Explainer

How to check if an email address exists

You can ask a mail server whether it would accept a recipient, and hang up before sending anything. Here is how it works and where it stops working.

Updated October 1, 2026 · 2 min read

Step 1: Syntax

The address must follow the format rules: one @, a local part of up to 64 characters, a valid domain. See the syntax checker.

Step 2: The domain and its mail servers

A DNS query for the domain’s MX records returns the servers that receive its email. No MX record (and no A record) means nobody can receive mail there. Try the MX lookup.

Step 3: The SMTP handshake

The verifier connects to the highest-priority mail server on port 25 and starts a normal delivery, but stops before the message:

S: 220 mx.company.com ESMTP
C: EHLO verifier.example
S: 250 mx.company.com
C: MAIL FROM:<check@verifier.example>
S: 250 OK
C: RCPT TO:<anna@company.com>
S: 250 OK                  ← mailbox exists
   (or: 550 5.1.1 User unknown  ← it does not)
C: QUIT

No DATA command is sent, so no email is delivered.

Step 4: Catch-all detection

Some servers answer 250 OK to every recipient. To spot them, the verifier also asks about a random address like x7q2k9z@company.com. If that is accepted too, the domain is catch-all and the result for the real address is “risky”. More in catch-all email addresses.

Why you should not do this yourself

  • Port 25 is blocked on most home connections and many clouds (AWS, Google Cloud, Azure by default).
  • Reputation: mail servers notice repeated probes from one IP and block or blacklist it.
  • Greylisting rejects first attempts on purpose; you need retries with delays.
  • Provider quirks: each big provider behaves differently.

A verification service runs this from dedicated, well-reputed IPs and returns a clean result. Try the email validator.

Frequently asked questions

Is it legal to verify email addresses?

Checking whether an address can receive mail does not send anything to the person. You still need a legal basis to process the addresses you hold, for example under the GDPR.

Why can't Yahoo addresses be verified reliably?

Some large providers accept every recipient during the SMTP conversation and bounce later, so the handshake cannot tell real from fake mailboxes. Validators report such addresses as unknown or risky.

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

Read the docs

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "disposable": false,
  "role": true,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox"
}

Keep reading

Start using our email validation software today!

Get 100 validations per month for free