What one check call covers
Sent to a dead address, an email doesn't just fail, it testifies against you: every hard bounce tells mailbox providers you don't know your own list. A check API runs the layers before that happens: syntax, then MX records on the domain, then whether the mailbox itself exists and accepts, then disposable and role-address flags.
Explicit validation operations
Nitrosend validates an exact audience as a durable prepaid operation. Quote it without mutation, inspect the maximum charge, then start it with an idempotency key. Choose exactly one audience selector: contact channel IDs, contact IDs, a list, or a segment. Contact-profile enrichment is separate.
curl -X POST https://api.nitrosend.com/v1/my/validation_operations/quote \ -H "Authorization: Bearer $NITROSEND_API_KEY" \ -H "Content-Type: application/json" \ -d '{"contact_channel_ids": [123]}' curl -X POST https://api.nitrosend.com/v1/my/validation_operations \ -H "Authorization: Bearer $NITROSEND_API_KEY" \ -H "Content-Type: application/json" \ -H "Idempotency-Key: validation-channel-123" \ -d '{"contact_channel_ids": [123]}' → { "operation_id": "...", "status": "held" }
Poll GET /v1/my/validation_operations/{id} for durable state and GET /v1/my/validation_operations/{id}/items for per-candidate results. Nitrosend does not trigger paid validation automatically on signup, import, schedule, or send, and no plan includes an allowance. If your product needs validation at signup, call this operation explicitly.
Signup is also where we check ourselves. After a bot wave hit our own signup form with disposable-domain addresses, we hardened the gate with a curated blocklist, subdomain-aware matching, and closed the side doors the bots were routing through. And every brand-new account's first multi-recipient campaign without a verified sending domain lands in a manual review queue before it goes anywhere. The checks we sell are the checks we live behind.
When the send really matters, I stack the checks. Before one recovery send I filtered on prior-blacklist flags, plus the full suppression list, plus verification-valid, plus a real engagement signal, and only then let the send go. Belt, braces, and a second belt. That send recovered the domain's reputation.
Full parameters and responses live in the REST API docs and the API reference.
Go deeper
Why the bounce math is unforgiving: the email validation API guide, with the 22.8%-to-0.20% story. Security side: API-based email security. A clean list is the shortest path to a low bounce rate, and it keeps you clear of blacklist monitoring.