Every answer the API gives names its data in a sources block: the dataset, and the date it was last synced or published. This page is the longer version of that block — one section per product, in the order the products appear on the site, each saying where the facts come from, how often they refresh, what is measured every week and how, what the product deliberately does not claim, and what is kept about a lookup. It describes what runs today. The status page shows the same datasets with their current dates, and the security page states the data-handling rules in full.
Three rules hold across every product. A flag is tri-state: false is a checked negative, null means the signal was not evaluated, and nothing fabricates a negative from a missing dataset. Every risk score is arithmetic over published weights that the same response lists in risk_signals, so it can be recomputed or ignored. And a measurement is published with its date, as agreement with the best public reference there is, never as ground truth.
Email verification
An email lookup runs from public data and one handshake. The address is parsed against RFC 5322 and then against the username rules of the large providers. MX records are resolved live at query time: a domain with no MX record but an A record is reported as implicit MX, a null MX record as a domain that declines all mail, MX hosts pointing at dead or private addresses as unresolvable. SPF and DMARC records are read from DNS and the DMARC policy reported. The domain is matched against the open disposable-provider list, including domains whose mail is handled by a listed operator, with a curated allow-list and deny-list on top; the local part against the open role-address list; the domain against the open free-provider list; and a curated map catches typo-squats of the major providers. Those three open lists are synced weekly. The domain's registration age is read from the registry's RDAP record and cached for a week, skipped for free providers.
The mailbox handshake is the one step that leaves the server. When the free signals have not settled the answer, an SMTP conversation asks the receiving server whether the mailbox exists, through partner infrastructure, and ends before any message data is transmitted. Nothing is ever sent to an address you check. When a server will not say, the answer degrades honestly: smtp_checked is false, the verdict is risky with the reason unverified, and that answer is free.
Three more signals read from data already on the server. The username's own shape is described without any network call: its naming pattern (first.last, flast, a lone name, digits, a word), the name tokens the bundled name lists recognise, and whether it looks machine-made or a placeholder. A permanent alias service (Firefox Relay, SimpleLogin, Addy.io, DuckDuckGo) is read before the burner list, because an alias is a real mailbox and the public burner lists carry those domains anyway. And the mail hosts themselves are looked at: whether the nameservers belong to a parking service, whether any MX host resolves into a network on the threat blocklists the IP product installs, and what class of network the first one sits in.
The weights are published beside the fields and every answer lists the ones that fired in risk_signals: disposable 80, a parked domain 60, a known typo-squat 60, mail served from a blocklisted network 60, a web-only domain 30, role 30, catch-all 30 (15 behind a security gateway that accepts every recipient by design), a domain registered under 30 days ago 30, a mailbox that exists again after answering not-found 30, a full mailbox 20, a gibberish local part 20, a generated-looking one 20, a no-reply address 20, an address many other accounts checked today 20, a domain under 180 days 10, no SPF on a business domain 10, an unverified mailbox 10, a registration ending within 30 days 10, a plus-tag alias 5, a relay alias 5; undeliverable is always 100 with nothing listed. The bounce and complaint outcomes you report shape your own later answers, and three derived figures cross accounts, each a count or a date and never an address or who reported it: the share of reported sends to a domain that bounced, counted only once a domain has five outcomes; the naming convention a domain's confirmed deliveries follow, tallied as pattern shapes; and how many other accounts looked an address up inside the last day. One more memory crosses time rather than accounts: a definitive "no such mailbox" answer is kept for a year under a keyed hash, so a mailbox that exists again later is reported as previously invalid.
What is measured: every week, for each verdict, the share of reported sends that were delivered or bounced, published on the status page only when a verdict has at least a hundred outcomes from at least three accounts and no single account holds more than half of them. A verdict below those floors is not published rather than published on one customer's mail performance.
What is never claimed: that mail was sent, that a catch-all server holds the mailbox, or that a provider refusing to answer means the address is bad.
What is kept: email is the one product with a history row — the address, its verdict, reason and score, and what it cost — deleted after 30 days. Beside it, two keyed hashes that carry no address: which accounts looked an address up, for a day, and the date a mailbox last answered not-found, for a year. Both are erased with the address. Repeats inside seven days are free.
Phone intelligence
A phone lookup is answered from libphonenumber, which ships with the service and carries every numbering plan's formats and plan-level line types, and from the regulators' own allocation tables copied onto the server: NANPA for the United States (its central-office codes and, inside a pooled code, the holder of each block of a thousand), CNAC for Canada, Ofcom for the United Kingdom, ARCEP for France, ACMA for Australia, ACM for the Netherlands, the Number Administration Deed register for New Zealand, the CRT (formerly the IFT) for Mexico, UKE for Poland and MIMIT for Italy. The tables are synced weekly, NANPA's daily. A geographic number in a block a complete table does not allocate is unassigned; a Polish number in the space UKE lists as held in reserve is unassigned from that row itself; a table too old to trust withholds that inference rather than guessing. Fictional ranges the regulators reserve for drama ship with the service, and two public lists of numbers used by SMS-receiving websites, with the date each was last seen, are synced daily; a number that leaves the lists is kept at its last-seen date for two years, so it ages rather than vanishing, and it scores as disposable for 90 days after that date rather than a year. For North American numbers, the complaints consumers file with the Federal Trade Commission about unwanted calls are read from the daily files it publishes each weekday, synced nightly and counted over 90 days by the number each names as the caller. A bundled, versioned map names the network brand behind a carrier's registered name.
Two fields carry a source beside them, because two datasets can answer them: the numbering plan decides line_type everywhere except in the North American plan, where mobiles and landlines share blocks and only the block holder's kind can settle it, and the block holder outranks libphonenumber's carrier metadata for carrier.
The weights: fictional 80, disposable 70, or 40 once a listing is stale (last seen more than a year ago while the lists still carry the number, more than 90 days ago once they have all dropped it), premium rate 60, a reserved block 40, virtual 40, VoIP 30, pager 30, a digit pattern 30, a number not listed itself in a 1,000-number range holding ten or more SMS-receiving listings that are not stale 30, an international-network or satellite calling code (+870, +881, +882, +883) 30, shared cost 20, FTC complaints naming a North American number as the caller three or more times on two or more days within 90 days 20; your own abuse reports 60 and undelivered reports 50 within 90 days, three or more accounts reporting abuse 40 within 30 days; and from your own traffic, five or more numbers your account looked up in one 1,000-number range within the hour 40 (range_burst), and five or more numbers tried from one client address within the hour 30 (numbers_per_client), except from an address the local IP data places on a mobile carrier or a corporate proxy. A UK 084 or 087 number is shared cost, not premium rate, because Ofcom's numbering plan classes those ranges as service numbers with a capped charge; in the plan, premium rate is the 09 range (0871 to 0873 still fall under Ofcom's premium-rate-services rules, so a sender that treats them as premium rate should block shared_cost too).
What is measured: every week, the coverage of each regulator table — what share of its blocks are allocated and what share settle a line type — from the tables themselves, published as shares of the regulators' data and not of real traffic; and how well the crowded 1,000-number ranges predict the SMS-receiving list — how many listed numbers they would catch if the list missed them, and how many of the week's new listings already sat in one.
What is never claimed: that a North American number is a mobile or a landline when the block does not say, or that a number is reachable; the live carrier check is a licensed premium answer and is not enabled, so hlr_checked answers false rather than guessing.
What is kept: nothing about a lookup beyond a keyed seven-day repeat marker holding a hash (a second one when a live check was paid for), and, for single and browser lookups, the account's own traffic counts: each number as a truncated keyed hash filed under keyed hashes of its range and client address for the hour the velocity signals look back over, and lookups per country and hour as counts for thirty days, behind destination_new_for_you and the owner's destination alerts. None of it is read for another account. Of the public data about numbers, the FTC complaints are kept for the 90 days the count reads and an SMS-receiving listing for two years after the lists last showed it, and an erasure of a number deletes its complaints and any listing the sites no longer publish. Eight test numbers in a fiction block answer fixed results and are never logged.
IP intelligence
An IP answer is built from a local database and compiled feeds, so the address never leaves the server unless you ask for the registry's abuse contact. The location and the network come from the DB-IP Lite city and ASN databases, synced monthly. Around them sit more than fifty feeds, each declared in configuration with its URL, its parser and its minimum size, downloaded and compiled into seekable indexes daily, with three groups refreshed hourly: the Tor Project's bulk exit list and its Onionoo relay data, the botnet C2 list from abuse.ch, and the attack-source lists.
The feeds by what they answer:
- Location declared by the operator. Every RFC 8805 geofeed the five registries point at, discovered weekly; Apple's iCloud Private Relay egress list; the server lists of Mullvad, NordVPN, Private Internet Access, IVPN, AirVPN and the VPN Gate volunteer relays; the geofeeds DigitalOcean, Linode and Vultr publish. Where one covers an address, its declaration wins over the database.
- Hosting. The published ranges of Amazon Web Services, Google Cloud, Microsoft Azure, Oracle Cloud, DigitalOcean, Linode, Vultr, Cloudflare, Fastly and GitHub's Actions runners, plus the open X4BNet datacenter list.
- Anonymity. The Tor lists and a thirty-day exit history rebuilt after every Tor sync; the named VPN lists and the open X4BNet VPN list; Apple's relay list. Cloudflare publishes no list of its WARP egress, so WARP is inferred as Cloudflare's own network outside the CDN ranges it does publish and outside the public resolvers, and the answer says
(inferred)so an inference is never mistaken for a list. - Corporate gateways. The cloud enforcement node ranges Zscaler publishes for its clouds.
- Crawlers. The range files Google, Microsoft, OpenAI, Perplexity, DuckDuckGo and Ahrefs publish for verification, and forward-confirmed reverse DNS for the operators that document it, on request.
- Registries. The five regional registries' daily delegated statistics, which answer who allocated a block, for which country and when, and whether any registry allocated it at all.
- Threat lists. Spamhaus DROP and ASN-DROP, used with the credit their terms ask for, and abuse.ch's Feodo Tracker; and, apart from them, the attack-source lists of hosts seen attacking in the last days: Emerging Threats' compromised hosts, CINS Army and blocklist.de.
- Curated files that ship with the service. The public resolvers' anycast ranges; the satellite and mobile-carrier autonomous systems, positive-only; the privacy-regime map; the compliance file naming the countries under a comprehensive OFAC programme, under any country-related OFAC programme, and on the FATF lists, each with its source and the date it was checked; the country and region time-zone map, backed by the GeoNames list of populated places for the split countries the map cannot settle, searched inside the located country only.
The weights, in the published order: an address on one of your deny lists 100, unallocated space 100, a threat blocklist 80, a Tor exit 70, your own abuse report 60, an attack-source list 50, a datacenter range 40, three or more accounts' reports 40, an exit seen within seven days 40, a VPN exit 30, relay egress 10, capped at 100. The datacenter weight is skipped for relay egress, verified crawlers and corporate gateways, which sit on infrastructure by design. An address on one of your allow lists scores 0 whatever else fired, with a single entry saying why.
What is measured: every week, a sample of addresses from the operator-declared ranges is looked up in the database and the two are compared on country and city. The result grades location_confidence for the following week per country and is published with its date. It is agreement with what operators declared about their own networks — the best public reference there is — not ground truth about where any person is.
What is never claimed: that an address is a person. An address is a network; on a hosting, VPN, relay or gateway address the country is the operator's, city-level precision from free data is approximate everywhere, residential proxies are not detectable from open data and are not claimed, and the mobile, satellite and connection-type answers come from positive evidence only, so null never means residential by default. Sanctions and FATF facts are facts about a place and carry no weight.
What is kept: nothing about a lookup — no history row, no log line with the address — beyond a keyed seven-day marker and a velocity count under the same hash, both skipped by privacy: true. Outcome reports are stored as salted hashes for 90 days; the one thing read across accounts is the number of accounts that reported an address. Your own allow and deny lists are the one signal in the answer that is yours rather than the Internet's.
Address verification
A postal address is read against its own country's format from a table covering 207 countries and territories and the postal operators' box rules for 52, both shipped with the service and versioned. Where an official register of buildings is synced — thirteen countries and three German Länder today — the building can be confirmed; the United States' national address database and France's national address base are partial by their publishers' own account, Brazil's census address list because a census list is a snapshot, and each Land's register because it covers one Land. Great Britain's register, Ordnance Survey's Open Names, lists streets and never buildings, so from open data a British street can be confirmed and a British building cannot; in the United States a house number can also be placed inside a range the Census Bureau publishes for its street. Where a postcode directory is synced — the ONS Postcode Directory for Great Britain, without Northern Ireland, and GeoNames postal codes for about a hundred other countries — a postcode's existence is confirmed, and in Great Britain whether it is live or terminated; only a directory that reaches the operator's published total may say a postcode does not exist. The open company registers say how many companies are registered at an address, counting only the companies each register still lists — a dissolved, withdrawn, revoked or merged company is not counted, nor a French establishment whose owner has opposed publication of its address — and the mail-receiving operators' own branch lists say whether it is a mail drop. Registers refresh weekly or monthly, as each publisher releases them, and the US number ranges monthly; the postcode directories, the company index and the mail-drop lists refresh weekly, on Saturdays.
What is measured: every week, a sample of rows taken straight out of each register's own file is sent through the ordinary pipeline, and the share that comes back as a premise match is published. It is a self-consistency check — whether the index can find what the register holds — and it is presented as that, never as coverage of a country's addresses. Every Sunday, too, a seeded sample of up to 2,000 addresses from each installed company register — registered offices and business addresses as the companies filed them — goes through the ordinary lookup, uncharged and unlogged, and the address product page publishes how far each got: the building, the street, the postcode only, nowhere, no register to ask, or refused as written. That measures the matcher on addresses other people wrote, skewed urban and towards formation agents; it is not coverage either, and only counts are kept.
What is never claimed: that an address absent from a partial register does not exist (exists is null there, and the weight for a missing address fires only when a complete register says so); who lives or works at an address; deliverability, which is a licensed answer and is not enabled, so the response says the check did not run.
What is kept: nothing about a lookup beyond the keyed seven-day marker. A monitored list is the one place an address is stored, because re-checking it later is the point; outcome reports about addresses are your own account's and are never pooled across accounts.
Business verification
A business identifier is read against register copies downloaded onto the server: the Legal Entity Identifier reference data the Global Legal Entity Identifier Foundation publishes daily under a CC0 dedication, synced weekly, and the UK company data Companies House publishes monthly under the Open Government Licence, so a UK answer can be up to five weeks behind the live register and says so. No third party sits in the request path. The LEI check digit is verified as a typing check, and an identifier a register does not carry answers "not carried here", never "does not exist".
What is measured: every week, that each register file parses to the identifiers it should; a register that parses to nothing is reported as unmeasured and fails the check, because nothing measured must never read as a clean sheet.
What is never claimed: affiliation with the foundation that publishes the LEI data, official status for any register copy, or a registered address, which is deliberately not in the answer because an identifier alone does not say whether a company or a sole trader stands behind it.
What is kept: nothing about a lookup beyond the credit ledger entry that bills it, and a monitor's saved identifiers with their last status.
Cross-signal consistency
A consistency call runs any subset of an email address, a phone number, an IP address and a postal address through the product that owns each, then compares fields those four pipelines already computed. No dataset stands behind the comparison, it touches no database and no network, and it is free; each leg bills as its own product does.
What it answers is evidence, never a verdict: a comparison is emitted only when both its signals answered; a null field withholds as missing_value and never reads as a disagreement; when the IP is a VPN exit, a relay, a datacenter egress or a corporate gateway, the country comparisons are withheld as low_confidence, because that country is the operator's; the distance between an IP's location and a postal address is reported in kilometres and never raises a flag. There is deliberately no score, no risk level and no recommendation.
What is kept: exactly what the legs keep — the email leg's history row, nothing from the other three — and the comparison itself is returned, not retained.