Docs · Guides
Email verification
MagpieCRM finds a prospect's work email by checking likely addresses with the company's mail server. This page is for self-hosted copies, which run their own verification server.
On Magpie Cloud
Email verification is included and needs no setup. Checks run from our own pool of verification IPs with our own domain, never yours, and those IPs are checked against blocklists every 6 hours. You can skip the rest of this page.
How verification works
When you reveal an email or save a prospect, MagpieCRM builds likely addresses from the person's name and company domain (such as jane.smith@ or jsmith@) and asks the company's mail server, over SMTP, whether each mailbox exists. No email is sent.
- It tries at most 6 addresses per person, and stops after 2 "couldn't check" answers.
- A confirmed address teaches the domain its format, such as
{first}.{last}. Only the format is remembered, never the name or address. - Catch-all domains accept every address, so nothing can be confirmed there. They're detected once and remembered for 180 days.
Without a verification server the app still works, but every address is an unverified best guess. Under Settings, then Email verification, Only give verified emails is on by default: reveals and saves only hand over addresses the mail server confirmed, and catch-all, risky and unconfirmed guesses are withheld with the reason. That keeps bounces off your sending domain. With verification off and this setting on, no emails are given.
Outbound port 25
Mail servers are reached on port 25. Most large clouds block it by default, so check from the machine that runs the verification server:
timeout 8 bash -c '</dev/tcp/gmail-smtp-in.l.google.com/25' && echo open || echo blocked- Blocked: you need at least one proxy on a server where port 25 is open.
- Open, on a home or office connection: fine for low volume, but residential IPs are on blocklists and some mail servers refuse them. Add proxies before any real volume.
- Open, on a server with clean reverse DNS: you can run without proxies, though spreading checks over a few IPs keeps any one from being flagged.
Connect the verification server
Run an SMTP email verifier as its own service. From a checkout of the repository, bun run verifier:up starts one. Then, in Settings, then Email verification:
- Set the service to Verification server.
- Enter the Server URL and the secret you gave the verification server.
- Set the FROM address and HELO name the checks introduce themselves with (see the proxy section below).
- Adjust Daily checks per IP if you need to. The default is 1,500.
- Save, then press Test verification. It checks a made-up address at Gmail and at Microsoft 365, directly or through each proxy, and reports whether each route got a clear answer. No real mailbox is contacted.
Proxies
Proxies let checks come from servers with port 25 open and clean IPs, and spread the load. Any small Linux VPS works if its provider allows outbound port 25. The repository has a script that turns a fresh Ubuntu or Debian server into a SOCKS5 proxy which only accepts your verification server's IP, requires a username and password, and only relays to port 25:
scp docker/proxy-node/setup-dante.sh root@PROXY_IP:
ssh root@PROXY_IP \
"ALLOW_FROM=<public IP of the verification server> PROXY_USER=verify PROXY_PASS='<long random password>' bash setup-dante.sh"Add each proxy under Verification proxies on the same settings page (host, port 1080, username and password), save, and run Test verification again. Saved proxies are stored encrypted. One server with several IPs can run one proxy per IP; the script sets that up too.
Then give each IP a name mail servers trust:
- Pick a hostname on a domain you control, such as
verify1.yourdomain.com, and point an A record at the proxy's IP. - Set the IP's reverse DNS (PTR) to that hostname in your VPS provider's panel.
- Use that hostname as the HELO name, and an address on that domain as the FROM address.
Keep verification apart from sending
Use a domain you don't send campaigns from, so a flagged verification IP can't touch your sending reputation. Never send email from verification IPs.
The proxy guide covers several IPs on one server, reverse DNS and reputation in more detail.
Rate limits and IP health
The app keeps every IP's checks gentle. Adding a proxy adds capacity.
- Per IP: 20 checks a minute, with Microsoft at 6 and Google at 10, and the daily limit you set (1,500 by default).
- Per company, across all IPs: up to 12 checks in any 3 minutes. Saves wait for a slot.
- Per company per day: 20 rejected guesses, then that company waits until tomorrow. Checks that hit a real mailbox don't count.
When an IP runs into trouble:
- An IP on a spam blocklist stops being used until a health check finds it clean.
- An IP whose recent checks are mostly blocked rests for an hour and you get a notification. Several blocks or timeouts in a row rest it for 15 minutes.
- A blocklisted FROM domain pauses all verification, unless you tick Keep verifying anyway for that domain while testing.
- A company that refuses one IP is checked through your other IPs for the next 6 hours.
The health panel on the settings page checks each IP and the FROM domain every 6 hours, and when you press Check now. Counts are kept in memory, so a restart resets them.
Something wrong or missing? Email pele@magpiecrm.com or open an issue.