Verify emails behind Mimecast

Mimecast is built to stop anyone working out which mailboxes exist on a domain, which is why most verifiers hand back Unknown. Giggal.ai takes a different route and returns a real email verification result.

No card required. Credits never expire.

What Mimecast does to email verification

Mimecast sits in front of the real mail server and answers on its behalf. Mail headed for the domain reaches Mimecast first, and so does anything trying to check whether a mailbox exists. The verifier never actually talks to the system that knows the answer.

Blocking that kind of mailbox lookup is a deliberate feature, not a side effect. Mimecast is supposed to prevent exactly the kind of probing a verifier does, because the same technique is how an attacker would map out a company's users. Stopping it is the point.

When probed, Mimecast returns a deliberately vague response rather than confirming or denying the mailbox. A verifier that takes that response at face value has two options, and both are bad. It can guess, which puts wrong results into your list, or it can give up and mark the address Unknown, which leaves a real contact unresolved.

The response Mimecast sends back

People who hit this usually see one of two things: a verification result stuck on Unknown, or a bounce message from their own sending tool. The wording varies, but it commonly mentions an internal resource being temporarily unavailable, or a recipient not being allowed. These are messages Mimecast sends when something asks about a mailbox it is set up to protect.

The one behaviour our engine relies on here is specific: it recognises the "internal resource temporarily unavailable" anti-enumeration response and does not treat it as a result. Everything else in this space is real-world context for what you might see, not a claim that we pattern-match every possible string a gateway can return.

Why "recipient is not allowed" does not mean the address is invalid

That message reflects a gateway policy decision about how mail is accepted, not a statement about whether the mailbox exists. The address behind it is often perfectly valid. You are reading the gateway's rules, not the mail server's answer.

How Giggal.ai handles Mimecast

The domain's MX records identify Mimecast before any probing happens, so the address is on the Mimecast path from the start rather than after a failed attempt.

SMTP probing is skipped entirely. Not retried, not throttled, skipped. There are two reasons. Mimecast refuses the check, so there is nothing to gain. And repeated attempts flag the sending IP, which would degrade results across every other domain being verified in the same run.

The email verification result comes from a different signal instead, one that does not rely on Mimecast answering a probe. When that vague response does show up, it is recognised and never recorded as a real answer. The address comes back as a real deliverable or undeliverable result, or as Unknown with the credit refunded, but not as a guess dressed up as an answer.

What you get back

ResultMeaning
DeliverableThe mailbox exists and will accept mail
UndeliverableThe mailbox does not exist
RiskyThe address exists but carries deliverability risk
UnknownWe could not verify the address

When we cannot verify an address, the credit is refunded automatically. You only pay for verifications we complete.

Frequently asked questions

Usually not. Mimecast messages of that kind reflect a gateway policy decision, not a statement about whether the mailbox exists. The address is often perfectly valid.

They ask the mail server over SMTP whether a mailbox exists. Mimecast intercepts that and answers with something deliberately vague, so the verifier has nothing to work with.

No. We skip SMTP entirely on Mimecast domains. It gets refused, and repeated attempts damage sender IP reputation, which would degrade results on every other domain in the list.

No. Mimecast domains are identified automatically from MX records during the run.

No. Standard verification is 1 credit regardless of what gateway sits in front of the domain.

Related

Stop losing Mimecast contacts to Unknown

1,000 free credits, no card required.

Free trial Credits never expire Refunds on Unknown