GET/v1/emails/verify
Verify Email
Checks that a mailbox exists by asking the mail server directly. Returns a status, a reason, and catch-all and disposable flags.
- status
- reason
- isCatchAll
- isDisposable
- mx
Send one address. EnvoAPI asks the recipient's mail server whether the mailbox exists, without sending an email, and returns valid, invalid or unverifiable with the reason, plus catch-all and disposable flags. Fewer bounces, fewer fake signups, cleaner lists. Start with 100 free credits.
Read the API reference2 credits per check100 free creditsNo credit card required
[email protected]mx: aspmx.l.google.comaccepted · no email sentstatus: validWhere it fits
The same check works at signup, before a campaign, and on the way into your CRM.
Catch typos and fake addresses while the user is still on the page. Ask for a correction instead of losing them to a bounced welcome email.
Clean a list before a send. Remove invalid addresses so bounces stay low and your sending domain keeps its reputation.
Verify leads before they enter a sequence. Flag catch-all domains so reps know which addresses are confirmed and which are a guess.
Check purchased or imported lists as they arrive. Route unverifiable rows for review instead of dropping them or sending blind.
Only have a name and a company? Pair it with the Email Finder API, which finds the address first and verifies it in the same call.
How it works
One request runs four checks in order and stops at the first one that fails.
The address is parsed and split into the local part and the domain.
EnvoAPI looks up the domain's mail servers. A domain with no MX record cannot receive email, so the check ends here with reason no_mx.
EnvoAPI asks the mail server whether it accepts this exact address. No email is sent, so nothing lands in anyone's inbox.
You get a status, the reason behind it, and whether the domain is catch-all or disposable.
Every check is live. Results are never cached, so you always see the mail server's current answer.
The response
One JSON object per address. Four fields tell you whether to send. The rest tell you what was checked.
{ "data": { "email": "[email protected]", "user": "Sarah Collins", "domain": "brightpathlabs.com", "mx": "aspmx.l.google.com", "status": "valid", "reason": "accepted", "isCatchAll": false, "isDisposable": false }, "meta": { "creditCost": 2 }}statusvalid means the mail server accepted the mailbox. invalid means it rejected it. unverifiable means it could not confirm either way.
reasonWhy you got that status, as a fixed code you can switch on. All 8 codes are explained below.
isCatchAlltrue when the domain accepts every address. A valid result on a catch-all domain is weaker proof that this specific mailbox exists.
isDisposabletrue when the domain is a known throwaway email provider.
email, user, domain and mx echo what was checked, including the mail server that answered. user and mx can be null.
Reason codes
The reason never changes meaning between releases, so you can build on it.
| Reason | What it means | What to do |
|---|---|---|
accepted | The mail server accepted the mailbox. | Send |
rejected | The mail server said the mailbox does not exist. | Remove |
no_mx | The domain has no mail servers, so it cannot receive email. | Remove |
catch_all | The domain accepts every address, so this one cannot be confirmed on its own. | Review |
timeout | The mail server did not answer in time. | Retry later |
mx_error | The mail server returned an error during the check. | Retry later |
limited | The mail server limited how much it would answer. | Retry later |
spam_block | The mail server blocked the check as anti-spam protection. | Review |
Using the result
Most teams sort results into three buckets. Copy this as a starting point and adjust it to your risk.
data.status === "valid" && !data.isCatchAll && !data.isDisposableThe server accepted a real mailbox on a normal, non-throwaway domain.
data.status === "unverifiable" || data.isCatchAllThe server could not confirm the mailbox, or the domain accepts everything. Retry later, or send only when the lead is worth the bounce risk.
data.status === "invalid" || data.isDisposableThe server rejected the mailbox, the domain has no mail server, or it is a throwaway domain.
If an address matches two buckets, use the stricter one. Your rules may differ: sales teams often still email catch-all domains, newsletters usually do not.
One GET request with your API key and the address. Each check costs 2 credits, so your 100 free credits cover 50 checks.
curl -G "https://api.envoapi.com/v1/emails/verify" \ -H "Authorization: Bearer $ENVO_API_KEY" \ --data-urlencode "[email protected]"const api = "https://api.envoapi.com";const key = process.env.ENVO_API_KEY;const email = "[email protected]";const url = new URL("/v1/emails/verify", api);url.searchParams.set("email", email);const res = await fetch(url, { headers: { Authorization: `Bearer ${key}` },});const { data } = await res.json();function bucket({ status, isCatchAll, isDisposable }) { if (status === "invalid" || isDisposable) { return "dont-send"; } if (status === "unverifiable" || isCatchAll) { return "review"; } return "send";}console.log(bucket(data), data.reason); // send acceptedGood to know
No surprises on the invoice. This is how every verification is charged and when you get credits back.
Every verification costs the same, including unverifiable results, because the mail server was asked.
Addresses at yahoo.* domains, ymail.com and rocketmail.com cannot be verified yet. They return 422 with error code email_unverifiable and the credits come back.
If the verification provider is at capacity or unavailable, you get 503, a Retry-After header, and a refund.
Every response carries X-Credits-Remaining and X-RateLimit-* headers so you can pace a list and stop before you run out.
Each call is a live check. Checking the same address twice means two live checks and two charges.
Email endpoints
They share the same key, the same response shape and the same credit balance.
GET/v1/emails/verify
Checks that a mailbox exists by asking the mail server directly. Returns a status, a reason, and catch-all and disposable flags.
GET/v1/emails/disposable
Tells you if the domain is a known throwaway provider. Free on every call, so you can run it on every signup.
GET/v1/emails/find
Give a first name, last name and company domain. EnvoAPI tests common address patterns with the mail server and returns the one it accepts.
FAQ
No. EnvoAPI asks the recipient's mail server whether the mailbox exists. Nothing is delivered to the inbox you are checking.
The mail server would not confirm or deny the mailbox. The reason code says why, for example timeout, limited, mx_error or spam_block. Many of these cases clear up on a retry later.
A domain whose mail server accepts every address, real or not. Verify Email flags it with isCatchAll. Find Email returns no address for these domains, because every pattern would be accepted.
A regex only checks the format. It cannot tell you whether the domain has mail servers or whether the mailbox exists. Verification asks the server that would deliver the email.
2 credits per address. The free plan includes 100 credits, enough for 50 checks, and no credit card is needed.
Yes, 2 credits like any other check, because the mail server was asked. Credits are refunded only when the check could not run: Yahoo addresses (422) and provider capacity errors (503).
Each request verifies one address. To clean a list, call the endpoint once per address and use the X-RateLimit-* headers to pace the job.
No. Every call is a live check against the mail server, so you always see its current answer.
Not yet. Addresses at yahoo.* domains, ymail.com and rocketmail.com return 422 with error code email_unverifiable. The request is not retryable and the credits are refunded.
If the verification provider is at capacity or unavailable, the request fails with a 503, the credits are refunded, and the Retry-After header says when to try again.
Yes. Check Disposable Email costs no credits, including when the domain is not listed. It only checks the domain, not whether the mailbox exists.
Verify Email checks an address you already have. Find Email discovers an address from a name and a company domain, then verifies it.
Parameters, response schemas and error codes are in the endpoint reference. Plans and credit packs are on the pricing page.