-
Step 1: Choose your Phantom (and your source)
-
Step 2: Build a narrow Sales Navigator search URL
-
Step 3: Run a test extraction before the full list
-
Step 4: Dedupe and enrich before email verification
-
Step 5: Verify emails in real time (not after the send)
- Step 6: Check DMARC before you send anything
-
The mistakes I'd rather forget
Real talk: a lot of B2B lead-gen tutorials end at 'export the CSV and upload it to your email tool.' They skip the two parts that decide whether you get replies or a spam complaint: verifying those sales leads and checking your domain's DMARC record.
In 2020, you could upload 3,000 unverified emails to Mailchimp and get away with it. In 2025, deliverability will punish you first. What was best practice in 2020 may not apply in 2025. The fundamentals haven't changed, but the execution has transformed.
I've spent the last seven years building outbound pipelines for B2B teams. I've personally made (and documented) at least eleven significant lead-gen mistakes, totaling roughly $14,000 in wasted budget. Now I maintain our team's checklist so the new SDRs don't repeat my failures. This is that checklist. If you're following a Phantombuster LinkedIn scraping tutorial and want results instead of a list, use it.
First, the Phantombuster vs Dripify question, because it will block you if you don't settle it: they solve different problems. Dripify is built for LinkedIn outreach sequences. Phantombuster is built for extracting data and automating the nonsense around it. I use both—Phantombuster for scraping and data sync, Dripify only for the sequence after the list is clean.
Here are the six steps. Step six is the one almost everyone skips.
Step 1: Choose your Phantom (and your source)
Log in to Phantombuster and create a new API Graph; that's what Phantoms are called now. Search the library for 'LinkedIn Sales Navigator Scraper' and open it.
Before you add filters, decide who you're going after. Two layers of the ICP matter more than anything:
- Role: Head of Sales, RevOps, Founder, etc.
- Account size: 20-200 employees, 500+, etc.
I usually start with 2nd-degree connections, not 1st. First-degree connections are warm-ish, but they're also more likely to be existing contacts; scraping them for a cold sequence feels wrong and gets poor replies. Second- and third-degree is where the sales leads actually live.
Step 2: Build a narrow Sales Navigator search URL
Phantombuster takes a Sales Navigator URL as input. The narrower your URL, the cleaner your output. Use filters like:
- Seniority: Owner, Partner, C-level, VP, Director
- Locations: pick 2-3 regions, not Worldwide
- Industries: your ICP industries
- Network: 2nd and 3rd degrees
Then copy the URL and paste it into the Phantom's Search URL field. If you don't have Sales Navigator, plain LinkedIn search works, but the results are messy and there's a higher chance of duplicates. Sales Navigator is worth the cost for this workflow.
Here's a mistake I made in my first year (2017): I used a wide LinkedIn search for 'VP Sales' with no location filter. The list was technically 3,000 leads, but 40% were outside our service area. I spent a weekend cleaning garbage. The list is still in a Google Sheet somewhere titled 'never use this again.'
Step 3: Run a test extraction before the full list
Set the Phantom to run a small batch first—50 to 100 profiles, not 5,000. I know it's tempting to run everything at once. I promise the patience saves you from importing duplicate profiles and wrong columns.
Export the test to Google Sheets, or send it to a webhook. I normally use Make to add a lead_source column and push each row to a pipeline. If you use Zapier or n8n, the logic is the same.
Check that these columns are present and readable:
- Profile URL / LinkedIn URL
- First name, last name
- Headline
- Company and company URL
- Location
If the URL column contains tracking junk, clean it before moving on. (Should mention: I've seen exports where the profile URL was truncated by a semicolon. A small data-cleaning step here saves you 1,000 dead links later.)
Step 4: Dedupe and enrich before email verification
The least glamorous step, but the one that separates good lead-gen from messy lead-gen. Dedupe by LinkedIn profile URL, not by name. There are at least 40 'John Smith' VPs of Sales in the US. (I made that mistake once. The follow-up sequence got... awkward.)
Then remove:
- Anyone already in your CRM
- Competitors, if you don't want them in your data
- Existing customers (unless this is an upsell campaign)
This is also the time to add a column for which search query produced the lead. When the campaign works, you want to double down on the segments that replied; without query tags, you're guessing.
Step 5: Verify emails in real time (not after the send)
Real-time email verification means every address is checked the moment it enters your pipeline—not when you export a CSV and run a batch check an hour before the send. The difference matters because catch-all servers and temporary domains change constantly.
In my stack, the Google Sheets row goes to Make, which calls a verification API (I've used MillionVerifier and ZeroBounce). Then a status column is added: valid, catch-all, invalid, unknown. I filter the Phantom list for valid only, and sometimes catch-all if the domain pattern looks strong.
Why is this step non-negotiable? We didn't have a formal verification process at my old company. The third time we sent 1,500 emails with a 22% bounce rate, I finally built the verification webhook. I should have done it after the first time.
Honestly, I'm not sure why some verified emails still bounce. My best guess is that catch-all servers accept everything and only reject during delivery. That's why you still need to monitor your bounce rate even after verification.
Step 6: Check DMARC before you send anything
What is DMARC and when should a B2B sales team use it?
Here's the step that most people ignore, and the one that has already saved me from a very bad month. DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email validation protocol that tells receiving mail servers what to do with messages that fail SPF and DKIM checks. It's defined in RFC 7489, and you can think of it as a set of instructions on your domain: 'If an email claims to be from us and doesn't authenticate, do nothing, quarantine it, or reject it.'
A B2B sales team should care about DMARC before sending automated outreach—especially if you're using a new sending domain. Without a DMARC record, your domain is easier to spoof, and legitimate emails are more likely to be treated with suspicion. In 2025, that suspicion means Promotions or Spam instead of the inbox.
How to check yours:
dig TXT _dmarc.yourdomain.com
Or use a tool like MXToolbox and search for your domain. You're looking for something like:
v=DMARC1; p=none; rua=mailto:[email protected]
If you don't have a record, ask whoever manages DNS to publish one. Start with p=none, monitor reports, then move to p=quarantine after a few weeks.
I learned this in April 2023 when our campaign from a fresh subdomain landed 31% in spam. We'd verified every email address. We'd made the message sound like a human wrote it. We'd forgotten the part that tells the internet our domain wasn't an impostor. (Ugh.)
Use this step whenever you:
- Send more than 100 emails in a day
- Use a new sending domain or subdomain
- Send from a tool that fires emails automatically on third-party triggers
- Have ever seen one of your own emails in spam (not just the Promotions tab)
The mistakes I'd rather forget
This checklist didn't appear fully formed. It came from a stack of expensive embarrassments:
- Scraped 1,000 leads, verified none, watched 38% bounce. The account's reputation took months to recover. (Cost: roughly $1,200 in wasted credits and lost follow-up timing.)
- Used first-degree connections as cold leads. The person was a former client. The reply started with 'I know we just had lunch.' (Note to self: always exclude existing relationships.)
- Ran 3,000 profiles through a single Phantom run on a new LinkedIn account. The account got a restriction warning within hours. Phantombuster worked; my volume didn't. LinkedIn changes fast, so respect rate limits and use a warm account.
Also: this was accurate as of June 2025. Phantombuster, LinkedIn, and email authentication rules change fast, so verify current guidelines before you commit to a workflow.
If this checklist saves you one bounced campaign, it was worth writing. If you only remember one number, remember the DMARC check. I almost skipped it last month to hit a Friday deadline. So glad I didn't—the first batch went out Monday morning and landed in the inbox, not spam. (The 'almost skipped it' version of me is not thinking about that right now.)


