Use MailSift when you need more than a regex and less hand-holding than an enterprise implementation project. The product is shaped for developers, revops teams, and operators who need fast answers at batch scale.
Each call runs a comprehensive pipeline that goes far beyond basic syntax and MX validation.
RFC-compliant local part and domain checks plus provider-aware normalization for Gmail-style aliases.
"syntax": truePull live MX records and ignore null-MX domains so undeliverable hosts never enter your funnel.
"mx": trueCatch throwaway addresses from 500k+ known providers. MX heuristics detect new ones automatically.
"disposable": falseUnmask SimpleLogin, AnonAddy, Apple Hide My Email, and Firefox Relay that hide the real sender.
"relay": falseCheck domain age, MX provider, and whether the domain is routable, disposable, or parked.
"domain_age_days": 4823Suggest corrections for common domain typos like gmial.com — before they turn into hard bounces.
"did_you_mean": "gmail.com"Validate SPF and DMARC records to confirm the domain has proper email security configuration.
"spf": true, "dmarc": trueFlag info@, sales@, and other inboxes that route to teams instead of a single human.
"role": falseIdentify gmail, yahoo, outlook, and other free providers for clean segmentation downstream.
"free": trueSpot domains that accept every address so you can route catch-all hits to a separate workflow.
"catch_all": falseMap every domain to its hosting provider — Google, Microsoft, Proofpoint, Mimecast, and more.
"mx_provider": "Google"Detect synthetic patterns like long-digit prefixes that often slip past basic regex validators.
"score": 82All 15+ signals combine into a single 0-100 score. Route by risk, not guesswork. Tune per environment.
"score": 95Canonical address form for deduplication — strips plus-aliases, dots, and provider-specific noise.
"normalized_email": "[email protected]"Standard is the default on every endpoint. Deep adds one thing: an SMTP conversation with the recipient’s mail server about the mailbox itself. Same endpoints, same credit balance, one parameter apart.
Some providers will not confirm mailbox existence. Yahoo and AOL accept recipients they cannot vouch for. Secure gateways like Proofpoint, Mimecast and Barracuda accept every recipient at the perimeter. For those, MailSift returns unknown, usually with catch_all true, instead of dressing an acceptance up as proof. The raw result stays in the response so you can route on it yourself.
Same request, same response shape. The second address is not an error and not a failed check. It is a mailbox the provider will not discuss, reported as exactly that. Full smtp field and status reference →
Pick the right entry point for the job — call us inline, run a batch, or listen for events.
A single GET request returns disposable status, domain reputation, risk score, and 15+ checks. Sub-second median response times in every region.
Upload a CSV, get a job id back instantly, and stream progress over SSE. Read parsed rows for in-app filtering or download the finalized output.
Signed webhooks deliver bulk job events to your endpoints so you can wire them into a CRM, queue, or warehouse without polling.
Choose your language. The request shape stays the same in every SDK.
Sign up, generate a key, and run your first verification in under five minutes. Credits never expire.