Skip to content

Verify an email, a phone, an IP, an address or a company with one API call.

Five signals, one key and one credit balance. Spaw reads each against the datasets that actually decide it — live DNS and an SMTP handshake that never sends a message, national numbering plans, network and threat feeds, postal formats and registers, company registers — and a sixth endpoint checks the first four against each other. Every verdict names its reason and its sources, and invalid input or a lookup that finds no match never costs a credit.

100 free credits a month · no credit card · one credit per answer (five IP lookups to the credit), everything included

Live demo

POST /demo/email · no key needed

try:

Response

{

"syntax_valid": true,

"mx_found": true,

"mx_provider": "other",

"domain_category": "disposable",

"disposable": true, (flagged)

"is_relay": false,

"role": false,

"free_provider": true,

"risk_score": 90,

"deliverable": "risky",

"ok_to_send": false, (flagged)

"blocked_by": "disposable", (flagged)

…

}

Disposable a recorded answer, abridged — run the lookup above for the live one

Six endpoints, one response shape.

Every call returns the same envelope: a verdict, the fields behind it, and the source that produced them. These are the fields teams reach for first; the full set ships in every response.

POST /api/v1/email

Email verification

Catch disposable inboxes, role accounts, dead domains, and typos at the signup form, before they reach your list.

field type example
deliverablestring"risky"
risk_scorenumber90
disposablebooleantrue
mx_providerstring | null"google"
mailbox_existsboolean | nulltrue
did_you_meanstring | nullnull

1 credit per fresh answer

Try it live

POST /api/v1/phone

Phone intelligence

Normalize any number to E.164, learn its line type, carrier and block status, and catch fictional, disposable and virtual numbers before you dial or text.

field type example
validbooleantrue
e164string"+14155550142"
line_typestring"fixed_line_or_mobile"
block_statusstring | null"reserved"
is_fictionalbooleantrue
risk_scorenumber | null100

1 credit per fresh answer

Learn more

POST /api/v1/ip

IP intelligence

Place every visitor on the map and flag the ones that are not visitors at all: cloud and datacenter ranges, Tor exits, named VPN exits, and iCloud Private Relay.

field type example
countrystring"US"
asnnumber15169
orgstring"Google LLC"
is_datacenterbooleantrue
risk_scorenumber40

1 credit per 5 fresh answers

Learn more

POST /api/v1/address

Address verification

Read a postal address against its own country’s format, name the delivery point behind it, check the postcode against the national directory, and see how many companies are registered there.

field type example
validbooleantrue
address_typestring"private_mailbox"
postal_code_validbooleantrue
existsboolean | nullnull
companies_registerednumber | null4218
risk_scorenumber | null60

1 credit per valid answer

Learn more

POST /api/v1/entity

Business verification

Read a Legal Entity Identifier or a company number against the public registers, synced locally: the legal name, whether the entity is still live, and where it was formed.

field type example
foundbooleantrue
namestring | null"ACME HOLDINGS LIMITED"
statusstring | null"active"
jurisdictionstring | null"GB-ENG"
registered_atstring | null"1998-03-11"
checksum_validboolean | nulltrue

1 credit when a register answers

Learn more

POST /api/v1/consistency

Cross-signal consistency

Run any of the signals above in one call and see where they agree and where they do not. No score and no verdict — the comparisons quote both sides so you can see the working.

field type example
signalsobject{ email, phone, ip, address }
country_agreementstring | null"agree"
comparisonsarray8 entries
flagsstring[]["ip_country_differs_from_address_country"]
withheldstring | null"low_confidence"

The signals you ask for; the comparison is free

Learn more

How credits work

You pay for answers, not attempts. One balance covers every endpoint, and the meter only moves when Spaw tells you something useful.

A hard stop, never a surprise bill

Run out of credits and the API answers with a typed 402 before any work runs. Nothing is billed behind your back.

Free credits that accumulate

The monthly grant lands on every account, paid or not. What you do not use stays on your balance. Pack credits never expire; plan credits roll over up to three months' allowance and stay usable for 60 days after you cancel.

Bulk jobs with signed webhooks

Send up to 100,000 rows in one job. We call your webhook, signed, when it finishes.

outcome credits
Fresh lookup with a usable answer1 credit
Five fresh IP lookups with a usable answer1 credit
Email answer whose mailbox check was uncertain (unverified)0
Undeliverable email verdict within the fair-use allowance0
Undeliverable email verdict past the fair-use allowance1 credit
Invalid input or no match0
Repeat of a recent lookup, within 7 days0
Rejected or failed request0
Monthly free grant, every account+100

Anything you paid to check once is free to check again for a week.

Where the answers come from

Every response includes a sources array naming the dataset and version behind each field, so any verdict can be traced, reproduced, and challenged.

endpoint dataset refreshed
/v1/emailLive DNS MX, SPF, and DMARC resolutionat request time
/v1/emailCurated disposable-domain listsweekly
/v1/emailOpen role-address and free-provider listsweekly
/v1/emailProvider username rules and typo-squat mapcurated in-repo
/v1/emailRelay-service, parking-nameserver, domain-category and name listscurated in-repo
/v1/emailThreat blocklists over the MX hosts (Spamhaus DROP, Feodo)daily, shared with IP
/v1/emailRDAP registry registration and expiry datesat request time, cached a week
/v1/emailSMTP mailbox checks, partner infrastructureat request time
/v1/phoneGoogle's libphonenumber metadatawith each upstream release
/v1/phoneNANPA central office code and thousands-block tables (US, territories), CNAC code table (Canada)daily (NANPA), weekly (CNAC)
/v1/phoneOfcom National Numbering Scheme tables (UK)weekly
/v1/phoneARCEP, ACMA and ACM numbering registers (France, Australia, the Netherlands)weekly
/v1/phoneNAD and CRT (formerly IFT) numbering registers (New Zealand, Mexico)weekly
/v1/phoneUKE and MIMIT numbering tables (Poland, Italy)weekly
/v1/phoneTwo open lists of numbers used by SMS-receiving websitesdaily
/v1/phoneFTC reported-calls data (US unwanted-call complaints)each weekday file, kept 90 days
/v1/phoneFictional and drama number rangescurated in-repo
/v1/ipDB-IP Lite city and ASN databasesmonthly
/v1/ipTor Project exit list and relay data, with a thirty-day exit historyhourly
/v1/ipX4BNet datacenter and VPN listsdaily
/v1/ipPublished ranges and geofeeds of AWS, Google Cloud, Microsoft Azure, Oracle Cloud, DigitalOcean, Linode, Vultr, Cloudflare, Fastly, and GitHub Actionsdaily
/v1/ipMullvad, NordVPN, Private Internet Access, IVPN, AirVPN, and VPN Gate server lists; Apple’s iCloud Private Relay egress listdaily
/v1/ipZscaler cloud enforcement node ranges (corporate gateways)daily
/v1/ipSpamhaus DROP and ASN-DROP threat blocklists; abuse.ch Feodo Tracker botnet C2 listdaily
/v1/ipAttack-source lists: Emerging Threats compromised hosts, CINS Army, blocklist.dehourly
/v1/ipCrawler ranges published by Google, Microsoft, OpenAI, Perplexity, DuckDuckGo, and Ahrefsdaily
/v1/ipGeoNames populated places (time zones by nearest place)monthly
/v1/ipOFAC country programmes and FATF lists; mobile carrier and satellite operator ASNscurated in-repo
/v1/ipRFC 8805 geofeeds discovered across the five regional registriesweekly
/v1/addressPostal formats and postcode patterns for 207 countries and territoriesbundled and versioned
/v1/address52 postal operators’ own naming for boxes, lockers and routescurated in-repo
/v1/addressOfficial building registers of thirteen countries and three German Länder, Great Britain’s streets from OS Open Names, and the Census Bureau’s US house-number rangeswith each publisher release
/v1/addressONS Postcode Directory for Great Britain (Northern Ireland excluded)with each ONS release
/v1/addressGeoNames postal codes for about a hundred more countriesweekly
/v1/addressCompanies House, INSEE Sirene, the Brønnøysund register, and the Colorado, New York, Oregon, Connecticut and Hawaii business registrieswith each published snapshot
/v1/addressBranch lists mailbox and mail-forwarding operators publishwith each publisher release

Block data reflects the original allocation, never a later port. Live carrier status is next on the roadmap, behind the same envelope and a published premium credit.

Plain REST with typed errors.

Send the value you want checked with a bearer key and branch on what comes back. Every failure is a stable, documented code, and rate-limit headers ship on every response.

error.code http when
UNAUTHENTICATED401The key is missing, malformed, or revoked.
VALIDATION_FAILED422The input could not be parsed as an email, phone, IP, or address.
RATE_LIMITED429You went over the endpoint's requests per second.
INSUFFICIENT_CREDITS402The balance is empty. The lookup did not run.
KEY_SPEND_CAP_REACHED429A browser key spent its daily credit cap. Resets each day.
ADDRESS_LIST_UNAVAILABLE501No licensed list or open street listing covers the country or the postcode asked for. Nothing is charged.
$ curl https://spaw.co/api/v1/email \
    -H "Authorization: Bearer sk_live_…" \
    -H "Content-Type: application/json" \
    -d '{"email": "[email protected]"}'

{
  "success": true,
  "data": {
    "deliverable": "deliverable",
    "disposable": false,
    "risk_score": 10,
    "sources": [
      { "dataset": "disposable-domains", "version": "2026-08-29" }
    ],
    …
  },
  "meta": { "credits_used": 1, "credits_remaining": 499, … }
}

Agents reach the same endpoints over the Model Context Protocol: twelve tools, your own API key, the same billing and the same answers.

/docs/mcp
$ claude mcp add --transport http spaw https://spaw.co/mcp \
    --header "Authorization: Bearer sk_live_…"

Pricing

One balance pays for every product, one credit per answer. Plans deposit credits every month for less than the same credits bought once as a pack. What never costs a credit is listed on the pricing page.

Billing interval

Yearly is ten months' price, billed once; the credits still arrive every month.

Paid checkout is not open yet. Every account starts with the free credits, and they work on every product today.

Free

$0a month

No card on file

  • 100 credits a month
  • +500 once, when you confirm your email
  • Email support
Start free

Starter

$7a month

Billed monthly

  • 1,000 credits a month
  • $7.00 per 1,000 credits
  • Pack: $9 once, never expires
  • Email support

Growth

$29a month

Billed monthly

  • 5,000 credits a month
  • $5.80 per 1,000 credits
  • Pack: $39 once, never expires
  • Email support

Scale

$119a month

Billed monthly

  • 25,000 credits a month
  • $4.76 per 1,000 credits
  • Pack: $149 once, never expires
  • Priority support

Higher volumes: Volume, Pro, Business and Enterprise, 100,000 to 1,000,000 credits a month, from $349 a month.

Compare every tier

Every tier, free included, gets every product and every response field. Plan credits roll over up to three months' allowance and stay usable for 60 days after you cancel; pack credits never expire. Priority support puts your request at the top of the support queue; no tier carries a response-time promise. Prices in US dollars.

Common questions

Something else on your mind? Ask support.

What happens when I run out of credits?

The API returns a clear 402 response before running the lookup, so you are never billed for work that cannot complete. Your free credits are added again at the start of each month.

Do failed lookups cost credits?

No. Lookups that return no match cost nothing, email answers whose mailbox check was uncertain cost nothing, and repeat lookups served from the seven-day cache cost nothing. Undeliverable email verdicts are free within a fair-use allowance. Credits are only spent on fresh answers, and one credit covers five IP lookups.

Where does the data come from?

From auditable sources: international numbering plans and the regulators’ number-block allocation tables for phone; live DNS and curated domain lists for email; and, for IP, openly licensed geolocation databases plus the Tor exit list, the cloud providers’ own published ranges, VPN providers’ server lists, Apple’s relay egress list, and the Spamhaus and abuse.ch threat blocklists; and, for postal addresses, the countries’ own postal formats, the operators’ naming for boxes, the official building registers of thirteen countries and three German Länder, the ONS Postcode Directory and GeoNames postal codes, and open company registers. Every response names the exact dataset and version that produced it.

Is the free tier really recurring?

Yes. 100 credits are added at the start of every month with no card on file, and unused ones carry over. That is enough to try every endpoint and keep a test integration alive.

Can I verify a whole list at once?

Yes, on every account. Send up to 100,000 rows to the bulk endpoint or upload a CSV from the dashboard. Jobs run in the background and call your webhook, signed, when they finish.

What do you keep after a lookup?

Inputs are processed to answer the request and retained only for your own usage logs and the short result cache. We do not resell or enrich submitted data, and you can purge a workspace at any time.

Start verifying today.

Create a key, make your first call, and keep 100 free credits a month.

Get your API key