AGENT 05 / 07

Cleaning

The verification worker checks email, phone, profile, and extracted data before it reaches a governed action — keeping downstream work grounded in records that actually exist.

cleaningfathom worker

cleaning · autonomous

01What it does

Verification before a governed action

verify_email01

The email gauntlet

RFC 5322 syntax, MX lookup over DNS-over-HTTPS, disposable-domain and role-based filters, optional SMTP RCPT probe — every signal folded into one deliverability confidence score.

verify_phone02

Numbers that dial

libphonenumber metadata turns "+7 (495) 710-75-80" into +74957107580 — E.164, country RU, and line type when metadata supports it.

verify_social_profile03

Profiles that exist

GitHub verified through the public API; every other platform by page fetch with soft-404 content detection. Bot walls (401/403/429) are reported honestly, never guessed away.

suggest_emails04

Fill the gaps

Up to 9 candidates from name permutations (first.last, flast, last.first…), ranked by the corporate pattern inferred from known colleague addresses — each scored by the same verification pipeline.

dedup & merge05

One list, no twins

Duplicates are found on normalized keys — lower-cased email, digits-only phone — then merged atomically: blanks filled, socials/tags/notes moved over, the duplicate row deleted.

side-effect safety06

Signals before action

Role addresses and disposable inboxes are flagged, and SMTP outcomes are kept as explicit evidence. Operators can review confidence before a worker performs a side effect.

02How it works

Six gates between input and action

1

Candidates

The raw list arrives from the contact DB: emails, phones, social URLs, each with its extraction confidence.

2

Email checks

Syntax → MX via DoH (Google, Cloudflare fallback) → A-record fallback → disposable & role-based filters.

3

SMTP probe

Optional port-25 dialogue: banner, HELO, MAIL FROM, RCPT TO — never sends DATA. Accepted, rejected or inconclusive.

4

Phone checks

Parsed against region metadata, validated for length and type, normalized to E.164, classified mobile vs landline.

5

Social checks

Profile fetched with a browser UA; soft-404 content scans decide existence; blocked checks surface as notes.

6

Rank & review

Pattern-matched candidates receive confidence signals; blocked and inconclusive records remain visible for operator review before any governed action.

03Under the hood

Thresholds, filters and formulas

Confidence formulainvalid syntax 0.0 · base 0.5 + 0.4 live domain · capped 0.9 without SMTP · ≥ 0.95 SMTP-accepted · ≤ 0.2 SMTP-rejected · disposable −0.3
Syntax rulesRFC 5322 subset: local part ≤ 64 chars, domain ≤ 253, no leading/trailing/consecutive dots, non-numeric TLD
MX lookupDNS-over-HTTPS: dns.google → cloudflare-dns.com fallback, 5 s timeout · RFC 5321 A-record fallback · RFC 7505 null MX means "accepts no mail"
Disposable domainsConfigured disposable-domain rules are matched exactly or as wildcard subdomains; blocked or unknown checks remain visible
Role-based local partsDepartment addresses such as info@, support@, admin@, sales@, and hr@ are flagged as non-personal records
SMTP probeconnect timeout 10 s, per-read 5 s · 250/251 = accepted, 5xx = rejected, 4xx = inconclusive · probe bails before DATA — no mail is ever sent
E.164 phones"+7 (495) 710-75-80" → +74957107580 · RU · landline · 17 number types · default_country resolves national formats
suggest_emails9 patterns: first.last, firstlast, f.last, first.l, last.first, first_last, f_last, flast, first-last · pattern match +0.15, capped 0.95
Social verificationsoft-404 content scan on HTTP 200 · 404/410 dead · 401/403/429 reported as bot-blocked · og:title name + follower count when public
Dedup & mergenormalized email (trim + lowercase) and digits-only phone keys · atomic merge fills blanks and moves socials/tags/notes

03.5Results

What cleaning buys you

0.95
maximum confidence assigned to an SMTP-confirmed mailbox
9
candidate patterns available to suggest_emails
E.164
normalized phone representation for downstream tools
Review
blocked, inconclusive, and role-based signals stay visible

04Tools

The verification toolbox

verify_emailverify_phoneverify_social_profilesuggest_emails

Feeds downstream workers

Verified inputs keep actions safe

Downstream workers receive only validated values and explicit confidence signals. Bad addresses, malformed records, and disposable domains stay out of governed actions, whether the next step is outreach, a report, or an update to another system.

verify_email("[email protected]")
→ syntax: valid · domain: exists
→ disposable: no · role-based: no
→ confidence: 0.90   # LIKELY VALID

verify_phone("+7 (495) 710-75-80")
→ +74957107580 · RU · landline · valid

# reviewable survivors reach the next worker —
# governed actions use recorded evidence

Clear signals make governed actions safer