Verification

How email verification works (without sending a thing)

If you have ever wondered how email verification works, the honest answer is that a good checker finds out whether an address is real without ever emailing the person behind it. It reads the address, looks up the server responsible for that domain, and starts a short machine-to-machine conversation that stops before any message is delivered. This article walks through each step in plain language, the eight signals that feed a verdict, and why a few addresses come back marked Unknown and cost you nothing.

How email verification works without sending mail

Email delivery runs on a protocol called SMTP, which is really just a scripted conversation between two servers. One side announces who it is, names the sender, names the recipient, and then offers the message body. A verifier walks through the opening lines of that same conversation. It identifies itself, says it has mail for a given address, and listens to how the receiving server responds. The moment the server reveals whether it would accept that recipient, the verifier hangs up. Nothing is handed over, so nobody on your list gets a message, sees a trace in their inbox, or knows a check happened.

Because the test is a lookup rather than a send, you can run it across an entire list before a campaign, instead of discovering bad addresses the hard way, as bounces, after you have already hit send.

The checks, step by step

A verdict is built up in order, cheapest test first, so an address that fails early never wastes effort on the slower network checks.

Syntax. First the address is read against the rules for what an email address may contain. A missing @, a space in the local part, or a domain with no dot is caught here before anything touches the network.

Domain. Next the domain itself is checked. Does it resolve to a real, registered domain, rather than a typo or a dead one that stopped working years ago?

Mail server, or MX. Every domain that can receive mail publishes MX records that name the servers responsible for its inbox. The verifier looks these up. No MX record and no fallback means there is no way to receive mail, which is a strong sign the address will bounce.

Mailbox. With the right server identified, the verifier opens the SMTP conversation described above and asks, in effect, would you accept mail for this exact person. A clean yes is the signal that the mailbox exists.

Each stage can end the process on its own. There is no reason to open an SMTP conversation with a server that does not exist, so a domain or MX failure settles the verdict without going any further.

Catch-all detection with a made-up address

Some domains are configured to accept mail for every possible address, whether the mailbox exists or not. These are called catch-all domains, and they are the single biggest reason a plain yes from a server cannot always be trusted. If a server says yes to everything, then yes for your contact means very little.

Sends Verified handles this by testing each domain with an invented address first, something no human would own. If the server accepts that made-up address, the domain is flagged as catch-all rather than waved through as Safe. That way a catch-all is labelled honestly instead of inflating your clean count with addresses that might not exist. For Microsoft 365 catch-all domains the check goes one step further, confirming the specific mailbox against the provider's own directory and promoting a confirmed address to Deliverable with a confidence score. For more on this behaviour, see what is a catch-all email.

The eight signals behind every verdict

Under the hood, each address is scored on eight signals: syntax, domain, mail server (MX), mailbox, catch-all, disposable, role, and spam traps. The first four establish whether the address can receive mail at all. The last four describe what kind of address it is: a throwaway inbox, a shared function address, or a trap you should never touch. Those signals combine into a single result category. Here is what each category means and what to do with it.

ResultWhat it meansWhat to do
SafeThe mailbox exists and accepted the checkSend with confidence
RoleValid, but a function address like support@ or info@Send with care; a person may not read it
Catch-allThe domain accepts any address, so SMTP alone cannot confirm the personTreat as lower confidence; Microsoft 365 mailboxes are confirmed and promoted
DisposableA temporary throwaway inboxDrop it; it will not last
Inbox fullA real mailbox that is over quota and refusing mail for nowKeep it, retry later
InvalidNot registered, no mail server, or malformedRemove it; it will bounce
DisabledA real account the provider has switched offRemove it
Spam trapA known trap or an obvious typo of a big provider, such as gmial.comRemove it; never send
UnknownThe server would not give a definite answer in timeNo charge, retry later

A spam trap deserves special mention, because hitting one damages your sender reputation more than an ordinary bounce does. Sends Verified recognises both classic typo domains and known trap addresses, and it never contacts or mails them. The article what is a spam trap goes deeper on why they are so costly and how they end up on lists in the first place.

Why some results are Unknown, and free

Not every server plays along. Large providers rate-limit how fast any one source may query them, and some servers use greylisting, a tactic that deliberately gives a vague answer the first time and asks the sender to try again later. When a server stalls, refuses outside checks, or runs out the clock, the verifier will not guess. It returns Unknown.

Unknown is never a billing event. The credit for an Unknown result is returned automatically when the task finishes, and immediately for a single check, so you are only ever charged for a real answer. That design matters, because it removes any incentive to turn a shaky maybe into a confident Safe. An honest Unknown that costs nothing is better for your list than a guess you paid for.

Speed follows the same logic. Small mail servers tend to answer in seconds, while company-heavy lists built on Google, Microsoft, and Yahoo take longer, because those providers throttle how fast queries arrive. Slow or greylisted servers simply read as Unknown and cost nothing, so a big corporate list never leaves you paying for the servers that refused to answer.

What a clean verdict does and does not promise

Verification tells you the mailbox was real and accepting mail at the moment of the check. It cannot promise the message will land, because deliverability also depends on your side of the connection: your SPF, DKIM, and DMARC alignment, whether your sending IP sits on a blocklist, and whether the receiving server is throttling you that day. A verified list removes one large category of failure, the dead address, and frees you to focus on the sending-side work that lifts inbox placement. For the full picture of putting a clean list to work in a cold campaign, see putting a clean list to work in a cold campaign.

Lists also decay. People change jobs, companies fold, and mailboxes close, so an address that verified as Safe in spring may bounce by autumn. Re-verify any list older than about three months, and treat verification as regular hygiene rather than a one-time cleanup. If bounces are already climbing, start with the practical steps in how to reduce your email bounce rate, then verify what remains before the next send.

FAQ

Does email verification send a test message to the address?

No. Verification opens an SMTP conversation with the receiving mail server and asks whether it would accept mail for the address, then hangs up before anything is sent. Nobody on your list receives a message or sees any sign that a check ran, which is why you can verify a whole list quietly before a campaign.

What does a Catch-all result mean?

It means the domain is set up to accept mail for every address, so the server's yes does not prove your specific contact exists. Catch-all results are lower confidence by nature. For Microsoft 365 catch-all domains, Sends Verified confirms the individual mailbox against the provider's directory and promotes it to Deliverable with a confidence score where it can.

Will I be charged for Unknown results?

No. Unknown means the server would not give a definite answer in time, or refuses outside checks altogether. The credit is returned automatically when the task finishes, or immediately for a single check, so you only ever pay for a real verdict.

If an address verifies as Safe, can it still bounce?

Yes. Safe means the mailbox existed and accepted the check at that moment. A message can still bounce for reasons on your side, such as SPF, DKIM, or DMARC problems, a blocklisted sending IP, a server refusing mail temporarily, or the mailbox closing after you checked it. Re-verify lists older than about three months to keep the gap between check and send small.

Clean your next list before you hit send.

Unknown results are always free. Create an account and verify your first addresses in minutes.

Start free