I tested 500 emails against HIBP. My validator found a major flaw.
I tested 500 emails against HIBP. My validator found a major flaw. api, #security, #python, #webdev On September 30, 2026, at 17:08 UTC, I sent test@gmail.com to the email validator I had just shipped and got back a deliverability score of 75 , five Google MX records, and one line that wrecked the feature I’d spent a week building: "breach_status_error" : "HIBP_API_KEY invalid or unauthorized"…
On September 30, 2026, an email validator that the reporter had recently developed encountered a significant flaw while testing. The validator was designed to check 500 emails, but upon testing with the address test@gmail.com, it returned a deliverability score of 75 and several Google MX records. However, a crucial component of the validation process, which checks if the email has been compromised in a data breach, failed.
The breach_status returned a value of 'HIBP_API_KEY invalid or unauthorized', indicating that the API key used for the validation was invalid or unauthorized. Despite passing syntax checks, MX record lookups, and disposable email checks, the breach_check failed to execute. Consequently, the is_trusted_identity field was left as null, leading consumers to incorrectly assume that the email was trustworthy.
The reporter's validator made a GET request to the API endpoint, which returned the JSON response with the breach_status_error, signaling a flaw in the email validation process.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.