Contact List Reality Check
The other half of deliverability: who you're sending to. A perfectly-authenticated sender still tanks on a dirty list.
Your addresses never leave your browser. Your list is analyzed entirely on your device — no upload, no account, nothing stored. Domain checks send only bare domain names (like gmail.com) to a public DNS resolver, never an email address. How this works ↓
Drop a CSV here — it's read in your browser, never uploaded.
Your list is only half of deliverability. Watch the other half — your domain's sending reputation — for free.
Monitor your domain for free →Contact list FAQ
Is my contact list uploaded anywhere?
No. Your list is read and analyzed entirely in your browser — the email addresses are never sent to us or anyone else, there's no account, and nothing is stored. You can verify it yourself: open your browser's DevTools, watch the Network tab, and you'll see that no request contains an email address.
Then how do you check whether a domain is real?
For each unique domain in your list — the part after the @, like gmail.com — your browser asks Cloudflare's public 1.1.1.1 DNS resolver whether that domain has a mail server, exactly as any mail server does before delivering a message. Only the bare domain name is sent, never an email address, and the query goes to the public resolver, not to us.
What does “passes technical preflight” mean?
The address has valid syntax, isn't a duplicate or on a disposable/burner domain, and its recipient domain is live (a real mail server, not a null-MX or non-existent domain). It does not mean the individual mailbox exists, that the person opted in, or that they're engaged — browser-only checks can't verify any of those. Every row is tiered Pass, Review, Exclude, or Unverified (domain couldn't be checked), each with a suggested action.
How is this different from ZeroBounce, Kickbox or other list validators?
Two ways. First, those tools upload your list to their servers; we never do — everything runs on your device. Second, we connect list health to your sending posture (authentication, reputation, monitoring), so deliverability is one picture instead of two disconnected silos.
What are role, disposable and dead-domain addresses?
Role addresses are shared functional mailboxes like info@, sales@ or noreply@ — higher complaint and lower engagement risk, though they can be legitimate, so we mark them Review, not Exclude. Disposable addresses use throwaway or burner domains. A domain is Undeliverable when it doesn't exist (NXDOMAIN), explicitly refuses mail (a null MX record, RFC 7505), or has no mail server at all — those hard-bounce. A domain with no MX but an A/AAAA record is technically routable, but its mailbox is unverified, so it's Review rather than Exclude.
What can you tell from the address itself, without a lookup?
A surprising amount — and it never leaves your browser. From the part before the @ we flag digit-heavy names (like user48213@), which are sometimes scraped or machine-generated but often legitimate (employee IDs, academic accounts) — so it's a low-confidence review signal, not a strike — and we show how many read as a named person (first.last style). From the domain we identify the mail provider — privacy-first mailboxes like Proton and Tuta (hidden by design: they block open/click tracking and filter strictly), and secure email gateways like Proofpoint and Mimecast, which sit in front of a corporate mailbox and enforce strict inbound security. Each tells you how hard that recipient is to reach and how much authentication matters.
Do unusual domain endings like .bio, .security or .live count against my list?
No. New top-level domains are perfectly valid — plenty of real people and companies use them — so we don't flag them as problems. The only domain-name pattern we call out is punycode / IDN (xn--) domains, because those can be look-alikes of a well-known brand and are worth a human glance.
Can you verify individual mailboxes or catch spam traps?
Not here — and not honestly from the browser. This tool tells you what it can prove on your device: syntax, duplicates, disposable and role addresses, and whether a domain can actually receive mail. Confirming that an individual mailbox exists needs live SMTP probing, and spam-trap detection needs data no single list can see — so we don't guess at them or show fake confidence.
Is there a limit on list size?
The analysis runs on your device, so it's bounded by your browser's memory and CPU rather than by us — for a smooth run keep files under roughly 100k rows. Domain-existence lookups are capped at a few thousand unique domains to keep the check fast; anything over the cap is shown as Not checked (Unverified), and the result tells you how many were skipped.