getting started

Introduction

What the isBusinessEmail API answers, how a check works, and where to start: work vs personal email, disposable, relay, Google Workspace and Microsoft 365.

View as Markdown

isBusinessEmail is a free API that answers one question for B2B products: is this signup a work email?

A work email lives on the company’s own custom domain (jane@acme.io). A personal email lives on a shared-domain provider, where one domain hands out inboxes to many unrelated people (jane@gmail.com, jane@outlook.com). On top of that split, every check tells you:

  • whether the address is disposable, a relay (Apple Hide My Email, Firefox Relay…) or on a blocklist
  • whether the domain is education or government
  • whether the company runs Google Workspace or Microsoft 365, and for Microsoft 365 the tenant ID, region and whether sign-in is federated (Okta, ADFS…)
  • a recommendation (allow, review or block) for the policy you pick, plus the reason codes behind it
curl -sG https://api.isbusinessemail.com/v1/check \
  --data-urlencode "email=business@test.isbusinessemail.com"

That call needs no key: test.isbusinessemail.com addresses return fixed results and are never counted. See Test addresses.

How a check works

Each check runs through layers, cheapest first. Most requests finish in milliseconds from cache.

Layer What happens
Normalize Trim, lowercase, Unicode-normalize, convert IDNs to punycode, strip +tag, find the registrable domain, flag role accounts, typos and lookalikes
Lists Match against curated lists: shared providers, disposable, relay, education, government, business allowlist, blocklists
DNS MX, SPF, DMARC, DKIM and verification TXT records of the registrable domain, over DNS-over-HTTPS
Workspace Google Workspace and Microsoft 365 / Entra ID detection, including the tenant ID
Deep (optional) Domain age via RDAP and a homepage check (deep=true)
Verdict Rules first, then a confidence score; low confidence becomes unknown → review

The full signal list is in Reason codes. The Workspace and Microsoft 365 logic is in Workspace detection.

What it does not do

We don’t verify individual mailboxes. There is no SMTP probing, no Microsoft GetCredentialType lookups and no Google account probes. Those techniques enumerate people, break provider terms, get IPs blocked and are unreliable (catch-all domains, greylisting). We classify the domain and the shape of the address, which is what decides whether a signup belongs to a company and whether your integrations will work.

If you need “will this exact mailbox accept mail?” before a newsletter send, use a deliverability verification service alongside us.

Free, with fair-use limits

The API is free for everyone. New accounts get 100 checks a day and move up automatically after 7 clean days. See Rate limits.

Where to go next