What validation actually checks

Validation is typically limited to: syntax correctness (does it match the general structure of a valid email address per the relevant RFCs), and DNS/MX record existence (does the domain have a mail server configured at all). Both checks can be done instantly and at essentially zero cost, since they involve no network connection to the recipient’s actual mail infrastructure.

What verification adds on top

Verification includes everything validation does, plus a live SMTP handshake against the recipient’s actual mail server to test whether the specific mailbox exists (via the RCPT TO response). This is the only layer that can distinguish “the domain can receive mail” from “this specific address has an active mailbox,” and it’s meaningfully more expensive to run at scale — which is why it’s usually the metered, paid layer of a verification product.

Why the distinction matters when evaluating a list

A list that’s been “validated” but never “verified” can still have a high real-world bounce rate, since validation alone can’t catch an address with correct syntax pointing to a domain with valid MX records but no actual mailbox behind that specific local part. If you’re trying to protect sender reputation and bounce rate specifically, validation alone is insufficient — verification’s SMTP layer is the part that actually predicts bounce behavior.

Why some addresses can’t be fully verified either way

Catch-all domains and servers that accept all RCPT TO commands regardless of validity make even full SMTP verification inconclusive for a share of addresses — no verification method, however thorough, can turn an inherently ambiguous server response into certainty. The best tools resolve a confidence-scored verdict for most of these cases rather than claiming false certainty.