Email verification APIs for outbound teams (2026): accuracy, catch-all handling, price per 1,000
What we learned verifying 413,049 addresses for our own outbound, and six APIs read on their own sites this week.
The short version
4 things that decide this
- 01A verifier's headline accuracy counts only the addresses it reached a verdict on. Catch-all and unknown results leave the count first, and on B2B lists they're a quarter or more of the file.
- 02Hunter's benchmark of 15 verifiers on 3,000 real business addresses, published 3 November 2025, scored the whole field between 31.2% and 70.0% once unknowns counted against accuracy.
- 03Of the 413,049 addresses we verified for our own outbound, 32% came back valid, 26% catch-all, 34% invalid and 8% unknown. The catch-all quarter is where your bounce rate hides.
- 04Judge an API on four things: whether it bills unknowns, how it labels a catch-all domain, whether role and disposable are flags or verdicts, and the price per 1,000 at the volume you actually send.
What 413,049 verified addresses taught us
We run cold outbound for Hashlogics, and until this month we ran our own verifier beside the scrapers. It held 413,049 addresses when we took it out of the pipeline in September 2026: 132,086 valid, 106,887 catch-all, 141,117 invalid and 32,959 unknown. So a third of what we'd gathered was dead, and a quarter was a coin toss. If you buy or scrape lists, your file looks like this too.
A cleanup the same month gave us the second lesson. Our scrapers had pushed 56,189 contacts into the CRM before the verify step was enforced. When we re-ran them against the verified files, 17,506 came back, and 38,683 were gone. Every one of those had an address that would've looked fine to you on screen.
You'll see that shape on any scraped or purchased list, whatever your volume. It's why every outbound automation pipeline we build puts the verify step before the sequence, never after the first bounce report.
Why a 99% accuracy claim skips the hard addresses
Every verifier you can buy runs the same handshake. It looks up the domain's mail server, opens a connection, names a recipient and reads the reply code. A 250 means accepted and a 550 means no such user. Nobody on your list gets an email, because the connection closes before any message is sent.
Your trouble starts with the domains that answer 250 to everything. A catch-all domain accepts any name, so the probe tells you nothing. Yahoo and AOL say yes to every recipient on purpose, to stop address harvesting. Gmail and Microsoft 365 block or throttle probes from cloud ranges, so your vendor's IP pool matters. A greylisting server rejects your first attempt with a temporary code, by design.
ZeroBounce's own status docs call catch-all addresses "impossible to validate without sending a real email and waiting for a bounce". NeverBounce labels its catchall result "Accept-all (Unverifiable)". Both labels are honest. Neither shows up in the headline accuracy figure you're shown, because that figure is measured on the addresses that reached a verdict.
- 01Hunter tested 15 verifiers on 3,000 real business addresses and published the results on 3 November 2025. Overall accuracy ran from 31.2% to 70.0%, because unknown results counted against the score.
- 02In our pool, catch-all plus unknown came to 139,846 addresses, or 34% of the file. A 99% claim that leaves them out describes the other two thirds.
- 03Role addresses such as info@ and sales@, and disposable domains, are list lookups rather than handshakes. They're the one part of the job every vendor gets right.
- MX lookupNo mail server means invalid, no probe needed
- RCPT TOThe recipient is named; no message is ever sent
- 550No such user: invalid, deleted
- 250, and a random name also gets 250Catch-all: the domain accepts everything
- 4xx, timeout or blockedUnknown: greylisting or a probe block; retry later
- 250 for the real name onlyValid: safe for the cadence
The reply code to RCPT TO is the whole verdict. Every vendor in the table reads the same codes; they differ in what they call them and what they bill.
How to evaluate an email verification API
Ask four questions before you buy credits, in this order. Your answers decide your bounce rate more than any accuracy claim does.
- 01Does it bill unknowns? Five of the six vendors below say no on their own pages. A vendor that charges for a non-answer is charging you for its blocked IPs.
- 02How does it label a catch-all domain? You want a distinct result you can route, whether the wire value is catch_all, accept_all or risky. A catch-all that comes back as valid will bounce on your sender's reputation, not the vendor's.
- 03Are role and disposable flags or verdicts? A flag sits beside valid or invalid, so you can keep sales@ on a partner list and drop it from cold email. A verdict throws that choice away.
- 04What's the price per 1,000 at your real volume? At 100,000 addresses the spread in the table below is more than three to one, for the same handshake.
Six email verification APIs, read on 25 September 2026
Every figure below was read on the vendor's own page on the date shown, so you can check it yourself. Where a site blocked automated reads, the cell says so rather than carrying a third-party number. Prices are pay-as-you-go list prices in US dollars.
| Vendor | Accuracy claim | Catch-all result | Unknowns billed? | Price per 1,000 at 10k / 100k | Free credits | Source |
|---|---|---|---|---|---|---|
| ZapBounce (built by Hashlogics) | Reports coverage and accuracy as two numbers, never one headline % | catch_all, a distinct result billed once; role, disposable and free_provider are flags | No. Duplicates and syntax rejects are free too | $2.50 / $1.39 ($25 per 10,000; $139 per 100,000); $5 per 1,000 entry; credits never expire | 100 a month, no card | zapbounce.com/pricing, 25 September 2026 |
| ZeroBounce | 99.6%, described as guaranteed | catch-all status, "impossible to validate without sending a real email"; role_based and disposable sit under do_not_mail | No | Pay-as-you-go from $39 per 2,000 ($19.50 per 1,000 at entry); volume tiers on a slider; subscription from $99 a month | 100 a month | zerobounce.net pricing and status-codes docs, 25 September 2026 |
| NeverBounce | Not readable: neverbounce.com returned 403 to automated reads | catchall, "Accept-all (Unverifiable)"; disposable is a fifth result; role_account is a flag | Not stated in the developer docs | Pay-as-you-go plus a subscription; figures not read (site blocked) | Not read | developers.neverbounce.com single-check reference, 25 September 2026 |
| Bouncer | None published; states under 2% unknown results | acceptAll yes / no / unknown on the domain, status risky; toxic field; role, disposable and free flags | No, nor duplicates | $6.00 / $4.00 ($60 per 10,000; $400 per 100,000); credits never expire | 100 | usebouncer.com/pricing and docs.usebouncer.com, 25 September 2026 |
| Kickbox | None published; cites 40 billion email signals a day | accept_all true / false beside deliverable; Sendex quality score 0 to 1; role, free and disposable flags | No, the credit is refunded | $7.00 / $5.00 ($70 per 10,000; $500 per 100,000) | 100 | kickbox.com/pricing and docs.kickbox.com, 25 September 2026 |
| Emailable | None published | accept_all boolean with a risky state; score field; role, disposable and free flags | No, refunded along with duplicates | $6.00 / $4.20 ($60 per 10,000; $420 per 100,000); credits never expire; 250,000 in about 7 minutes | 250 | emailable.com/pricing and docs, 25 September 2026 |
Run verification as a pipeline step, not a one-off cleanup
Verify at ingest, before an address can reach one of your sequences, and route the four results differently. Valid goes to your cadence and invalid gets deleted. Catch-all goes to a low-volume lane on a warmed domain, where a bounce costs you less. Unknown gets re-checked after a delay: greylisting servers answer on the second try, so a retry with backoff turns many unknowns into answers for free.
Keep the flags apart from the verdicts in your CRM. Role addresses are fine on your partner list and poison in your cold email, and a disposable domain is never worth a credit. We store one field per flag, which is the shape the APIs return, and it's the first thing we wire up when you bring us an integration against your CRM's API. Before you buy credits anywhere, run your sending domain through ZapBounce's free SPF, DKIM and DMARC tools: a clean list on a broken domain still bounces.
ZapBounce is the verifier we built for this workflow, and you can try it on 100 free checks a month with no card. It runs our own SMTP check on port 25, closes the connection before DATA, returns four results, and never bills you for an unknown. If you're weighing it against the vendors above, ZapBounce's side-by-side comparison pages carry the same dated figures, and its pricing page prints the whole ladder from 1,000 to a million.
Questions this raises
01Can an email verification API verify a catch-all address?+
No API can verify a catch-all address. The domain accepts every recipient, so the SMTP probe returns the same code for a real mailbox and a made-up one. A vendor that marks some catch-alls as valid is scoring them by probability, and you pay for the misses in bounces. Treat those rows as a separate lane with its own bounce budget, and you'll keep your main sender clean.
02Why do most verifiers charge nothing for an unknown result?+
An unknown is the absence of an answer, and the vendor knows it. Five of the six vendors in the table say so on their own pages. Usually you're looking at a greylisting server, a blocked probe at Gmail or Microsoft 365, or a timeout. Re-check a day later and you'll often get your answer.
03What bounce rate should a verified list give you?+
ZeroBounce says its valid results bounce at under 2%, and that's the only bounce figure you'll find on these six vendors' pages. What you control is where you send. Send to valid only from your cold domain, work catch-all rows from a separate warmed sender, and send nothing to invalid or disposable.
Related
- Outbound AI calls work when the job is narrow →The same lesson for the phone channel: narrow the job before you scale it.
- Business process automation →Where the verify-at-ingest step lives in the pipelines we build.
- API integration →Wiring a verifier's results and flags into your CRM.
- Exponential backoff →The retry pattern that turns greylisted unknowns into answers.
- ZapBounce email verification →Our own SMTP check, four results, unknowns never billed.
