Shopify + VerifyAnyEmail

API recipe

Shopify checkout fields can’t be blocked by third-party apps on most plans, so the practical pattern is to verify after the fact and tag risky customers. All integrations call POST https://api.verifyany.email/v1/verify with an Authorization: Bearer <API_KEY> header and a JSON body of {"email":"..."}. The response includes result.status (deliverable / undeliverable / risky / unknown) and result.score.

Setup

  1. 1
    Trigger on new customer/order

    Use Shopify Flow (or a customers/create webhook to your own endpoint) to fire when a customer is created.

  2. 2
    Verify the email

    Call POST /v1/verify with X-VAE-Source: shopify for the customer’s email.

  3. 3
    Tag the customer

    If the status is undeliverable or risky, add a customer tag (e.g. “email-risky”) so you can review or suppress them in marketing.

Handling the result

Every verification returns a result object with a status, a 0–100 score and a “did you mean” suggestion for typos. Branch on the status:

statusMeaningRecommended action
deliverableMailbox exists and accepts mailAccept
undeliverableInvalid syntax, no MX, or rejected mailboxBlock / reject
riskyAccepts but low quality (catch-all, role, disposable)Allow with caution, or challenge
unknownCouldn’t determine (greylist, timeout, blocked port)Allow (fail-open) or retry later

For sign-up and checkout forms, the safe default is to block only undeliverable so you never turn away a real customer, and to surface the suggestion (“did you mean gmail.com?”) inline to recover typos.

Security & reliability

  • Keep your API key server-side. Never expose it in client-side JavaScript. In Shopify, store it in the integration’s credential/secret store, not in a shared script.
  • Fail open. If the API errors or times out, let the address through rather than blocking a real user over a transient issue.
  • Retry transient errors. Back off and retry on 429 (rate limit) and 5xx; don’t retry 4xx validation errors.
  • Cache per address. One credit is spent per unique verification — cache results (e.g. 12–24h) so re-submits don’t re-charge.
  • Tag the source. This recipe sends X-VAE-Source: shopify so your dashboard shows where verifications come from.

Troubleshooting

ResponseCause & fix
401Missing or wrong API key — check the Authorization header is Bearer YOUR_API_KEY.
402Out of credits — top up in the dashboard. (The plugin fails open in this case.)
429Rate limited — slow down or upgrade your plan; back off and retry.
No result writtenConfirm you’re reading result.status, and that the request body is { "email": "…" } as JSON.

This is an API recipe, not a one-click app — you wire it up once with the steps above. See the full API reference for every field and error code.

You’ll need a VerifyAnyEmail API key — create a free account and find it in the dashboard under API keys. New accounts include free verification credits.