Candidate discovery
Start with a company, domain, and role rather than a blind list request. The agent can assemble possible business-email patterns, attach the public context that informed them, and keep the distinction between found and inferred addresses. A candidate remains unverified until subsequent checks are complete.
Syntax and domain inspection
Normalize casing and structure, identify malformed addresses, inspect domain resolution, and record mail-exchange availability. These checks remove obvious errors but cannot establish that a particular person controls a mailbox. DNS state also changes, so the retrieval time belongs with the result.
Mailbox-risk assessment
Provider-dependent checks may classify disposable domains, role accounts, catch-all behavior, or mailbox response. Rate limits, greylisting, anti-abuse systems, and privacy-preserving mail servers can create ambiguous responses. The correct state is review or unknown when evidence is not conclusive.
Human decision gate
Apply account fit, role relevance, suppression, consent basis, regional requirements, and channel policy before approving outreach. A technical verification result does not establish lawful use and does not guarantee inbox placement. The operator retains the decision and its audit trail.