How many businesses in a US ZIP code can you actually email?
Between 13% and 19%. The rest have no address that can legitimately be obtained, because no place API returns email addresses and roughly a third to a half of local businesses have no website to read one from.
We measured this while building an outreach platform for a client, because the brief assumed a ZIP code yields a mailing list and we wanted to know whether that was true before anyone paid for it. It is not true. What follows is what we found, including the parts that were inconvenient for the product.
The funnel, measured
Two US ZIP codes, chosen to be different from each other: dense downtown and suburban. Counts are from live sources, not estimates.
| Austin TX 78701 | Kennesaw GA 30144 | |
|---|---|---|
| Businesses found | 2,737 | 1,169 |
| Have a phone number | 926 (34%) | 830 (71%) |
| Have a website | 1,208 (44%) | 850 (73%) |
| Published an email in source data | 154 (5.6%) | 153 (13.1%) |
| Contactable by email | 357 (13.0%) | 226 (19.3%) |
The suburban ZIP has far better raw data, 73% with websites against 44%, and a much worse crawl yield, 13% against 25%. Suburban businesses skew toward chains and franchises that route inquiries through a web form rather than publishing an address. Denser data does not mean more reachable.
Why the other 80% cannot be reached
No place API returns email addresses.Not Google Places, not Yelp, not Foursquare. They return name, address, phone, category, sometimes a website. Email is not a field in any of them, and this is equally true of the paid ones. Any product advertising “scrape emails by area” is crawling the businesses’ own sites, buying from an enrichment vendor, or generating addresses that do not exist.
Many businesses have no website at all. 56% in downtown Austin, 27% in suburban Kennesaw. No vendor can sell an address that was never published.
The ones with websites skew to chains. The most common domains in the crawlable set were starbucks.com with 19 locations, 7-eleven.com with 13, then cvs.com, heb.com, walgreens.com. Emailing Starbucks corporate about one downtown store is not outreach. Deduplicating by domain cut 1,057 rows to 820 real targets.
The sending ceiling is lower than the data ceiling
This is the part that surprises people. Google Workspace permits 2,000 messages per day per user. Microsoft 365 permits 10,000 recipients per day per mailbox. Those are the numbers before the account breaks, and they are not the numbers that matter.
The rate that avoids the spam folder is roughly 30 to 50 cold emails per mailbox per day. Every established vendor converges on it independently: Instantly recommends 30, Apollo caps at 50 and advises adding mailboxes rather than raising the limit, and its own managed mailboxes are hard-capped at 20. Nobody sends 2,000.
So one ZIP code is roughly six to nine days of sending from a single mailbox. That is a healthy campaign. It is a very different shape from “scrape a ZIP and blast it,” and it means per-business personalization is affordable, because volume was never the lever.
The scaling trick that is also the risk
The standard industry answer to that ceiling is inbox rotation: many mailboxes across lookalike domains. Four of the six major outreach vendors will sell you the domains to do it. Google’s developer policy names that pattern as prohibited, and bulk sender classification is permanent, in Google’s own words: senders classified as bulk senders are permanently classified as such. Microsoft built a tenant-wide external recipient ceiling that is structurally designed to defeat one tenant with fifty mailboxes.
The realistic exposure here is not a fine. It is losing the mailbox the business actually runs on.
What US law requires
Cold B2B email is legal in the US. CAN-SPAM requires no opt-in consent, which puts it in a very different position from the EU, where Germany requires express prior consent for B2B with no business exemption, or Canada, which requires opt-in.
What it does require: accurate routing and a non-deceptive subject line, a valid physical postal address in every message, and a clear opt-out honored within ten business days.
Two things are worth knowing beyond that. Liability does not transfer— the FTC is explicit that hiring another company to handle your email marketing does not contract away responsibility. And while CAN-SPAM has no private right of action, California’s Business and Professions Code § 17529.5 does, at $1,000 per email. Ninth Circuit case law points it at pseudonymous sender identities and lookalike domains, which is precisely the rotation architecture above.
Method, and what would change the answer
Businesses were collected from OpenStreetMap, which is free, keyless, permits storage and covers the US well. Websites were then crawled for a published address. Contactable counts are direct for addresses already in the source data, and projected from a measured sample for the crawl stage.
The honest limits: two US ZIP codes, one source. Google Places would find more businesses and more websites, widening the top of the funnel, but returns no email addresses either, so it raises the numerator and the denominator together. A third ZIP could move the range. Running the crawl without a sample limit replaces the projection with an exact count.
If you are deciding whether to build this
Two things are worth putting on the table before anyone commits. Phone reach is far better than email reach: 830 of 1,169 Kennesaw businesses have a phone number against 226 with an email. If the goal is contact rather than email specifically, that is where the reach is. And scale by mailbox, not by send rate — which is a business decision with reputational cost, not a setting.
We ran this study while building the platform it describes. If you are weighing something similar, we would rather tell you what it will not do before you pay for it.
Tell us the problemAll research