Start with the mailbox specification
Write down the provider, quantity, age requirement and whether phone verification is part of the package. If you need a specific region or language, include that too. A provider name by itself is not a complete specification.
For Gmail, an app password is a separate feature tied to account security settings. If the package specifically advertises app passwords, confirm whether two-step verification is enabled and whether the app password is already created.
Recovery access is not an afterthought
Ask what recovery email, phone or security information remains on the account and what the buyer is expected to change. A login that works at delivery can still be difficult to manage later if recovery ownership is unclear.
Keep credentials in an encrypted password manager rather than a plain spreadsheet, especially for large batches. Limit access to the people who genuinely need it.
Compatibility can change
Mail providers regularly update anti-abuse systems, login checks and application-access rules. If you need accounts for a particular legitimate tool, verify the tool’s current authentication requirements before placing a large order.
A seller cannot reasonably guarantee that an external application will keep accepting the same login method forever. Treat compatibility as something to validate, not a permanent property of the mailbox.
Use email accounts lawfully
Do not use purchased mailboxes for spam, phishing, impersonation, fake reviews or attempts to evade platform enforcement. Bulk access should still be used in accordance with applicable law and the provider’s terms.
If your use case is ordinary business email, a managed domain mailbox may be more stable and auditable than buying third-party consumer accounts.
If a detail affects whether you would buy the package, include that detail in the written order before payment. Clear specifications are more useful than vague promises.