 covers personal data not obtained from the data subject and Article 14(3)(a) requires the information to be given "within a reasonable period after obtaining the personal data, but at the latest within one month". There is a disproportionate-effort exemption at Article 14(5)(b), but it is narrow and is drafted around archiving, research and statistical purposes rather than around commercial outreach being inconvenient.
How stale is a purchased B2B contact list?
No independent body publishes a decay rate you can rely on, and any specific percentage you see quoted almost always traces back to a vendor measuring its own product. What you can measure is your own: run a sample of 200 rows through verification and through a real send, then count hard bounces and "no longer with the company" replies. That number is about your source and your segment, which is the only number that should influence a purchase.
What counts as a first-party lead source?
A first-party source is one where you observed the interaction yourself — someone filled in a form, booked a meeting, replied to a message, downloaded something, attended your webinar or was introduced to you by an existing customer. The defining property is that you hold a record of how the data reached you. That provenance is what makes the legal footing straightforward and what makes the data fresh, because it was current at the moment you captured it.
Can I email B2B contacts in India the way I would in the US?
No, the legal grounds are structured differently. India's Digital Personal Data Protection Act, 2023 permits processing of personal data on consent or on one of the "certain legitimate uses" listed in Section 7, and it does not carry a general legitimate-interests ground of the kind the GDPR provides at Article 6(1)(f). That absence matters most for outbound marketing, which is often the exact use case a legitimate-interests assessment is written to support in Europe.