Engineering notes
What email validation actually does against live DNS.
How email validation actually behaves against live DNS: typo correction, RFC 7505 null MX, the SERVFAIL/NXDOMAIN split, and failing open in a signup flow.
Validation engine
-
An Email Regex Is Syntax, Not Validation
A regex answers one question: does the string parse? Domain existence, typo intent, and disposable policy need DNS and curated data. Keep the regex client-side and let an API decide.
-
One Mail Host Serves Both gmai.com and hotmial.com
Typo domains are an unenumerable long tail, but the operators collecting mail for them reuse infrastructure, so the MX host is the tractable signal.
-
Suggest the Correction Instead of Rejecting the Signup
Rejecting a mistyped address ends the session; naming the intended address recovers it, which means the interesting engineering is in the suggestion.
DNS and RFCs
-
MX Lookups over DNS-over-HTTPS: What the JSON Actually Returns
Measured against Cloudflare's DoH resolver on 2026-10-07: five DNS answer shapes a validator really sees, the resolver caches they arrive from, and the verdict each one must produce.
-
MX Validation Does Not Catch the Typos That Matter
An MX lookup accepts the four most common Gmail and Hotmail misspellings, because typo domains are registered and resolve correctly.
-
Null MX, RFC 7505, and Why Reserved Domains Need Their Own Reason Code
A domain publishing MX 0 . is telling you it accepts no mail at all, and example.com does the same — but breaking your test suite is not the same problem as a bad signup.
-
SERVFAIL Is Not NXDOMAIN, and Conflating Them Accepts Bad Addresses
A resolver failure and a nonexistent domain arrive as different DNS status codes and demand opposite responses: fail open on one, reject on the other.
Signup flows
-
Fail Open: Email Validation Must Never Block a Signup
Treat the validator as advisory infrastructure: set a timeout, branch on the verdict, record what was actually checked, and let users through when it cannot answer.
-
Handle Email Validation Verdicts in a React Signup Form
Keep the API key on the server, call your own route from React, and branch the form on suggestion, reject, accept, and unchecked states instead of a single boolean.
-
How to Batch-Validate a List of Email Addresses
POST /v1/check/batch returns one verdict per address keyed by email_sha256; chunk oversized lists, check remaining quota first, and act on suggestions instead of only counting rejects.
-
How to Handle an Email Validation Timeout at Signup
A signup-path timeout is a client decision, not a verdict: abort the request, accept the user, annotate mxChecked=false, and never retry the same submit.
-
How to Handle Disposable Email Addresses at Signup
Throwaway domains produce a real, working mailbox, so blocking them is a product rule rather than a validity fact: annotate the record, gate high-value actions, and only block abusers you can count.
-
How to Handle Role Email Addresses at Signup
A role-account flag describes an address pattern, not who reads the inbox. Accept and annotate by default; enforce personal-identity requirements separately from email validity.
-
How to Test Email Validation Without Live DNS
Test your signup policy locally, audit the public fixture contract separately, and keep live DNS checks out of the assertions that decide whether a merge is safe.
-
How to Validate an Email Address in Go
Use net/http and context.WithTimeout to validate signup emails in Go, map all four verdicts, and recover mistyped domains instead of rejecting them.
-
How to Validate an Email Address in Java
Use the JDK's own HttpClient and a couple of records to validate signup emails in Java, map all four verdicts, and recover mistyped domains instead of rejecting them.
-
How to Validate an Email Address in Node.js
Call /v1/check from server-side Node.js, fail open when the request cannot finish, and turn a suggested correction into a recoverable signup instead of an error.
-
How to Validate an Email Address in PHP
Skip filter_var and the inbox-probing libraries: call /v1/check with ext-curl, fail open on timeouts, and offer the suggested correction instead of rejecting.
-
How to Validate an Email Address in Python
Skip the regex and the inbox-probing libraries: call /v1/check from the standard library, fail open on timeouts, and offer the suggested correction instead of rejecting.
-
How to Validate an Email Address in Ruby
Skip the regex and the inbox-probing gems: call /v1/check with Net::HTTP, fail open on timeouts, and offer the suggested correction instead of rejecting.
-
Retry Email Validation Without Spending Quota Twice
Background validation retries need a stable operation key and an unchanged request body; completed replays consume no extra quota, while fresh checks require fresh keys.
-
Validate Email Addresses From an AI Agent
An autonomous agent can obtain access, validate an address and recover from an error without a human in the loop, provided every step is a single HTTP request.
-
Validate Email Addresses Over MCP
Call check_email, check_email_batch and friends as MCP tools from any MCP client: the key is a tool argument, results arrive as frozen verdict objects, and suggestions still recover the signup.
Choosing a validator
-
How to Choose an Email Validation API
Accuracy percentages on vendor pages are unfalsifiable, so evaluate the response contract, the failure behaviour and the retention policy instead.
-
nobounce.dev vs ZeroBounce: Not a Like-for-Like Choice
ZeroBounce wins at per-mailbox certainty and list cleaning; nobounce.dev wins at inline signup typo recovery, price floor and retention. Pick by requirement, not by accuracy percentage.
-
Should You Build Email Validation In-House?
You can write a working MX validator in twenty lines today. This page enumerates what that version silently gets wrong against live DNS, and states plainly when building it yourself beats paying for an API — and when it does not.
-
Why nobounce Will Never Do SMTP RCPT TO Probing
The technique that promises per-mailbox certainty depends on infrastructure reputation, returns weak signals at the largest providers, and is permanently outside this product's scope.