Email verification tells you whether an address can receive mail, without sending a message to it. This page covers how the check works, where it fails, and where to read the result in LeadOcean.
Key takeaways
- Verification asks the receiving mail server whether the mailbox exists. A syntax check alone cannot do that.
- Some domains accept every address. Those results are
catch_all, and no tool can fully resolve them. - A verification result goes stale. Treat it as a dated reading, not a permanent fact.
- In LeadOcean the result is the
email_statusfield, andemailStatusis the filter that selects on it.
What it is
Email verification is a set of checks that decide whether an address is real, reachable and safe to mail.
The checks run in layers. The cheap ones run locally. The expensive one talks to the recipient's mail server over SMTP, the protocol defined in RFC 5321 (checked September 2026).
The output is a status per address, not a yes or no. Verified, catch-all, risky and invalid each call for a different decision.
How it works
A verifier runs five steps in order. It stops at the first failure.
- Syntax. Is the address well formed?
jane.doe@acmehas no top-level domain and fails here. - Domain. Does the domain exist and publish MX records? RFC 5321 describes how a sender locates the mail host from the domain.
- Mailbox probe. The verifier opens an SMTP session and issues
RCPT TOfor the address. It does not send a message body. A250reply means the server accepts the recipient. A550means the mailbox is unavailable. - Catch-all test. The verifier probes a random address at the same domain. If the server accepts that too, the domain accepts everything, so step 3 proved nothing about Jane.
- Risk flags. The address is compared against known patterns: role mailboxes such as info@, disposable domains, and known spam traps.
A worked example
Take jane.doe@acme.com, a placeholder address.
The syntax passes. Acme's domain publishes MX records that point to a hosted mail provider. The verifier probes jane.doe@acme.com and gets a 250. It then probes a random string at acme.com and gets a 550.
Only the real mailbox was accepted. The result is verified. If it had also returned 250, the result would be catch_all, and Jane's mailbox would stay unconfirmed.
Email verification vs email validation
Email validation checks that an address looks right. Email verification checks that it works. People use the two words as if they were the same, and vendors often blur them.
| Validation | Verification | |
|---|---|---|
| Question answered | Is the format correct? | Will a message arrive? |
| Needs a network call | No | Yes, DNS and SMTP |
Catches typos like acme..com | Yes | Yes |
| Catches a dead mailbox | No | Yes, in most cases |
| Handles catch-all domains | No | Flags them, cannot resolve them |
| Where it runs | A form field, in the browser | A server, before send |
Validation is a good first filter on a signup form. It is not enough before a cold send. An address like jane.doe@acme.com is valid by format even if Jane left two years ago.
When it matters
Verification matters wherever a bad address has a cost. These are four places it pays off.
Cold outbound
Bounces hurt your sending domain. A list with a high share of dead addresses teaches mailbox providers that you do not know your recipients. Verify before the first send, and keep the bounce rate low from day one.
LeadOcean does not refund or credit back bounced emails. Read email_status before you send, not after.
Signup forms and product data
Typos and throwaway addresses pollute a user table. Format validation catches the typos. Verification catches the domains that do not exist and the disposable addresses that will never open your onboarding mail.
Buying or exporting a list
A list vendor's claim that addresses are good is not a check. Ask who ran the probe and when. In LeadOcean, a business address is verified only when our own verifier sent to it and it accepted.
Re-checking an old list
Addresses decay as people change jobs and domains change providers. A list that was clean last year is not clean now. Re-verify before any re-send, and treat the date of the check as part of the answer.
How LeadOcean handles it
LeadOcean stores a deliverability status on each person's best email, and exposes it on search rows, enrichment and exports. The field is email_status. The filter is emailStatus. The 13 values are verified, catch_all_valid, catch_all, risky, unknown, untested, invalid, role, disposable, spam_trap, abuse, derived and none.
What each group means in practice:
- Safe to send:
verified, andcatch_all_valid. The second is a mailbox on a catch-all domain whose existence was confirmed through the provider's identity check, which covers Microsoft 365 managed tenants and Google Workspace only. - Cannot be confirmed:
catch_all. The domain accepts everything. - Use with care:
risky,role(a shared mailbox like info@) andderived(built from the company's address pattern, never tested). - Do not send:
invalid,spam_trap,abuse,disposable. - Not checked yet:
untested. Nobody has tested the address, so it may be fine.unknownmeans a check ran and was inconclusive.
Three details change how you read the field:
- On a personal address,
verifiedstill means a supplier asserted it. We do not verify consumer domains. Treat it as a lead to check. - People search does not carry per-address verification provenance. A person can come back
verifiedin a search row anduntestedwhen enriched. The enriched answer is the correct one, so treat a search count ofverifiedas an upper bound. - The default mailable count in
count_leadscoversverified,catch_all_validandcatch_all. PassinghasEmailoremailStatusreplaces that default.
Size the list first. A search with count=true and limit=1 is free, and meta.total is capped at 100,000.
curl -X POST "https://api.leadocean.io/v1/people/search?count=true" \
-H "x-api-key: $LEADOCEAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"jobLevel":["VP"],"jobFunction":["Sales & Business Development"],"country":["CA"],"emailStatus":["verified","catch_all_valid"],"emailType":["work"],"limit":1}'That count answers "how many people at this level have a safe-to-send work address." It is not a total of everyone in the segment. Drop emailStatus to see the wider audience.
To check one person, enrich by person_id. Set reveal_email to get the address, at no extra record.
curl -X POST https://api.leadocean.io/v1/people/enrich \
-H "x-api-key: $LEADOCEAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"person_id":"PERSON_ID","reveal_email":true}'Each address in the response carries its own status. A verified_batch_date tells you which verification run checked it. A null date means the check was not ours. It does not mean the address is unverified.
For bulk work, POST /v1/exports takes the same filters and writes email_N_status next to email_N_address in the CSV. You can run the same export from the Exports page in the app. The record price is shown before you start.
Free covers 1,000 records, once. Pro is $499 a month. See pricing. For the full list of tools that do this job, see best email verification tools.
Related reading: every email status, explained and catch-all emails explained. More guides are in the blog.
FAQ
Is email verification the same as email validation?
No. Validation checks the format of an address. Verification checks whether the mailbox can receive mail, using DNS and an SMTP probe. You want both, in that order.
Can verification be 100% accurate?
No. Catch-all domains accept every address, so a probe cannot tell a real mailbox from a made-up one. Some servers also hide the answer or rate-limit probes. That is why statuses such as catch_all and unknown exist.
Does verifying an email send a message?
No. The SMTP probe stops before the message body. It asks whether the recipient would be accepted, then closes the session.
How often should I re-verify a list?
Re-verify before each new campaign on an old list. People change jobs and domains change providers. There is no safe age for an address, so check the date on the status.
What does LeadOcean say about a catch-all address?
Where we can confirm the mailbox through the provider's identity check, the status is catch_all_valid. Where we cannot, it stays catch_all. Both match the catch_all filter, and catch_all_valid alone selects the narrow set.
Filter your next list by email status before you send
Free to start. No credit card. 1,000 records to spend whenever you like.
Get your free API key →