Show HN: Deep Email Validator
github.com
github.com
RFC 5321 section 5 specifies that you lookup the MX and, if absent, use the A/AAAA record. I'm simplifying a bit, but that's the gist of it.
Using just the A record is more common than you might expect.
> Validates email looks like an email i.e. contains an "@" and a "." to the right of it.
But what about emails coming from a hostname without a dot, or a TLD without a subdomain?
Even the HTML email field supports emails without a dot after the @ because it's technically valid.
For non-FQDN hostnames, it's kinda pointless, as you can only use that on your own domain. So if you were to do that, just make up your own pseudo-TLD like ".x" with an alternate DNS system. You could even have it point to the regular DNS system through CNAMEs.
https://github.com/mfbx9da4/deep-email-validator/blob/master...
All that happens if that naïve code fails is that it does an MX lookup that's bound to fail, and then the code returns a bad error message ("couldn't find MX" instead of more properly "syntax error in domain part").
(If, and only if, no MX record for the domain is present, treat the domain as if it had an MX record with the given domain as the target hostname and a preference value of 0)
It opens an SMTP connection and runs through the handshake. If this fails then, it will fail with a real delivery just the same.
It's still a bad test to do, but for other reasons.
On signup for my app we validate like this, with MX and SMTP check - before sending a account verify message
Email is a very old protocol with a lot of hacks and backwards compatibility. At this point, pretty much any string could be a valid email address. You can certainly run a bunch of tests and get a decent signal, but it's a lot of work, and if you reject an email address without testing it you're going to cause someone some trouble at some point. It's a lot easier and more accurate to just accept the string and try to send email to it.
I'm using a similar technique to check deliverability, i.e. parsing SMTP responses.
Assuming this uses that technique.