A quick follow-up for those in the infra space: I'm seeing a weird discrepancy where 'Verified' status from most APIs seems to rely on the RCPT TO command.
However, I've noticed more enterprise gateways are now returning a 250 OK for every address at a domain to thwart enumeration, but then silently dropping the packet at the transport layer if there's no sender history.
If the SMTP handshake is now a 'liar,' is there any technical signal left that actually confirms a mailbox is reachable, or are we effectively flying blind?
No comments yet.