Do I need an API key?
No. The DNS lookup and the disposable domain list are free and open. The signed verdict uses a throwaway demo key that the page requests from the live AffixIO API on its own.
Public tool
Type any email address. Email Verification Gate checks the format, looks up the domain mail server against Google public DNS, tests it against a blocklist of disposable inboxes, and flags role addresses, then asks the live AffixIO API for a signed yes or no.
Type a full email address. The check runs the moment you click Verify.
AffixIO proof
Stamped by the live AffixIO API and signed with ML-DSA-65, the FIPS 204 post-quantum algorithm. Nothing personal goes into the payload.
Three moves, no sign-up.
Paste or type any full email address into the field.
The tool checks the format, looks up the mail server for the domain, tests it against a disposable inbox blocklist, and flags role addresses like admin@ or noreply@.
A YES means the address passes every check. A NO tells you which check failed, with a signed proof from the live AffixIO API.
Email Verification Gate runs four checks in sequence. First, a syntax check against the standard email format. Second, an MX record lookup against Google public DNS over HTTPS to confirm the domain actually receives mail. Third, a test against an open blocklist of disposable and temporary inbox domains. Fourth, a flag for role addresses such as admin@, postmaster@ and noreply@ which tend to be unmonitored.
The MX lookup uses Google DNS over HTTPS, which is free and keyless. The disposable domain list is an open source blocklist that is updated regularly.
The proof card shows the answer stamped by the live AffixIO API: a proof id, an audit id, the policy version, and an ML-DSA-65 signature over the payload digest. That is the same post-quantum signature family the production platform uses.
No. The DNS lookup and the disposable domain list are free and open. The signed verdict uses a throwaway demo key that the page requests from the live AffixIO API on its own.
No. The address is checked in your browser. Only a throwaway demo key request and the final proof call touch the network, and neither stores the address.
A role address is a generic inbox like admin@, sales@ or noreply@. They usually work, but they are often shared or unmonitored, so many businesses filter them out at sign-up.
The answer stamped by the live AffixIO API: a proof id, an audit id, the policy version, and an ML-DSA-65 signature over the payload digest.