{
  "id": 11234136,
  "title": "I tested 500 emails against HIBP. My validator found a major flaw.",
  "url": "https://urgent.news/2026/10/01/i-tested-500-emails-against-hibp-my-validator-found-a-major-flaw",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T16:42:38.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/onizuka/i-tested-500-emails-against-hibp-my-validator-found-a-major-flaw-5dg4"
  },
  "original_language": "en",
  "account": "On September 30, 2026, an email validator that the reporter had recently developed encountered a significant flaw while testing. The validator was designed to check 500 emails, but upon testing with the address test@gmail.com, it returned a deliverability score of 75 and several Google MX records. However, a crucial component of the validation process, which checks if the email has been compromised in a data breach, failed. The breach_status returned a value of 'HIBP_API_KEY invalid or unauthorized', indicating that the API key used for the validation was invalid or unauthorized. Despite passing syntax checks, MX record lookups, and disposable email checks, the breach_check failed to execute. Consequently, the is_trusted_identity field was left as null, leading consumers to incorrectly assume that the email was trustworthy. The reporter's validator made a GET request to the API endpoint, which returned the JSON response with the breach_status_error, signaling a flaw in the email validation process.",
  "summary": "I tested 500 emails against HIBP. My validator found a major flaw. api, #security, #python, #webdev On September 30, 2026, at 17:08 UTC, I sent test@gmail.com to the email validator I had just shipped and got back a deliverability score of 75 , five Google MX records, and one line that wrecked the feature I’d spent a week building: \"breach_status_error\" : \"HIBP_API_KEY invalid or unauthorized\"…",
  "key_points": [
    "Reporter's validator tested 500 emails",
    "Found major flaw in breachcheck",
    "Returned null istrustedidentity"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}