Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

Email Validation API Best Practices: Implementation Guide for Developers

On this page

When to Use an Email Validation API

Email validation APIs verify email addresses in real time or in batch by checking syntax, domain, mailbox existence and reputation. They sit between your application and the email recipient:

Validation level What it checks Can be done locally Needs API
Syntax validation RFC 5322 format compliance Yes No
Domain validation (DNS/MX) Domain exists and has mail servers Yes (DNS lookup) No (but API is faster)
Disposable email detection Domain is a temporary/throwaway email service Yes (with maintained blocklist) Better via API (lists are larger and updated)
Role-based detection Address is a group (info@, admin@, support@) Yes (pattern matching) No
SMTP verification Mailbox exists on receiving server Possible but complex Yes (recommended)
Reputation scoring Email or domain has spam/abuse history No Yes
Catch-all detection Domain accepts all addresses (can not confirm individual) Possible but unreliable Yes
Typo suggestion "gmial.com" should be "gmail.com" Yes (with dictionary) Better via API

Common validation API providers

Provider Real-time API Batch API Pricing model Response time
ZeroBounce Yes Yes Per-credit ($0.007-$0.01) 200-500ms
NeverBounce Yes Yes Per-credit ($0.003-$0.008) 300-800ms
Kickbox Yes Yes Per-credit ($0.005-$0.01) 200-600ms
Abstract API Yes No Per-credit ($0.003-$0.01) 200-500ms
Debounce Yes Yes Per-credit ($0.002-$0.005) 200-600ms
Emailable Yes Yes Per-credit ($0.003-$0.007) 300-700ms
Hunter.io Yes Yes Included in plans 300-800ms
Mailgun (Mailgun Validate) Yes Yes Per-validation ($0.01) 200-500ms

Architecture Decisions

Real-time vs batch validation

Factor Real-time (on form submission) Batch (after collection)
User experience Immediate feedback; can correct errors No feedback at signup; bad emails enter system
API cost Validates every submission (including abandoned forms) Validates only collected emails
Latency Adds 200-800ms to form submission Runs in background; no user-facing latency
Accuracy Most current result at time of signup May be stale if time passes between collection and validation
Error handling Must handle API failures gracefully (user is waiting) Can retry failures; no user impact
Implementation complexity Higher (UX, error handling, timeout management) Lower (background job)
Best for Signup forms, checkout, account creation List imports, migration, periodic cleaning

Where to validate in the stack

Location Pros Cons Best for
Client-side (JavaScript) Instant feedback; no server round-trip Exposes API key; can be bypassed; limited validation Syntax check only; typo suggestions
Server-side (on form submit) Secure; full validation; API key protected Adds latency to form submission Real-time validation at signup
Background job (async) No user latency; can retry; handles volume Delayed feedback; bad emails may enter system temporarily Batch validation; list cleaning
Webhook (post-submit) Non-blocking; decoupled architecture Complex setup; delayed result Event-driven architectures

Implementation Patterns

Real-time validation on signup

Step Action Notes
1 Client-side: syntax validation + typo suggestion Instant feedback; catches obvious errors before API call
2 On form submit: server-side API call Validate with API; 200-800ms latency
3 Handle API response Accept, reject, or warn based on result code
4 Handle API timeout/failure Fall back to local validation; accept and validate async
5 Store validation result Save API response code with contact record for future reference

Response handling decision matrix

API result Action User message
Valid (deliverable) Accept None (proceed normally)
Invalid (undeliverable) Reject "This email address does not appear to be valid. Please check for typos"
Risky (catch-all domain) Accept with flag None (accept; flag for monitoring)
Disposable Reject or warn "Please use a permanent email address" (if business policy)
Role-based (info@, admin@) Accept or reject Depends on use case; B2B may accept; B2C may request personal email
Unknown (API could not determine) Accept with flag None (accept; validate async)
Typo detected Suggest correction "Did you mean user@gmail.com?"
API error / timeout Fall back to local validation None (accept; validate async)

Batch validation workflow

Step Action Notes
1 Export email list to CSV Include all emails to validate
2 Upload to batch validation API Most APIs accept CSV upload or API batch endpoint
3 Wait for processing Minutes to hours depending on list size
4 Download results CSV with validation status per email
5 Process results Segment by status; remove or flag invalid; keep valid
6 Update database Mark each record with validation status and date

Error Handling and Fallbacks

API failure scenarios

Failure Impact Fallback strategy
API timeout (request exceeds time limit) User waiting on form submission Accept email; queue for async validation
API rate limit exceeded Validation requests rejected Queue requests; process when rate limit resets
API server error (5xx) Validation unavailable Fall back to local validation (syntax + MX check)
API key expired / invalid All requests fail Alert engineering; fall back to local validation
Network error Can not reach API Accept email; queue for async validation
Unexpected response format Can not parse result Log error; fall back to local validation

Fallback validation (local)

When the API is unavailable, local validation provides basic protection:

Check What it catches Implementation
Syntax validation Malformed addresses Regex or library (RFC 5322 compliant)
MX record lookup Non-existent domains DNS lookup for MX records
Disposable domain check Known throwaway domains Maintain blocklist (open-source lists available)
Typo detection Common domain misspellings Dictionary of common domains + Levenshtein distance

Caching Strategies

Caching validation results reduces API costs and latency:

Strategy How it works Cache duration Cost savings
Result caching (by email) Cache API result for each validated email 24-72 hours High (duplicate submissions)
Domain caching Cache domain-level results (MX check, catch-all status) 24-48 hours Medium (many emails per domain)
Negative caching Cache invalid results to immediately reject known-bad addresses 7-30 days Medium (repeated bad addresses)
Disposable domain caching Cache disposable domain list locally Update weekly High (avoid API call for known disposables)

Cache invalidation considerations

Factor Guidance
Email deliverability changes Mailboxes are created and deleted; do not cache "valid" longer than 72 hours
Domain changes MX records change; refresh domain cache every 24-48 hours
Disposable domains New disposable services launch daily; update list weekly
Invalid results Invalid emails rarely become valid; safe to cache longer (7-30 days)

Rate Limiting and Throttling

Scenario Rate limit approach Implementation
Real-time signup validation 1 request per form submission No throttling needed (user-driven rate)
Batch import validation 10-100 requests per second (per API provider limits) Queue with rate limiter; respect API rate headers
Background re-validation Low priority; process during off-peak hours Scheduled job with configurable concurrency
High-volume events (product launch, campaign) Pre-validate list before event; real-time only for new signups Batch validate in advance; cache results

Performance Optimisation

Technique Benefit Implementation
Client-side pre-validation Eliminate obviously invalid emails before API call Syntax check + typo suggestion in JavaScript
Async validation (non-blocking) No latency added to form submission Validate after submit; flag bad emails later
Connection pooling Reduce TCP handshake overhead for batch requests HTTP connection pool in your HTTP client
Parallel requests Faster batch processing Send concurrent requests up to API rate limit
Result caching Avoid duplicate API calls Cache by email address for 24-72 hours
Circuit breaker Prevent cascading failures when API is down Fail fast after consecutive errors; fall back to local

Preparing Lists for API Validation

Before sending email lists through a validation API, clean and deduplicate them first. Upload your raw lists (CSV exports from forms, CRM dumps, scraped data, purchased lists) to Email Extractor to extract and deduplicate email addresses. This reduces API costs by eliminating duplicate addresses that would each consume a validation credit and ensures you are validating a clean, unique list.

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)