Prompt
I’m building a cold email app and need email validation at scale
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
For cold email at scale, you’ll want layered validation, not just “is this syntactically an email?”
What to validate
- Syntax
- Valid email format
- Unicode/IDN handling if needed
- Domain
- DNS MX lookup
- Fallback A record if no MX
- Domain exists / resolvable
- Mailbox
- SMTP-level verification where possible
- Catch-all detection
- Disposable email detection
- Risk
- Role accounts like
info@,sales@ - Temporary/disposable domains
- Greylisting / rate-limit behavior
- Role accounts like
- Deliverability
- Spam traps won’t be reliably detectable
- Use verification + bounce tracking + engagement signals
Recommended architecture
1) Fast pre-check
Use a cheap local validator first:
- regex / parser for syntax
- normalize case, trim whitespace
- reject obvious bad domains and disposable providers
2) DNS verification
- Cache MX lookups aggressively
- Use async DNS resolver
- Retries with backoff
- Store domain verification results with TTL
3) SMTP verification service
For scale, don’t do this from your app servers directly. Use a separate worker pool:
- per-domain throttling
- connection pooling when possible
- timeout and retry controls
- support for greylisting
- classify outcomes:
- valid
- invalid
- catch-all
- unknown/timeout
4) Result caching
Cache by:
- full email
- domain
- verification class Use TTLs:
- domain DNS: 1–24h
- mailbox result: shorter, maybe 7–30d depending on usage
5) Async workflow
Don’t block signup/import on full verification:
pendingon ingest- queue verification jobs
- update status later
- allow “soft accept” with risk scoring
Practical scale tips
- Batch imports and process in workers
- Use a job queue like SQS/RabbitMQ/Redis Queue/Kafka
- Limit concurrency per MX host to avoid being blocked
- Observe provider-specific behavior:
- Gmail, Outlook, Yahoo often rate-limit or don’t reveal much
- Expect false positives/negatives; no validator is perfect
Important caution
SMTP verification can be sensitive and may violate some providers’ policies if abused. At scale, use it responsibly and keep rates low, with clear timeouts and backoff.
Good strategy for a cold email app
A solid production setup is:
- syntax + DNS at ingest
- SMTP verification only for high-value leads or before sending
- bounce suppression list
- engagement-based list hygiene
- automatic re-validation of old leads before campaigns
If you want, I can help you design:
- a validation pipeline architecture,
- a database schema for email statuses, or
- a Node/Python implementation for high-scale validation.