Architecture
Modular verification engine — what's active, what's probed, and what requires external infrastructure.
Verification modules
Syntax Validation
ActiveRFC 5321/5322 structural checks — local, active, no network.
Email Normalization
ActiveLowercase, trim, Gmail dot/plus collapse for dedup. Original preserved.
Duplicate Detection
ActivePer-list dedup using normalized keys — identifies repeats.
Disposable Detection
ActiveLocally maintained reference list (400+ domains). No external API.
Role Detection
ActiveFlags shared role mailboxes (info@, sales@) as risky.
Typo Detection
ActiveLevenshtein against popular-provider domains; suggestions need approval.
DNS Validation
Ready (opt-in)Real MX/A/AAAA resolution over DNS-over-HTTPS. Honest results, no fakes.
Risk Scoring
ActiveAggregate flags into ACCEPTABLE / RISKY / INVALID / DUPLICATE / UNKNOWN.
SMTP Verification
DisabledMailbox exchange. Disabled — external engine required (interface ready).
Catch-All Detection
ExternalAccept-all domain assessment. External engine only — never local probing.
Bounce Analysis
ExternalBounce-code classification. Requires SMTP feedback or external data.
Verification History
ActiveLocal IndexedDB history of every cleaned list. Deletable on demand.
Runtime capability assessment
External SMTP engine interface
Disabled — awaiting authorization
The SMTP verification interface is implemented and ready, but remains disabled until a separately hosted engine's infrastructure, authorization, and rate limits are approved. It will never perform unrestricted SMTP probing or bulk mailbox enumeration.
Batch verification
Submit a job, poll for progress
Per-address results
Deliverable / catch-all / invalid / unknown
Timeouts & retries
Configurable per request
Rate limiting
Requests-per-minute cap
Catch-all assessment
Accept-all domains flagged, not verified
Unknown status handling
Never promoted to valid