Shopify + VerifyAnyEmail
API recipeShopify checkout fields can’t be blocked by third-party apps on most plans, so the practical pattern is to verify after the fact and tag risky customers. All integrations call POST https://api.verifyany.email/v1/verify with an Authorization: Bearer <API_KEY> header and a JSON body of {"email":"..."}. The response includes result.status (deliverable / undeliverable / risky / unknown) and result.score.
Setup
- 1Trigger on new customer/order
Use Shopify Flow (or a customers/create webhook to your own endpoint) to fire when a customer is created.
- 2Verify the email
Call POST /v1/verify with X-VAE-Source: shopify for the customer’s email.
- 3Tag the customer
If the status is undeliverable or risky, add a customer tag (e.g. “email-risky”) so you can review or suppress them in marketing.
Handling the result
Every verification returns a result object with a status, a 0–100 score and a “did you mean” suggestion for typos. Branch on the status:
| status | Meaning | Recommended action |
|---|---|---|
| deliverable | Mailbox exists and accepts mail | Accept |
| undeliverable | Invalid syntax, no MX, or rejected mailbox | Block / reject |
| risky | Accepts but low quality (catch-all, role, disposable) | Allow with caution, or challenge |
| unknown | Couldn’t determine (greylist, timeout, blocked port) | Allow (fail-open) or retry later |
For sign-up and checkout forms, the safe default is to block only undeliverable so you never turn away a real customer, and to surface the suggestion (“did you mean gmail.com?”) inline to recover typos.
Security & reliability
- Keep your API key server-side. Never expose it in client-side JavaScript. In Shopify, store it in the integration’s credential/secret store, not in a shared script.
- Fail open. If the API errors or times out, let the address through rather than blocking a real user over a transient issue.
- Retry transient errors. Back off and retry on
429(rate limit) and5xx; don’t retry4xxvalidation errors. - Cache per address. One credit is spent per unique verification — cache results (e.g. 12–24h) so re-submits don’t re-charge.
- Tag the source. This recipe sends
X-VAE-Source: shopifyso your dashboard shows where verifications come from.
Troubleshooting
| Response | Cause & fix |
|---|---|
| 401 | Missing or wrong API key — check the Authorization header is Bearer YOUR_API_KEY. |
| 402 | Out of credits — top up in the dashboard. (The plugin fails open in this case.) |
| 429 | Rate limited — slow down or upgrade your plan; back off and retry. |
| No result written | Confirm you’re reading result.status, and that the request body is { "email": "…" } as JSON. |
This is an API recipe, not a one-click app — you wire it up once with the steps above. See the full API reference for every field and error code.