Catch impersonated senders before anyone replies

Lookalike domains and spoofed senders slip past busy teams and turn into wire fraud. Verify the domain age, DMARC and SPF posture, and risk behind every sender before anyone trusts the email.

https://phonevalidation.abstractapi.com/v1/
    ? api_key = YOUR_API_KEY
    & phone = 14154582468

{
    "phone": "14154582468",
    "valid": true
    "risk_score": 0.1,
    "registered_location": "San Francisco",
    "carrier": "Verizon USA",
    "line_type": "Mobile",
    "local_format": "4154582468",
    "international_format": "+14154582468",
"country_prefix" : "+1",
    "country_code": "US",
    "country_name":
"United Stated of America"
}

phone number validation api

{ "email": "ceo@acme-corp.co", "domain_age": 4, "is_free_email": false, "is_disposable_email": false, "is_dmarc_enforced": false, "is_spf_strict": false, "domain_risk_status": "high" }

The signals that expose an impersonated sender

A brand-new domain age on a sender claiming to be an established brand.
Missing or weak DMARC and SPF posture on the sending domain.
A free-webmail or disposable address using an executive's name.
A clear domain and sender risk status you can act on. SOC 2 compliant.
A clear domain and sender risk status you can act on. SOC 2 compliant.
Trusted to stop email impersonation by teams at
stars rating
4.8 from 1,863 votes
Logo compass
Wolters (1)
SalesforceLogo googleLogo pepsicoLogo wellfargo
Logo linkedinLogo paramount
Shadow left.avifShadow right.avif

How to verify a sender before you trust it

Every request resolves in real time and returns structured data in under 300ms.
Send the sender's address
Pass the from-address to Abstract at vendor onboarding, invoice approval, or signup.
Check domain and auth posture
Get domain age, DMARC and SPF posture, free and disposable flags, and a risk status.
Trust, review, or block
Approve known-good senders, review the borderline, and block the clear impersonations.
Real time, not static
Every field is fetched at request time from current sources, not served from a stored snapshot that ages between refreshes.
Verify senders through the API
stars rating
4.8 from 1,863 votes
Check domain age, DMARC and SPF posture, and sender risk in one call.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
No credit card required

Why teams verify senders with Abstract

Domain age and lookalikes
Flag brand-new domains and lookalikes registered to imitate a brand you trust.
Free, disposable, and risky senders
Catch free-webmail and disposable addresses, and domains on risky top-level domains.
DMARC and SPF posture
Check whether a sending domain enforces DMARC and a strict SPF policy, or leaves the door open.
A risk status you can act on
Get a clear sender risk status you feed into vendor onboarding, invoice approval, or signup checks.
For more information check our

The best build
on Abstract

Spammy signs up were an issue for us for a while, and we struggled to come up with the best way to identify all the variations in bad emails we were getting. Thankfully we found and quickly integrated with Abstract's email validation API, which saved us a bunch of time and gave us peace of mind.
Chris Stanley, Scope

Frequently asked questions

What is email impersonation?

Email impersonation is when someone poses as a trusted person or company to trick your team, usually to move money or steal data. It comes in two forms: spoofing a real domain, and registering a lookalike domain that reads almost the same. The goal is to get a busy person to trust the sender and act.

What is CEO fraud?

CEO fraud is a type of impersonation where an attacker poses as an executive and pressures an employee to pay an invoice, send gift cards, or share data fast. The email often comes from a lookalike domain or a free address using the executive's name, counting on urgency and authority to skip the usual checks.

What is the difference between spoofing and impersonation?

Spoofing forges the real domain in the From address, which SPF, DKIM, and DMARC are designed to catch. Impersonation is broader: it also includes lookalike domains and display-name tricks that pass authentication because the sender technically owns that domain. Stopping both needs authentication checks plus domain and sender risk signals.

How do SPF, DKIM, and DMARC stop spoofing?

SPF, DKIM, and DMARC verify that an email actually came from the domain it claims, so they block most direct spoofing of a domain you protect. What they cannot catch is a lookalike domain the attacker legitimately owns, or a free-webmail account using a real name. That gap is where domain-age and sender-risk signals matter.

How can you check if a sender is legitimate?

Check the identity behind the address before you trust it. Look at the domain age, whether it is a free or disposable provider, its DMARC and SPF posture, and its overall risk status. A brand-new lookalike domain with no DMARC and a high risk score is a strong impersonation signal, even when the email looks legitimate.

What is a lookalike domain?

A lookalike domain is one registered to closely resemble a real one, using swaps like rn for m, a different top-level domain, or an extra word. It passes email authentication because the attacker owns it, so authentication alone will not flag it. Domain age and risk signals are what expose it.

How does Abstract help catch impersonated senders?

Abstract verifies the sender identity behind an address in the flows you control, like vendor onboarding, invoice approval, or signup. Call the Email Reputation API to get domain age, free and disposable flags, DMARC and SPF posture, and a risk status. It is a sender-verification layer, not an inbox-security product, so pair it with your email gateway. Start free.

Start verifying senders for free
stars rating
4.8 from 1,863 votes
Free to start. No credit card required.
get free api key
No credit card required