A spammer got into one of our systems and blasted a junk list from our domain. Most of it bounced. Within days AWS had suspended our account and Outlook had blocked us. Our own emails stopped reaching the people who mattered. BounceShift is how we clawed our way back.
It started with an email blast we never sent.
A few months ago, someone got into one of our systems and used it to send spam. They'd brought a huge, bought list of Outlook.com addresses and blasted an insurance-offer campaign to every one of them. Most of those addresses didn't exist. They bounced all at once, from our domain.
That single blast was enough. Our sender reputation collapsed. AWS suspended our account. Microsoft blocked our domain at Outlook.
Overnight, our own emails stopped arriving — password resets, invoices, replies to customers. Bounced, spam-filed, or just gone.
Then came the cleanup: getting our AWS account reinstated, and the slower, harder work of earning back trust one inbox at a time. It cost us weeks, and a lot of customers who simply never heard back from us.
Two things became painfully clear:
So we built the tool we wished we'd had, and ran it on our own systems first. Once it was quietly protecting us, we opened it up to everyone who sends email.
Most teams discover bad emails after they've already hurt their sender reputation. We built BounceShift to catch invalid addresses at the point of entry: in signup forms, during imports, before campaigns go out.
Email addresses in our reputation database are stored as one-way cryptographic hashes. We literally cannot read, export, or sell them. The original addresses don't exist in our system. Your validation data is processed, then deleted.
No monthly minimums. No expiring credits. No surprise overages. You buy credits, you use them when you need them. Simple.
Our API docs aren't an afterthought. They're written by the engineers who built the API, with real examples, clear error messages, and code snippets that actually work.
We're a small team. We built BounceShift because we needed it, after a deliverability disaster of our own. Every verification layer in here exists because we learned, the hard way, what happens without one.
We're building the email validation service we'd want to depend on ourselves. That means it has to be fast, and it has to be honest about what it cannot verify. An address we can't confirm comes back marked as unconfirmed, never quietly rounded up to valid.
Buy what you need. Use it when you need it. No "use it or lose it" pressure.
Connect Mailgun, SendGrid, Postmark, or SES. We automatically track bounces and complaints to build your reputation database over time.
Syntax is the first check, not the only one. We verify MX records, validate SMTP responses, detect disposable domains, identify catch-all servers, and flag role-based addresses.
Manage API keys, track usage by project, and control permissions across your organization.
Start with 100 free validations. No credit card required.