Skip to main content
POST
Bulk-validate recipient email addresses

Authorizations

Authorization
string
header
required

Dashboard JWT token from Clerk

Headers

Idempotency-Key
string

Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.

Required string length: 1 - 255
X-Test-Mode
enum<string>

Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.

Available options:
true,
false

Body

application/json
emails
any

Address list to validate — 1 to 1,000 entries, each 3–254 characters. De-duplicated case-insensitively before validation; one result row per distinct address, input order preserved (required).

Response

The batch verdict wrapped in the standard { data, meta } envelope: data.summary carries the aggregate counts (total, valid, invalid, risky) and data.results one row per distinct address — email, valid, the machine-readable reason (deliverable, invalid_syntax, no_mx_record, disposable_domain, role_account, possible_typo, mx_unknown), mx_verified, the risk band + 0–1 risk_score, disposable, role_based, and a suggested_correction where a likely typo was found.

The batch verdict wrapped in the standard { data, meta } envelope: data.summary carries the aggregate counts (total, valid, invalid, risky) and data.results one row per distinct address — email, valid, the machine-readable reason (deliverable, invalid_syntax, no_mx_record, disposable_domain, role_account, possible_typo, mx_unknown), mx_verified, the risk band + 0–1 risk_score, disposable, role_based, and a suggested_correction where a likely typo was found.