openapi: 3.2.0 info: title: EmailRep Alpha Query email address API version: 1.0.0 description: 'EmailRep is a system of crawlers, scanners and enrichment services that collects data on email addresses, domains, and internet personas. EmailRep uses hundreds of data points from social media profiles, professional networking sites, dark web credential leaks, data breaches, phishing kits, phishing emails, spam lists, open mail relays, domain age and reputation, deliverability, and more to predict the risk of an email address. Operated by Sublime Security' servers: - url: https://emailrep.io - url: http://emailrep.io tags: - name: Query email address paths: /{email}: get: tags: - Query email address summary: Query an email parameters: - name: email in: path description: Email address being queried required: true schema: type: string - name: summary in: query description: Return human-readable summary required: false schema: type: boolean responses: '200': description: Query successful content: application/json: schema: $ref: '#/components/schemas/QueryResponse' '400': description: Invalid email '401': description: Invalid api key (for authenticated requests) '429': description: Too many requests. Contact us for an api key operationId: getByEmail x-operation-id-source: derived components: schemas: QueryResponse_details: type: object properties: blacklisted: type: boolean example: false description: the email is believed to be malicious or spammy malicious_activity: type: boolean example: false description: the email has exhibited malicious behavior (e.g. phishing or fraud) malicious_activity_recent: type: boolean example: false description: malicious behavior in the last 90 days (e.g. in the case of temporal account takeovers) credentials_leaked: type: boolean example: true description: credentials were leaked at some point in time (e.g. a data breach, pastebin, dark web, etc.) credentials_leaked_recent: type: boolean example: false description: credentials were leaked in the last 90 days data_breach: type: boolean example: true description: the email was in a data breach at some point in time first_seen: type: string example: 07/01/2008 description: the first date the email was observed in a breach, credential leak, or exhibiting malicious or spammy behavior ('never' if never seen) last_seen: type: string example: 02/25/2019 description: the last date the email was observed in a breach, credential leak, or exhibiting malicious or spammy behavior ('never' if never seen) domain_exists: type: boolean example: true description: valid domain domain_reputation: type: string example: high description: high/medium/low/n/a (n/a if the domain is a free_provider, disposable, or doesn't exist) new_domain: type: boolean example: false description: the domain was created within the last year days_since_domain_creation: type: integer example: 10289 description: days since the domain was created suspicious_tld: type: boolean example: false description: suspicious tld spam: type: boolean example: false description: the email has exhibited spammy behavior (e.g. spam traps, login form abuse) free_provider: type: boolean example: false description: the email uses a free email provider disposable: type: boolean example: false description: the email uses a temporary/disposable service deliverable: type: boolean example: true description: deliverable accept_all: type: boolean example: true description: whether the mail server has a default accept all policy. some mail servers return inconsistent responses, so we may default to an accept_all for those to be safe valid_mx: type: boolean example: true description: has an MX record spoofable: type: boolean example: false description: email address can be spoofed (e.g. not a strict SPF policy or DMARC is not enforced) spf_strict: type: boolean example: true description: sufficiently strict SPF record to prevent spoofing dmarc_enforced: type: boolean example: true description: DMARC is configured correctly and enforced profiles: type: array example: - spotify - linkedin - myspace - instagram - twitter - flickr - vimeo - angellist - pinterest description: online profiles used by the email items: type: string QueryResponse: type: object properties: email: type: string example: bill@microsoft.com description: email address queried reputation: type: string example: high description: high/medium/low/none suspicious: type: boolean example: false description: whether the email address should be treated as suspicious or risky references: type: integer example: 59 description: total number of positive and negative sources of reputation. note that these may not all be direct references to the email address, but can include reputation sources for the domain or other related information details: $ref: '#/components/schemas/QueryResponse_details' securitySchemes: Key: type: apiKey name: Key in: header