Validator accuracy pass
End-to-end audit of the eight-validator pipeline ahead of public launch. Four real bugs caught and fixed: (1) null-MX domains (RFC 7505 — example.com and any corporate apex that explicitly disables mail) were being marked deliverable; now correctly flagged as unreachable. (2) Typo suggestions fired against short legitimate domains — x.com → me.com, b.com → me.com, etc — because the Damerau-Levenshtein budget wasn't length-aware. Short domains now require distance 1, longer ones still allow 2. (3) The .zip and .mov TLDs (Google 2023 release, immediate phishing favourites) were missing from the risky-TLD set; added. (4) Homograph attacks (Cyrillic 'аpple.com', Greek 'αpple.com') were slipping through as deliverable. Non-ASCII domain detection added — real IDNs use Punycode and remain accepted.