-
1. Ask what "valid" actually means to the API
-
2. Check whether it's truly verifying or just guessing
-
3. Build a seed list and test the API on it
-
4. Measure speed for your deadline, not theirs
-
5. Look beyond database size at data freshness
-
6. Evaluate deliverability outcomes, not just accuracy
-
7. Test the integration against your actual stack
-
Common mistakes (and when this checklist doesn't apply)
If you're researching AI sales platforms this week—reading G2 reviews, comparing Artisan AI to other sales automation competitors, or trying to figure out what actually matters in an email verification API—this checklist is for you.
I'm a RevOps manager at a mid-size B2B SaaS company. In six years, I've coordinated 200+ outreach launches, including same-day verifications for teams whose campaign dates weren't moving. I've also cleaned up after the two times a bad verification decision cost us a deliverability issue. That cleanup was slower and more expensive than the money we saved on the tool.
This is the evaluation checklist I actually use before trusting any email verification tool with our list. It's not the comparison-page version. It's the one that matters when your send date is on the calendar.
1. Ask what "valid" actually means to the API
Every vendor says they catch bad emails. Very few define what "bad" means.
Some tools treat an address as valid if it passes syntax checks and the domain has MX records. Others probe the actual mailbox to see whether it accepts mail. Others still use ML models that predict bounciness from historical send data. These approaches produce very different results on the same list.
It's tempting to think "valid email" is one objective fact. It isn't. An address can be syntactically fine, technically deliverable, and still be a role inbox nobody reads. Or it can sit on a catch-all domain that accepts the server handshake and bounces three weeks later.
Before evaluating anything else, get the vendor to explain—on the record—what their "valid" flag means and what it doesn't.
2. Check whether it's truly verifying or just guessing
This is where verification tools quietly split into two camps. Some do real-time SMTP handshakes: they connect to the mail server, issue a RCPT TO command, and read the response. That's actual mailbox checking. It's slower and pricier, but it's the only way to confirm an inbox exists.
The other camp uses pattern matching: regex syntax checks, disposable-domain blocklists, and domain reputation scoring. That catches obvious garbage, but it can't distinguish a real inbox at [email protected] from a nonexistent one at [email protected].
In March 2024, 36 hours before a webinar invite went out, we needed to verify 45,000 records on a partner list. The tool we'd been using had great accuracy numbers in its own marketing docs. But its catch-all handling was weaker than advertised—we shipped an estimated 8% more bad addresses than we should have, and the bounce report from that send took a quarter to fully work out of our domain reputation.
That incident is why I now ask this question early:
"Show me your SMTP handshake success rate, and show me what happens on catch-all domains."
If the answer is vague, I treat it as a red flag.
3. Build a seed list and test the API on it
Vendor accuracy claims are made on vendor test data. Your data is messier—stale domains, role addresses, typos, and the occasional 2004-era catch-all. So build a seed list:
- Addresses you know are valid (your team's internal addresses work)
- Addresses you know are dead (former employees, disabled inboxes)
- Role inboxes (info@, sales@, support@)
- Disposable domains
- A few catch-all records if you have them
Send 1,000–2,000 records through and compare the results to what you actually know. In Q4 2025, I tested four verification APIs this way. Their advertised accuracy ranged from 95.2% to 99.1%. In practice, the gap that mattered was catch-all detection: one tool flagged catch-all addresses correctly roughly half the time; another caught nearly all of them. Same list, same data, wildly different outcomes.
The "99% accurate" tool wasn't the one that gave us a clean list. That distinction cost us a deliverability problem we're still careful about.
4. Measure speed for your deadline, not theirs
Vendors quote throughput in ideal conditions—clean payloads, empty queues, off-peak hours. That's not the number that matters when a sales rep needs 5,000 verified emails before tomorrow morning.
Run a real test: submit a batch of the size you'd actually use in production, during business hours, and measure time to completion. Ask about rate limits, queueing behavior, and what happens when malformed records cause the API to error and retry. (Note to self: this is the step I keep trying to skip when we're short on time, and it's the one that burns me every time.)
The most useful question I've ever asked a vendor:
"If I submit 100,000 records at 9:00 AM, what time will I have results?"
The honest answer tells you more than any pricing page.
5. Look beyond database size at data freshness
A 300M contact database sounds impressive. It's a number several platforms advertise these days—Artisan AI's included—and if the data is fresh, it's a real strength. But a large database is only as valuable as its recency. An address that was valid in 2023 could be a spam trap in 2026.
Ask how often records are refreshed. Not "we continuously update"—ask for specifics. What percentage of the database is re-verified each quarter? Do customer bounce reports feed back into the dataset? When a mailbox goes dark, how long until the API knows?
This matters if you're using verification inside an AI SDR platform that enriches and verifies on the fly. A 300M-record database is an asset. One with eighteen-month-old verification data is a liability.
6. Evaluate deliverability outcomes, not just accuracy
Verification accuracy is table stakes. What you actually care about: your sending reputation stays intact. No spam trap hits. No hard bounces. No promotions tab.
This is where managed email deliverability as a category comes in. Some tools stop at the API response—here's your cleaned list, good luck. Others monitor spam trap hits, feed bounce reports back into their dataset, and surface domain reputation signals in your dashboard.
Since February 2024, Google and Yahoo have required bulk senders to authenticate with SPF, DKIM, and DMARC. Google Postmaster Tools has long treated a spam rate above 0.3% as poor. A verification tool that doesn't help you stay on the right side of those thresholds is not doing its job.
I'd rather use a tool that protects sender reputation at a 92% catch rate than one that hits 99% on an accuracy benchmark while quietly damaging my domain. The first one gets me more meetings.
7. Test the integration against your actual stack
Finally, verify the integration is real, not just documented. Some platforms have a polished integration page and an API that maps fields in surprising ways.
If you use HubSpot or Salesforce, set up a test flow:
- Push a test list through the verification step
- Check which fields are written back (validity, bounce score, custom properties)
- Test deduplication behavior
- See what happens when the API returns "unknown" instead of "valid" or "invalid"
In 2023 I used a tool that synced "unknown" responses as "valid" into HubSpot. We didn't catch it until a campaign went out and the bounce data contradicted the CRM. Fixing the mapping took a day. The reputation damage took a quarter.
(For what it's worth: Artisan has native HubSpot and Salesforce integrations, and I still ran them through this same test. "Native" doesn't always mean "complete".)
Common mistakes (and when this checklist doesn't apply)
A few things I've learned the hard way:
- Don't make price the deciding factor. It's tempting to think verification is a commodity—every API checks email addresses, so buy the cheapest one. It isn't. A discount verification service caused two of our worst deliverability incidents. The "savings" were small; the recovery cost was real.
- Don't assume a bigger database means better verification. The verification logic—how records are checked and refreshed—matters more than the headcount in the dataset.
- Don't skip the seed list test. A vendor's accuracy claim on their dataset is not a forecast for yours.
Full disclosure: we use the Artisan AI platform at my company, including its email verification and managed deliverability features. I still run every new list through this checklist. I'd run it the same way if we were evaluating a standalone verification API tomorrow.
One caveat: this checklist is built for teams doing regular B2B outreach at scale. If you're a small team sending a few hundred emails a month, a full verification API is probably overkill. Your ESP's built-in validation or a pay-as-you-go tool will do.
I'm a RevOps practitioner, not a deliverability engineer. I can't speak to DNS tuning or the finer points of IP warmup. What I can tell you from running campaigns for six years is what breaks in practice: unclear validity definitions, weak catch-all handling, and integrations that quietly misrepresent API results.
Whatever you evaluate, test it on your own data, at your own scale, on your own timeline. The seven steps above will catch the problems the comparison pages won't show you.
