Our accuracy, with the denominator

Every verifier in this market advertises a number above 99%. An independent test of the field measured 63% to 70%. Both are arithmetically correct, and the gap between them is this page.

The short version

  • A vendor accuracy figure answers: of the addresses we returned a verdict on, how many were right. It says nothing about how many we refused to judge.
  • The refused ones are the hard ones. Catch-all domains, Yahoo, Microsoft throttling, greylisting.
  • We report coverage and accuracy together. Neither means much alone, and accuracy alone can be improved by guessing.
  • We have not measured ours yet, so this page publishes no ZapBounce percentage. When the benchmark runs, it publishes in full, including where we lose.

How a 99% figure is built

Not by fraud. By choosing a denominator and not mentioning it.

Run 100,000 B2B addresses through a verifier. Perhaps 71,000 come back valid and 13,000 invalid. Around 9,700 sit on catch-all domains that accept every address, and roughly 6,000 land on servers that throttled, greylisted or lied.

A vendor can now report accuracy against the 84,000 it judged, and quietly set the other 16,000 aside. Score well on the easy ones and 99% is comfortably true. The number simply does not describe the part of the job you were worried about.

There is a worse version. Resolve ambiguous addresses to valid rather than labeling them, and both the coverage figure and the accuracy figure improve, while the list you send to gets worse. The metric rewards the behavior you least want.

The same 100,000 addresses, with nothing hidden

valid
71,40271.4%
invalid
12,88112.9%
catch-all
9,7309.7%
unknown
5,9876.0%

Unknown means the server would not give a straight answer. We report it, and we do not bill it.

An illustration of the shape a B2B list usually takes, not a measured ZapBounce result. The catch-all share reflects the roughly 28% reported for B2B lists.

The two numbers

Reported together, always. The component that renders them will not accept one without the other.

What it answersHow it can be gamed
CoverageWhat share of your list did we reach a defensible verdict on?By guessing. Resolve every ambiguous address to valid and coverage hits 100%, which is why it is meaningless alone.
AccuracyOf the verdicts we returned, how many held when mail was actually sent?By judging less. Refuse everything hard and accuracy approaches 100% on what remains.

Each number can be improved by making the product worse. Moving both at once is the only honest kind of progress, which is why we publish them as a pair.

How we verify

Our own SMTP check, over port 25, rather than a third-party API with our name on it.

We look up the domain’s mail servers, open a connection, greet the server, name a sender, and ask about the recipient with RCPT TO. The server’s answer to that one command is the whole test. Then we close the connection, before the stage where a message would be transmitted, so nothing is delivered and the mailbox owner sees nothing.

We then ask about an address that cannot exist. If the server accepts that too, the domain takes everything and we label it catch-all rather than valid.

Port 25 is blocked by most residential ISPs and many cloud providers, and how servers respond depends partly on the reputation of the address asking. That is a real infrastructure cost and it is part of why verification quality varies between vendors running the same protocol.

What we have not measured

What nobody can measure

No verifier can confirm a mailbox on a catch-all domain, because the server accepts every address by design and there is no question left to ask. Yahoo and AOL behave that way deliberately to defeat address harvesting, so Yahoo-hosted domains effectively always classify as catch-all.

Gmail and Microsoft 365 block verification traffic from cloud addresses and throttle what they do not block. Pristine spam traps look identical to working mailboxes at the protocol level, so no product can reliably strip them.

And none of it tells you whether a person reads the mailbox. A perfectly valid address abandoned three years ago still verifies as valid.

Questions about the method

What accuracy is actually achievable?

On domains that answer honestly, 95 to 98 percent is defensible. Across a whole list including catch-alls and anti-enumeration providers, the independent benchmark of the field measured 63 to 70 percent.

Does verifying send an email?

No. The connection closes after the recipient question and before the stage where a message body would be transmitted.

Why do two verifiers disagree about one address?

Usually because one guessed. Catch-all domains and throttled servers give ambiguous answers, and vendors differ in whether they resolve that to valid, to risky, or to an honest unknown.

Do you charge for unknowns?

No. An unknown is work we could not complete, and billing for it would make the honest verdict the expensive one. A catch-all is different. There the server did answer, the finding about the domain is real, and it costs a credit like a valid or an invalid.

When will the benchmark be published?

When it has been run properly on a dataset we can describe. Publishing a number early would contradict the only thing this company is arguing.

Check the unresolved share yourself

100 free checks a month, no card. Run a sample and count what came back unknown.