Free
$0
500 / month
Enough to wire the API and try a real list.
Email validation API
Emvali checks syntax, disposable and role signals, and MX records, then returns a risk score and a status. The hosted API is api.emvali.com.
curl -s -X POST https://api.emvali.com/v1/validate \
-H "Authorization: Bearer $EMVALI_API_KEY" \
-H "Content-Type: application/json" \
-d '{"email":"ada@example.com"}'
{
"email": "ada@example.com",
"format_valid": true,
"disposable": false,
"mx_found": true,
"role_account": false,
"free_provider": false,
"catch_all": null,
"risk_score": 0,
"status": "valid"
}
Every authenticated call counts toward the monthly quota, including addresses Emvali marks invalid. A 400 does not.
format_valid is a practical format check: one @, a local part, a dotted domain, and an alphabetic TLD.
mx_found is true when DNS returns a mail exchanger for the domain.
Matched against a small disposable-domain seed, including subdomains. The seed is not a full feed.
Local parts such as admin, info, and noreply. A plus-tag still counts as the base role.
Best effort. catch_all stays null unless an optional SMTP probe reaches a conclusion.
risk_score is 0–1. status is valid, risky, invalid, or unknown.
Included validations reset each month. Past that, overage is about $0.004 per validation.
$0
500 / month
Enough to wire the API and try a real list.
$12
5,000 / month
For signup forms and a steady stream of checks. 10 per second, 120 per minute.
$29
25,000 / month
Higher volume, same response shape. 30 per second, 600 per minute.
Upgrade opens Paddle Checkout for the API key in this tab. Card details stay with Paddle. The account id is sent to Paddle as custom data. Overage is about $0.004 per validation after the included amount and is not billed yet. Emvali is not sold through a marketplace.
The contract is OpenAPI 3.1. It covers health, validation, usage, signup, and API keys.
{"email":"..."}.{"plan":"starter"} or {"plan":"growth"}. Opens Paddle Checkout.Create a free account on api.emvali.com. The free plan includes 500 validations a month. Emvali shows the API key once and stores only a hash. This form does not collect a card. To upgrade, stay in this tab and choose a plan under Pricing.
Use the form, or POST /v1/signup with an email and password. Later, POST /v1/login issues another key.
The plaintext secret is returned once. Emvali keeps a SHA-256 hash. Send it as Authorization: Bearer.
Call /v1/validate. Branch on status and risk_score. GET /v1/account shows remaining quota.