All posts

Mailgun Email Validation Alternatives for Developers in 2026

··6 min read

Mailgun's validation API is convenient if you already send through Mailgun, but it is priced well above dedicated verifiers: $100 for 10,000 validations on its October 2026 pricing page, against $11.90 to $70 elsewhere. Dedicated APIs from Kickbox, ZeroBounce, Emailable, Bouncer and NeverBounce also document their timeouts and rate limits more precisely.

This post is for developers deciding whether to keep validation on Mailgun or move it. It compares what each API actually exposes, and ends with a status mapping you can use in a migration. For a broader API comparison, see email verification APIs compared.

What Mailgun's validation API gives you

From Mailgun's single validation and bulk validation docs, read on 1 October 2026:

Item Mailgun
Endpoint GET or POST /v4/address/validate
Auth HTTP basic auth, api:YOUR_API_KEY
result deliverable, undeliverable, do_not_send, catch_all, unknown
risk high, medium, low, unknown
Reasons e.g. mailbox_does_not_exist, mailbox_is_disposable_address, mailbox_is_role_address, catch_all, no_mx, smtp_error
provider_lookup Default true; false skips contacting the mailbox provider and can return no_data
Rate limit "rate limited to a set number of active requests at a time"; 429 means wait and retry
Bulk CSV or gzip up to 25MB; maximum 5 jobs processing in parallel

Two details matter for design. First, provider_lookup=false is a speed setting that stops Mailgun asking the mailbox provider; results without it cannot confirm a mailbox. Second, the rate limit is described as concurrent active requests without a published number, so you discover it from 429s.

What Mailgun validation costs

Mailgun prices validations in marginal bands, per 100, on its pricing page:

Band Price per 100 Per 1,000
First 5,000 $1.20 $12.00
Next 45,000 $0.80 $8.00
Next 50,000 $0.50 $5.00
Next 150,000 $0.35 $3.50
Next 250,000 $0.25 $2.50

The Scale plan ($90 a month) lists the first 5,000 as included. On other plans, a month with 10,000 validations costs $100, with 100,000 it costs $670, and with 500,000 it costs $1,820.

The alternatives, side by side

API Auth Results Timeout Rate limit (documented) 10,000 checks
Mailgun Basic auth 5 results + risk Not stated in the pages we read Concurrent requests, number not stated $100
Kickbox apikey query param deliverable, undeliverable, risky, unknown + Sendex 0–1 Default 6s, max 30s Not stated in the pages we read $70
ZeroBounce api_key param valid, invalid, catch-all, unknown, spamtrap, abuse, do_not_mail 3–60s 80,000 requests per 10 seconds $129
Emailable api_key or access_token deliverable, undeliverable, risky, unknown 2–10s, default 5 25/s verify, 5/s batch $60
Bouncer x-api-key header deliverable, risky, undeliverable, unknown Default 10s 1,000/min real-time $60
NeverBounce key query param valid, invalid, disposable, catchall, unknown timeout in seconds Not stated on the check endpoint Not readable today

Sources: Kickbox docs, ZeroBounce docs, Emailable docs and rate limits, Bouncer docs, NeverBounce docs. Prices are each vendor's pay-as-you-go price for 10,000, read from its pricing page on 1 October 2026. NeverBounce's pricing page returned HTTP 403 to our requests.

If price is the main driver and you can live with stricter concurrency, Reoon ($11.90 for 10,000) and DeBounce ($25) are cheaper still. Reoon's API docs ask you not to run more than 5 continuous threads, and note that its Quick mode does not check individual mailboxes, so use its Power mode for anything you need confirmed.

Things to check before you migrate

Where the key travels

Kickbox, ZeroBounce, Emailable and NeverBounce document the API key as a query parameter. Bouncer uses a header, and Mailgun uses basic auth. Keys in query strings are easy to leak into access logs, proxy logs and error trackers. Whatever you choose:

  • Call the API only from your server. Never from browser code, where the key is visible to anyone.
  • Strip query strings from logged URLs, or log the email domain only.

Timeouts and your signup budget

A signup form cannot wait 60 seconds. Set the vendor timeout below your own request budget and decide in advance what happens on timeout. The safe design is fail open: accept the signup, mark the address unverified, and re-check it in the background. Blocking signups because a third-party API was slow loses real users.

Rate limits under load

Translate the documented limit into your peak. Bouncer's 1,000 a minute is about 16 a second; Emailable's is 25 a second; Reoon's is 5 continuous threads. If a marketing push sends 50 signups a second, queue verifications rather than calling inline.

What "risky" means in each

Mailgun splits uncertainty across catch_all, unknown and a risk score. Others fold catch-all into risky or report it separately. Read each vendor's definitions and map them deliberately, or your suppression rules will silently change during the migration.

A status mapping to start from

This is a starting point, not a vendor-endorsed equivalence. Adjust it after reading each vendor's reason codes.

Your internal status Mailgun ZeroBounce Kickbox / Emailable / Bouncer NeverBounce
send deliverable (risk low) valid deliverable valid
send with care catch_all; deliverable with risk medium catch-all risky (check reason) catchall
retry later unknown unknown unknown unknown
suppress undeliverable; do_not_send invalid, spamtrap, abuse, do_not_mail undeliverable invalid, disposable

In code, keep the vendor's raw result alongside your normalised one, so you can remap later without re-verifying:

type Internal = "send" | "send_with_care" | "retry" | "suppress";

const fromMailgun = (result: string, risk: string): Internal => {
  if (result === "deliverable" && risk === "low") return "send";
  if (result === "deliverable" || result === "catch_all") return "send_with_care";
  if (result === "unknown") return "retry";
  return "suppress";
};

Write one function like this per vendor, and test it against a handful of known addresses: a fabricated Gmail address must map to suppress, and your own address to send.

When to stay on Mailgun

Stay if your validation volume is small, you already pay for the Scale plan (which includes 5,000 validations), and having sending and validation on one bill matters more than the per-check price. At a few thousand validations a month, the difference is tens of dollars, which may not justify engineering time. Above that, the gap grows quickly; our cheapest verification services breakdown shows the full curve.

Disclosure — our product

SimpleVerifier, which publishes this blog, is a $29.99-a-month flat-fee verifier built around CSV uploads and a web app, with a free single-address checker at /tools/verify-email. It does not publish a public verification API, so it is not a replacement for any of the APIs above.

The takeaway

Keep Mailgun validation for convenience at low volume. If you move, compare documented timeouts and rate limits against your signup peak, keep keys server-side, design the call to fail open, and map statuses explicitly so your suppression rules mean the same thing after the switch.

Common questions

How much does Mailgun email validation cost?

Mailgun's pricing page in October 2026 listed validations at $1.20 per 100 for the first 5,000, then $0.80, $0.50, $0.35 and $0.25 per 100 on later bands. Its Scale plan, at $90 a month, includes the first 5,000. That works out to $100 for 10,000 validations on top of any sending plan.

What results does the Mailgun validation API return?

The result field is one of deliverable, undeliverable, do_not_send, catch_all or unknown, and a separate risk field is high, medium, low or unknown. A reason array gives detail such as mailbox_does_not_exist or mailbox_is_role_address.

Which email validation API is cheapest?

On published October 2026 prices for 10,000 checks, Reoon ($11.90), DeBounce ($25) and MillionVerifier ($39) were cheapest, against Mailgun's $100. API terms differ, though: check rate limits and concurrency rules before choosing on price.

Is it safe to put an email verification API key in the query string?

Several vendors document it that way, but query strings tend to end up in server logs, proxies and error trackers. Call verification APIs only from your backend, never from browser code, and scrub URLs in logging if the key travels as a query parameter.

Verify unlimited addresses for $29.99/month

Real SMTP mailbox checks. No credits, no per-email fees.

Get Started