Step 1: Syntax
The address must follow the format rules: one @, a local part of up to 64 characters, a valid domain. See the syntax checker.
Step 2: The domain and its mail servers
A DNS query for the domain’s MX records returns the servers that receive its email. No MX record (and no A record) means nobody can receive mail there. Try the MX lookup.
Step 3: The SMTP handshake
The verifier connects to the highest-priority mail server on port 25 and starts a normal delivery, but stops before the message:
S: 220 mx.company.com ESMTP
C: EHLO verifier.example
S: 250 mx.company.com
C: MAIL FROM:<check@verifier.example>
S: 250 OK
C: RCPT TO:<anna@company.com>
S: 250 OK ← mailbox exists
(or: 550 5.1.1 User unknown ← it does not)
C: QUIT
No DATA command is sent, so no email is delivered.
Step 4: Catch-all detection
Some servers answer 250 OK to every recipient. To spot them, the verifier also asks about a random address like x7q2k9z@company.com. If that is accepted too, the domain is catch-all and the result for the real address is “risky”. More in catch-all email addresses.
Why you should not do this yourself
- Port 25 is blocked on most home connections and many clouds (AWS, Google Cloud, Azure by default).
- Reputation: mail servers notice repeated probes from one IP and block or blacklist it.
- Greylisting rejects first attempts on purpose; you need retries with delays.
- Provider quirks: each big provider behaves differently.
A verification service runs this from dedicated, well-reputed IPs and returns a clean result. Try the email validator.