Real-time email validation API for signup forms

Validate addresses as users submit them: syntax, mail server and mailbox in one call, with disposable and role-based flags so you decide what to accept. Our email validation api blocks bad data at the door, keeping fake accounts out of your database.

Backend signup handlerForm Decision
// 1. Receive submitted form data
const { email } = req.body;

// 2. Validate via API
const { data } = await checkEmail(email);

// 3. Make real-time form decision
if (data.status === 'undeliverable') {
  return res.status(400).json({ error: 'Please enter a valid, active email address.' });
}
if (data.details.attributes.disposable) {
  return res.status(400).json({ error: 'Temporary or disposable emails are not allowed.' });
}

// 4. Proceed with account registration
await createUser({ email });

1,000 free credits, no card needed. Credits never expire.

Why regex alone isn't email validation

A regular expression checks only string structure: whether an @ symbol exists, if the domain format looks plausible, and whether characters fall within standard ASCII ranges. Regex answers only whether an input looks like an email address, not whether anyone can receive messages there.

Typing user@example.com or asdf12345@gmail.com passes every RFC-compliant regex perfectly. Yet one domain may have no active mail servers, and the other mailbox may not exist.

Our email validation api json service goes far beyond regular expressions. In a single request, it inspects DNS records, performs MX host lookups, connects to the destination mail server to test mailbox responsiveness, and verifies the domain against extensive disposable lists.

Rigid regex patterns also cause false rejections. Custom expressions frequently reject uncommon top-level domains like .studio or .cloud, valid international characters, or legitimate addresses with unusual punctuation. Our API handles all RFC 5322 syntax specifications automatically, eliminating the need to maintain fragile regex libraries in your codebase.

1

Syntax check

Catches basic typos, missing TLDs, illegal punctuation, and spacing issues before any external network lookups.

2

DNS & MX verification

Verifies domain registration status and discovers configured mail exchangers capable of accepting inbound messages.

3

SMTP socket handshake

Talks to the remote mail exchange socket directly to confirm whether the specific mailbox exists and has storage space.

What to block, flag or allow at signup

Different businesses have different signup requirements. A B2B enterprise SaaS might enforce company emails, while a consumer social app welcomes personal Gmail addresses. Here is the recommended decision matrix based on real API response attributes:

API ResultField conditionWhat the form should do
Invalidstatus === "undeliverable"Block immediately. Display: "Please enter a valid, active email address."
Disposabledetails.attributes.disposable === trueBlock, or ask for another address. Display: "Temporary email addresses are not permitted."
Role Accountdetails.attributes.role_account === trueAllow; flag on B2B forms. Alert account managers or route to general leads bucket.
Free Emaildetails.attributes.free_email === trueAllow on B2C apps; require corporate work email on B2B demo or trial forms.
Catch-Alldetails.attributes.catch_all === trueCheck catch_all_verdict: if "valid" allow; if "invalid" block; if null permit registration.
Unknownstatus === "unknown"Accept and re-check later (refunded). Fail open so legitimate users are never blocked.

Add email validation to your signup form

Follow this four-step sequence to integrate real-time validation safely. Because requests require your private API key, run the check from your backend server.

Why the fail-open pattern matters: Signup forms are sensitive to delays. If an external API call experiences network latency, blocking the form could lose a real customer. Setting a short timeout and automatically allowing the registration to proceed ensures legitimate users are not turned away, while your backend queues the address for a background check later.

1

Form posts to your backend

When a visitor submits registration details, your browser client transmits the email address to your application endpoint.

2

Backend calls validation API

Your server sends a synchronous POST request to Giggal using your private key stored in an environment variable.

3

Backend applies decision table

Parse the JSON attributes. If the email is disposable or undeliverable, return a clear error prompt back to the browser.

4

Fail open on timeouts

If upstream network communication times out, fail open: accept the registration and enqueue a background job to verify later.

Implementation code examples

Backend: Node.js (Express Route)server-side only
// server.js (Express Route)
const timeoutMs = 5000; // adjust to what your form can tolerate

app.post('/api/signup', async (req, res) => {
  const { email, password } = req.body;

  try {
    const apiRes = await fetch('https://api.giggal.ai/v1/verify', {
      method: 'POST',
      headers: {
        'Authorization': `Bearer ${process.env.GIGGAL_API_KEY}`,
        'Content-Type': 'application/json',
      },
      body: JSON.stringify({ email }),
      signal: AbortSignal.timeout(timeoutMs), // fail-open timeout
    });

    const result = await apiRes.json();
    if (result.success) {
      const { status, details } = result.data;

      // Decision checks
      if (status === 'undeliverable') {
        return res.status(400).json({ error: 'This email address does not exist.' });
      }
      if (details.attributes.disposable) {
        return res.status(400).json({ error: 'Disposable email addresses are not accepted.' });
      }
    }
  } catch (err) {
    // Fail open: log timeout and let user proceed
    console.warn('Email check timed out, failing open:', err.message);
  }

  // Create user in database
  const user = await db.users.create({ email, password });
  return res.json({ success: true, userId: user.id });
});
Backend: Python (Flask Route)server-side only
# app.py (Flask Route)
import os, requests
from flask import Flask, request, jsonify

app = Flask(__name__)
timeout_seconds = 5  # adjust to what your form can tolerate

@app.route("/api/signup", methods=["POST"])
def signup():
    email = request.json.get("email")

    try:
        resp = requests.post(
            "https://api.giggal.ai/v1/verify",
            headers={"Authorization": f"Bearer {os.environ['GIGGAL_API_KEY']}"},
            json={"email": email},
            timeout=timeout_seconds  # fail open on timeout
        )
        data = resp.json().get("data", {})
        if data.get("status") == "undeliverable":
            return jsonify({"error": "Email address is invalid."}), 400
        if data.get("details", {}).get("attributes", {}).get("disposable"):
            return jsonify({"error": "Disposable emails are prohibited."}), 400
    except requests.exceptions.RequestException:
        # Fail open: proceed with signup on timeout
        pass

    # Complete user registration
    return jsonify({"success": True})
Frontend: Browser client (calls your own backend)client-side script
// Frontend form submit handler
const form = document.querySelector('#signup-form');

form.addEventListener('submit', async (e) => {
  e.preventDefault();
  const email = document.querySelector('#email-input').value;

  const res = await fetch('/api/signup', {
    method: 'POST',
    headers: { 'Content-Type': 'application/json' },
    body: JSON.stringify({ email }),
  });

  const payload = await res.json();
  if (!res.ok) {
    showFormError(payload.error); // Show friendly user feedback
  } else {
    redirectToDashboard();
  }
});

Important: Never call the Giggal API endpoint directly from client-side scripts. Keep your credentials private on your server.

Stop disposable and fake signups

Temporary inboxes degrade your product analytics, consume free trial quotas, and never convert into paid customers. Our service actively monitors and flags high-risk signup patterns.

Disposable inboxes

Checked against our active registry of 100,000+ temporary domains. Learn more about how we identify throwaway mailboxes with our disposable email checker.

Plus-addressing detection

Flags aliases created with plus-tagging (user+trial@domain.com), preventing single users from creating duplicate trial accounts.

No-reply mailbox detection

Detects broadcast and automated mailboxes that discard incoming communication, preventing users from signing up with non-interactive addresses.

Avoid auto-correcting user typos

Never silently transform user inputs (e.g. changing gnail.com to gmail.com automatically). If an address fails validation, prompt the user with a clear message to verify their entry. Silent rewriting risks delivering account activation tokens or billing receipts to the wrong party.

Where to validate emails in real time

Validate email addresses wherever users submit forms across your product.

User registration forms

Prevent registration spam and help ensure welcome emails and verification links reach active inboxes.

E-commerce checkout

Ensure shipping notices, receipts, and order confirmations reach customers without delivery failures.

Lead and demo requests

Filter out fake competitor entries and verify company domains before routing prospects to sales representatives.

Newsletter subscriptions

Protect your broadcast domain reputation by rejecting malformed entries and bot signups at opt-in.

Webhook automations

Trigger validation automatically on form webhooks using our pre-built Zapier and n8n integrations.

Account profile updates

Verify new email destinations when existing users modify their profile or billing contact settings.

Response fields you'll use at signup

A compact reference of the core JSON fields required to enforce form validation logic.

JSON FieldTypeSignup Usage
data.is_validbooleanQuick boolean check. True when address syntax and mail server tests pass.
data.statusstringPrimary delivery status: "deliverable", "undeliverable", "unknown".
data.deliverability_scorenumber (0-100)Quality score based on socket responses, MX stability, and reputation checks.
data.details.attributes.disposablebooleanTrue when the domain is a known temporary or disposable inbox service.
data.details.attributes.free_emailbooleanTrue for consumer providers (Gmail, Outlook). Enforce corporate domains on B2B forms.
data.details.attributes.role_accountbooleanTrue for organizational addresses like info@, admin@, or support@.
data.catch_all_verdict"valid" | "invalid" | nullIn-line resolution for catch-all domains. Recover valid leads without discarding.

For complete endpoint definitions, parameter schemas, and error codes, refer to the full API reference.

Email validation API pricing

Pay only for the validations you execute, with no monthly minimums or commitments. Each API validation call consumes 1 credit, with in-line catch-all checks included. Unknown results are refunded automatically, and your first 1,000 credits are completely free.

Volume
3,000Credits
Rate$0.0017 / credit
Save
-
Price
$5.00one-time
Volume
10,000Credits
Rate$0.0010 / credit
Save
Save 41%
Price
$9.90one-time
Volume
30,000Credits
Rate$0.0009 / credit
Save
Save 44%
Price
$28.00one-time
Volume
50,000Credits
Rate$0.0008 / credit
Save
Save 53%
Price
$39.00one-time
Volume
100,000CreditsPopular
Rate$0.0008 / credit
Save
Save 54%
Price
$76.00one-time
Volume
300,000Credits
Rate$0.0007 / credit
Save
Save 56%
Price
$222.00one-time
Volume
500,000Credits
Rate$0.0007 / credit
Save
Save 57%
Price
$360.00one-time
Volume
800,000Credits
Rate$0.0007 / credit
Save
Save 58%
Price
$559.00one-time
Volume
1,000,000Credits
Rate$0.0007 / credit
Save
Save 59%
Price
$680.00one-time

Explore all volume plans and monthly subscription discounts on our pricing overview page.

Email validation API FAQ

Answers to common implementation questions regarding registration forms and real-time validation.

Yes. Every new account receives 1,000 free credits upon registration, with no credit card required. You can generate an API key in your developer dashboard and begin testing real-time form validations immediately. The free credits never expire and provide full access to all validation attributes and checks.

No. Calling the API directly from client-side JavaScript would expose your secret API key to anyone inspecting browser network requests. Always submit user form inputs to your own backend server or serverless function first, and have your server execute the request to https://api.giggal.ai/v1/verify.

No message is ever dispatched. The API executes an SMTP socket handshake with the destination mail exchanger and simulates delivery up to the recipient verification command. It closes the session before any email data or body content is transmitted, ensuring zero inbox noise for your users.

Yes. Every check inspects the domain against our registry of over 100,000 disposable, throwaway, and temporary email domains. If a match is found, details.attributes.disposable returns true and the status is set to undeliverable, allowing your backend to block temporary accounts.

It depends on your business model. For consumer apps, role accounts like support@ or info@ may represent legitimate organizations. For self-serve B2B SaaS where user accountability is necessary, many companies choose to flag or disallow generic role accounts to prevent shared credential abuse.

Catch-all domains accept all recipient addresses unconditionally, making standard SMTP checks inconclusive. Our API runs in-line deep catch-all verification to evaluate whether the mailbox exists. If the catch-all check returns "valid", you can safely allow signup; if "invalid", the address will bounce and should be stopped.

We recommend implementing a fail-open pattern. If your backend call experiences a network timeout or connection error, allow the registration to complete rather than blocking a potential customer. Queue the unvalidated address in your background worker to re-check delivery status later.

Choose an email validation API when you need real-time checks on web registration forms to stop typos, disposable inboxes, and bots on form submission. Choose an email verification API when auditing existing marketing databases, synchronizing CRM contacts, or cleaning bulk email files before sending campaigns.

Protect your signup forms today

1,000 free credits, no card needed. Credits never expire.

Free trial Credits never expire Refunds on Unknown