Email Deliverability
August 12, 2026

Verifications.io: what happened, why it matters, and what to use now

Verifications.io has been defunct since a 2019 breach that exposed 763 million records. Here's what happened, why it matters, and the best B2B alternatives.

Email Domain Sender Reputation Cover
Get a Free 14-Day Trial
Identify valid & invalid contacts on enterprise and catch-all servers with precision on up to 1,000 records.
Try Free Today

Table of Contents

If you are looking up Verifications.io, the first thing to know is that it no longer exists. The email verification company has been defunct since March 2019, when a single data breach ended the business within weeks.

Most people who search the name now arrive from a Have I Been Pwned notification, a Mozilla Monitor alert, or a procurement question about a vendor that suddenly vanished. The breach behind it was one of the largest exposures of personal data on record, and its lesson outlived the company: a verification vendor's security posture is not a detail.

This article covers all of it: what Verifications.io was, what happened in the breach, what its collapse taught the email verification industry, and which vendors B2B teams should evaluate now.

TL;DR: Verifications.io was a popular email validation service that permanently collapsed in March 2019 after leaving an unencrypted, password-less database exposed to the public internet, compromising the personal information of over 763 million users. While the catastrophic breach did not expose passwords, it serves as a stark procurement warning for modern B2B revenue teams: treating list-cleaning software as a low-stakes, tactical purchase can expose your organization to massive compliance and operational liabilities. Because legacy verifiers often stockpile unnecessary CRM data indefinitely and fail to conclusively resolve strict enterprise catch-all domains, relying on them creates hidden risks for both your data security and your deliverability. To safely execute outbound campaigns, RevOps leaders must graduate to a specialized, SOC 2-compliant deliverability API like Allegrow, which pairs conclusive B2B catch-all resolution with strict, automated data deletion policies to protect both your sender reputation and your corporate infrastructure.

What was Verifications.io?

Verifications.io was an email address validation service that operated until February 2019. The model was simple: marketing teams and email senders uploaded their contact lists, and Verifications.io returned a validity result for each address.

Its footprint was a little murky. The company listed itself as Estonian, headquartered in Tallinn, though press filings pointed to operations in Boca Raton, Florida, and its customers were mainly email marketing platforms.

How it verified is worth pausing on, because it helps explain what came later. The firm checked each address by sending it a message and treating it as valid if the message did not bounce. That process touched the recipient's server directly, and Verifications.io stored the results, which is part of why it ended up holding so much data.

The company did not survive the breach. The website went offline during the disclosure, and Verifications.io has been defunct since March 2019. An archived copy of the old site is still viewable, but the service itself is gone.

The Verifications.io data breach: what happened

The breach is the whole story, so here it is in order.

Discovery and disclosure

On February 25, 2019, security researchers Bob Diachenko and Vinny Troia found a MongoDB database belonging to Verifications.io sitting on the public internet with no password and no authentication of any kind. Diachenko published the findings on Security Discovery days later, and Have I Been Pwned added the breach to its database on March 9, 2019.

The scale of the exposure

The numbers are the reason this breach is still talked about.

The largest single database held 809 million records, of which 763 million were unique email addresses, and the original Security Discovery disclosure traced more than 2 billion records across three further databases. At the time, several outlets reported it as the largest exposure of US citizens' personal information on record.

What data was compromised

It was not just email addresses. Each record could carry a detailed personal profile.

Confirmed by Have I Been Pwned and Mozilla Monitor, the exposed fields included:

  • Email addresses
  • Names
  • Phone numbers
  • IP addresses
  • Physical addresses
  • Dates of birth
  • Genders
  • Geographic locations
  • Job titles
  • Employers

One important point: no passwords were exposed. This breach was personal information, not login credentials.

How the breach happened

The cause was mundane, which is the unsettling part.

A MongoDB database was left facing the public internet with no password and no two-factor protection, so anyone who knew the IP address could read it directly. This is one of the most common misconfigurations in data handling, the kind procurement teams now ask about specifically because it has happened so many times.

No clever attack was needed. It took someone scanning public IP ranges for unsecured databases, which is exactly what security researchers do as routine work.

The aftermath

Verifications.io pulled its website offline during the disclosure. The company's defence was that the data had been gathered from public sources, which did not explain why so much of it sat in a single unsecured database.

Then the business simply stopped.

Within weeks, industry reporting noted that Verifications.io seemed to be out of business following the breach, and it has been listed as defunct since March 2019. The breach data, though, did not disappear with the company. People affected are still being notified today through Have I Been Pwned and Mozilla Monitor.

If you were affected by the Verifications.io breach

If a breach-notification service sent you here, here is the practical version, kept short.

What the breach exposed about you

Your email address was exposed, along with whatever else Verifications.io held on you. That could include your name, phone number, IP address, physical address, date of birth, employer, and job title.

What was not exposed: passwords. If you have seen a generic "change your password" prompt, treat it as good hygiene rather than something specific to this breach.

Practical protection actions

A handful of habits cover most of the risk:

  • Use a unique, strong password on every account, kept in a password manager rather than reused.
  • Turn on two-factor authentication wherever it is offered.
  • Be sparing with personal details like your phone number, address, or date of birth on new signup forms unless they are genuinely required.
  • Consider an email aliasing service such as Firefox Relay, SimpleLogin, or Apple's Hide My Email for accounts where your real address is not essential.
  • Keep your devices, browsers, and software updated, since most exploitation of breach data targets unpatched systems.

Why the Verifications.io breach still matters for B2B teams in 2026

If you are not a breach-notification visitor but a buyer evaluating verification vendors, this is where the story turns into a procurement lesson. Three of them, really.

A reminder that vendor security failure can collapse a business overnight

Verifications.io was a working company on February 24, 2019. Within weeks it was gone.

Customers were left with no service, no support, and no recourse on their contracts. For any B2B team that wires email verification into outbound, sales, and marketing workflows, that is a concrete operational risk rather than a hypothetical: a vendor can vanish because of a security incident, taking your pipeline tooling with it.

A reminder that data accumulation is itself a risk

The most striking part of the breach was not the misconfiguration. It was how much data was sitting there to expose.

A verification service does not need to keep 800 million records of customer-submitted contacts. Verification is a query, not a permanent store. When a vendor accumulates and retains data well beyond what its core service requires, the blast radius of any breach grows in direct proportion.

That is why "how do you handle and retain customer data" is now a first-order procurement question, not a footnote.

A reminder that procurement questions matter even for low-stakes categories

Email verification is usually treated as a tactical purchase, a credit-card line item rather than a reviewed contract. The Verifications.io breach is the argument against that habit. A tool that looks low-stakes can still hold enormous volumes of personal data, and the scrutiny it deserves is the same you would apply to any vendor touching customer contact information at scale.

What B2B buyers should ask any email verification vendor today

By now the questions almost write themselves. The Verifications.io collapse is a procurement checklist in disguise, so here it is made explicit, in the order worth asking.

Security certifications and posture

Start with the credentials, because they are the easiest thing for a serious vendor to produce and the hardest for a careless one to fake.

Ask whether the vendor holds SOC 2 (Type 1 or, better, Type 2) and ISO 27001, both standard for any B2B vendor handling personal data. Ask whether they publish a trust centre or security overview, since transparency about controls is itself a signal. And ask plainly about breach history and how any past incidents were handled.

Data handling and retention

Then ask what happens to the lists you upload. How long are customer-submitted contacts retained, are they hashed or anonymised at rest, and where are they hosted, in the EU, the US, or multiple regions? GDPR posture matters the moment you touch a European contact, and so does whether verification results are deleted automatically and whether you can trigger deletion yourself.

This is the exact territory Verifications.io got catastrophically wrong.

Encryption and infrastructure

The basics here are not optional. Data should be encrypted both on the move (in transit, via TLS) and while stored (at rest, via AES or equivalent), on a documented cloud like AWS, GCP, or Azure rather than an opaque self-hosted box, with customer-managed keys available for enterprise contracts.

None of this is exotic. It is the table stakes that an open MongoDB instance failed entirely.

Operational transparency

Ask how the vendor behaves when something breaks. Is there a public status page for uptime and incidents? Are API rate limits and reliability commitments documented rather than discovered the hard way, and does the vendor commit to a breach-notification timeline? Companies confident in their operations publish these; the ones that hide them are a quieter version of the same risk.

B2B verification capability

Security is necessary but not sufficient. The tool still has to verify well.

Does it resolve catch-all domains into conclusive results rather than returning everything as "unknown"? Does it handle enterprise contacts on Microsoft 365 and Google Workspace tenants? Does it return reason codes and risk classifications, or only a flat valid-or-invalid output? And is there a published accuracy rate, ideally benchmarked independently rather than self-reported?

This is where a verifier earns its keep, and where the cheapest options quietly fall short.

Criterion What good looks like Why it matters Verifications.io
Security posture SOC 2 Type 2, ISO 27001, public trust centre Independent proof of controls No attestation; open database
Data handling and retention Short documented retention, hashed at rest, deletion you control Limits the blast radius of any breach Retained 800M+ records indefinitely
Encryption and infrastructure TLS in transit, AES at rest, reputable cloud Basic protection of stored data Unsecured MongoDB, no password
Operational transparency Status page, documented SLAs, breach-notification commitment Predictability when things break Went dark, no recourse for customers
B2B verification capability Conclusive catch-all results, enterprise coverage, benchmarked accuracy Determines whether the data is usable at all Bounce-only method, no catch-all resolution

What email verification vendors should B2B teams evaluate now?

With the criteria in hand, here are the vendors worth a serious look, starting with the one built for exactly the B2B problem Verifications.io served, but with the verification quality and security posture that era lacked.

Allegrow: the right choice for serious B2B email verification

Allegrow is purpose-built for B2B outbound, where the verification problem is defined by the hard cases: catch-all domains, enterprise contacts behind secure email gateways, and sender reputation that punishes a single bad send. It runs the deeper checks that turn "unknown" and "catch-all" into actionable valid-or-invalid results for individual enterprise mailboxes through its B2B email verification, the exact job Verifications.io set out to do, done properly.

Those hard cases are the contacts that matter most, the VPs and decision-makers cheap verifiers return as unknown, and Allegrow resolves them with conclusive catch-all verification and a low false-positive rate.

On the dimension this whole article is about, security, Allegrow answers every question the framework above asks. It is SOC 2 Type 1 compliant, hosts and stores all data in the EU on AWS (Ireland), and encrypts it with TLS in transit and AES-256 at rest across every database, backup, and snapshot. Customer data is kept only for the life of your licence, then deleted on request or automatically within six months of the licence ending, with access, export, and deletion rights set out in its data processing agreement.

Pros:

  • Conclusive catch-all and enterprise-mailbox resolution where others return "unknown"
  • Low false-positive rate that protects sender reputation
  • High-scale API, plus a supporting deliverability layer (Safety Net, hourly SPF/DKIM/DMARC monitoring, inbox-placement monitoring)
  • SOC 2 Type 1, EU data residency (AWS Ireland), TLS and AES-256 encryption, and documented deletion within six months of licence end

Cons:

  • Specialised for B2B, so it is not aimed at high-volume consumer or B2C list cleaning
  • Focused on verification and deliverability rather than a broad all-in-one marketing suite

Allegrow is the pick when result quality, catch-all resolution, and a modern security posture all have to be true at once, which is the difference between clean sending and outbound risk you cannot see.

NeverBounce

NeverBounce is one of the most established names in verification, widely used and widely reviewed. Its catch-all detection is genuinely strong, but it’s only detection, not resolution; its spam-trap data is solid, and its API and uptime record are dependable.

It is a sensible mid-market choice for marketing and B2C senders who value broad integrations and reliable bulk cleaning. Its weaker spot, for this audience, is the B2B edge: catch-all-heavy and enterprise-dominated lists, where resolving individual mailboxes matters more than bulk throughput.

Pros:

  • Strong catch-all detection and spam-trap data
  • Dependable API, good uptime, broad integrations

Cons:

  • Less specialised for enterprise B2B contacts
  • Catch-all-heavy lists still return "unknown" more often than a B2B-focused tool

Read our full NeverBounce review for the deep dive.

ZeroBounce

ZeroBounce is a feature-rich verifier with published accuracy claims, clear catch-all flagging (not resolution), and licensed spam-trap data. It layers on extras most rivals skip, like abuse and toxic-email detection, alongside broad integrations and a solid regulatory posture.

That makes it a good fit for marketing and lifecycle teams that want richer output classification across a mixed list. For B2B outbound specifically, the gap shows on enterprise mailboxes, where accuracy on real business contacts trails a tool built for that case.

Pros:

  • Rich output classification (abuse, toxic, catch-all flags)
  • Published accuracy claims and broad integrations

Cons:

  • Premium positioning relative to mid-market rivals
  • Enterprise-mailbox accuracy trails specialised B2B verification

Read our full ZeroBounce review for the full breakdown.

Kickbox

Kickbox is the developer-friendly option, with strong catch-all detection (not resolution), spam-trap data, clean API documentation, and integrations with the major ESPs. It is well-built and easy to wire into a product.

That makes it a natural pick for engineering teams embedding verification into their own workflows. The honest limitation for B2B outbound is enterprise-contact-heavy lists, where independent benchmarks have shown accuracy variance on real business emails.

Pros:

  • Excellent, developer-friendly API and documentation
  • Strong ESP integrations

Cons:

  • Accuracy variance on catch-alls and enterprise B2B contacts in independent tests
  • Less tailored to high-stakes B2B outbound

Read our full Kickbox review for the details.

Bouncer

Bouncer stands out on exactly the dimension this article is about: data handling. It publishes the procurement-grade specifics Verifications.io never did, including EU hosting, a clear GDPR posture, automatic deletion of verification results, and AWS infrastructure, alongside published accuracy claims.

With a broader deliverability suite around the verifier, it suits marketing teams that want verification bundled with adjacent tooling. Where Allegrow pulls ahead is the specialised B2B focus, resolving catch-all and enterprise mailboxes with a conclusiveness a generalist suite does not target.

Pros:

  • Strong security and data-handling transparency (EU hosting, GDPR, auto-deletion, AWS)
  • Published accuracy claims and a broad deliverability suite

Cons:

  • Generalist focus rather than specialised B2B verification
  • Catch-all and enterprise resolution less conclusive than a B2B-built tool

Read our full Bouncer review for the complete picture.

Which verification vendor is right for your team?

Stripping the marketing away, the right choice comes down to three honest questions about your own situation.

What is your list composition?

This is the question that decides most of it.

If your list is mostly consumer addresses, on Gmail, Yahoo, or Outlook.com, the mid-market verifiers (Bouncer, ZeroBounce, NeverBounce) perform perfectly well, since those domains are straightforward to check. If it is mostly enterprise B2B, contacts on Microsoft 365 and Google Workspace tenants and named-brand corporate domains, you need specialised B2B verification with conclusive catch-all resolution, which is exactly what Allegrow is built for.

Mixed lists split the difference: run the enterprise portion through a B2B-specialised tool, since the consumer addresses are simple no matter what you use.

What are your procurement requirements?

If you sit inside formal enterprise procurement, with SOC 2 attestation, GDPR documentation, and operational transparency on the checklist, then every vendor on your shortlist should be able to hand over formal documentation, and the ones that cannot are answering the question for you. Allegrow's position here is direct: verification quality plus a modern, documented security posture.

And if you have no formal review process at all? That is precisely where Verifications.io's customers got burned. Even informal procurement should still ask the basic questions from the framework above.

Why does result quality matter more than the sticker price?

Because the price of getting it wrong dwarfs the price of the tool.

A false positive on a catch-all enterprise mailbox becomes a hard bounce, and hard bounces feed the bounce-rate thresholds Gmail and Microsoft now enforce. A spike of them, from stale or trap addresses a shallow verifier missed, damages sender reputation across all your sending, not just the bad segment.

For B2B outbound where a single inbox carries real pipeline value, one reputation incident costs tens of thousands in lost pipeline, not a handful of verification credits. Against that maths, price differences between verifiers are noise. Result quality is the number that matters.

Conclusion

Verifications.io was a working email verification vendor until February 2019. A single MongoDB instance left open to the internet exposed 763 million unique addresses, the company collapsed within weeks, and the breach data still circulates through Have I Been Pwned and Mozilla Monitor today.

The lessons outlived the company. Vendor security posture is not optional. Data retained beyond what the service needs is itself a liability. And procurement scrutiny matters even for categories that feel tactical, because a modern verifier should be able to answer every question in the framework above with documented specifics, not reassurances.

For B2B teams choosing a verification vendor now, especially those whose lists are dominated by enterprise mailboxes, where catch-all resolution decides result quality and sender reputation rides on the accuracy of every send, Allegrow is the right choice. Specialised B2B verification and a documented, modern security posture are exactly what serious procurement should require, and Allegrow has both.

See it on your own data. Start a 14-day free trial, verify your first 1,000 contacts free, and watch Allegrow return conclusive results on the catch-all and enterprise contacts that shallow verifiers quietly miss.

Frequently asked questions

Is Verifications.io still operating?

No. Verifications.io has been defunct since March 2019, following the data breach disclosed that February. The website went offline during the disclosure and never returned, and Wikipedia and industry sources list the company as out of business.

How big was the Verifications.io data breach?

Very large. The biggest single database held 809 million records, of which 763 million were unique email addresses, and across all four databases found in the investigation the total passed 2 billion records. At the time it was reported as the largest exposure of US citizens' personal information on record.

What data was exposed in the Verifications.io breach?

Far more than email addresses. The records included names, phone numbers, IP addresses, physical addresses, dates of birth, genders, geographic locations, job titles, and employers, alongside the email addresses themselves. No passwords were exposed; this breach was personal information, not login credentials.

How did the Verifications.io breach happen?

Through a basic misconfiguration, not a sophisticated attack. A MongoDB database was left facing the public internet with no password and no two-factor protection, and security researchers Bob Diachenko and Vinny Troia found it through routine scanning. Anyone who knew the IP address could have read it.

Was Verifications.io legitimate?

It operated as a real email verification service for marketing platforms until the breach. The company claimed the exposed data had been gathered from public sources, though the sheer volume and depth of personal detail raised serious questions. The point is now moot: the business collapsed in March 2019.

What should I do if my data was in the Verifications.io breach?

No password action is needed, because no passwords were exposed. Treat it as background risk: use unique, strong passwords with a password manager, turn on two-factor authentication, consider an email aliasing service for non-essential signups, and be cautious about handing personal details to new services.

What is the best alternative to Verifications.io for B2B email verification?

For B2B specifically, Allegrow. It is purpose-built for the hard cases Verifications.io served, conclusive catch-all resolution, enterprise contact handling, a high-scale API, and low false-positive rates, paired with a documented modern security posture (SOC 2 Type 1, EU hosting, AES-256 encryption). For consumer-heavy lists, mid-market verifiers like Bouncer or NeverBounce also work well.

How do I evaluate an email verification vendor after Verifications.io?

Ask two sets of questions. First, on security: SOC 2 or ISO 27001, data retention and deletion, encryption, hosting and GDPR posture, and incident-notification commitments. Then, on capability: catch-all resolution, enterprise contact handling, accuracy benchmarks, and API reliability. A vendor that cannot document both should not pass review.

What other email vendors have suffered similar breaches?

Verifications.io is the most cited because of its scale, but it is not unique; the broader email and contact-data category has seen several incidents over the years. The lesson is not about one vendor. The procurement framework above applies to any vendor handling email and contact data at volume.

Lucas Dezan
Lucas Dezan
Demand Gen Manager

As a demand generation manager at Allegrow, Lucas brings a fresh perspective to email deliverability challenges. His digital marketing background enables him to communicate complex technical concepts in accessible ways for B2B teams. Lucas focuses on educating businesses about crucial factors affecting inbox placement while maximizing campaign effectiveness.

Ready to optimize email outreach?

Book a free 15-minute audit with an email deliverability expert.
Book audit call