VerifIP gives apps that serve customers in India an IP fraud score, VPN, proxy and Tor detection, and +91 phone and email checks through one API, with a Free plan of 10,000 requests a month and no card needed.
Before you block anything, read the section on carrier-grade NAT: on mobile networks one IP address can stand for many customers.
What does VerifIP check?
One API key covers four kinds of input, separately or together:
| Endpoint | Checks | Key fields |
|---|---|---|
GET /v1/check | IP reputation, VPN, proxy, Tor, datacenter, location, network | fraud_score, verdict, is_vpn, is_proxy, is_tor, connection_type, asn |
GET /v1/phone | Validity, country, line type, VoIP | valid, country_code, line_type, is_voip, risk_score |
GET /v1/email | Disposable domain, mail server, free or role mailbox, domain age | is_disposable, mx_found, domain_age_days, risk_score |
GET /v1/url | Phishing listings, domain age, TLS | is_phishing, domain_age_days, ssl_valid, risk_score |
GET /v1/assess | Any combination of the four, as one request | overall_risk and each answer |
Latency is <50ms p50, measured at our edge. Paid plans add batch endpoints that take 1–100 items per request. Every field is in the VerifIP reference.
Why is CGNAT a problem for IP blocking in India?
Mobile networks often share one public IPv4 address among many subscribers with carrier-grade NAT (CGNAT), so treat any mobile address as possibly shared. For an app whose customers are mostly on mobile data, that changes how IP rules behave:
- One bad actor can taint a shared address. Blocking it blocks every innocent customer sharing it at that moment.
- Per-IP rate limits misfire. A busy shared address can look like a bot simply because many people use it.
- An address does not identify a person. Two sign-ups from the same mobile address are not necessarily the same customer.
How to handle it with VerifIP:
- Enforce on
verdict, not onfraud_scoreorblocklist_count. Classification alone (VPN, proxy, Tor, hosting) keeps an address at allow; a challenge needs accusing evidence such as attack-feed listings. - Use
connection_type. VerifIP classifies the network from its ASN organisation name, and a network whose name contains Jio or Airtel comes back as Mobile, including their broadband. Prefer a step-up check (a one-time code, email confirmation) over a block for mobile addresses. - Check the person, not just the network. Add
/v1/phoneand/v1/email, or send all of them to/v1/assessas one request. - You should never see 100.64.x.x. The CGNAT range inside carriers (100.64.0.0/10) is not routable on the internet. VerifIP answers it with
is_bogon: true, score 100 and block; if your server logs one, it is reading an internal address instead of the client's public one, so fix how it reads proxy headers.
If customers reach you over IPv6, VerifIP checks those addresses too. Fewer threat lists cover IPv6, so every IPv6 answer lists the sources it could not consult in signals_unavailable.
How do I validate +91 phone numbers?
Send the number in international format, with the + encoded as %2B:
curl -sS --max-time 10 \ -H "Authorization: Bearer $VERIFIP_API_KEY" \ "https://verifip.hextner.com/v1/phone?phone=%2B91XXXXXXXXXX"
The answer includes valid, the number in E.164 form, country_code (IN), line_type (mobile, landline, voip, toll_free and others) and is_voip. A national number without the +91 prefix is not valid. Validation uses libphonenumber's numbering plans, offline: it does not tell you the operator (carrier is always empty), whether the number is active, or whether it has been ported. An invalid number scores 100, a VoIP number 30 and a toll-free number 10. Use a one-time code when you need proof that the customer holds the number.
What does a typical sign-up check look like?
curl -sS --max-time 10 \ -H "Authorization: Bearer $VERIFIP_API_KEY" \ --get \ --data-urlencode "ip=203.0.113.7" \ --data-urlencode "email=user@example.com" \ --data-urlencode "phone=+91XXXXXXXXXX" \ "https://verifip.hextner.com/v1/assess"
203.0.113.7 is a documentation address and comes back as a bogon; send the real client IP. overall_risk is the highest of the parts after weighting (IP × 1.0, URL × 0.9, email × 0.8, phone × 0.7), rounded down, and the response includes each full answer. The whole call counts as one request against your allowance.
How much does it cost?
| Plan | Requests / month | Price |
|---|---|---|
| Free | 10,000 (up to 1,000 a day) | $0 |
| Starter | 50,000 | $49 / month |
| Growth | 250,000 | $199 / month |
| Scale | 1,000,000 | $699 / month |
| Enterprise | Custom volume | Custom |
Prices are listed in US dollars; the pricing page explains how checkout is charged and the yearly options. The Free plan covers every single-item endpoint; batch endpoints need a paid plan.
What support do customers in India get?
The same as everyone: email support at contact@hextner.com. Starter plans get a first reply within one business day, and Growth and Scale get priority email with a first reply within 4 hours. To protect the browser side as well, see bot detection for Indian websites and apps. Get a free API key; no card needed.