Architecture

Modular verification engine — what's active, what's probed, and what requires external infrastructure.

Verification modules

Syntax Validation

Active

RFC 5321/5322 structural checks — local, active, no network.

Email Normalization

Active

Lowercase, trim, Gmail dot/plus collapse for dedup. Original preserved.

Duplicate Detection

Active

Per-list dedup using normalized keys — identifies repeats.

Disposable Detection

Active

Locally maintained reference list (400+ domains). No external API.

Role Detection

Active

Flags shared role mailboxes (info@, sales@) as risky.

Typo Detection

Active

Levenshtein against popular-provider domains; suggestions need approval.

DNS Validation

Ready (opt-in)

Real MX/A/AAAA resolution over DNS-over-HTTPS. Honest results, no fakes.

Risk Scoring

Active

Aggregate flags into ACCEPTABLE / RISKY / INVALID / DUPLICATE / UNKNOWN.

SMTP Verification

Disabled

Mailbox exchange. Disabled — external engine required (interface ready).

Catch-All Detection

External

Accept-all domain assessment. External engine only — never local probing.

Bounce Analysis

External

Bounce-code classification. Requires SMTP feedback or external data.

Verification History

Active

Local IndexedDB history of every cleaned list. Deletable on demand.

Runtime capability assessment

Loading…

External SMTP engine interface

Disabled — awaiting authorization

The SMTP verification interface is implemented and ready, but remains disabled until a separately hosted engine's infrastructure, authorization, and rate limits are approved. It will never perform unrestricted SMTP probing or bulk mailbox enumeration.

Batch verification

Submit a job, poll for progress

Per-address results

Deliverable / catch-all / invalid / unknown

Timeouts & retries

Configurable per request

Rate limiting

Requests-per-minute cap

Catch-all assessment

Accept-all domains flagged, not verified

Unknown status handling

Never promoted to valid