Why we built isBusinessEmail
Personal-email signups kept stalling our B2B onboarding at the integration step. Here's the internal check we built, and why we made it a free API.
We didn’t set out to build an email API. We set out to fix an onboarding funnel.
The team behind isBusinessEmail also builds Noium, a B2B product from Tilfortis MB in Lithuania. Noium connects to the systems companies already run, and for most of our customers that means Google Workspace or Microsoft 365. Like most B2B tools, we let people sign up with any email address. That turned out to be the problem.
The pattern we kept seeing
A new user would sign up with @gmail.com, @yahoo.com or @outlook.com. Sign-up went fine. Activation went fine. Then they reached the step that mattered: connect your company’s workspace.
And it didn’t work, because it couldn’t:
- A personal Gmail account has no Google Workspace organization behind it. There’s no Admin console, no Shared Drives, and nobody who can authorize domain-wide delegation for a service account. The APIs that operate at the organization level simply have no organization to operate on.
- A personal Microsoft account (Outlook.com, Hotmail, Live) isn’t part of a Microsoft Entra ID tenant the way a work account is. There’s no admin who can grant organization-wide consent to an app, no SharePoint Online sites, no OneDrive for Business, no Teams organization to read from.
From the user’s point of view, the product was broken. From ours, the user had signed up with the wrong account three steps earlier and we had let them. The conversations that followed were predictable: “Why can’t I see our SharePoint?” “Why does it say admin approval required?” “I don’t have an admin, I’m using my Gmail.” Support tickets piled up. Some users switched to their work account and started over. Many didn’t come back.
None of this was the user’s fault. Browsers autocomplete personal addresses. “Sign in with Google” doesn’t tell you which kind of Google account you’re about to use. And our signup form had asked for “email”, not “work email”.
The internal check
The first fix was the obvious one: a list of free email providers and a warning on the signup form. It helped, and it immediately ran into the limits of lists:
- Shared providers are a long tail. Regional webmail, ISP domains, paid consumer services: the list never ends, and it changes.
- Disposable inboxes appear daily. Some run on fresh domains that look like ordinary businesses.
- Custom domains aren’t all equal. A company domain on Microsoft 365 is a very different onboarding from a custom domain forwarding to someone’s personal inbox.
- Typos are common.
gmial.comisn’t a company, and the person behind it deserves a “did you mean?” rather than a rejection.
So the check grew. It started reading DNS: who handles the domain’s mail, whether it publishes SPF and DMARC, which SaaS tools have verified the domain. Then it learned the thing we actually needed for onboarding: does this company run Google Workspace or Microsoft 365? For Microsoft, Microsoft’s public discovery documents even tell you the tenant ID, which lets you send an admin straight to the consent screen for their organization. You can read how detection works in the docs.
With that in place, onboarding changed shape. A signup on a Microsoft 365 domain sees the Microsoft connector first. A signup on a personal address is told, at signup, that connecting SharePoint will need their work account. The “integration step surprise” mostly went away.
Why make it public, and free
Once the check existed, a few things became clear.
Every B2B product needs it. Talk to anyone running a B2B signup flow and you hear the same story: trial abuse from throwaway inboxes, sales time spent on personal addresses, integrations that can’t work for the account that signed up.
It gets better with use. A classifier like this improves when it sees more domains and gets more corrections. A disposable service one customer reports is one every customer stops seeing. Keeping it internal would have kept it worse.
It should be a commodity. “Is this a work email?” is a basic building block, like “is this a valid address?”. We’d rather it be free and dependable than another line item.
So we turned the internal check into isBusinessEmail: a free public API and website, run by the same team, used in production by Noium.
Principles we kept
Some decisions shaped everything else:
- We classify domains, not people. No SMTP probing, no asking Google or Microsoft whether a specific person has an account. Those techniques are user enumeration: they break provider terms, they’re unreliable, and they tell third parties that someone signed up somewhere. A domain’s own DNS answers our question better anyway.
- We never store full email addresses. We keep the domain and a keyed hash of the local part, so we can notice a domain that behaves like a shared provider without being able to list anyone’s address. Details: Privacy and data.
- Every verdict explains itself. Responses include reason codes such as
mx_microsoft_365,dmarc_rejectordisposable_provider, so you can show users and support staff why. - Fail open. Our docs tell you to let signups through if we’re slow or down, and we design for that: if DNS fails, you still get an answer from our lists, marked
degraded. - Verdicts are probabilistic. We measure accuracy on a hard test set and publish it on the stats page, but we don’t promise perfection. Use
reviewfor the cases in between, and tell us when we’re wrong.
What it is, and what it isn’t
isBusinessEmail tells you whether a signup is a work email (on the company’s own custom domain) or personal (on a shared-domain provider), whether it’s disposable, a relay or blocked, and whether the company uses Google Workspace or Microsoft 365, with an allow / review / block recommendation for the policy you choose.
It isn’t a deliverability verifier: it won’t tell you whether jane@ exists before a newsletter send. It isn’t a fraud platform. And it doesn’t decide anything about your users. You do.
Try it
The fastest way to see it is the checker on the home page, or a test address that needs no key:
curl -sG https://api.isbusinessemail.com/v1/check \
--data-urlencode "email=m365@test.isbusinessemail.com"
Then get a free key and read the quickstart. If you run into a domain we got wrong, report it. That’s how this gets better for everyone, including us.
Frequently asked questions
What is isBusinessEmail?
A free public API and website that tells you whether a signup is a work email on the company's own domain or a personal one on a shared-domain provider, whether it's disposable, a relay or blocked, and whether the company uses Google Workspace or Microsoft 365. Each check comes with an allow, review or block recommendation for the policy you choose.
Why can't a personal Gmail account connect a company's Google Workspace?
A personal Gmail account has no Google Workspace organization behind it: no Admin console, no Shared Drives and nobody who can authorize domain-wide delegation. APIs that operate at the organization level have no organization to operate on.
Is isBusinessEmail an email verifier?
No. It classifies domains and doesn't probe mailboxes, so it won't tell you whether a specific address exists before a newsletter send. It isn't a fraud platform either.
Does isBusinessEmail store email addresses?
No. It keeps the domain and a keyed hash of the local part, so it can notice a domain that behaves like a shared provider without being able to list anyone's address.
Who runs isBusinessEmail?
The team behind Noium, a B2B product from Tilfortis MB in Lithuania. It started as Noium's internal signup check, and Noium still uses it in production.