> ## Documentation Index
> Fetch the complete documentation index at: https://docs.avraapi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# PHP SDK security services

> Use the AvraAPI PHP SDK to check IP-risk signals and disposable-email signals.

Use `$avraapi->security()` for the two released Security operations. Both
methods return an `ApiResponse`. A `false` signal means the configured provider
did not classify the value for that signal; it is not a standalone allow or
block decision.

<Note>
  Every Security operation can use the shared one-request privacy control:
  `$avraapi->security()->withPrivacyMode()->checkVpn('IP_ADDRESS')`. It sends
  `X-Privacy-Mode: 1` only for that next request, then clears automatically.
  Privacy Mode keeps normal routing, billing, and usage tracking while
  suppressing request and response payload storage.
</Note>

## Check VPN, proxy, and IP risk

`checkVpn(string $ip): ApiResponse` evaluates one permitted IPv4 or IPv6
address for VPN, proxy, Tor, relay, and hosting signals.

**SDK function**

```php title="Copy the SDK call" theme={null}
$response = $avraapi->security()->checkVpn(
    ip: 'IP_ADDRESS',
);
```

| Argument | Use |
| - | - |
| `ip` | Permitted IPv4 or IPv6 address. |

```php title="Read IP-risk signals" theme={null}
<?php

// AvraAPI SDK call.
$response = $avraapi->security()->checkVpn('194.195.93.1');

// Your application code.
$riskSignals = [
    'vpn' => $response->data['is_vpn'],
    'proxy' => $response->data['is_proxy'],
    'tor' => $response->data['is_tor'],
    'hosting' => $response->data['is_hosting'],
];
$networkName = $response->data['network_name'];
$requestId = $response->requestId;
```

### Response

```json theme={null}
{
  "success": true,
  "request_id": "1fa95b0c-f0da-4b07-9b1d-5235aca6ca20",
  "data": {
    "ip_address": "194.195.93.1",
    "is_vpn": true,
    "is_proxy": false,
    "is_tor": false,
    "is_relay": false,
    "is_hosting": true,
    "country_code": "US",
    "city": "San Jose",
    "asn": "AS212238",
    "network_name": "Datacamp Limited",
    "provider_name": "iplocate"
  }
}
```

Some network fields can be `null`. Combine the returned signals with your own
risk policy and only submit IP addresses that you are permitted to process.
For field and error details, read [Check VPN, proxy, and IP risk](/api-reference/security/vpn-shield).

## Check a disposable email address

`checkBurnerEmail(string $email): ApiResponse` evaluates one email address for
syntax and configured disposable-domain signals.

**SDK function**

```php title="Copy the SDK call" theme={null}
$response = $avraapi->security()->checkBurnerEmail(
    email: 'EMAIL_ADDRESS',
);
```

| Argument | Use |
| - | - |
| `email` | Email address to evaluate. |

```php title="Use a disposable-email signal" theme={null}
<?php

// AvraAPI SDK call.
$response = $avraapi->security()->checkBurnerEmail('customer@example.com');

// Your application code.
$isDisposable = $response->data['is_disposable'];
$domain = $response->data['domain'];
$matchSource = $response->data['source'];

if ($isDisposable) {
    // Apply your application's registration or recovery policy.
}
```

### Response

```json theme={null}
{
  "success": true,
  "request_id": "82512122-5a64-459c-a0cb-0ba07be4a600",
  "data": {
    "email": "hodil14324@ellbit.com",
    "domain": "ellbit.com",
    "is_valid_syntax": true,
    "is_disposable": true,
    "source": "custom",
    "execution_time_ms": 5.89
  }
}
```

`is_disposable: false` means the configured lists did not contain a matching
domain. It does not verify ownership, inbox reachability, or user trust.
Process only email addresses you are permitted to use. For the complete
contract, see [Check a disposable email address](/api-reference/security/burner-email-shield).

## Handle Security errors

Security methods throw typed SDK exceptions for API failures. Keep
`$exception->getRequestId()` with your support record, avoid exposing provider
diagnostics to a browser, and follow the common handling pattern in
[PHP Overview and setup](/sdk/php/overview-and-setup#handle-errors-safely).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.