Skip to content
ProofTell
Sign inSign up
Fraud detection & risk signals

Every fraud
has a tell.

ProofTell checks a phone number, an email address and an IP address in one API call, and returns a risk score, a verdict and the reasons behind it.

Sandbox keys are free. Evaluating for your company? Ask for a $10 credit from your dashboard.

Sign-up check
+1 500 555 0002
3 signals · reference signup-48213
Deny95 / 100
  • The IP address is a Tor exit node.
    203.0.113.66
    +40
  • The email address uses a disposable provider.
    disposable@sandbox.prooftell.com
    +35
  • The number is a VoIP line, easy to obtain anonymously.
    +1 500 555 0002
    +20
Checkout check Allow
order-77300 / 100
Valid mobile lineMailbox existsSame country
Phone engine
Veriphone
In production since 2019
Email engine
Verimail
Asks the mail server, sends nothing
Phone coverage
243
Countries and territories
Hosting
European Union
Belgium, on Google Cloud
One call

Send what you know. Get back what matters.

  1. 1
    Send a phone, an email, an IP, or all three
    Whatever you collect at sign-up, login or checkout.
  2. 2
    We run every signal in parallel
    The numbering plan and line type, the mailbox and its domain, the network behind the address.
  3. 3
    You get a score, a verdict and the tells
    A number from 0 to 100, allow, review or deny, and every point explained in plain words.

The sample is the sandbox’s real answer. Run it with a pt_test_ key and you get exactly this, free. With a live key the same call costs $0.0045.

Read the API reference
curl https://api.prooftell.com/v1/assess \
  -H "Authorization: Bearer $PROOFTELL_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "phone": "+15005550002",
    "email": "disposable@sandbox.prooftell.com",
    "ip": "203.0.113.66",
    "reference": "signup-48213"
  }'
const res = await fetch("https://api.prooftell.com/v1/assess", {
  method: "POST",
  headers: {
    "Authorization": `Bearer ${process.env.PROOFTELL_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    phone: "+15005550002",
    email: "disposable@sandbox.prooftell.com",
    ip: "203.0.113.66",
    reference: "signup-48213",
  }),
})
const { score, verdict, reasons } = await res.json()
import os, requests

res = requests.post(
    "https://api.prooftell.com/v1/assess",
    headers={"Authorization": f"Bearer {os.environ['PROOFTELL_KEY']}"},
    json={
        "phone": "+15005550002",
        "email": "disposable@sandbox.prooftell.com",
        "ip": "203.0.113.66",
        "reference": "signup-48213",
    },
)
result = res.json()
print(result["verdict"], result["score"])
Response
{
  "id": "asm_oxyq6rmz74bzsrxm",
  "mode": "test",
  "reference": "signup-48213",
  "score": 95,
  "verdict": "deny",
  "reasons": [
    { "code": "phone_voip", "points": 20,
      "message": "The number is a VoIP line, easy to obtain anonymously." },
    { "code": "email_disposable", "points": 35,
      "message": "The email address uses a disposable provider." },
    { "code": "ip_tor", "points": 40,
      "message": "The IP address is a Tor exit node." }
  ],
  "signals": {
    "phone": { "status": "ok", "cost": "0.0000", "result": { … } },
    "email": { "status": "ok", "cost": "0.0000", "result": { … } },
    "ip":    { "status": "ok", "cost": "0.0000", "result": { … } }
  },
  "ruleset": "2026-10-01",
  "cost": "0.0000",
  "currency": "USD",
  "createdAt": "2026-10-01T07:55:41Z"
}
The tells

Fraud leaves traces. We know where to look.

No black box. Every score comes with the signals that drove it, so your team can explain every decision, to a customer or to an auditor.

Phone

VoIP or virtual number

Cheap to create by the thousand and easy to obtain anonymously. The favorite of fake-account farms.

Phone

A number that cannot exist

Wrong length, unassigned prefix, a typo or an invention. It fails the numbering plan of its own country.

Email

Disposable inbox

A mailbox that expires in ten minutes rarely belongs to a customer who plans to stay.

Email

A mailbox nobody owns

The mail server says there is no such user. Real customers give addresses that receive mail.

IP

Hidden network

Tor exits, VPN providers and datacenter ranges, where real shoppers rarely come from.

Phone + IP

Two countries at once

A number from one country, a connection from another. Not damning alone; it weighs in with the rest.

Explainable by design

A score your team can defend.

Every point has a reason
Each rule that fires adds points and a sentence. The score is their sum, capped at 100. Nothing hides inside a model.
The cut-offs are yours
You decide where review starts and where deny starts, per organization, from the dashboard.
A versioned rule set
Every response names the rule set that produced it, so a decision can still be explained after the rules have moved on.
An outage never lowers the bar
When a signal cannot answer, the response says so and the verdict is raised to at least review. A gap is never filled with a guess.
How the score works
Login check
+44 7700 900123
3 signals · rule set 2026-10-01
Review
45 / 10020 + 15 + 10
0Allow · Review · Deny100
  • The IP address belongs to a VPN provider.
    +20
  • The phone number’s country (GB) differs from the IP address’s (NL).
    +15
  • The domain accepts any address, so the mailbox could not be confirmed.
    +10
phoneemailpt_phone_typept_email_result
+14155550132dana@northwind.examplemobiledeliverable
+442079460958sales@contoso.examplefixed_linecatch_all
+15005550002x9@tempbox.examplevoipdisposable
+33639980123lee@fabrikam.examplemobileundeliverable
Bulk

A whole file, checked the same way.

Upload a CSV or an Excel file, pick the columns, and download it back with the results added to every row, in the order you sent them. Duplicates run once. Files are deleted 30 days after upload.

Bulk verification
Pricing

Pay for what you check. In dollars.

One public rate card for everyone. You are charged per signal that returns a result, from a balance that never expires.

Phone intelligence
$1.00 per 1,000

$0.0010 per number.

Email verification
$3.00 per 1,000

$0.0030 per address.

IP intelligence
$0.50 per 1,000

$0.0005 per address.

Volume is rewarded on the money, not on the rate: top up $5,000 and we add $750. Enterprise contracts are invoiced.

See the rate card
Security & privacy

Built to keep little. Written to pass a review.

Where your data goes, who touches it and when it is deleted are published, down to the sub-processor list and the things we do not have.

Hosted in the EU

The API, the database and file storage run in Belgium, on Google Cloud.

Retention you control

Assessments are kept 90 days by default. Choose a shorter period, or zero, and nothing is stored.

Inputs stay out of logs

Phone numbers, addresses and IPs travel in request bodies and never reach our logs or error messages.

A DPA you can file today

Pre-signed, GDPR Article 28, applies to every account. No call, no countersignature.

Where it pays off

One check, at every door.

Account opening

Score every sign-up before it costs you a welcome bonus, a free trial or a support ticket.

Checkout

Send the order’s phone, email and IP. Let the clean ones through, hold the rest for a second look.

Lead capture

A real mobile line and a mailbox that exists are stronger buying signals than a form that was merely filled in.

List hygiene

Upload the file you already have and get it back with every phone, address and IP checked.

FAQ

Questions, answered plainly.

What does ProofTell check?
Three things about the person in front of you: the phone number (is it valid, what kind of line, which carrier, which country), the email address (does the mailbox exist, is it disposable, a catch-all or a role account) and the IP address (Tor, VPN or datacenter, and where it is). The risk score weighs them together.
How is the score calculated?
By a transparent, versioned set of rules. Each rule that matches adds points and a readable reason; the score is the sum, capped at 100; your thresholds turn it into allow, review or deny. There is no machine-learning model in the path, so the same signal results always give the same score, and every score can be explained.
What happens when one of the signals is down?
You still get an answer. The score comes from the signals that ran, the missing one is reported as unavailable at no charge, and the verdict is raised to at least review, so an outage can never turn a deny into an allow. If none of the signals you asked for could run, the call fails with a 503 and your own fallback applies.
Do you contact the person I am checking?
No. Nothing is sent to the phone and no message lands in the inbox. The email check asks the mail server whether the mailbox exists and stops before any message is delivered. ProofTell does not send one-time codes.
Can I use a single signal on its own?
Yes. /v1/phone, /v1/email and /v1/ip each sell one signal at its own rate, and file uploads run them over a whole list. /v1/assess is the one endpoint that scores.
How much does it cost?
You pay per signal that returns a result, from one balance in US dollars: $1.00 per 1,000 for phone intelligence, $3.00 per 1,000 for email verification, $0.50 per 1,000 for IP intelligence. A full check with all three is $4.50 per 1,000. No plans and no credits. The pricing page has the whole rate card.
Is there a free trial?
There is no free plan. Sandbox keys are free: they return simulated, deterministic results for documented inputs, so you can build your integration without paying. If you are evaluating ProofTell for your company, sign up with your work email and ask for a $10 evaluation credit from the Billing page of your dashboard.
Where is my data processed, and for how long is it kept?
In the European Union, in Belgium, with one exception the email check requires: asking an address’s mail server whether the mailbox exists goes through verification servers in several countries. Single lookups are not stored. Assessments are kept for 90 days by default so you can review them, and you can choose a shorter period or switch storage off. Uploaded files are deleted 30 days after upload, or as soon as you delete them. The security page has the detail.
Do you sign a DPA, or our own contract?
The data processing agreement is published and pre-signed, and applies to every account. If your policies require a signed master services agreement, a service level agreement or a negotiated DPA, that is what the enterprise agreement is for.

Find the tell before it costs you.

Create an account, take a sandbox key, make your first call in minutes.