Acceptable use
A verifier is a tool for keeping a list you are entitled to hold in good order. It is also, in the wrong hands, a tool for building one you are not.
Last updated September 2026.
1. Lists you have no right to hold
Don't upload addresses you bought, scraped or were handed without the owners knowing. Verification removes the ones that bounce. It does nothing about consent, so a clean purchased list is still a purchased list, and sending to it is still your risk and your recipients' problem.
We say this on the product pages too, because it costs us sales and we would rather lose them. A valid verdict is not permission to email someone.
2. Harvesting
Don't use the API to find out which addresses exist. Guessing at firstname.lastname@ patterns and keeping the ones that come back valid is harvesting, whatever the list is later used for. The same goes for running a dictionary of names against a domain.
3. Abuse of the mail servers we talk to
Every check opens a connection to somebody else's mail server. The API is rate limited for that reason, and the limits are in the documentation. Don't try to get round them with multiple accounts or keys. Volume that gets our addresses blocked by a large provider degrades results for every other customer.
4. The ordinary prohibitions
Don't use ZapBounce to break the law, to send or prepare spam, to stalk or harass anyone, or to check addresses as part of taking over an account that isn't yours. Don't probe, scan or attack the service, and don't resell access to it without asking us first.
The short version
- Upload only lists you are entitled to hold.
- Verification does not create consent and never stands in for it.
- No pattern-guessing or dictionary runs to discover addresses.
- Stay inside the documented rate limits, on one account.