Explainer

What is email verification?

Email verification tells you whether an address can receive mail before you send anything to it. Here is what a verifier checks, what its answers mean and where its knowledge ends.

Updated October 9, 2026 · 8 min read

Email verification of anna@example.com: syntax, MX, SMTP, catch-all, role, disposable and free-provider checks, and the four result states

Email verification is the process of checking whether an email address exists and can receive mail, without sending a message to it. A verifier answers with a verdict (for example deliverable, undeliverable, risky or unknown) and the reasons behind it, so you can decide whether to accept the address on a form, keep it on a list or remove it.

How does email verification work? It runs the same steps a mail server would take to deliver a message (read the address, find the domain’s mail server, ask it about the recipient) and stops right before the message would be handed over. The rest of this page goes through each check, explains what the results mean and where every verifier reaches its limits.

How does email verification work? The checks, step by step

#CheckQuestion it answersField in the result
1SyntaxIs the address written correctly?format_valid
2DomainDoes the domain exist?covered by mx_found
3MX recordsDoes the domain have mail servers?mx_found
4SMTP mailbox checkDoes the mail server accept this mailbox?smtp_check
5Catch-allDoes the server accept every address?catch_all
6Role addressIs it a shared inbox like info@?role
7DisposableIs it a throwaway inbox?disposable
8Free providerIs it a free webmail account?free

1. Syntax. The address must follow the format rules: one @, a local part of up to 64 characters, a domain made of valid labels, at most 254 characters in all. Spaces, double dots and missing top-level domains fail here. A likely typo in a well-known domain (jane@gmial.com) gets a suggestion in did_you_mean. The rules are in email address format.

2. Domain. The domain has to exist in the DNS. A typo such as example.con usually fails here.

3. MX records. The verifier looks up the domain’s MX records, the DNS entries that name its mail servers. A domain can also publish a “null MX” (MX 0 .) to declare that it accepts no mail at all (RFC 7505). Missing or invalid MX records make the address undeliverable with the reason invalid_mx. The MX lookup shows a domain’s records.

4. SMTP mailbox check. The verifier connects to the domain’s mail server and starts a normal delivery: it greets the server, names a sender and then names the recipient with RCPT TO. If the server knows the mailbox, it answers 250; if it knows the address isn’t deliverable, it answers 550 (RFC 5321, section 3.3). The verifier then ends the conversation without sending the DATA command, so no message is delivered and the person never notices. How to check if an email exists shows the full SMTP dialog.

5. Catch-all. Some domains accept mail for any address, real or not. The verifier tests this by asking about an address that can’t exist, such as a random string. If the server accepts that too, a 250 for the real address proves nothing. In the emailvalidation.io API this test runs when you send catch_all=1 (Small plan and up); otherwise catch_all is null. More in catch-all email.

6. Role address. Addresses such as support@, sales@ or postmaster@ usually reach a team or a shared inbox rather than a person. They can be perfectly deliverable; the flag lets you treat them differently in marketing.

7. Disposable. Addresses at temporary inbox services are typically used for one sign-up and then abandoned. The disposable email checker checks a single domain.

8. Free provider. Addresses at free webmail services (Gmail, Yahoo, Outlook.com and many others) are flagged in free. Useful when a business sign-up form should get work addresses.

The order matters: each step only runs if the one before it passed. An address with broken syntax never gets an MX lookup, and a domain without mail servers never gets an SMTP conversation.

What email verification results mean

A verifier sums up the checks in a status. emailvalidation.io returns one of four states, each with a reason, and a score from 0 (bad) to 1 (good):

StateReasonWhat it meansWhat to do
deliverablevalid_mailboxA valid mailbox that can receive emailAccept the address
undeliverableinvalid_formatThe address format is invalidBlock it or ask for a correction
invalid_mxMX records are missing or invalidBlock it or ask for a correction
invalid_smtpThe mail server did not respond correctlyBlock it or ask for a correction
invalid_mailboxThe mail server refused the addressBlock it or ask for a correction
riskylow_deliverabilityA person is unlikely to read the emailAccept with care, or ask again
low_qualitySeveral people appear to use the addressAccept with care, or ask again
unknownno_connectNo connection to the mail serverRetry later
timeoutThe SMTP connection timed outRetry later
unavailable_smtpThe server did not allow verificationRetry later
unexpected_errorAn unexpected error occurredRetry later

Branch on the state and keep the reason for your logs and your support team. The score helps you sort within a state, for example when you want to mail the best risky addresses first. Every result also carries the individual checks (format_valid, mx_found, smtp_check, catch_all, role, disposable, free) and the parts of the address (user, tag, domain), 15 fields in all. The email validation API page documents each one.

Other verifiers use their own labels, but the split is the same: the server said yes, the server said no, the server said yes to everything, or the server didn’t answer.

Email verification vs. email validation

The two terms are used for the same thing, and search engines show the same results for both. Where people do draw a line, it runs like this:

Validation (narrow sense)Verification (narrow sense)
ChecksFormat, sometimes the domainFormat, domain, MX and the mailbox over SMTP
Needs a network connectionNot for the format checkYes
Catches a domain without mail serversNoYes
Catches jane.doe@ that left the companyNoYes, if the server rejects the mailbox

A regular expression in a form is validation in the narrow sense: useful for catching obvious mistakes, but it can’t know whether the mailbox exists. The email regex guide shows a pattern that rejects the obvious mistakes without blocking valid addresses. emailvalidation.io uses “validation” and “verification” for the full set of checks.

Benefits of email verification

Limits: what verification can’t tell you

Every verifier, whatever it charges, works with the answers mail servers give. Where the server doesn’t give a clear answer, nobody can:

Email validation best practices

  1. Check in real time on forms. Call the API when the address is entered and show the did_you_mean suggestion. Don’t block risky or unknown; ask the person to double-check instead.
  2. Keep format rules loose. Accept plus addresses (jane+news@example.com), long domains and new top-level domains. Let the mailbox check decide.
  3. Confirm with double opt-in for newsletters. Verification proves the mailbox exists; the confirmation click proves its owner wants your mail.
  4. Re-verify before campaigns to lists you haven’t mailed in a few months, with the bulk email verifier or the email list cleaning service.
  5. Retry unknown results later instead of deleting them; the cause is often temporary, like a timeout or greylisting.
  6. Handle catch-all and role addresses separately: smaller batches, and removal of those that bounce or never engage.

Try it

Enter any address in the free email checker to see these checks run, or use the email validator for a single address with every field explained. For your own app, the email validation API returns the same result as JSON; the free plan includes 100 checks a month.

Stop bounces before they happen

Most hard bounces come from addresses that don't exist. An email verification asks the receiving server about the mailbox without sending anything, so you can remove bad addresses before your next send.

Frequently asked questions

What is email verification?

Email verification is the process of checking whether an email address is correctly formatted, belongs to a domain that can receive mail, and is accepted by that domain's mail server, without sending a message to it. The result is a verdict such as deliverable, undeliverable, risky or unknown.

How does email verification work?

A verifier checks the syntax of the address, looks up the domain's MX records, then opens an SMTP conversation with the mail server and asks whether it would accept the mailbox at the RCPT TO step. It disconnects before any message is sent. Further checks flag catch-all domains, role addresses, disposable inboxes and free email providers.

Is email verification accurate?

For addresses whose mail server gives a clear answer, the result is reliable at the moment of the check. It can't be certain where the server accepts every address (catch-all), defers the check (greylisting) or only bounces mail later. Those addresses come back as risky or unknown instead of a guess.

What is the difference between email verification and email validation?

In practice none: both terms are used for the same set of checks. Some people use validation for format checks only and verification for the mailbox check over SMTP. emailvalidation.io runs all of them in one request.

What does a risky email verification status mean?

The mail server accepted the address, but delivery or engagement is doubtful: a person is unlikely to read the mail (low_deliverability), or several people appear to use the address (low_quality). Send with care, or ask the person to confirm the address.

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Keep reading

Start using our email validation software today!

Get 100 validations per month for free