Free
$0
500 / month
Enough to wire the API and try a real list.
Email validation API
Emvali checks syntax, disposable and role signals, and MX records, then returns a risk score and a status. The hosted API is api.emvali.com.
curl -s -X POST https://api.emvali.com/v1/validate \
-H "Authorization: Bearer $EMVALI_API_KEY" \
-H "Content-Type: application/json" \
-d '{"email":"ada@example.com"}'
{
"email": "ada@example.com",
"format_valid": true,
"disposable": false,
"mx_found": true,
"role_account": false,
"free_provider": false,
"catch_all": null,
"risk_score": 0,
"status": "valid"
}
Every authenticated call counts toward the monthly quota, including addresses Emvali marks invalid. A 400 does not.
format_valid is a practical format check: one @, a local part, a dotted domain, and an alphabetic TLD.
mx_found is true when DNS returns a mail exchanger for the domain.
Matched against a small disposable-domain seed, including subdomains. The seed is not a full feed.
Local parts such as admin, info, and noreply. A plus-tag still counts as the base role.
Best effort. catch_all stays null unless an optional SMTP probe reaches a conclusion.
risk_score is 0–1. status is valid, risky, invalid, or unknown.
Included validations reset each month. Past that, overage is about $0.004 per validation.
$0
500 / month
Enough to wire the API and try a real list.
$12
5,000 / month
For signup forms and a steady stream of checks.
$29
25,000 / month
Higher volume, same response shape.
Overage is about $0.004 per validation after the included amount. These are catalog prices. This page does not start a charge, and Emvali is not sold through a marketplace checkout.
The contract is OpenAPI 3.1. It covers health, validation, usage, signup, and API keys.
{"email":"..."}.Create a free account on api.emvali.com. The free plan includes 500 validations a month. Emvali shows the API key once and stores only a hash. Nothing here collects a card.
Use the form, or POST /v1/signup with an email and password. Later, POST /v1/login issues another key.
The plaintext secret is returned once. Emvali keeps a SHA-256 hash. Send it as Authorization: Bearer.
Call /v1/validate. Branch on status and risk_score. GET /v1/account shows remaining quota.