getting started
Introduction
What the isBusinessEmail API answers, how a check works, and where to start: work vs personal email, disposable, relay, Google Workspace and Microsoft 365.
isBusinessEmail is a free API that answers one question for B2B products: is this signup a work email?
A work email lives on the company’s own custom domain (jane@acme.io). A personal email lives on a shared-domain provider, where one domain hands out inboxes to many unrelated people (jane@gmail.com, jane@outlook.com). On top of that split, every check tells you:
- whether the address is disposable, a relay (Apple Hide My Email, Firefox Relay…) or on a blocklist
- whether the domain is education or government
- whether the company runs Google Workspace or Microsoft 365, and for Microsoft 365 the tenant ID, region and whether sign-in is federated (Okta, ADFS…)
- a recommendation (
allow,revieworblock) for the policy you pick, plus the reason codes behind it
curl -sG https://api.isbusinessemail.com/v1/check \
--data-urlencode "email=business@test.isbusinessemail.com"
That call needs no key: test.isbusinessemail.com addresses return fixed results and are never counted. See Test addresses.
How a check works
Each check runs through layers, cheapest first. Most requests finish in milliseconds from cache.
| Layer | What happens |
|---|---|
| Normalize | Trim, lowercase, Unicode-normalize, convert IDNs to punycode, strip +tag, find the registrable domain, flag role accounts, typos and lookalikes |
| Lists | Match against curated lists: shared providers, disposable, relay, education, government, business allowlist, blocklists |
| DNS | MX, SPF, DMARC, DKIM and verification TXT records of the registrable domain, over DNS-over-HTTPS |
| Workspace | Google Workspace and Microsoft 365 / Entra ID detection, including the tenant ID |
| Deep (optional) | Domain age via RDAP and a homepage check (deep=true) |
| Verdict | Rules first, then a confidence score; low confidence becomes unknown → review |
The full signal list is in Reason codes. The Workspace and Microsoft 365 logic is in Workspace detection.
What it does not do
We don’t verify individual mailboxes. There is no SMTP probing, no Microsoft GetCredentialType lookups and no Google account probes. Those techniques enumerate people, break provider terms, get IPs blocked and are unreliable (catch-all domains, greylisting). We classify the domain and the shape of the address, which is what decides whether a signup belongs to a company and whether your integrations will work.
If you need “will this exact mailbox accept mail?” before a newsletter send, use a deliverability verification service alongside us.
Free, with fair-use limits
The API is free for everyone. New accounts get 100 checks a day and move up automatically after 7 clean days. See Rate limits.
Where to go next
- Quickstart: your first call in 30 seconds
- Authentication: secret and publishable keys
POST /v1/check: the main endpoint- Response fields: every field explained
- Block personal emails at signup: a UX guide that doesn’t lose good users
- API reference: generated from
/openapi.json