Verify emails protected by SEG gateways

Secure email gateways sit in front of a company's real mail server and refuse the checks most verifiers depend on. Giggal.ai routes around them and returns a real email verification result, valid or invalid, instead of an Unknown.

No card required. Credits never expire.

What is a secure email gateway?

A secure email gateway is a filtering layer that sits in front of a company's real mail server. Every message headed for the domain passes through the gateway first. Companies run one to block spam and malware, to stop phishing, and to enforce data loss prevention rules before anything reaches a mailbox. Vendors in this space include Proofpoint, Mimecast, Barracuda, and Cisco IronPort.

Because the gateway stands in front of the mail server, it also answers on the mail server's behalf. Anything that tries to ask the mail server a question, including an email verifier, ends up talking to the gateway instead of the system that actually knows which mailboxes exist.

Why gateways break email verification

Standard email verification works by opening an SMTP conversation with the mail server and asking, in effect, whether a given mailbox exists. On a normal domain the server answers, and the verifier records a valid or invalid result.

Behind a gateway that conversation never reaches the mail server. The gateway intercepts it and answers on the server's behalf. Gateways are built to prevent exactly this kind of probing, since the same technique is used by attackers mapping a company's users. So the gateway gives a deliberately vague answer, accepts every address whether it exists or not, or refuses the connection outright.

The verifier is left with nothing it can turn into an email verification result. It reports the address as Unknown or Risky, and the contact stays unresolved. On a business list where a large share of domains sit behind a gateway, that is a real part of your list you cannot confidently use.

The IP reputation problem

Retrying makes it worse. Probing an SMTP endpoint that refuses the check, over and over, gets the sending IP flagged. Once that happens, results degrade across every domain that verifier touches, not just the gateway domains. This is why Giggal.ai skips SMTP entirely on gateways that behave this way rather than retrying into a block.

How Giggal.ai verifies behind a gateway

Giggal.ai reads the domain's MX records first, before any probing, to work out what is actually in front of the mailbox. That tells us whether the domain answers directly or sits behind a gateway.

Domains behind a gateway are routed down a different verification path than domains that answer directly. Where a gateway refuses SMTP probing, the email verification result does not depend on that SMTP answer at all. We verify the address through a different signal, so it still comes back valid or invalid when a plain SMTP check would return nothing.

Gateways also return responses designed to hide whether a mailbox exists, deliberately vague answers meant to throw off a verifier. Giggal.ai recognises these and does not mistake one for a real result. When the only thing coming back is noise, we treat it as no answer rather than guessing. So the address comes back valid or invalid, where most verifiers hand back an Unknown.

Gateways we detect

MimecastProofpointBarracudaCisco IronPortSophosTrend MicroSymantecFortinetForcepointCloudmarkMailRouteAppRiverZixSonicWallCRAM Cloud

Detection happens automatically from the domain's MX records. You do not need to tell us anything about a list before you run it.

Proofpoint

Proofpoint is one of the most widely deployed secure email gateways on enterprise domains. If you sell into large companies, a meaningful part of your list sits behind it. Proofpoint fronts the real mail server and filters inbound mail for threats, which is also why a plain SMTP check against a Proofpoint domain tends to come back without a usable answer. Giggal.ai identifies Proofpoint from the domain's MX records and routes the address down the gateway path, so instead of an Unknown you get a real deliverable or undeliverable result on the mailbox behind it.

Mimecast

Mimecast is built to stop anyone working out which mailboxes exist on a domain, and it answers probes with a deliberately vague response rather than confirming or denying the address. Giggal.ai recognises that behaviour and skips SMTP against Mimecast entirely, rather than triggering the response and taking a reputation hit. It verifies the address another way, so it comes back with a real email verification result instead of an Unknown.

how Mimecast verification works

Barracuda

Barracuda is common on mid-market domains and, like other gateways, sits in front of the real mail server and filters inbound mail. A standard verifier probing a Barracuda domain over SMTP usually cannot get a clear answer about the mailbox, because the gateway is the thing responding. Giggal.ai detects Barracuda from the domain's MX records and sends the address down the gateway verification path. You get a deliverable or undeliverable result on the mailbox itself, not a Risky or Unknown label that leaves you guessing about whether the contact is real.

What you get back

ResultMeaning
DeliverableThe mailbox exists and will accept mail
UndeliverableThe mailbox does not exist
RiskyThe address exists but carries deliverability risk
UnknownWe could not verify the address

When we cannot verify an address, the credit is refunded automatically. You only pay for verifications we complete.

A catch-all domain is a related but different problem. If your list has those too, we also verify catch-all & risky emails.

Pay only for what you verify

Standard
1 credit
per email verification
Catch-All, same run
1.5 credits
per catch-all email
Catch-All, standalone
2 credits
per catch-all email

No monthly fees, no minimums, and credits never expire. Start with 1,000 free credits, no card required. See full pricing and credits.

Frequently asked questions

No. A gateway is a filtering layer, not a signal about the mailbox behind it. Plenty of valid, active addresses sit behind Proofpoint or Mimecast. The gateway just makes them harder to check.

Most verifiers ask the mail server directly over SMTP. Behind a gateway, that question gets intercepted and answered by the gateway instead, which is built to not tell you anything useful. Without an answer, the verifier has nothing to report.

Fifteen, including Proofpoint, Mimecast, Barracuda, Cisco IronPort, Sophos, Trend Micro, Symantec, Fortinet and Forcepoint. Detection is automatic from the domain's MX records.

No. Upload the list as it is. Domains behind a gateway are identified and routed automatically during the run.

No. A standard verification is 1 credit regardless of what sits in front of the domain. Catch-all verification is priced separately at 1.5 credits when enabled during the run, or 2 credits standalone.

The address comes back as Unknown and the credit is refunded automatically.

Run a list and see the difference

1,000 free credits, no card required.

Free trial Credits never expire Refunds on Unknown