# Report a wrong verdict

> POST /v1/feedback tells us a verdict was wrong. Reports are reviewed by people, weighted by reporter trust, and never applied automatically.

Source: https://isbusinessemail.com/docs/feedback-endpoint

```text
POST https://api.isbusinessemail.com/v1/feedback
```

Think we got one wrong? A company domain marked `personal`, a new disposable service marked `business`? Tell us. Feedback is the fastest way to fix the lists for everyone.

Secret keys only. Limit: **50 reports a day per key**. Feedback doesn't count toward your check quota.

## Request

```json
{
  "domain": "tempbox.example",
  "expected_category": "disposable",
  "comment": "Throwaway inbox service launched last week; see its homepage."
}
```

| Field | Required | Notes |
|---|---|---|
| `email` or `domain` | one of them | What you checked. If you send an email, we keep only its domain and an HMAC of the local part, like every other check. |
| `expected_category` | yes | One of `business`, `personal`, `disposable`, `relay`, `education`, `government`, `invalid`, `unknown` |
| `comment` | no | Free text, up to a few sentences. Evidence helps: a link, the provider's name, what the domain is used for. **Don't include personal data.** |

An `Idempotency-Key` header is accepted, so retrying after a network error won't file the report twice.

```bash
curl -s https://api.isbusinessemail.com/v1/feedback \
  -H "Authorization: Bearer $IBE_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{"domain":"tempbox.example","expected_category":"disposable"}'
```

## Response

A `2xx` status with a small JSON acknowledgement means we received the report. The exact schema is in [`/openapi.json`](https://api.isbusinessemail.com/openapi.json). Errors follow the usual [problem+json format](https://isbusinessemail.com/docs/errors): `400 invalid_input` for a bad category, and a `429` once a key passes 50 reports in a day.

## What happens next

1. The report lands in our review queue with the domain's signals and history.
2. It's weighted by how much we trust the reporting account. A flood of reports about one domain is flagged rather than trusted.
3. A person decides. If the report is right, the domain gets an override and moves to the correct list. The change reaches every edge location within about a minute, and cached verdicts for that domain are cleared.

**Feedback is never applied automatically.** That protects every customer from someone trying to get a competitor's domain marked as disposable.

You can also report from the dashboard (**Report wrong verdict**) or from any `/check/<domain>` page.

## When not to use feedback

- **Your own policy differs from ours.** If you want to accept `relay` addresses or block a specific customer, change the [policy](https://isbusinessemail.com/docs/categories-and-policies) or keep an allowlist on your side.
- **A single person's mailbox.** We don't classify individual mailboxes; report the domain.
