How to tell if an email is a business email
How to tell if an email is a business email: read the domain, compare it with free provider lists, look up MX records and rule out disposable addresses.
To tell if an email is a business email, look at the domain after the @. If it belongs to a shared provider such as gmail.com, outlook.com or yahoo.com, the address is personal. If it is the organization’s own domain, such as acme.io, and that domain is set up to receive mail, it is a business email. The six steps below show how to confirm that by hand, how to rule out disposable and relay addresses, and how to automate the whole check.
If you want the definition first, start with What is a business email?
Step 1: Read the domain, not the name
The part before the @ tells you very little. ceo@ can be anyone, and jane.doe@ says nothing about where Jane works. The domain is what you check.
Before you judge it, clean it up:
- Lowercase and trim it.
Jane@ACME.ioandjane@acme.ioare the same address. - Reduce it to the registrable domain.
jane@mail.eu.acme.co.ukbelongs toacme.co.uk. The Public Suffix List tells you where the registrable part starts. - Look for typos.
gmial.com,outlok.comandyaho.comare mistyped personal addresses, not company domains. Ask the user to fix them. - Look for lookalikes. A domain that imitates a well-known provider with look-alike characters often shows up in punycode (
xn--…). - Ignore
+tags.jane+news@acme.iois stilljane@acme.io.
| Address | Domain to check | First read |
|---|---|---|
jane@acme.io |
acme.io |
Custom domain, probably business |
jane@gmail.com |
gmail.com |
Shared provider, personal |
j.doe@mail.acme.co.uk |
acme.co.uk |
Custom domain, probably business |
jane@gmial.com |
gmial.com |
Typo of gmail.com, ask the user |
Step 2: Compare it with free email provider lists
A shared-domain provider gives addresses on one domain to many unrelated people. Gmail, Outlook.com (outlook.com, hotmail.com, live.com), Yahoo, iCloud and AOL are the obvious ones. Regional webmail such as web.de, yandex.ru, qq.com or naver.com, and ISP mailboxes such as comcast.net or btinternet.com, count too.
“Free” really means “shared”. Paid consumer services count as well: an @icloud.com or @proton.me address is personal even if its owner pays for it.
This is the step people skip, and the one that catches the most. There are thousands of shared domains, and a regional provider looks just like a small company if you have never heard of it. Free email providers walks through them by region. You can download our free email provider list or check a single address with the free email provider checker.
When you match against a list, compare the whole domain and its parent domains, never a substring. A rule like “contains mail” would flag mailchimp.com, which is a company.
Step 3: Look up the MX records
MX records name the servers that receive mail for a domain. They are public, and they show who actually runs the mail. On macOS or Linux:
dig +short MX acme.io
For a company on Google Workspace, the answer looks something like this:
1 smtp.google.com.
The host names follow recognizable patterns:
| MX host | Mail is hosted by | Suggests |
|---|---|---|
smtp.google.com, aspmx.l.google.com |
Google Workspace | Business |
gmail-smtp-in.l.google.com |
Consumer Gmail | Personal |
<domain>.mail.protection.outlook.com |
Microsoft 365 (Exchange Online) | Business |
*.olc.protection.outlook.com |
Outlook.com, Hotmail | Personal |
*.yahoodns.net |
Yahoo Mail | Personal |
*.pphosted.com, *.mimecast.com |
Proofpoint, Mimecast gateways | Business, strong signal |
mx.zoho.com, mail.protonmail.ch |
Zoho Mail, Proton | Business, or one person’s own domain |
No MX, or a null MX (0 .) |
Nobody | Can’t receive mail |
A null MX is an explicit “this domain accepts no mail” (RFC 7505). Any address on it is undeliverable.
MX has blind spots. A security gateway hides the suite behind it. A forwarding service sends mail somewhere else, possibly to Gmail. A small regional webmail provider on its own servers looks exactly like a company. That is why the list check comes first. Detecting business emails with MX records goes deeper, and the MX lookup tool names the provider for you.
Step 4: Look for signs of a real organization
A custom domain with working MX is a good start. Anyone can register a domain for a few dollars, though, so for anything that matters, gather a little more evidence:
- The website. Does the domain host a real site that matches the company the person claims? A parking page or a “domain for sale” page is a warning sign.
- The domain’s age. A domain registered last week isn’t automatically bad. A brand-new domain with no website, signing up for a free trial, is a pattern worth noticing. Registration dates are public through RDAP or WHOIS.
- SPF and DMARC. Organizations that send mail publish SPF, and most publish DMARC. A
p=quarantineorp=rejectpolicy means someone actively manages the domain’s mail. The SPF & DMARC checker shows both. - Verification records. TXT records such as
MS=ms…, or verification tokens for business software like Atlassian, Slack or DocuSign, show the domain is used to run a business.
None of these proves a company exists. Together they raise or lower your confidence. A freelancer on jane-consulting.com still has a business address: it’s her own domain, and that is what the rule asks.
Step 5: Check for Google Workspace or Microsoft 365
Knowing which suite a company runs tells you whether Google or Microsoft integrations can work, and helps route leads. The evidence is public:
Google Workspace
- MX on
smtp.google.comoraspmx.l.google.com(consumer Gmail usesgmail-smtp-in.l.google.com). - A DKIM key at
google._domainkey.<domain>.googleis the default selector, and it reveals Workspace even behind a Proofpoint or Mimecast gateway. - SPF containing
include:_spf.google.com.
Microsoft 365
- MX on
<domain>.mail.protection.outlook.com. Consumer Outlook.com uses*.olc.protection.outlook.com. - Microsoft’s public OpenID discovery document,
https://login.microsoftonline.com/<domain>/v2.0/.well-known/openid-configuration, returns a tenant ID for domains that belong to a Microsoft Entra ID tenant. - A
MS=ms…TXT record or SPF containinginclude:spf.protection.outlook.com.
Both can be true at once: some companies sign in with Microsoft and keep mail on Google, or are mid-migration. The Google Workspace checker and Microsoft tenant lookup run these checks for a domain. How to find out which email provider a company uses covers Zoho, Proton, self-hosted mail and gateways too.
Step 6: Rule out disposable, relay and role addresses
Three kinds of address need their own check, because they fail the “is it a company?” question in different ways.
- Disposable addresses come from throwaway inbox services that last minutes or hours. There are tens of thousands of these domains and new ones appear daily, often on the same mail servers as older ones. Use the disposable email checker or the disposable domains list. The disposable email problem explains why they matter.
- Relay addresses forward to a hidden real inbox:
privaterelay.appleid.com(Apple Hide My Email),mozmail.com(Firefox Relay),duck.com(DuckDuckGo) and SimpleLogin. A real person is behind them, but the domain isn’t a company’s and you can’t see the employer. Email verification vs email classification covers relays in detail. - Role accounts such as
info@,sales@andsupport@sit on a business domain but aren’t one person. Fine for a contact form; weaker for a user account or a sales lead. Close cousins are shared inboxes (one mailbox a team answers from, such as a Microsoft 365 shared mailbox) and groups (a Google Group or distribution list that forwards to everyone, such asteam@). Their DNS looks exactly like a person’s mailbox, so only the name gives them away. isBusinessEmail reports each as its own hint,shared_inboxandgroup: low confidence when the name matches, certain for@googlegroups.com.
Put the steps together: a decision flow
Run the cheap checks first and the DNS checks only when you need them:
- Is the address well-formed? If not, it’s invalid.
- Is the domain on a disposable or relay list? Then it’s disposable or relay.
- Is it on a free email provider list? Then it’s personal.
- Is it a school or public-sector domain (
.edu,.ac.uk,.gov,.gouv.fr)? Then it’s education or government. - Does the domain receive mail? No MX, or a null MX, means invalid. MX on a consumer-only host such as
gmail-smtp-in.l.google.commeans personal. - Is there enough evidence of an organization? Workspace or Microsoft 365, a security gateway, SPF and DMARC, or a real website: business. Too little evidence (brand new, parked, forwarding only): unknown, so look again.
What you do with each answer is a policy decision, not a fact about the address. A typical B2B setup, which is also the default b2b policy in our API (categories and policies):
| Result | What it means | Typical action |
|---|---|---|
business |
The organization’s own domain | Allow |
education, government |
A school or public body | Allow |
unknown |
Custom domain, too little evidence | Review |
personal |
Shared provider | Block or ask for a work email |
relay |
Forwarding alias | Block or ask for a work email |
disposable |
Throwaway inbox | Block |
invalid |
Can’t receive mail | Block, ask for a correction |
Edge cases
- A founder on Gmail. The check classifies the address, not the person.
founder@gmail.comis personal; whether you accept it is up to your policy. - Custom domains on consumer services. iCloud+, Fastmail and Proton can host a custom domain. It’s still the owner’s domain, so it counts as business, with weaker evidence than Workspace or Microsoft 365.
- Forwarding-only domains. The domain has no mailboxes of its own and may forward to a personal inbox. Treat it as uncertain.
- Subdomains of organizations.
alumni.university.edumight be a lifelong forwarding address for former students, not staff mail. Specific entries beat the parent domain.
Manual checks vs automated checks
| Approach | Good for | Watch out for |
|---|---|---|
| By hand: domain, MX lookup, website | One lead, an email you are about to send | Slow; easy to miss regional providers |
| A provider list in your code | Offline checks at high volume | Lists go stale; no answer for unlisted domains |
| List plus DNS in your code | Full control | Timeouts, fingerprints to maintain, registrable domains |
| An API | Sign-up forms, CRM imports, lead routing | A network dependency: set timeouts and fail open |
Check for a business email in JavaScript, Python and PHP shows the do-it-yourself version. With isBusinessEmail, one call runs every step above and explains the verdict:
curl -s https://api.isbusinessemail.com/v1/check \
-H "Authorization: Bearer $IBE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"email":"jane@acme.io"}'
An excerpt of the response:
{
"domain": "acme.io",
"category": "business",
"is_business": true,
"recommendation": "allow",
"is_free_provider": false,
"is_disposable": false,
"is_relay": false,
"is_role_account": false,
"did_you_mean": null,
"workspace": {
"google_workspace": { "detected": true, "evidence": ["mx_google", "dkim_google"] },
"microsoft_365": { "detected": false }
},
"reasons": ["mx_google_workspace", "dmarc_reject", "txt_saas_tokens:3"]
}
category is what the address is, recommendation is what to do under your policy, and reasons says why. Every field is described in Response fields. You can try it without a key using the test addresses, such as business@test.isbusinessemail.com. The API is free; new accounts get 100 checks a day and move up automatically after 7 clean days (rate limits).
The API classifies addresses. It doesn’t find addresses, and it doesn’t probe mail servers to confirm that a mailbox exists.
Next steps
- One address, right now: paste it into the checker on the homepage.
- A spreadsheet of addresses: use the bulk email checker.
- A sign-up form: read How to require a work email at sign-up and the signup form guide.
- Your own code: start with the quickstart.
Read next: Business email vs personal email, and why the difference matters for ownership, security and trust.
Frequently asked questions
How can I tell if an email address is a work email?
Look at the domain after the @. If it belongs to a shared provider such as gmail.com, outlook.com or yahoo.com, the address is personal. If it is a custom domain that receives mail, such as acme.io, it is almost always a work email.
Is a Gmail address ever a business email?
An address ending in @gmail.com is personal, even when someone uses it for work. Companies that use Google for email run Google Workspace on their own domain, so their addresses look like jane@acme.io.
Can an email on a custom domain be personal?
Yes. Anyone can register a domain, so a custom domain proves ownership, not that a company exists. That is why MX records, a real website and the domain's age are worth checking too.
How do I look up a domain's MX records?
Run dig MX followed by the domain on macOS or Linux, or nslookup -type=mx followed by the domain on Windows, or use a free online MX lookup tool. The host names in the answer show which provider receives the domain's mail.
Are .edu and .gov addresses business emails?
They are organizational addresses on an institution's own domain, not shared consumer accounts. isBusinessEmail, for example, returns the categories education and government for them and counts both as organizations, not personal email.
Does this check prove the mailbox exists?
No. Classification tells you what kind of domain an address is on. Whether a specific mailbox exists is a separate question, best answered by sending a confirmation email.