Download OpenAPI specification:Download
Checks you run before taking a piece of data at face value: signing someone up, sending them a verification code or accepting a payment.
Every check goes through the same call. The SERVICIO parameter picks which one, and parameters that do not belong to that check are ignored: you can always send the same structure and only change SERVICIO. New checks (email, IP…) will arrive here, with no second URL for you to integrate.
| SERVICIO | What it checks |
DatosTelefono | Who is behind a number: the carrier serving it, its porting history (which carrier it came from and when it was ported) and the line type. |
DatosEmail | What is behind an address: whether the domain receives mail and is free, disposable or its own, whether the account belongs to a person or to a department, and whether the mailbox exists. |
DatosIP | Where someone connects from: country, city, carrier, whether it is a home line, a mobile or a data centre, and whether it arrives through an anonymous network. |
Of everything you can learn about a number without calling it, these two are the ones that actually change a decision.
The porting date. A number that changed carrier three days ago, right before a significant operation, is the signature of a SIM swap: the attacker moves the victim's number to another carrier and from then on receives their verification codes. If you are about to send a code to that number, verify through another channel first.
The line type. An Internet line (VoIP) where a mobile should be is usually a throwaway number: minutes to get, minutes to abandon. And premium-rate or machine-to-machine numbering is nobody's personal phone.
On top of that, the response carries a calculated risk from 0 to 100 with the reasons in plain text. It is not a verdict and it does not decide for you: it is what the data supports, explained, so your system can apply your own policy.
It is the same check we run before every Certified Email delivery, made available to you. It goes from cheap to expensive and stops as soon as it has the answer:
1. Syntax of the address.
2. The domain receives mail: its mail records are looked up in DNS. A domain without them cannot receive anything, so the address does not exist —and that is known without asking anyone.
3. Disposable domain, the kind created in a second that nobody ever reads again.
4. Free domain and account type: a person, a department (info@, support@…) or a tagged alias (john+shop@).
5. Whether that address already bounced a delivery of ours. This is our own information, and it beats any prediction: it is not that it will probably fail, it is that it already did.
6. And only then, whether the mailbox exists, by asking the destination mail server.
Step 6 uses two different verifiers: some servers greylist, some drop the connection, some answer differently depending on who is asking, so when the first one says «I don't know» the second one is consulted. Even so, catch-all domains accept any address: there nobody can confirm a specific account exists, and we say exactly that instead of inventing a yes.
For Spanish mobile numbers we use our own porting registry, which is what lets us tell you the carrier the number came from and the exact date of the change. For Spanish landlines and any foreign number we query international numbering data. You do not have to choose: send the number and it is resolved wherever it has to be.
The Fuente field of the response tells you which was used. Not every country publishes porting history: when there is no data, Portabilidad.Consta comes back as 0 —which is not the same as «not ported», and that is why they are told apart.
You are charged per resolved check. If it cannot be resolved the call returns -4 and nothing is charged.
The same check repeated within a minute (a double submit, a retry from your system) returns the previous result flagged with Repetida=1 and is not charged either. After that minute it is looked up again for real and charged again: the data may have changed, and yesterday's porting is precisely the one you care about.
Same as the rest of our APIs: Basic authentication with your user and your API Token, which you will find in your panel under Your data → Configure → Security. Remember to authorise there the public IP address you will be calling from.
Runs an anti-fraud check. The SERVICIO parameter picks which one: DatosTelefono returns the carrier, the porting history and the line type of the number; DatosEmail returns the domain, the account type and whether the mailbox exists; DatosIP returns where someone connects from and what kind of connection they use. All three also return the calculated risk and its reasons.
Response fields depend on the check: Numero, Linea, Operadora and Portabilidad only come with DatosTelefono, Email, Dominio, Cuenta, Buzon, Historial and Reputacion only with DatosEmail, and IP, Ubicacion, Operador, Conexion and ListasNegras only with DatosIP. Res, Servicio, Consulta, Riesgo, Fuente, Creditos and Cred always come back.
| Servicio | string Enum: "DATOSTELEFONO" "DATOSEMAIL" "DATOSIP" Example: Servicio=DatosTelefono Check you want to run. Case insensitive.
|
| Telefono | string Example: Telefono=600000000 Number to check, required with |
| Prefijo | string Example: Prefijo=+34 International dialling code of the number's country, with or without |
string Example: Email=name@domain.com Email address to check, required with | |
| Listasnegras | string Enum: 0 1 Example: Listasnegras=1 Only with |
| Filtraciones | string Enum: 0 1 Example: Filtraciones=1 Only with |
| Ip | string Example: Ip=80.24.10.5 IPv4 address to check, required with |
| Resp | string Enum: "TXT" "JSON" "XML" Example: Resp=JSON Response format for this call.
|
Parameters are sent in the body of the POST request, either as a JSON object (Content-Type application/json, RECOMMENDED) or as an application/x-www-form-urlencoded form. In the form format, array or object parameters are sent as a JSON-encoded string. Parameter names are case-insensitive. The detailed description of each parameter is in the parameters section of this operation.
| Servicio | string |
| Telefono | string |
| Prefijo | string |
string | |
| Listasnegras | string |
| Filtraciones | string |
| Ip | string |
| Resp | string |
| Res required | integer <int32> Result of the call
|
| Servicio | string Check that was run. |
| Consulta | string The data that was checked, normalised to international format. |
Array of arrays Only with | |
| Dominio | Array of arrays Only with |
| Cuenta | Array of arrays Only with |
| Buzon | Array of arrays Only with |
| Historial | Array of arrays Only with |
| Reputacion | Array of arrays Email checks only. |
| Numero | Array of arrays Only with |
| Linea | Array of arrays Only with |
| Operadora | Array of arrays Only with |
| Portabilidad | Array of arrays Only with |
| IP | Array of arrays Only with |
| Ubicacion | Array of arrays Only with |
| Operador | Array of arrays Only with |
| Conexion | Array of arrays Only with |
| ListasNegras | Array of arrays Public abuse blocklists. With |
| Filtraciones | Array of arrays Only with |
| Aviso | string A warning about the call itself when there is one: for instance, that breaches could not be checked and therefore the extra was not charged. Empty or absent otherwise. |
| Riesgo | Array of arrays Risk from 0 to 100, its |
| Fuente | string Where the data comes from: |
| Repetida | integer Set to |
| Creditos | number Credits charged for this call. |
| Cred | number Credits left after the check. |
| Error | string Description of the problem when Res is negative. |
{- "Servicio": "DatosTelefono",
- "Telefono": "600000000",
- "Prefijo": "+34",
- "Email": "name@domain.com",
- "Listasnegras": "1",
- "Filtraciones": "1",
- "Ip": "80.24.10.5",
- "Resp": "JSON"
}[- {
- "Res": "1",
- "Servicio": "DatosTelefono",
- "Consulta": "+34600000000",
- "Email": "{\"Direccion\":\"name@domain.com\",\"Cuenta\":\"name\",\"Dominio\":\"domain.com\",\"Sintaxis\":1,\"Sugerencia\":\"\"}",
- "Dominio": "{\"RecibeCorreo\":1,\"Tipo\":\"gratuito\",\"TipoTexto\":\"Free (personal mailbox)\",\"Servidores\":\"mx1.domain.com, mx2.domain.com\",\"AntiguedadDias\":8412}",
- "Cuenta": "{\"Tipo\":\"personal\",\"TipoTexto\":\"Personal\"}",
- "Buzon": "{\"Estado\":\"valido\",\"Detalle\":\"The destination mail server confirms the account exists.\",\"Concluyente\":1}",
- "Historial": "{\"Rebotado\":0,\"MotivoRebote\":\"\"}",
- "Reputacion": "{\"Trampa\":0,\"Detalle\":\"\",\"Puntuacion\":12,\"Filtrada\":1,\"NumFiltraciones\":3,\"AbusoReciente\":0,\"VistaDesde\":\"2014-08-11\",\"Plataformas\":7,\"ListaPlataformas\":\"Google, Amazon, Spotify, Linkedin\"}",
- "Numero": "{\"E164\":\"+34600000000\",\"Nacional\":\"600000000\",\"Prefijo\":\"+34\",\"Pais\":\"ES\",\"PaisNombre\":\"Spain\",\"Formato\":\"600 00 00 00\",\"Valido\":1}",
- "Linea": "{\"Tipo\":\"movil\",\"TipoTexto\":\"Mobile\"}",
- "Operadora": "{\"Nombre\":\"MOVISTAR\",\"Id\":1,\"MCC\":\"214\",\"MNC\":\"7\",\"Pais\":\"ES\"}",
- "Portabilidad": "{\"Portado\":1,\"Donante\":\"ORANGE\",\"Fecha\":\"2026-08-06\",\"Dias\":6,\"Consta\":1}",
- "IP": "{\"Direccion\":\"80.24.10.5\",\"Version\":4}",
- "Ubicacion": "{\"Pais\":\"ES\",\"PaisNombre\":\"Spain\",\"Region\":\"Madrid\",\"Ciudad\":\"Madrid\",\"Continente\":\"EU\",\"ZonaHoraria\":\"+02:00\",\"EnEuropa\":1}",
- "Operador": "{\"Nombre\":\"Telefonica de Espana\",\"ASN\":\"3352\",\"ASNNombre\":\"TELEFONICA_DE_ESPANA, ES\",\"Bloque\":\"80.24.0.0/14\",\"BloqueDesde\":\"2001-06-11\",\"PaisBloque\":\"ES\"}",
- "Conexion": "{\"Tipo\":\"domestica\",\"TipoTexto\":\"Home connection\",\"Anonima\":0,\"DnsInverso\":\"80.24.10.5.dyn.user.ono.com\",\"InversoConfirmado\":1}",
- "ListasNegras": "{\"Listada\":0,\"Listas\":\"\",\"SinComprobar\":0}",
- "Filtraciones": "{\"Consultado\":1,\"Filtrada\":1,\"Numero\":4,\"Primera\":\"2013-05-02\",\"Ultima\":\"2019-01-11\",\"Sitios\":\"LinkedIn, Dropbox\",\"AnosVisible\":13}",
- "Aviso": "",
- "Riesgo": "{\"Puntos\":45,\"Nivel\":\"MEDIO\",\"Motivos\":[\"Ported to another carrier 6 days ago. Such a recent carrier change is the usual signature of a SIM swap.\"]}",
- "Fuente": "propia",
- "Repetida": "0",
- "Creditos": "0.3",
- "Cred": "1520.4",
- "Error": "The given number is not in a valid format"
}
]