Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

SMTP Verification: How It Works and When to Use It

On this page

What Is SMTP Verification?

SMTP verification is a method of checking whether a specific email address exists on a mail server without actually sending an email. It works by initiating the SMTP handshake, the same protocol mail servers use to deliver messages, but stopping before any message is transmitted.

The process determines whether the recipient's mail server accepts the address. If the server says yes, the mailbox exists. If it says no, the address is invalid.

How the SMTP Handshake Works

When one mail server delivers an email to another, they exchange a series of commands. SMTP verification replicates the first few steps of this exchange.

Step 1: Find the mail server

Before connecting, the verifier performs a DNS lookup for the domain's MX (Mail Exchange) records. MX records tell the verifier which server handles email for that domain.

For example, looking up the MX records for example.com might return mail.example.com with a priority of 10.

Step 2: Connect

The verifier opens a TCP connection to the mail server on port 25 (the standard SMTP port).

The server responds with a greeting:

220 mail.example.com ESMTP ready

Step 3: EHLO/HELO

The verifier identifies itself:

EHLO verifier.example.net

The server responds with its capabilities:

250-mail.example.com Hello verifier.example.net
250 OK

Step 4: MAIL FROM

The verifier specifies a sender address:

MAIL FROM:<check@verifier.example.net>

The server responds:

250 OK

Step 5: RCPT TO (the key step)

The verifier specifies the email address being checked:

RCPT TO:<john@example.com>

This is where the verification happens. The server's response reveals whether the mailbox exists.

If the address is valid:

250 OK

If the address does not exist:

550 No such user

If the address is temporarily unavailable:

450 Mailbox temporarily unavailable

Step 6: QUIT

The verifier ends the connection without sending any message:

QUIT

No email is sent. The server processed the handshake but never received any message data.

What SMTP Verification Can Tell You

Mailbox exists (250 response)

The server confirmed that the mailbox accepts mail. This is the strongest signal that the address is valid and deliverable.

Mailbox does not exist (550 response)

The server explicitly rejected the address. This is a definitive signal that the address is invalid. Sending to it would produce a hard bounce.

Temporary failure (4xx response)

The server could not confirm or deny the address right now. This could mean the server is busy, the mailbox is over quota, or greylisting is in effect (see limitations below).

Limitations of SMTP Verification

Catch-all domains

Some domains are configured to accept mail for any address, whether or not a specific mailbox exists. These "catch-all" servers return 250 for every RCPT TO command, making it impossible to determine if a specific mailbox is real.

For more on this, see What Is a Catch-All Email Domain?.

Greylisting

Greylisting is a spam prevention technique where the server temporarily rejects email from unknown senders. The server returns a 450 (temporary failure) on the first attempt. Legitimate mail servers retry, and the second attempt succeeds. SMTP verification tools that do not retry will incorrectly flag these addresses as unverifiable.

Rate limiting and blocking

Major providers like Gmail, Microsoft 365 and Yahoo rate-limit or block SMTP verification attempts. They detect the pattern of connecting, checking an address and disconnecting without sending, and treat it as suspicious activity. Repeated attempts from the same IP can result in temporary or permanent blocks.

Anti-spam measures

Some servers always return 250 regardless of whether the mailbox exists, specifically to prevent address harvesting through SMTP verification. Others delay responses or require additional authentication steps.

Full mailboxes

A mailbox that exists but is full may return a 452 error. The address is valid but cannot currently receive mail. This is a temporary state, not an indication of invalidity.

When to Use SMTP Verification

Before a large campaign

Running SMTP verification on your email list before sending identifies invalid addresses that would otherwise bounce. Removing them protects your sender reputation.

After extraction

If you used Email Extractor to pull addresses from documents, the extracted list contains every address found in the source material. Some may be outdated or invalid. SMTP verification catches the ones that no longer exist.

For high-value outreach

When sending personalised emails to a small number of important prospects, verifying each address first avoids the embarrassment and wasted effort of bouncing.

As part of a multi-step validation pipeline

SMTP verification is most effective as one step in a validation sequence: syntax check, MX record lookup, then SMTP verification. Each layer catches what the previous one missed. See How to Check If an Email Address Is Valid.

When Not to Use SMTP Verification

For real-time form validation

SMTP checks are too slow and unreliable for validating email addresses as users type them into a form. Use syntax validation and MX lookup for real-time checks, then verify via a confirmation email.

Against providers that block it

Repeated SMTP verification against Gmail, Microsoft 365 or Yahoo can get your verification server's IP blocked. Use a dedicated verification service that manages IP reputation and retry logic. See Best Email Verification Services.

As the only validation method

SMTP verification alone misses catch-all domains, greylisting, disposable addresses, role-based addresses and spam traps. Combine it with other checks for comprehensive validation.

SMTP Verification vs. Verification Services

Dedicated email verification services (ZeroBounce, NeverBounce, Bouncer and others) use SMTP verification as one component of their checks. They also add:

  • Disposable email detection
  • Role-based address detection
  • Spam trap databases
  • Historical bounce data
  • Catch-all domain identification
  • IP rotation to avoid blocks

For most users, a verification service is more practical than running SMTP verification directly, because the service handles the infrastructure, rate limiting and provider-specific workarounds.

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)