What we cannot verify, and why

The complete list, with the reason for each. Most of them are not fixable by anyone.

Start with what a probe does. We open a connection on port 25, greet the server, name a sender, name one recipient and read the response. Then we close the connection before any message body is transmitted. Nothing is delivered and nobody receives anything.

That exchange can tell us the address was rejected, the address was accepted, or the server would not answer. Everything a verifier sells is built on those three outcomes, and most of what people want to know is not in there.

Catch-all domains accept every recipient, so acceptance means nothing on roughly 28% of business addresses. Yahoo and AOL accept everything by anti-harvesting policy. Proton Mail accepts everything as a privacy stance. Gmail and Microsoft 365 block probes from many cloud IP ranges, so we frequently get no answer at all rather than a wrong one.

Greylisting returns a temporary failure on a first contact by design, and a single-shot verifier reads that as a problem with the address. Microsoft throttles hard enough that the same address can produce two different results an hour apart.

The things no protocol can reach

Whether a human reads the mailbox. A shared inbox, an alias pointing at somebody who left in 2019, and an active mailbox all answer identically.

Whether the address is a pristine spam trap. Those are ordinary mailboxes that were never used by a person and are monitored by a blocklist operator. At the protocol level they are indistinguishable from a real address, which is why nobody can remove them and why we do not claim to.

Whether the person will engage. That is your own open and click history, and it is a better predictor of campaign performance than any verification verdict.

Whether an address is about to stop working. An employee resigns on Friday and the mailbox is deleted on Monday. A verdict is true at the moment it is measured.

Where this argument costs us something

The short version

  • Use verification for what it measures: whether the mailbox accepts mail right now.
  • Use engagement data for everything else, because it answers the questions verification cannot.
  • Be suspicious of any product claiming to remove spam traps.

Questions people ask

Does verification send an email?

No. The connection is closed before the message body stage, so nothing is delivered and the mailbox owner sees nothing.

Can you detect spam traps?

Recycled traps are sometimes flaggable by heuristic, and we label that as a heuristic. Pristine traps are undetectable at the protocol level, and any vendor claiming otherwise is selling probability as certainty.

See both numbers on your own list

100 free checks a month, no card. Addresses we could not get an answer on come back labeled, and we do not bill them.