Hashlogics
Case study · Email verification · Our own product

ZapBounce

Know what each address is before you send.

An email verification API and list cleaner we built and run ourselves, with our own SMTP check behind every result.

Client
Hashlogics (our own product)
Industry
Email verification · Deliverability · SaaS
Region
Global · hosted in the United States
Engagement
Product we built and run · API-first SaaS
Overview

ZapBounce is an email verification API and list cleaner that Hashlogics built and runs as its own live product. Its own SMTP check returns one of four results for every address: valid, invalid, catch-all or unknown. Your team collects addresses faster than it can trust them. Sign-up forms, CRM imports and lead lists carry dead mailboxes, throwaway domains and typos. Every bad address you send to pushes your bounce rate up.

The challenge

Why a simple valid or invalid check falls short.

01

Your lists pick up dead mailboxes, disposable domains, role accounts and typos from forms, imports and data providers.

02

A catch-all domain accepts every address you try, so a mail-server check can't confirm one mailbox on it.

03

Some mail servers answer the first attempt with a temporary failure, and others refuse probe traffic outright.

04

One team needs a single sign-up checked while the user waits. Another needs a whole list cleaned in the background.

05

Your developers want to call the same check from lead forms, CRM workflows and their own apps.

What success needed to look like

  • Give every address one clear result your code can act on.
  • Check a single address in real time, or a full list as a background job.
  • Tell your systems when a bulk job finishes, with a webhook they can trust.
  • Let each customer decide how long uploaded addresses are kept.
  • Never send a message to the mailbox being checked.
Our approach

How ZapBounce checks an address and protects your data.

  1. 01

    Run the SMTP check ourselves

    We built our own verification over port 25 instead of wrapping another vendor's API.

  2. 02

    Hang up before any message is sent

    The check asks the server whether it would accept the address, then closes the connection. Nothing ever lands in the mailbox you're checking.

  3. 03

    Keep four results, not two

    Valid, invalid, catch-all and unknown each get their own label. Role, disposable and free-provider addresses are flags on top, so they don't hide the real result.

  4. 04

    Put one engine behind every door

    Our web app, the bulk uploader and the REST API all call the same verification engine.

  5. 05

    Build deletion into the API

    Your uploaded lists are kept for 30 days by default. Each of your API keys can set its own window from 0 to 90 days, and one call deletes a batch at once.

The solution

What ZapBounce does, from one address to a full list.

ZapBounce checks one address in real time or a whole list in the background. You can paste addresses, upload a CSV or TXT file, or call the API from your own code. Each address passes through syntax, domain and mail-server checks, then comes back as valid, invalid, catch-all or unknown. Unknown results and duplicates are never billed.

Developers get a versioned REST API, sandbox keys for testing, and webhooks signed so your system can confirm who sent them. ZapBounce doesn't sell uploaded addresses, add them to a shared database, or contact the people on your list. It's live at zapbounce.com, and Hashlogics operates it.

How one address gets its resultLive
  1. SyntaxIs it shaped like an email address?
  2. Domain and MXDoes this domain accept mail at all?
  3. SMTP checkWe ask the receiving server if it would accept this mailbox.
  4. Catch-all probeA random address on the same domain shows whether the server accepts everything.
  5. ResultValid, invalid, catch-all or unknown, with role and disposable flags.

The connection closes before the message stage, so no email is ever sent to the address being checked.

Real-time checks for a single address, from the app or an API call.
Bulk jobs from a pasted list or an uploaded file, tracked from start to finish.
Four results on every address: valid, invalid, catch-all, unknown.
Flags for role accounts, disposable domains and free mailbox providers.
A typo suggestion when an address looks mistyped.
Signed webhooks that tell your systems when a batch completes or fails.
Sandbox keys, so your developers can test an integration before it touches real credits.
Several API keys per account, each with its own label and retention window.
A credit ledger that shows you every reserve and refund, beside an activity log of workspace actions.
Deletion on request: one call removes a batch, and another erases a single address across the account.
Deliverability tools that check your SPF, DKIM, DMARC and MX records, plus blacklists.
ZapBounce verify screen with Single, Paste list and Upload CSV tabs above a paste box with sample addresses.
Three ways in from the app: check a single address, paste a list, or upload a file.
How it's built

Verification engine

  • Own SMTP check on port 25
  • DNS and MX lookup
  • Catch-all probe
  • Disposable and role detection

Developer surface

  • REST API
  • Signed webhooks
  • Sandbox keys
  • CSV and TXT files

Infrastructure

  • Vercel
  • Amazon Web Services
  • Cloudflare and Google DNS-over-HTTPS
  • Stripe
More from the build
ZapBounce activity page: audit trail of an API key creation, verification jobs, a sign-up and a login, by date.
The activity page: sign-ins, new API keys and verification jobs.
The takeaway

What made this build hard was the mail servers that won't give a straight answer. A catch-all domain says yes to every address you try. Yahoo and AOL accept everything and bounce it later, while Gmail and Microsoft 365 block probes that come from cloud networks. Every verifier meets these same limits. ZapBounce labels each of those cases for what it is. When a server gives no answer at all, the result is unknown, and an unknown is never billed.

By , CEO, HashlogicsUpdated
Start

Let’s deploy working AI into your business.

We build AI agents and automation, ship them into the tools you already run, then stay on under an agreed service level. A senior engineer reads every brief, and your call gets scheduled within 24 hours.

What happens next

  1. 01

    You send a brief or book a call

    Two minutes, whichever you prefer.

  2. 02

    A senior engineer replies within 24 hours

    Not a sales rep.

  3. 03

    Honest scoping, in writing

    And if we’re not the right fit, we say so.

Abdul Basit, CEO of Hashlogics

“I started Hashlogics because too many teams ship a demo, get paid, and disappear. We build to a standard we’d run ourselves — and we stay to keep it running.”

Abdul Basit · CEO · a direct line

Not ready to talk? Take the checklist.

12 questions to ask any AI agency before you sign. They separate a demo shop from a team that ships to production.

Get the checklist

Free · no newsletter