Platform

Email fraud detection

Every email is scored the moment it arrives, so fake and high-risk addresses are caught before they become a lead, a customer record, or a training signal for your ads.

What it is

Email fraud detection is the email half of DataCops' own fraud engine, the same system that runs IP intelligence. Each address is scored from 0 to 100 on its domain, its mail setup, its username and the device it came from, and gets a plain-English list of reasons. SignupCops and LeadCops use the score to keep fake accounts away from your ad platforms, and you can call it from your own backend.

How a check runs

  1. The email arrives. Through the DataCops script when someone signs up, logs in or fills a form, through a LeadCops form, or through a call from your server.
  2. It is normalized. Lowercased, any +tag removed, and dots ignored for Gmail, so j.o.h.n+promo@gmail.com and john@gmail.com are seen as one person.
  3. The domain is checked. Against a list of nearly 160,000 known disposable domains, then its mail records, its age and the mail servers it shares.
  4. The username is checked for random strings and bulk-made patterns.
  5. The visit is checked. When it comes through the script, the visitor's IP and the other emails seen on the same device are checked too.
  6. You get a score, a label, an action and the reasons. Results are cached, so a repeat check is fast.

What it checks

SignalWhat it catches
Disposable domainThrowaway inboxes from temporary mail services.
Disposable infrastructureNew throwaway domains that run on the mail servers of known temp-mail services.
Shared fraud infrastructureDomains whose mail servers are shared with known fraud mail services.
Email authenticationDomains with no SPF, DKIM or DMARC set up, which real senders almost always have.
Domain ageDomains registered days or weeks ago.
Catch-all domainDomains that accept mail for any address, so the inbox may not be real.
Random usernameUsernames that look machine-made.
Bulk patternShapes like name.surname plus digits, long digit runs, or a doubled word.
Plus addressingOne inbox used to open many accounts with +tags.
Online presenceWhether the address has a public profile. None, on a free provider with a random name, points to a one-time address.
Lookalike domainDomains made to look like a real brand.
Risky TLD and IP velocityHigh-risk domain endings, and many emails from one IP in an hour or a day.

It also suggests a fix for common typos, like a misspelt gmail.com, so a real person with a typo is not treated as fraud.

Score, label and action

ScoreLabelAdvised action
80 to 100criticalBLOCK
50 to 79highCHALLENGE
30 to 49mediumCHALLENGE
0 to 29lowALLOW

The action is advice. Your app decides what to do. The block line is set higher than for IP checks on purpose, because turning away a real person's email costs you a customer. CHALLENGE usually means "ask them to confirm their email" rather than "reject".

What you get back

  • A risk score from 0 to 100, a label and an action.
  • Reasons in plain words, like "Domain is a known disposable/temporary email service", and short tags like throwaway_domain or random_username.
  • The mail setup: SPF, DKIM, DMARC and mail servers.
  • Flags for disposable, free provider, plus addressing, domain age and catch-all.
  • A presence score from 0 to 100 for how likely it is a real person.
  • Through the script: linked emails seen on the same device, which is how one person making many accounts is caught.

How it is used

  • SignupCops. Every new signup is scored. The signup itself goes ahead, but the CompleteRegistration conversion is held back from your ad platforms when the action is BLOCK, the label is high or critical, or the domain is disposable. It is also held when another recent account came from the same device.
  • LeadCops. Each form can block disposable emails, free emails, domains that cannot receive mail, and VPN submissions, with a clear message to the visitor. High-risk submissions are saved as blocked, are not billed and are not delivered.
  • Your dashboard. Each signed-up user shows its score and reasons, including checks from your own server.

Good to know

Good to know before you start

  • The check reads public records about the domain and the address. It does not send mail to the inbox.
  • SignupCops holds the ad conversion, not the signup. Your own app decides whether to let the account in.
  • Results are cached, so checking the same email again is fast.
  • For signups through the script, turn on auto identity capture or call identifyUser so DataCops sees the email.

Call it from your server

Use a private API key from Settings, API Keys. Never put a private key in browser code.

cURL
curl -X POST https://api.joindatacops.com/api/v1/services/email/check \
  -H "x-dc-key: dcp_your_private_api_key" \
  -H "Content-Type: application/json" \
  -d '{ "email": "person@example.com" }'

An example answer for a throwaway address, trimmed:

200 OK
{
  "success": true,
  "data": {
    "emailInfo": {
      "status": "ok",
      "normalized_email": "person@tempmail.example",
      "risk_score": 95,
      "risk_label": "critical",
      "action": "BLOCK",
      "reasons": ["Domain is a known disposable/temporary email service"],
      "tags": ["throwaway_domain"],
      "fraud_signals": { "disposable_domain": true }
    },
    "userInfo": null,
    "ipInfo": null
  }
}

If the email was already seen on your site through the script, userInfo and ipInfo are filled in from that visit, including linked emails from the same device. A missing email returns 400. The Node SDK wraps this call as checkEmail.

Plans and limits

Every site gets 500 email checks free, for life, not per month. On the Free plan that is the limit, and further checks return 429 until you upgrade. On paid plans checks continue and are billed per 500.

Was this page helpful?