Why configure Haraka SMTP for email verification?

You send emails. Some bounce. Some disappear into black holes. You don’t know why—until your deliverability starts slipping, your reputation dips, and your campaigns underperform.

Haraka SMTP configuration for outbound email verification isn’t about fancy tools or third-party APIs. It’s about running verification inside the actual email delivery pipeline—real-time, in code, with full visibility.

Haraka is an open-source, high-performance SMTP server built for scalable email delivery and inspection. When you configure it to validate addresses before sending, you catch invalid, disposable, or role-based emails before they hit the wire. That means fewer bounces, better sender reputation, and more predictable inbox placement.

Adding logging to that flow turns the system into a diagnostic tool. Every connection attempt, every validation decision, every error is recorded. You can trace why an email failed—was it a catch-all domain? A graylist delay? A malformed header?—and fix it before it harms your domain reputation.

Key takeaways

  • Haraka SMTP configuration enables real-time email verification at the transport layer, reducing outbound failures before messages are sent.
  • Full logging during verification allows audit trails for failed deliveries, catch-all detection, and reputation analysis over time.
  • Integrating verification into Haraka’s SMTP pipeline improves deliverability by filtering risky or invalid addresses at scale without relying on third-party services.

How does Haraka SMTP support email verification workflows?

Haraka SMTP handles outbound email verification by processing real-time SMTP transactions and logging every stage of communication. You can extend it with plugins to call external services like MailTester during the handshake, validating addresses before delivery. With logging enabled, you get full visibility into each connection, transaction, and response—critical for debugging delivery issues and tracking verification results.

SMTP Handshake Integration for Real-Time Checks

Let’s say you’re using Haraka as a mail relay during outbound campaigns. As each email is submitted, Haraka initiates the standard SMTP handshake: HELO, MAIL FROM, RCPT TO, and DATA. At the RCPT TO stage, you can insert a plugin that triggers an external verification service before accepting the recipient.

This is where tools like the MailTester email checker come in. By integrating via API during this phase, you avoid sending to invalid, disposable, or role-based addresses. This reduces bounces and protects your sender reputation.

Logging for Verification Debugging and Compliance

Haraka’s logging system records every connection, command, response, and timing detail. This includes IP addresses, error codes, and session duration—everything you need to analyze why a verification failed or a recipient was rejected.

For example, if a domain returns a 550 error during verification, the log shows whether it was due to a hard bounce, greylisting, or a catch-all policy. This data helps you tune your verification logic. Since Haraka is open-source, you can also audit the logs yourself or feed them into SIEM tools for compliance tracking.

While Haraka handles the transport layer, it’s designed so you can plug in verification logic at any stage—making it ideal for teams that need both control and visibility. The real-time nature of the logs means you spot failed deliveries or suspicious activity as it happens.

For teams relying on bulk validation, this level of control pairs well with services like MailTester's bulk verification, which runs thousands of checks efficiently and returns structured results. For ongoing verification, the MailTester API provides programmatic access to real-time validation during your SMTP workflow.

What are the core components of Haraka SMTP configuration for verification?

Haraka’s SMTP configuration for outbound email verification relies on three key parts: the SMTP listener that accepts incoming connections on port 25 or 587, plugin hooks that run validation logic during the session lifecycle, and a logging engine that tracks connection details, error codes, and timing. Together, they let you inspect every stage of an email transaction for reliability and compliance. You’re not just sending mail—you’re testing it.

SMTP Listener

  • Bind to port 25 (for inbound mail) or 587 (for submission) to receive email connections in real time.
  • Use port=25 or port=587 in the config/plugins file to define the listening interface.
  • Enforce TLS negotiation for port 587 to prevent plain-text transmission—this aligns with RFC 5321 standards for secure mail submission.

Plugin Hooks

  • Inject custom validation logic via hooks like RCPT (recipient check) and DATA (message body inspection).
  • Check for invalid syntax, blocked domains, or role-based addresses (e.g., admin@) before proceeding.
  • Integrate with a service like MailTester's email checker to validate addresses in real time using a verified API.
  • Fail early with a 5xx error code for known invalid or risky addresses, reducing delivery load.

Logging Engine

  • Enable log_level=debug in config/logging.ini to capture connection metadata like IP, TLS version, and user agent.
  • Store logs in structured format (e.g., JSON) for parsing and correlation with verification outcomes.
  • Track timing per SMTP stage—this helps identify delays, such as those caused by greylisting or rate limiting.
  • Use the logs to assess inbox placement: if a connection fails mid-flow, the timing and error code help diagnose deliverability issues.
  • Monitor catch-all behavior by flagging 250 responses even to non-existent users—this can reveal misconfigured mail servers.
When you’re testing outbound email verification, the real power isn’t in sending—but in knowing exactly what happened, why, and when.

Haraka’s strength lies in its modularity. You can replace or augment any component without rewriting the entire system. For instance, swap the internal logging system with a remote log aggregator, or hook in a third-party email validation API like MailTester’s verification API for real-time checks. This flexibility gives you full visibility into your email traffic and helps maintain sender reputation.

How to configure Haraka SMTP to integrate with MailTester's real-time API

You can integrate Haraka SMTP with MailTester’s real-time API by creating a custom plugin that intercepts recipient addresses during the RCPT TO phase, validates them via MailTester’s API, and either accepts or rejects them based on the response. This prevents bad emails from being queued and improves deliverability by reducing bounces and spam complaints. All responses are logged with timestamps for audit and debugging.

Set up Haraka and prepare the plugin environment

  1. Install Haraka using npm: npm install -g Haraka. This gives you the SMTP server with a built-in plugin system.
  2. Initialize a new instance: haraka -i /path/to/your/haraka. This creates the standard directory structure, including plugins/.
  3. Go into the plugins/ directory and create a file called verify-email.js. This is where you’ll insert the logic to call MailTester’s API before accepting recipients.
  4. Confirm Haraka is running and listening on port 25 or 587 by checking the console output. This ensures the SMTP server is ready to accept connections.

Implement the real-time verification logic

  1. In verify-email.js, define a plugin using exports.register = function (server, config) { ... }. Register the rcpt_to hook to intercept recipient addresses during delivery.
  2. Within the hook, extract the recipient email address. Use a simple regex to validate the format but don’t rely on it—real validation happens in the API call.
  3. Call MailTester’s real-time API at https://mailtester.com/api-email-checker/ with the address. Use your API key in an Authorization header. The API returns JSON with a result field: valid, invalid, risky, or catch-all.
  4. Based on the response, accept the recipient only if result === 'valid'. For invalid or risky, return a 550 error to reject the recipient immediately. catch-all domains may be logged but should generally be blocked unless you explicitly allow them.
  5. Log the full API response, timestamp, and email address to your logs using Node’s console.log or a file logger. This is essential for monitoring, debugging, and auditing failed attempts. Use RFC 5321 as a reference for SMTP command behavior and error codes.

You can extend this setup to handle bulk validation by processing lists in advance using MailTester’s bulk email verification tool. That reduces load on the real-time API and ensures high-volume senders only deliver to confirmed, valid addresses. This approach is an industry-standard way to maintain sender reputation and avoid blocklists.

Set up Haraka and prepare the plugin environmentThe 4 steps described in “Set up Haraka and prepare the plugin environment”, in order.1Install Haraka using npm: npm install -g Haraka. This gives you the SMTPserver with a built-in plugin system.2Initialize a new instance: haraka -i /path/to/your/haraka. This createsthe standard directory structure, including plugins/.3Go into the plugins/ directory and create a file called verify-email.js.This is where you’ll insert the logic to call MailTester’s API beforeaccepting recipients.4Confirm Haraka is running and listening on port 25 or 587 by checkingthe console output. This ensures the SMTP server is ready to acceptconnections.
The 4 steps described in “Set up Haraka and prepare the plugin environment”, in order.

What does the MailTester API integration return, and how to interpret it?

When you integrate MailTester’s API, you get a precise verdict for each email: valid, invalid, catch-all, or risky. Each response is based on real-time SMTP checks, DNS lookups, and behavioral analysis—no guesswork. Use these results to filter out dead or high-risk addresses before sending, reducing bounces and protecting sender reputation. You can automate this in bulk, ensuring only deliverable emails get sent.

Understanding the verdicts

  • Valid: The mailbox exists and accepts mail. It’s confirmed via successful SMTP connection and response codes. Use these addresses without hesitation.
  • Invalid: The address fails format validation (like missing @ or domain), or the domain doesn’t exist. These should be removed immediately—no retry.
  • Catch-all: The domain accepts all incoming mail, even for non-existent users. This means your message may land in a spam folder or be ignored. Avoid using these for targeted outreach.
  • Risky: The address is flagged as disposable (e.g., 10minutemail.com), a role-based account (admin@, sales@), or potentially spoofed. These increase spam risk and hurt deliverability.

How to act on the data

Let’s say you’re running a campaign. After checking with the MailTester API, you filter out all invalid and risky addresses. You then route valid addresses to your platform, and treat catch-all domains with caution—maybe only send low-sensitivity content, or suppress them entirely.

ItemDetails
ValidThe mailbox exists and accepts mail. It’s confirmed via successful SMTP connection and response codes. Use these addresses without hesitation.
InvalidThe address fails format validation (like missing @ or domain), or the domain doesn’t exist. These should be removed immediately—no retry.
Catch-allThe domain accepts all incoming mail, even for non-existent users. This means your message may land in a spam folder or be ignored. Avoid using these for targeted outreach.
RiskyThe address is flagged as disposable (e.g., 10minutemail.com), a role-based account (admin@, sales@), or potentially spoofed. These increase spam risk and hurt deliverability.
The 4 items listed under “Understanding the verdicts”, side by side.

According to RFC 5321, SMTP servers should reject non-existent users with a 5xx error code. MailTester uses those responses, along with domain reputation and historical data, to classify addresses accurately. This process avoids false positives and ensures your list reflects real delivery potential.

For a live test, try checking a single address first with the email checker. You’ll see the exact response you’ll receive via API, so you know what to expect.

How to enable and structure logging in Haraka for verification results

You can track every step of outbound email verification in Haraka by configuring detailed logging. Edit config/logging.ini to set the log level to info for operational visibility or debug for full SMTP protocol traces. Use a custom formatter to include verification status, API response time, and address verdict, then direct logs to a dedicated file like verify.log. Rotate this file regularly using logrotate to avoid disk exhaustion. This setup supports audit trails, debugging, and monitoring deliverability trends.

Configure logging levels and output

  1. Open config/logging.ini in your Haraka installation. Set level = info to capture all key events during verification, or debug if you need full SMTP conversation details for troubleshooting. The SMTP RFC specifies standard message flows; logging at debug ensures you see every handshake, including server responses and timeouts.
  2. Define a new logger in the config file specifically for verification tasks. Name it something like [verify] and point it to a dedicated output file, such as logs/verify.log. This isolates verification data from general mail logs, making it easier to parse and analyze later.
  3. Use a custom log formatter to include structured fields like address, verdict, response_time_ms, and api_status. Haraka supports custom formatters via JavaScript plugins. For example, format logs as: [2024-05-15 10:23:45] VERIFY: [email protected] → valid (214 ms, 200). This enables precise filtering and integration with monitoring tools.
  4. Set up logrotate on Linux to manage the size and retention of verify.log. Configure it to compress logs daily and keep only 7 days of history. This prevents disk exhaustion on high-volume verification systems, a common issue when running bulk verification pipelines.
  5. Validate your configuration by sending test emails through Haraka’s verification pipeline. Check the output file to confirm logs contain expected data. You can use tools like grep, jq, or a SIEM for real-time alerting based on verdicts (e.g., invalid or catch-all).

Monitor and integrate verification outputs

Once logs are structured, you can use them to assess deliverability health, identify suspicious domains, or refine your email list hygiene. For instance, a spike in catch-all verdicts may indicate a list with placeholder domains. Pairing Haraka’s logging with tools like MailTester’s bulk email verification helps validate your results with external data, reducing false positives and improving list quality at scale.

Common issues and how to resolve them with Haraka SMTP logging

You’ll hit roadblocks when verifying emails at scale—rate limits, delayed responses, missing logs, or catch-all false positives. Use Haraka’s SMTP logging to trace failures, implement exponential backoff for API limits, cache results to cut latency, verify plugin loading and file permissions, and filter catch-all verdicts before sending. These steps keep your outbound verification pipeline reliable.

Immediate fixes for known failures

  • When API calls fail due to rate limiting, implement retry logic with exponential backoff—start with 1 second, double on each retry up to 30 seconds. This prevents overwhelming the service and reduces throttling.
  • If verification latency is high (common with remote services), cache known valid or invalid addresses locally. This cuts repeated calls for the same email, especially for static lists used across campaigns.
  • Missing logs? Check your Haraka configuration: ensure the logging plugin is listed in the plugins array and the log directory (e.g., /var/log/haraka) has write permissions for the running user. Use ls -la to verify ownership and permissions.

Handling edge cases in email validation

  • Catch-all domains reply as valid for all addresses but aren’t useful for outreach. Filter out any address with a catch-all verdict before inclusion in your sending list. Haraka can log these, but verification logic must exclude them.
  • False positives from catch-alls are common—some servers accept all emails even when invalid. Combine Haraka’s real-time SMTP checks with bulk verification through a trusted service like MailTester’s bulk verification to validate at scale before sending.
  • When using Haraka’s SMTP interface, monitor connection timeouts and DNS lookups. If delays occur, consider switching to a dedicated email verification API—MailTester’s real-time API delivers 98.9% accuracy and integrates via standard HTTP requests.
  • Always verify the MX record and DNS configuration of domains you’re verifying. Use tools like MXToolbox to check if a domain’s mail servers are reachable and properly configured.

How does combining Haraka SMTP with MailTester improve deliverability?

By validating emails before sending through Haraka SMTP, you eliminate invalid, disposable, and catch-all addresses, reducing hard bounces and spam trap hits. A clean list lowers your bounce and complaint rates, which improves sender reputation and inbox placement—critical factors in long-term deliverability. This combination gives you real-time feedback and actionable data to keep your outbound verification reliable across campaigns.

Reducing bounce and spam risk with pre-send validation

When you send emails without verifying addresses first, you risk hitting spam traps, outdated domains, or invalid formats. Haraka SMTP handles the delivery layer, but it doesn't know which addresses are bad. That’s where MailTester comes in: by running list verification before your messages leave Haraka, you catch problems early. Common issues like typo-ridden addresses or role-based emails (e.g., [email protected]) are filtered out before they even reach the SMTP queue.

According to industry benchmarks, even a 0.5% bounce rate can trigger deliverability flags with ESPs like Gmail and Outlook. Every hard bounce degrades sender reputation. With MailTester, you identify and remove these addresses before sending—resulting in significantly lower bounce rates, reduced risk of blacklisting, and more consistent inbox delivery.

Maintaining sender reputation through clean, up-to-date data

Sender reputation isn’t static. Over time, email addresses become invalid, domains change, or users unsubscribe. Without ongoing validation, your list decays quickly. MailTester’s real-time API integration lets you check addresses on-demand. You can verify a single address before sending, or run bulk checks for entire campaigns.

This is where Haraka SMTP and MailTester work together seamlessly. You’re not just sending faster—you’re sending smarter. Each verified address has been tested for syntax, DNS existence, and deliverability, reducing the chance of triggering filtering rules. Tools like Spamhaus and MxToolbox monitor abuse patterns, and consistently clean lists help you avoid detection as a spamming source.

For ongoing campaigns, consider integrating MailTester’s real-time verification API into your workflow. It allows you to validate new signups instantly or verify dormant lists without manual effort. You can also test real inbox placement using MailTester’s inbox tester to preview how your messages land across Gmail, Outlook, and other major providers. Over time, consistent use of this approach builds stronger, more predictable deliverability.

What are the limitations of using Haraka SMTP for email verification?

Haraka is a solid SMTP server for sending and receiving mail, but it’s not designed to verify email addresses at scale. It only processes SMTP transactions—you’ll need to handle DNS checks, greylist detection, and bulk validation externally. Without built-in tools for catch-all detection or inbox placement testing, you’re left piecing together logic that’s better handled by purpose-built services.

What Haraka can’t do—by design

  • Haraka does not validate MX records or check DNS health—this means invalid domains or non-existent mail servers might pass silently.
  • It cannot detect transient SMTP errors like greylisting or message size rejections, so temporary bounces may be misclassified as hard failures.
  • Each verification adds delay to the SMTP handshake; performance depends entirely on network latency and your target server’s response speed, which varies widely.
  • There is no native support for bulk list preprocessing—running 10,000 addresses through Haraka one-by-one isn’t efficient or scalable.

When you need more than SMTP

SMTP-only checks lack context. A valid server may be rejecting mail due to sender reputation, rate limiting, or spam filtering—none of which Haraka can tell you. You need deeper insight: is the address deliverable? Is it likely to end up in spam? That’s where tools like MailTester come in.

For example, MailTester doesn’t just check if an SMTP session completes—it evaluates the full path to inbox placement. It flags risky roles, disposable domains, and catch-all accounts with high accuracy. And when you’re ready to send, you can use our real-time verification API to validate single addresses before sending.

Or if you’re cleaning a whole list, our bulk verification service gives you results fast, with a 98.9% accuracy rate—no need to build your own validation pipeline.

Haraka can be part of your outbound flow, but relying on it for verification alone leaves gaps. DNS, deliverability, and reputation are all outside its scope. Use it for transmission, not validation. For that, you want a system built to handle the full stack.

How does MailTester’s accuracy of 98.9% compare to other verification methods?

MailTester achieves 98.9% accuracy by combining real SMTP checks, DNS validation, and behavioral analysis—simulating a genuine email delivery attempt. Unlike tools that rely on pattern matching or syntax rules, it verifies addresses by testing actual mail server responses, reducing false positives on disposable or role-based addresses. This makes it more reliable than basic filters or third-party services that lack transparent, independent validation.

Real SMTP vs. Heuristic Rules

Many email verification tools use heuristics—checking for common patterns or known disposable domains—to guess validity. But these methods often flag legitimate addresses or miss problems that only show up during real delivery attempts. MailTester, instead, performs actual SMTP handshakes with the recipient’s mail server to confirm the mailbox exists and accepts messages.

For example, it checks DNS records like MX, SPF, and DKIM during the process, and observes server responses such as 250 (accepted) or 550 (rejected). This mirrors how actual senders behave, making the results both accurate and actionable. You’re not just checking if an email looks valid—you’re confirming it can receive mail.

Behavioral and Edge Case Handling

Role-based emails like admin@ or sales@ are frequently flagged as invalid by other services, even when they are real. MailTester reduces this risk by evaluating not just syntax, but context and behavior—such as whether the domain accepts mail to such addresses.

Similarly, disposable domains (like temp-mail.org) are often caught through real-time MX checks and correlation with known disposable domain lists. Tools that don’t use live SMTP checks may miss this distinction altogether, leading to higher false-positive rates.

While some competitors like ZeroBounce or NeverBounce claim high accuracy rates, their numbers aren’t independently verifiable or consistently published in public benchmarks. SMTP RFC 5321 defines the standard behavior MailTester follows, ensuring the check is protocol-compliant and reliable.

For teams testing bulk lists or needing inbox placement insights, MailTester’s approach ensures you’re not just cleaning a list—you’re validating deliverability in real conditions. Whether you’re using the bulk verification tool for large datasets or the real-time API for dynamic forms, the underlying accuracy comes from actual email delivery logic, not guesswork.

Conclusion: Haraka SMTP with MailTester is a reliable foundation for verified outbound email

Configuring Haraka SMTP with MailTester’s real-time API and logging provides a transparent, reliable system for validating email addresses before sending. This setup ensures you only communicate with active, deliverable inboxes.

By catching invalid addresses, catch-alls, and disposable domains early, you reduce bounce rates, avoid spam traps, and preserve sender reputation. These improvements directly impact inbox placement and long-term deliverability.

The integration is modular and scales across both real-time user signups and bulk email campaigns. It supports consistent hygiene without locking you into a rigid workflow. You can start testing immediately with 100 free verifications—credits never expire.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Can Haraka SMTP replace a dedicated email verification service?

No. Haraka handles SMTP transaction control and logging but does not validate email addresses on its own. It must be paired with a verification service like MailTester.

Does MailTester support bulk verification via API?

Yes. MailTester offers a real-time bulk verification API that allows testing large lists efficiently.

How accurate is MailTester’s email verification?

MailTester achieves 98.9% accuracy through real SMTP checks, DNS analysis, and behavioral data.

What is a catch-all email address, and why does it matter?

A catch-all address accepts all messages sent to any address on the domain, even non-existent ones. It reduces bounce rates but can increase spam risk.

Is Haraka compatible with cloud email services like SendGrid or Klaviyo?

Yes. Haraka can integrate with SendGrid, Klaviyo, and similar services by using their APIs for delivery after pre-validation.

How do I avoid rate limiting when calling the MailTester API from Haraka?

Implement request batching, respect API rate limits, and use cached results for known addresses to reduce redundant calls.

Can Haraka detect disposable email addresses?

Only indirectly. Haraka itself does not classify addresses. You must use an external service like MailTester to detect disposable domains.

What log files should I monitor when using Haraka for verification?

Monitor the main `mail.log`, `verify.log` (if custom), and `access.log` to track SMTP handshakes, verification results, and connection behavior.

How do I test my Haraka SMTP verification setup?

Send test messages to valid, invalid, and catch-all addresses using a script or tool like `telnet` or `swaks` to observe API calls and logging output.

Do MailTester credits expire?

No. Purchased credits never expire. You can use up to 100 free verifications to start testing your configuration.

What integrations does MailTester support?

MailTester integrates with Mailchimp, HubSpot, Klaviyo, and SendGrid for automated email list verification before campaigns.

Can I use Haraka for real-time inbox placement testing?

Haraka supports outbound SMTP delivery but not inbox placement testing. Use MailTester’s inbox-placement feature for that.