Lead Quality

How to Audit 250 Leads With No Install

The LeadShield.ai Team · 11 August 2026

How to Audit 250 Leads With No Install

You paid for the leads. They cost ad spend, sales time and space in the CRM. Yet most teams cannot say how many records were unusable before anybody followed up.

A free lead list audit checks 250 rows in about a minute using a CSV you already have. You do not install code, create an account or enter card details. It is not a complete lead-quality verdict. It shows what is already wrong in the file, which is a much better place to start than a polished demo with somebody else's data.

How can I check my leads for fakes without installing anything?

Export a recent sample from your CRM as a CSV and upload it to the public audit. The file is checked for deterministic list problems such as disposable addresses, mail-domain failures, common provider typos, implausible phone formats and duplicates. You receive the summary on screen.

This removes the usual trial delay. You do not need a developer to add a snippet, and you do not need to wait for new traffic. You are testing the records your team has already seen, including the awkward ones people remember chasing.

Most CRMs make the export straightforward. HubSpot documents how to export records, while Pipedrive supports CSV exports from its data and list views. A spreadsheet saved as CSV works too. The file needs a header row with an email column. If it also has phone numbers, those can be checked for plausible regional formatting.

The no-install lead audit in five steps

  1. Export a recent set of form submissions from the CRM or spreadsheet that holds the original records.
  2. Keep the email column, add the phone column if one exists, and remove fields the audit does not need. Use a copy rather than the master file.
  3. Take the latest 250 rows, or a clearly defined sample from one campaign or client. Do not cherry-pick the cleanest records.
  4. Upload the CSV and read the on-screen breakdown. The public audit screens the file in memory, does not store the list and partly masks example addresses.
  5. Record what was flagged and why. Keep typos, duplicates and no-mail domains in separate buckets because they call for different action.

That final distinction matters. A duplicated record is not the same thing as a fake person. A mistyped provider domain may belong to a genuine prospect who made an ordinary mistake. The audit is useful because it shows the reason, not because it turns every problem into the same verdict.

What does a 250-row lead audit actually check?

A 250-row lead audit checks the evidence present in the file itself. It can identify disposable email services, common provider misspellings, gibberish-looking local parts, duplicate addresses, domains that cannot accept mail and phone numbers that are structurally implausible for their stated region. It does not contact the person or inspect a browser session.

Disposable addresses are temporary by design. They may be useful to the person filling a form, but they are poor records for a sales team expected to follow up next week. Provider typos are different. An address ending in gmial.com may simply need correction, so it belongs in a repair queue rather than a fraud bucket.

Mail-domain checks need a little care. A domain can publish a null MX record to state formally that it accepts no email. RFC 7505 defines that mechanism and explains that delivery should fail immediately. Other DNS failures can have different causes, which is why the audit reason should be reviewed rather than translated into a claim about the person behind the address.

Phone checking is also structural. LeadShield uses Google's libphonenumber data to test whether a number could exist for the claimed region. That does not prove the line is active, owned by the named contact or likely to answer. It catches obvious formatting problems without pretending it made a call.

Duplicates are usually operational debt. They inflate raw lead counts, create conflicting notes and send two reps towards the same person. Removing them will not improve the underlying campaign by itself, but it gives the team a cleaner denominator when it reviews lead quality.

Why might my real junk rate be higher than the audit shows?

A CSV audit can prove that certain contact fields have deterministic problems. It cannot prove who submitted the form, how they behaved in the browser, which IP address they used or whether the message showed genuine buying intent. A normal spreadsheet does not contain that context, so bulk mode does not claim to analyse it.

This is why the result is best treated as a floor for detectable list-hygiene problems, not a complete junk-lead rate. A row may pass every CSV check and still come from automated traffic. It may contain a working company email and a plausible phone number while the original session triggered a honeypot or arrived from an abusive network.

The reverse matters too. A typo is a bad field, not proof of bad intent. Somebody using a temporary mailbox may still be a human. Deterministic checks tell you which records need repair, suppression or review. They do not read motives.

Live screening has access to evidence the file lacks, including form timing, interaction telemetry, IP reputation, device or browser context and message analysis. The article on AI-generated form spam and the signals that catch it explains why fluent wording alone is a poor fraud test and why independent signals need to agree.

That boundary makes the CSV result more useful, not less. You know exactly what ran. You can compare the reasons with records your team recognises, challenge a false flag and decide whether richer live screening is worth testing.

How should an agency run this audit for a client?

An agency should use the audit as a discovery exercise, not as a scare tactic. Take a defined 250-row sample from one client and one period, preserve the source labels, run the deterministic checks and report the categories found. Say what the audit measured, what it could not see and what should be fixed first.

The wording is simple: "In this sample, X rows were flagged by deterministic list checks." That is defensible. "X per cent of your leads are fake" is not, because a duplicate, a typo and a fraudulent submission are different things. It also ignores the live signals that were absent from the CSV.

Sampling deserves some thought. The most recent 250 records are easy to explain, but they can hide differences between campaigns. If one client receives leads from search, social and partners, keep those source fields and review the breakdown by source afterwards. Do not combine three clients and call the result a benchmark. It is a sample of their data, nothing more.

If the list will be used for marketing, accuracy is more than a reporting concern. The ICO says organisations using bought-in marketing lists must check that the list is accurate and collected fairly. Its broader accuracy guidance requires reasonable steps to correct or erase inaccurate personal data where appropriate. A hygiene audit can help with factual accuracy, but it does not prove consent, fair collection or a lawful basis.

Keep suppression records separate. If somebody opted out, do not clean them back into the active list because their address now passes a technical check. The audit answers whether fields look usable. Permission to contact them is a separate question.

There is also a paid-media reason to preserve source data. If one campaign repeatedly supplies unusable rows, the next job is to inspect which conversion event bidding receives. The guide to how junk leads train ad-platform optimisation covers that feedback loop. Cleaning the CRM after the event does not automatically correct the signal already sent to an ad platform.

What happens after the audit?

After the audit, fix what can be repaired, suppress what should not be contacted and keep the original result as a dated baseline. A low flagged count does not prove the traffic is clean. A larger count gives you a concrete reason to review acquisition sources, form handling and the way leads enter the CRM.

Start with obvious housekeeping. Merge true duplicates without erasing useful history. Correct provider typos only when the intended address is clear, and keep the original value in the audit trail. Remove or quarantine no-mail domains from outbound sequences. Send uncertain rows to review rather than inventing certainty.

For a larger test, every LeadShield plan and trial includes bulk CSV cleaning with a verdict, risk score and reasons for each row. Starter supports 250 rows per upload, Professional 1,000 and Enterprise 5,000. Trials include the full Professional feature set. Bulk mode remains deterministic-only at every tier because paying for a larger upload does not create a missing browser session or IP address.

The next useful comparison is between the cleaned baseline and future live submissions. If the CSV looks mostly sound but the sales team still sees junk, the problem probably sits in evidence the export could not carry. That is when form behaviour, network context and message analysis become relevant.

Frequently asked questions

Is the 250-row lead audit free?

Yes. The public audit accepts up to 250 rows and allows three audits per IP per day. It does not require an account, installation or payment card.

Does the public audit store my lead list?

The live audit page says the file is screened in memory and the list is not stored. Example addresses shown in the result are partly masked.

What file format does the audit accept?

Use a CSV with a header row and an email column. Common variants such as e-mail, email address and work email are accepted, and a phone column can be checked if present.

Can bulk cleaning run behavioural or AI analysis?

No. Bulk mode runs deterministic checks because a CSV row has no browser session or visitor IP. Behavioural, network, device and message-context analysis require a live submission where that evidence exists.

What if my list has more than 250 rows?

Professional supports 1,000 rows per upload and Enterprise supports 5,000. A trial includes the full Professional feature set and returns the annotated file with a verdict, risk score and reason for each row.

Want to see what's hiding in your own list? Run a free 250-row lead audit — no install, no signup, no card — and get the breakdown in about 60 seconds.

Fake leads draining your budget?

LeadShield blocks bots, disposable emails and AI spam at the form. 60-second install.

Start free 14-day trial