Endpoint
POST https://requiems.xyz/v1/systems/user/verify
Verify User
Deep-verify an email address using domain-level signals including WHOIS age, MX records, and domain availability. Optional IP check. Use for high-value or suspicious accounts.
Parameters
| Name |
Type |
Required |
Location |
Description |
email |
string |
yes |
body |
Email address to verify. Domain-level WHOIS, MX, and DNS checks are run automatically. |
ip_address |
string |
no |
body |
Optional IPv4 or IPv6 address. When provided, VPN and proxy signals are added to the result. |
Request Example
{
"email": "user@example.com",
"ip_address": "45.33.32.156"
}
Response Example
{
"data": {
"verified": true,
"confidence": 0.92,
"risk_score": 0.08,
"flags": [],
"signals": {
"email": {
"valid": true,
"disposable": false,
"mx_valid": true
},
"domain": {
"age_days": 4521,
"has_mx": true,
"has_a_records": true,
"available": false
},
"ip": {
"is_vpn": false,
"is_proxy": false,
"fraud_score": 0.02
}
}
},
"metadata": {
"timestamp": "2026-01-01T00:00:00Z"
}
}
Response Fields
| Field |
Type |
Description |
verified |
boolean |
True when risk score is below 0.3, confidence is above 0.5, email is valid, domain has MX, and domain is registered |
confidence |
number |
Confidence in the verification result, based on how many signals resolved |
risk_score |
number |
Composite risk score from 0.0 to 1.0 |
flags |
array |
Triggered risk flags. Possible values: email_invalid, disposable_email, no_mx, domain_not_registered, young_domain, whois_unavailable, ip_risk |
signals.email |
object |
Email validation result |
signals.domain |
object |
Domain intelligence including WHOIS age, MX and A record presence, and registration status |
signals.ip |
object |
IP risk signals. Null when ip_address was not provided |
Errors
undefined 422 — email field is missing or empty
undefined 401 — Missing or invalid API key
1---2name: identity-risk-post-verify3description: Deep-verify an email address using domain-level signals including WHOIS age, MX records, and domain availability. Optional IP check. Use for high-value or suspicious accounts.4---5
6## Endpoint
7
8**POST https://requiems.xyz/v1/systems/user/verify**
9
10## Verify User
11
12Deep-verify an email address using domain-level signals including WHOIS age, MX records, and domain availability. Optional IP check. Use for high-value or suspicious accounts.
13
14## Parameters
15
16| Name | Type | Required | Location | Description |
17| ---- | ---- | -------- | -------- | ----------- |
18| `email` | string | yes | body | Email address to verify. Domain-level WHOIS, MX, and DNS checks are run automatically. |
19| `ip_address` | string | no | body | Optional IPv4 or IPv6 address. When provided, VPN and proxy signals are added to the result. |
20
21## Request Example
22
23```json
24{
25 "email": "user@example.com",
26 "ip_address": "45.33.32.156"
27}
28```
29
30## Response Example
31
32```json
33{
34 "data": {
35 "verified": true,
36 "confidence": 0.92,
37 "risk_score": 0.08,
38 "flags": [],
39 "signals": {
40 "email": {
41 "valid": true,
42 "disposable": false,
43 "mx_valid": true
44 },
45 "domain": {
46 "age_days": 4521,
47 "has_mx": true,
48 "has_a_records": true,
49 "available": false
50 },
51 "ip": {
52 "is_vpn": false,
53 "is_proxy": false,
54 "fraud_score": 0.02
55 }
56 }
57 },
58 "metadata": {
59 "timestamp": "2026-01-01T00:00:00Z"
60 }
61}
62```
63
64## Response Fields
65
66| Field | Type | Description |
67| ----- | ---- | ----------- |
68| `verified` | boolean | True when risk score is below 0.3, confidence is above 0.5, email is valid, domain has MX, and domain is registered |
69| `confidence` | number | Confidence in the verification result, based on how many signals resolved |
70| `risk_score` | number | Composite risk score from 0.0 to 1.0 |
71| `flags` | array<string> | Triggered risk flags. Possible values: email_invalid, disposable_email, no_mx, domain_not_registered, young_domain, whois_unavailable, ip_risk |
72| `signals.email` | object | Email validation result |
73| `signals.domain` | object | Domain intelligence including WHOIS age, MX and A record presence, and registration status |
74| `signals.ip` | object | IP risk signals. Null when ip_address was not provided |
75
76## Errors
77
78- `undefined` **422** — email field is missing or empty
79- `undefined` **401** — Missing or invalid API key