How Email Risk Scoring Works
The Email Risk Scorer goes beyond simple valid or invalid binary verification by evaluating multiple risk signals to produce a numerical score from 0 (safest) to 100 (highest risk). When you submit an email address, the scoring engine runs a series of checks in parallel: syntax validation against RFC standards, domain DNS analysis including MX and A record verification, disposable email detection against our database of over 150,000 temporary domains, catch-all server detection via SMTP probing, domain age and registration data analysis, blacklist status checks, and historical complaint data evaluation. Each of these signals contributes a weighted component to the final risk score.
The weighting algorithm is calibrated using machine learning models trained on millions of email verification outcomes and engagement data points. For example, a valid syntax with active MX records on a reputable domain like Gmail receives minimal risk points, while an address on a recently registered domain with catch-all enabled and no DKIM records accumulates significant risk. The algorithm also considers the local part of the email address, identifying patterns commonly associated with spam traps (such as abuse@, postmaster@), role accounts (such as info@, sales@), and randomly generated strings that may indicate bot-created accounts. By combining all of these signals into a single score, the tool provides a nuanced assessment that helps you make informed sending decisions for addresses that fall into gray areas between clearly valid and clearly invalid.
When to Use This Tool
- Making send or no-send decisions for borderline addresses — When standard email verification returns an "Unknown" or "Risky" status, the risk score helps you decide whether the potential benefit of reaching the recipient outweighs the risk of a bounce or spam complaint.
- Prioritizing outreach campaigns — Score all addresses in your prospect list and prioritize outreach to low-risk contacts first. This approach maximizes your deliverability and engagement rates in the critical early stages of a campaign when your sending reputation is being established.
- Setting automated thresholds in registration flows — Integrate risk scoring into your signup forms to automatically accept low-risk addresses, flag medium-risk addresses for additional verification steps like email confirmation, and reject high-risk addresses that are likely to be fraudulent or disposable.
- Auditing list quality for compliance — Before importing email lists into your marketing platform, run a risk assessment to identify the percentage of high-risk addresses. Many email service providers require list quality standards, and a high average risk score indicates a list that needs cleaning before use.
Understanding Your Results
The risk score is divided into four bands that guide your action. A score of 0 to 20 indicates a safe address with strong signals of legitimacy: the domain is well-established, has proper authentication records, and the address pattern is consistent with a real user. A score of 21 to 50 represents moderate risk, where some signals are uncertain but the address is likely deliverable. You can generally send to these addresses but should monitor engagement and remove non-responders. A score of 51 to 80 means high risk, where multiple negative signals are present such as a new domain, catch-all configuration, or proximity to known disposable services. Exercise caution and consider additional confirmation before sending.
A score of 81 to 100 represents the highest risk level, where the address should not be used for sending under any circumstances. Addresses in this band typically have multiple critical flags such as disposable domain detection, blacklisted infrastructure, invalid MX records, or patterns matching known spam traps. The results also provide a breakdown of individual risk factors that contributed to the score, allowing you to understand exactly why an address received its rating. Each factor is listed with its contribution weight, so you can see whether the risk is driven primarily by domain reputation, address pattern, server configuration, or a combination of factors. This transparency helps you make informed decisions rather than relying on an opaque score alone.