Doing manual NVT to the users' mailservers' smtp-port won't help you much if it is a hardened SMTP-gateway.
It will lie to you and happily accept your email transmission, even if the email-address is invalid.
This is by design, to spoof all would-be spammers, so they can't figure out legal email-addresses.
For the same reason the old SMTP VRFY-method will most certainly be switched off on live mailservers.
VRFY would've solved your problem, though, it was designed just for this purpose.
Or, if you have LDAP-access to his local directory, you may be able to look up his address that way if you know his name.
But why not just call the person and ask him?
Or just try and email him?
What's your motive for being stealthy?