The SMTP way of checking if an email exists is on the wrong side of CANSPAM, beginning the sending process to check an address is specifically addressed. And this assumes you didn't systematically "guess" the address.
Interesting. So if they are doing this are they violating CANSPAM? EDIT: Looks like they are indeed doing the SMTP method: https://github.com/reacherhq/check-if-email-exists/blob/a052... I also found a similar, much bigger service here that appears to have been around for a while: https://emailverification.whoisxmlapi.com/api
There are products that definitely make it past the seed round and sometimes even as public companies before enforcement notice that their entire product runs afoul the law.