# isBusinessEmail > Know if a signup is a work email — and whether their company runs Google Workspace or Microsoft 365. Free REST API at https://api.isbusinessemail.com (POST /v1/check with a Bearer key). Classifies an email or domain as business, personal, disposable, relay, education, government, invalid or unknown, with an allow/review/block recommendation, reason codes, and Google Workspace / Microsoft 365 detection. Operated by Tilfortis MB (Lithuania). Full docs in one file: https://isbusinessemail.com/llms-full.txt. OpenAPI: https://api.isbusinessemail.com/openapi.json. MCP server (Streamable HTTP, OAuth 2.1 sign-in or an API key as Bearer token): https://api.isbusinessemail.com/mcp. Tools: check_email, check_domain, check_batch, get_usage, report_wrong_verdict. Setup: https://isbusinessemail.com/docs/mcp.md ## Getting started - [Introduction](https://isbusinessemail.com/docs/introduction.md): What the isBusinessEmail API answers, how a check works, and where to start: work vs personal email, disposable, relay, Google Workspace and Microsoft 365. - [Quickstart](https://isbusinessemail.com/docs/quickstart.md): Make your first isBusinessEmail API call in 30 seconds with curl, JavaScript or Python, then switch from test addresses to a real key. - [Authentication](https://isbusinessemail.com/docs/authentication.md): Secret keys (ibe_live_) for servers, publishable keys (ibe_pub_) for browsers, key rotation, and automatic revocation of keys leaked on GitHub. - [Test addresses](https://isbusinessemail.com/docs/test-addresses.md): Reserved test.isbusinessemail.com addresses return fixed results with no key and never count toward quotas. Use them in docs, CI and smoke tests. ## API reference - [Check an email, domain or website](https://isbusinessemail.com/docs/check-endpoint.md): GET and POST /v1/check: check one email address, domain or website URL, choose a policy, request deep enrichment, and read the full response. - [Batch checks](https://isbusinessemail.com/docs/batch-endpoint.md): POST /v1/check/batch checks up to 100 emails, domains or website URLs in one request. Each item counts toward your quota. Limits, response and retry advice. - [Report a wrong verdict](https://isbusinessemail.com/docs/feedback-endpoint.md): POST /v1/feedback tells us a verdict was wrong. Reports are reviewed by people, weighted by reporter trust, and never applied automatically. - [Usage and health](https://isbusinessemail.com/docs/usage-endpoint.md): GET /v1/usage returns your own quota and usage; GET /v1/health reports API status; /openapi.json is the machine-readable spec. - [Response fields](https://isbusinessemail.com/docs/response-fields.md): Every field in a /v1/check response: category, recommendation, confidence, flags, mail, workspace, integrations, reasons, degraded and more. - [Categories and policies](https://isbusinessemail.com/docs/categories-and-policies.md): The eight categories (business, personal, disposable, relay, education, government, invalid, unknown) and how the b2b, strict and lenient policies map them. - [Reason codes](https://isbusinessemail.com/docs/reason-codes.md): Every reason code isBusinessEmail returns in reasons[]: syntax, list matches, MX fingerprints, SPF/DMARC/DKIM, Microsoft tenant, domain age and more. - [Rate limits and quotas](https://isbusinessemail.com/docs/rate-limits.md): Per-second, daily and in-flight limits for each tier, how batch and deep checks count, rate-limit headers, and how to handle 429 responses. - [Errors](https://isbusinessemail.com/docs/errors.md): isBusinessEmail errors are RFC 9457 problem+json with a stable code. Every code, its HTTP status, what causes it, and how to handle it. - [Versioning and deprecation](https://isbusinessemail.com/docs/changelog-policy.md): How the isBusinessEmail API is versioned, which changes are non-breaking, and how deprecations are announced with Deprecation and Sunset headers. ## Guides - [MCP server for AI assistants](https://isbusinessemail.com/docs/mcp.md): Connect Claude, ChatGPT, Cursor, VS Code and other MCP clients to isBusinessEmail: server URL, OAuth sign-in, tools, example prompts and limits. - [Google Workspace and Microsoft 365 detection](https://isbusinessemail.com/docs/workspace-detection.md): How isBusinessEmail detects Google Workspace and Microsoft 365, finds the Entra tenant ID and federation, and what the detection deliberately does not do. - [Block personal emails at signup (without losing good users)](https://isbusinessemail.com/docs/signup-form-guide.md): A practical pattern for B2B signup forms: inline work-email hints, typo suggestions with did_you_mean, server-side enforcement and failing open. - [Code examples](https://isbusinessemail.com/docs/code-examples.md): Copy-paste isBusinessEmail API examples in curl, JavaScript, Node.js, Python, PHP, Go, Ruby, Java and C#, with timeouts and fail-open handling. - [Privacy and data handling](https://isbusinessemail.com/docs/privacy-and-data.md): What isBusinessEmail stores when you check an address (domain and an HMAC, never the full email), retention, EU hosting, processors and your obligations. - [Server-side integration (Node client)](https://isbusinessemail.com/docs/server-side.md): Use isBusinessEmail from a backend or a mail pipeline: the zero-dependency Node client with timeouts, retries, caching and fail-open checks. ## Articles - [Check business emails from your AI assistant with MCP](https://isbusinessemail.com/blog/check-emails-from-ai-assistants-mcp): Connect isBusinessEmail's MCP server to Claude, ChatGPT, Cursor or VS Code, then ask which emails are work emails and which companies use Microsoft 365. - [Domain age as a fraud signal: what a new domain tells you at sign-up](https://isbusinessemail.com/blog/domain-age-fraud-signal): A domain registered days ago is a real risk signal at sign-up, not proof of fraud. How to check domain age with RDAP and when to review instead of block. - [Are .edu, .ac.uk and .gov emails business emails? Education and government addresses explained](https://isbusinessemail.com/blog/education-and-government-emails): School, university and government addresses like .edu, .ac.uk and .gov are organizational, not personal. How they are classified and when it matters. - [Email relay addresses: privaterelay.appleid.com, mozmail.com and duck.com explained](https://isbusinessemail.com/blog/email-relay-addresses): Relay addresses on privaterelay.appleid.com, mozmail.com or duck.com forward to a hidden real inbox. How they work and how B2B sign-ups should handle them. - [Email typo domains: catch gmial.com and suggest the fix](https://isbusinessemail.com/blog/email-typo-domains): Email typo detection compares the domain with popular providers and offers a fix, like gmial.com to gmail.com. How it works, what typos cost, how to show it. - [Free trial abuse: the email signals that catch it, and where they stop](https://isbusinessemail.com/blog/free-trial-abuse-email-signals): Stop repeat free-trial sign-ups with email signals: disposable and relay inboxes, +tag and Gmail-dot variants, typo domains, new domains and a blocklist. - [Lookalike and punycode email domains: spotting homographs at sign-up](https://isbusinessemail.com/blog/lookalike-and-punycode-domains): Lookalike domains imitate gmail.com or paypal.com with Cyrillic letters, digits or rn for m. How punycode exposes them and how isBusinessEmail flags them. - [Plus addressing and Gmail dots: how to deduplicate sign-ups](https://isbusinessemail.com/blog/plus-addressing-signup-dedupe): Plus addressing sends jane+news@acme.io to jane@acme.io, and Gmail ignores dots. How to deduplicate sign-ups with a key, without blocking anyone. - [Role-based email addresses: should you accept info@ at sign-up?](https://isbusinessemail.com/blog/role-based-email-addresses): Role-based email addresses like info@ and sales@ belong to a team, not a person. When to allow, review or block them at sign-up, in marketing and in sales. - [Shared inbox vs group email: how to tell from the address](https://isbusinessemail.com/blog/shared-inboxes-and-google-groups): A shared inbox is one mailbox a team answers from; a group forwards to many members. Why DNS can't tell them apart, and what the address name can. - [Business email vs personal email: what's different and why it matters](https://isbusinessemail.com/blog/business-email-vs-personal-email): Business email vs personal email: how they differ in ownership, security, offboarding, deliverability, cost and integrations, and when each is fine. - [Check for a business email in JavaScript, Python and PHP](https://isbusinessemail.com/blog/check-business-email-in-code): Check for a business email in JavaScript, Python and PHP: a free-provider list plus MX lookup you can run today, its pitfalls, and calling an API safely. - [Email verification vs email classification](https://isbusinessemail.com/blog/email-verification-vs-classification): Email verification vs email classification: one checks whether an address can receive mail, the other what kind of address it is. When you need both. - [How to find someone's business email address](https://isbusinessemail.com/blog/find-a-business-email-address): How to find someone's business email address: company pages, email patterns, search operators and finder tools, then how to check it before you send. - [Free email providers: the list and what counts as personal](https://isbusinessemail.com/blog/free-email-providers): A list of free email providers worldwide, from Gmail and Outlook to GMX, Yandex, QQ and Naver, plus ISP and privacy mailboxes, and what counts as personal. - [How to tell if an email is a business email](https://isbusinessemail.com/blog/how-to-tell-if-an-email-is-a-business-email): How to tell if an email is a business email: read the domain, compare it with free provider lists, look up MX records and rule out disposable addresses. - [Lead scoring by email domain](https://isbusinessemail.com/blog/lead-scoring-by-email-domain): Lead scoring by email domain: why the domain is a strong signal, an example scoring model, routing to sales, CRM enrichment, pitfalls and measuring it. - [How to require a work email at sign-up (without losing good users)](https://isbusinessemail.com/blog/require-work-email-at-signup): How to require a work email at sign-up: choose block, review or allow per category, write error messages that work, fix typos, plan exceptions, fail open. - [What is a business email? Definition, examples and edge cases](https://isbusinessemail.com/blog/what-is-a-business-email): A business email is an address on an organization's own domain, like jane@acme.io, not a shared one like gmail.com. Definition, examples and edge cases. - [How to find out which email provider a company uses](https://isbusinessemail.com/blog/which-email-provider-does-a-company-use): How to find out which email provider a company uses: read its MX records, see past security gateways, then check SPF, DKIM and Microsoft 365 tenant data. - [Why we built isBusinessEmail](https://isbusinessemail.com/blog/why-we-built-isbusinessemail): Personal-email signups kept stalling our B2B onboarding at the integration step. Here's the internal check we built, and why we made it a free API. - [Google Workspace vs Gmail: tell them apart from DNS](https://isbusinessemail.com/blog/google-workspace-vs-gmail-dns): How to tell a Google Workspace domain from consumer Gmail using MX, DKIM and SPF records, where DNS misleads you, and the hd claim at sign-in. - [Microsoft 365 tenant vs Outlook.com: what your integration can and can't do](https://isbusinessemail.com/blog/microsoft-365-tenant-vs-outlook-com): Microsoft 365 work accounts vs Outlook.com accounts: admin consent, SharePoint, OneDrive for Business, Teams, and finding a tenant before sign-in. - [Should B2B SaaS block free email signups?](https://isbusinessemail.com/blog/should-b2b-saas-block-free-email-signups): The trade-offs of blocking Gmail and Outlook signups on a B2B product, the middle paths that keep good users, and how to decide with your own data. - [The disposable email problem (and why lists aren't enough)](https://isbusinessemail.com/blog/disposable-email-problem): Why disposable email lists always lag behind, how throwaway services evade them, and the DNS and domain signals that catch what lists miss. - [Detecting business emails with MX records](https://isbusinessemail.com/blog/detecting-business-emails-with-mx-records): What MX records reveal about an email domain (Workspace, Microsoft 365, gateways, hosting, forwarding), what they can't tell you, and pitfalls in code. ## Tools - [Bulk email checker](https://isbusinessemail.com/tools/bulk-email-checker): Upload a CSV of email addresses and see which are work emails, personal, disposable or invalid — with Google Workspace and Microsoft 365 detection. Free with an account. - [Disposable email checker](https://isbusinessemail.com/tools/disposable-email-checker): Check if an email address or domain is a disposable, temporary or throwaway inbox (Mailinator, 10minutemail, Guerrilla Mail and thousands more). Free, instant, no signup. - [Free email provider checker](https://isbusinessemail.com/tools/free-email-checker): Find out if an address uses a free or shared email provider such as Gmail, Outlook, Yahoo, iCloud, GMX or a consumer ISP — or a company-owned domain. - [MX lookup](https://isbusinessemail.com/tools/mx-lookup): Look up the MX records of any domain and see which email provider handles its mail — Google Workspace, Microsoft 365, Proofpoint, Mimecast and more. - [SPF & DMARC checker](https://isbusinessemail.com/tools/spf-dmarc-checker): Check a domain’s SPF record, its includes and its DMARC policy (none, quarantine or reject) in one lookup. - [Google Workspace checker](https://isbusinessemail.com/tools/google-workspace-checker): Find out if a company domain uses Google Workspace (formerly G Suite) — from MX, DKIM, SPF and verification records, even behind a mail gateway. - [Microsoft tenant lookup](https://isbusinessemail.com/tools/microsoft-tenant-lookup): Look up a domain’s Microsoft 365 / Entra ID tenant: tenant ID, region, managed or federated sign-in and the identity provider (Okta, ADFS, Ping…). ## Open data - [Free email providers](https://isbusinessemail.com/lists/free-email-providers.txt): Shared-domain providers and consumer ISPs: Gmail, Outlook, Yahoo, GMX, iCloud and thousands more. - [Disposable email domains](https://isbusinessemail.com/lists/disposable-email-domains.txt): Temporary and throwaway inbox services, merged from open lists and our own detection. - [Education domains](https://isbusinessemail.com/lists/education-domains.txt): Universities, colleges and schools worldwide, plus academic suffixes such as .edu and .ac.uk. ## Optional - [API reference](https://isbusinessemail.com/docs/api): Interactive OpenAPI reference - [Live stats](https://isbusinessemail.com/stats): Volume, latency and published accuracy - [Privacy Policy](https://isbusinessemail.com/privacy) - [Terms of Service](https://isbusinessemail.com/terms)