Email validation API for signup forms
Validate the address on submit, reject only what is certainly wrong, and never lose a real user to a maybe.
A signup form has one expensive mistake: rejecting a real person. A wrong "invalid" costs you a customer and a support ticket you cannot answer. So the verifier behind a signup form has to refuse to guess.
One call on submit gives you a verdict with its reason, a safe default in suggested_action, and evidence you can read when someone writes in. Unknowns are free, so you can set a tight timeout and let the form move.
Wire it in
// On the server: the key never reaches the browser.
const res = await fetch('https://api.verimail.io/v3/verify', {
method: 'POST',
headers: { Authorization: `Bearer ${process.env.VERIMAIL_KEY}` },
body: new URLSearchParams({ email, timeout: '2000', evidence: 'true' }),
});
const v = await res.json();
if (v.did_you_mean) return ask(`Did you mean ${v.did_you_mean}?`);
if (v.suggested_action === 'reject') return reject(v.reason); // undeliverable, or disposable
createAccount(email, { confirmed: v.verdict === 'deliverable' ? 'pending' : 'required' }); What to do with each answer here
| deliverable | Create the account. Send the welcome email as usual. |
| undeliverable | Show the reason in plain words next to the field ("that domain can't receive email"). Offer did_you_mean first when it is set. |
| risky | Create the account and require email confirmation before anything that costs you. A disposable address comes back suggested_action: reject; use that for free trials. |
| unknown | Same as risky. The server would not say, in two seconds; that is not a reason to turn a person away. Not billed. |
What this does not do
- It does not prove a human controls the address. Confirmation by email does; do both when the flow can wait for a click.
- It does not resolve catch-all domains. Those come back risky, with the domain's reply in the evidence.
- A brand-new disposable domain can pass until the daily list catches it.
Reference: the API, handling results, result codes. A free key gives you 100 verifications a month: get one.