ZapBounce
Know what each address is before you send.
An email verification API and list cleaner we built and run ourselves, with our own SMTP check behind every result.
- Client
- Hashlogics (our own product)
- Industry
- Email verification · Deliverability · SaaS
- Region
- Global · hosted in the United States
- Engagement
- Product we built and run · API-first SaaS
ZapBounce is an email verification API and list cleaner that Hashlogics built and runs as its own live product. Its own SMTP check returns one of four results for every address: valid, invalid, catch-all or unknown. Your team collects addresses faster than it can trust them. Sign-up forms, CRM imports and lead lists carry dead mailboxes, throwaway domains and typos. Every bad address you send to pushes your bounce rate up.
Why a simple valid or invalid check falls short.
Your lists pick up dead mailboxes, disposable domains, role accounts and typos from forms, imports and data providers.
A catch-all domain accepts every address you try, so a mail-server check can't confirm one mailbox on it.
Some mail servers answer the first attempt with a temporary failure, and others refuse probe traffic outright.
One team needs a single sign-up checked while the user waits. Another needs a whole list cleaned in the background.
Your developers want to call the same check from lead forms, CRM workflows and their own apps.
What success needed to look like
- Give every address one clear result your code can act on.
- Check a single address in real time, or a full list as a background job.
- Tell your systems when a bulk job finishes, with a webhook they can trust.
- Let each customer decide how long uploaded addresses are kept.
- Never send a message to the mailbox being checked.
How ZapBounce checks an address and protects your data.
- 01
Run the SMTP check ourselves
We built our own verification over port 25 instead of wrapping another vendor's API.
- 02
Hang up before any message is sent
The check asks the server whether it would accept the address, then closes the connection. Nothing ever lands in the mailbox you're checking.
- 03
Keep four results, not two
Valid, invalid, catch-all and unknown each get their own label. Role, disposable and free-provider addresses are flags on top, so they don't hide the real result.
- 04
Put one engine behind every door
Our web app, the bulk uploader and the REST API all call the same verification engine.
- 05
Build deletion into the API
Your uploaded lists are kept for 30 days by default. Each of your API keys can set its own window from 0 to 90 days, and one call deletes a batch at once.
What ZapBounce does, from one address to a full list.
ZapBounce checks one address in real time or a whole list in the background. You can paste addresses, upload a CSV or TXT file, or call the API from your own code. Each address passes through syntax, domain and mail-server checks, then comes back as valid, invalid, catch-all or unknown. Unknown results and duplicates are never billed.
Developers get a versioned REST API, sandbox keys for testing, and webhooks signed so your system can confirm who sent them. ZapBounce doesn't sell uploaded addresses, add them to a shared database, or contact the people on your list. It's live at zapbounce.com, and Hashlogics operates it.
- SyntaxIs it shaped like an email address?
- Domain and MXDoes this domain accept mail at all?
- SMTP checkWe ask the receiving server if it would accept this mailbox.
- Catch-all probeA random address on the same domain shows whether the server accepts everything.
- ResultValid, invalid, catch-all or unknown, with role and disposable flags.
The connection closes before the message stage, so no email is ever sent to the address being checked.

Verification engine
- Own SMTP check on port 25
- DNS and MX lookup
- Catch-all probe
- Disposable and role detection
Developer surface
- REST API
- Signed webhooks
- Sandbox keys
- CSV and TXT files
Infrastructure
- Vercel
- Amazon Web Services
- Cloudflare and Google DNS-over-HTTPS
- Stripe

What made this build hard was the mail servers that won't give a straight answer. A catch-all domain says yes to every address you try. Yahoo and AOL accept everything and bounce it later, while Gmail and Microsoft 365 block probes that come from cloud networks. Every verifier meets these same limits. ZapBounce labels each of those cases for what it is. When a server gives no answer at all, the result is unknown, and an unknown is never billed.
Read next
- Products we build and run →ZapBounce beside the other products Hashlogics operates.
- Email verification APIs for outbound teams →How the verification APIs on the market compare.
- API integration →The service behind API-first builds like this one.
- More Hashlogics case studies →Other systems we built, with the work behind each one.

