# Introduction

> What the isBusinessEmail API answers, how a check works, and where to start: work vs personal email, disposable, relay, Google Workspace and Microsoft 365.

Source: https://isbusinessemail.com/docs/introduction

isBusinessEmail is a free API that answers one question for B2B products: **is this signup a work email?**

A work email lives on the company's own custom domain (`jane@acme.io`). A personal email lives on a shared-domain provider, where one domain hands out inboxes to many unrelated people (`jane@gmail.com`, `jane@outlook.com`). On top of that split, every check tells you:

- whether the address is **disposable**, a **relay** (Apple Hide My Email, Firefox Relay…) or on a **blocklist**
- whether the domain is **education** or **government**
- whether the company runs **Google Workspace** or **Microsoft 365**, and for Microsoft 365 the **tenant ID**, region and whether sign-in is federated (Okta, ADFS…)
- a **recommendation** (`allow`, `review` or `block`) for the policy you pick, plus the **reason codes** behind it

```bash
curl -sG https://api.isbusinessemail.com/v1/check \
  --data-urlencode "email=business@test.isbusinessemail.com"
```

That call needs no key: `test.isbusinessemail.com` addresses return fixed results and are never counted. See [Test addresses](https://isbusinessemail.com/docs/test-addresses).

## How a check works

Each check runs through layers, cheapest first. Most requests finish in milliseconds from cache.

| Layer | What happens |
|---|---|
| Normalize | Trim, lowercase, Unicode-normalize, convert IDNs to punycode, strip `+tag`, find the registrable domain, flag role accounts, typos and lookalikes |
| Lists | Match against curated lists: shared providers, disposable, relay, education, government, business allowlist, blocklists |
| DNS | MX, SPF, DMARC, DKIM and verification TXT records of the registrable domain, over DNS-over-HTTPS |
| Workspace | Google Workspace and Microsoft 365 / Entra ID detection, including the tenant ID |
| Deep (optional) | Domain age via RDAP and a homepage check (`deep=true`) |
| Verdict | Rules first, then a confidence score; low confidence becomes `unknown` → `review` |

The full signal list is in [Reason codes](https://isbusinessemail.com/docs/reason-codes). The Workspace and Microsoft 365 logic is in [Workspace detection](https://isbusinessemail.com/docs/workspace-detection).

## What it does not do

We **don't verify individual mailboxes**. There is no SMTP probing, no Microsoft `GetCredentialType` lookups and no Google account probes. Those techniques enumerate people, break provider terms, get IPs blocked and are unreliable (catch-all domains, greylisting). We classify the **domain** and the shape of the address, which is what decides whether a signup belongs to a company and whether your integrations will work.

If you need "will this exact mailbox accept mail?" before a newsletter send, use a deliverability verification service alongside us.

## Free, with fair-use limits

The API is free for everyone. New accounts get 100 checks a day and move up automatically after 7 clean days. See [Rate limits](https://isbusinessemail.com/docs/rate-limits).

## Where to go next

- [Quickstart](https://isbusinessemail.com/docs/quickstart): your first call in 30 seconds
- [Authentication](https://isbusinessemail.com/docs/authentication): secret and publishable keys
- [`POST /v1/check`](https://isbusinessemail.com/docs/check-endpoint): the main endpoint
- [Response fields](https://isbusinessemail.com/docs/response-fields): every field explained
- [Block personal emails at signup](https://isbusinessemail.com/docs/signup-form-guide): a UX guide that doesn't lose good users
- [API reference](https://isbusinessemail.com/docs/api): generated from [`/openapi.json`](https://api.isbusinessemail.com/openapi.json)
