Email verification,
built for engineers.
One API call returns disposable status, domain reputation and a trust score, in under 100 ms on average. Deep Verification asks the receiving mail server whether the mailbox actually exists — so you catch fraud signups and hard bounces before they cost you.
Enter any email to check syntax, MX records, SPF, DMARC, disposable and role-based signals in real time. Protected by MailSift.
Every fraud signal in one call.
Disposable inboxes, relays, typos, role addresses and more — scored together so you can act on a single number.
Reject
Mail to these addresses will not arrive.Syntax & RFC
Strict parser rejects malformed addresses long before any network call.
"syntax": falseDead domains
Domains that cannot receive mail at all, caught before they hit your sender reputation.
"mx": falseMissing mailboxes
Deep Verification asks the receiving mail server whether the mailbox itself exists.
"smtp": { "status": "undeliverable" }Disposable inboxes
Throwaway addresses from 500k+ tracked providers, plus heuristics for new ones.
"disposable": trueReview
Deliverable, but probably not the person you think.Relay forwarders
SimpleLogin, AnonAddy, Apple Hide My Email, Firefox Relay and friends.
"relay": trueRole addresses
Generic inboxes like info@, admin@, support@ that lower engagement and CTR.
"role": trueCatch-all domains
Domains that accept any local part, masking whether the mailbox is real.
"catch_all": trueDomain typos
Suggests fixes for gmial.com, hotnail.com and other lookalikes in real time.
"did_you_mean": "gmail.com"Context
Signals to route and segment on.Domain age
Brand-new domains are flagged. Established providers get an integrity boost.
"domain_age_days": 4823SPF & DMARC
Live DNS lookup validates the domain has proper email authentication set up.
"spf": true, "dmarc": trueMX provider
Identifies Google, Microsoft, Proton and dozens more — useful for routing logic.
"mx_provider": "Google"Free providers
Tags gmail.com, outlook.com and similar so you can route signups by audience.
"free": trueTrust score 0–100
Every signal rolls up into one score. Route by risk, not handwritten if-trees.
"score": 95Mailbox verification
Deep VerificationEvery check above reads DNS and reputation. This one opens an SMTP conversation with the server that owns the mailbox and asks whether the address exists. Providers that refuse to answer are reported as unknown rather than guessed at, so a confirmed result means confirmed.
1 credit standard, up to 5 for deep →"smtp": { "status": "deliverable",
"catch_all": false }One request. Complete intelligence.
A single GET request returns disposable status, domain reputation, risk score and 15+ checks. Try it live — runs against the production API.
{ "email": "[email protected]", "status": "valid", "score": 92, "mode": "fast", "credits_used": 1, "checks": { "syntax": true, "free": true, "disposable": false, "mx": true, "relay": false, "spf": true, "dmarc": true, "role": false, "catch_all": false }, "domain": "gmail.com", "mx_records": [ "gmail-smtp-in.l.google.com", "alt1.gmail-smtp-in.l.google.com" ], "normalized_email": "[email protected]", "mx_provider": "Google", "is_catch_all": false, "domain_age_days": 11188, "response_time_ms": 46, "checked_at": "2026-04-01T17:32:18Z" }
Five layers, one verdict.
Raw email in. Routing decision out. Each layer runs in parallel and contributes to the final score.
- 01Syntax & format
- 02DNS & MX lookup
- 03Domain intelligence
- 04Mailbox verification
- 05Trust scoring
Pay once. Use anytime.
No subscriptions. No expiry. Credits never burn.
Starter
- 10 req/sec rate limit
- $0.40 per 1,000 checks
Growth
- 25 req/sec rate limit
- $0.35 per 1,000 checks
- All 15+ checks on every request
- Single, bulk CSV and API verification
- Deep Verification, charged per result
- Webhook notifications and CSV export
- Credits never expire
Start verifying in 60 seconds.
Grab an API key, drop in three lines of code, and stop fake signups before they hit your database. Free tier never expires.
MailSift is operated by NORTHPIN INC. Read the data processing agreement and the privacy policy, or check the service status.