curl --request POST \
--url https://avraapi.com/api/v1/security/burner-email-shield \
--header 'Content-Type: application/json' \
--header 'X-API-KEY: <api-key>' \
--header 'X-API-SECRET: <api-key>' \
--data '
{
"email": "documentation@example.invalid"
}
'const options = {
method: 'POST',
headers: {
'X-API-KEY': '<api-key>',
'X-API-SECRET': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({email: 'documentation@example.invalid'})
};
fetch('https://avraapi.com/api/v1/security/burner-email-shield', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://avraapi.com/api/v1/security/burner-email-shield",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'email' => 'documentation@example.invalid'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-KEY: <api-key>",
"X-API-SECRET: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"success": true,
"request_id": "82512122-5a64-459c-a0cb-0ba07be4a600",
"data": {
"email": "hodil14324@ellbit.com",
"domain": "ellbit.com",
"is_valid_syntax": true,
"is_disposable": true,
"source": "custom",
"execution_time_ms": 5.89
}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "unauthorized",
"message": "<string>",
"details": {}
},
"meta": {}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "insufficient_funds",
"message": "<string>",
"details": {}
},
"meta": {}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "validation_failed",
"message": "<string>",
"details": {}
},
"meta": {}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "rate_limit_exceeded",
"message": "<string>",
"details": {}
},
"meta": {}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "internal_error",
"message": "<string>",
"details": {}
},
"meta": {}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "project_paused",
"message": "<string>",
"details": {}
},
"meta": {}
}Check a disposable email address
Check one email address for disposable or temporary-email signals.
curl --request POST \
--url https://avraapi.com/api/v1/security/burner-email-shield \
--header 'Content-Type: application/json' \
--header 'X-API-KEY: <api-key>' \
--header 'X-API-SECRET: <api-key>' \
--data '
{
"email": "documentation@example.invalid"
}
'const options = {
method: 'POST',
headers: {
'X-API-KEY': '<api-key>',
'X-API-SECRET': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({email: 'documentation@example.invalid'})
};
fetch('https://avraapi.com/api/v1/security/burner-email-shield', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://avraapi.com/api/v1/security/burner-email-shield",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'email' => 'documentation@example.invalid'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-KEY: <api-key>",
"X-API-SECRET: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"success": true,
"request_id": "82512122-5a64-459c-a0cb-0ba07be4a600",
"data": {
"email": "hodil14324@ellbit.com",
"domain": "ellbit.com",
"is_valid_syntax": true,
"is_disposable": true,
"source": "custom",
"execution_time_ms": 5.89
}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "unauthorized",
"message": "<string>",
"details": {}
},
"meta": {}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "insufficient_funds",
"message": "<string>",
"details": {}
},
"meta": {}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "validation_failed",
"message": "<string>",
"details": {}
},
"meta": {}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "rate_limit_exceeded",
"message": "<string>",
"details": {}
},
"meta": {}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "internal_error",
"message": "<string>",
"details": {}
},
"meta": {}
}{
"success": false,
"request_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"error": {
"code": "project_paused",
"message": "<string>",
"details": {}
},
"meta": {}
}API endpoint
https://avraapi.com/api/v1/security/burner-email-shield
Request fields
| Field | Required | Rules |
|---|---|---|
email | Yes | A string containing an RFC-compatible email address, up to 255 characters. |
POST so an email address is not placed in the URL. Only submit addresses that you are permitted to process.
Result fields
| Field | Type | Notes |
|---|---|---|
email | string | The email address evaluated by the service. |
domain | string | The extracted, normalised domain. |
is_valid_syntax | boolean | Whether the address passed the service’s syntax validation. |
is_disposable | boolean | Whether the domain, or a parent domain, was found in a disposable-email list. |
source | string | Match source: custom, global, or none. |
execution_time_ms | number | Time spent evaluating the request, in milliseconds. |
is_disposable: false means the configured lists did not contain a matching domain. It is not a guarantee that an address is owned by a real person or safe to trust.
Request example
curl --request POST "https://avraapi.com/api/v1/security/burner-email-shield" \
--header "X-API-KEY: YOUR_PROJECT_CLIENT_ID" \
--header "X-API-SECRET: YOUR_PROJECT_CLIENT_SECRET" \
--header "X-ENV: development" \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '{"email":"documentation@example.invalid"}'
Response example
{
"success": true,
"request_id": "82512122-5a64-459c-a0cb-0ba07be4a600",
"data": {
"email": "hodil14324@ellbit.com",
"domain": "ellbit.com",
"is_valid_syntax": true,
"is_disposable": true,
"source": "custom",
"execution_time_ms": 5.89
}
}
Error codes
| HTTP | error.code | When it happens | What to do |
|---|---|---|---|
401 | unauthorized | Credentials are missing, invalid, inactive, or do not match the selected environment. | Check your backend secret configuration and X-ENV. |
402 | insufficient_funds | The selected Security integration requires credits that are unavailable. | Check the project’s current service configuration and balance. |
422 | validation_failed | email is missing, is not a string, is not a valid email address, or exceeds 255 characters. The response includes field details. | Correct the request field and submit a new request. |
422 | provider_selection_failed | The required Security provider is unavailable for the project environment. | Enable or configure the provider for the selected environment. |
429 | rate_limit_exceeded | The configured request limit was reached. | Respect Retry-After when present; do not retry in a tight loop. |
500 | internal_error | The disposable-email check could not complete. | Retry only if your workflow permits it, retaining the request ID. |
503 | project_paused | The project is paused. | Reactivate the project before retrying. |
request_id or X-APIX-Request-ID response header with your support record. It is the safest way for AvraAPI support to trace a request.Playground resources
The generated reference below lists this endpoint’s API standard details: request fields, authorizations, and response schema. The complete integration guide, request and response examples, and endpoint-specific error handling are above.Authorizations
Your Development project's Client ID. Enter your own value in the Documentation Playground.
Your Development project's Client Secret. Mintlify does not proxy these requests; the browser sends them directly to AvraAPI. Never enter a Production secret in the Documentation Playground.
Headers
Selects the Development credential environment. The Documentation Playground exposes Development values only; normal backend integrations may use their documented Production credentials outside this tool.
dev, development Requests a JSON response where the selected operation supports JSON.
"application/json"
Optional privacy override. Turn this on to request that AvraAPI suppress request-payload storage in observability logs for this request.
true
Body
An RFC-compatible email address.
255"documentation@example.invalid"
Was this page helpful?
