Email Risk

Email fraud risk and deliverability screening — LexisNexis (full fraud intelligence) and NeverBounce (deliverability validation) variants.

Checker Category: Risk — Communication

Used In Steps: Session Risk (as add-on), PII Validation (as add-on)

Used In Workflows: Any workflow where an email address is collected

Supported Countries: Global


Overview

Email Risk checkers screen the provided email address for fraud signals and deliverability issues before proceeding with verification. Two variants are available: LexisNexis provides comprehensive fraud intelligence including email age, domain risk, IP correlation, and behavioral signals; NeverBounce focuses on deliverability validation and disposable address detection.

Both variants run as zero-friction add-ons — no additional user input required beyond the email address already collected by the step.

End User Requirements

Email address (collected in the current step or passed via Login Hint).

Role in Layered Verification

Early-stage risk filter. Flags disposable addresses, high-risk domains, and fraud-associated email patterns before any PII is verified. Reduces downstream friction by blocking obvious fraud signals at the lowest-cost point in the flow.


Overview

Comprehensive email fraud intelligence from LexisNexis. Assesses email age, domain characteristics, IP correlation, behavioral fraud patterns, and cross-network reputation signals.

Acquired Attributes

Attribute NameAttribute CodeFieldsDescription
Email Creation DateEmailCreationDate—Date the email address was first created.
Email Age (Days)EmailAge—Age of the email address in days.
Email Domain AgeEmailDomainAge—Age of the email domain.
Email Domain Age (Days)DaysSinceEmailDomainCreation—Days since the email domain was created.
First Email Verification DateFirstEmailVerificationDate—Date the email address was first verified in LexisNexis systems.
Time since Email Verification Age (Days)DaysSinceFirstEmailVerification—Days since the first email verification.
Last Email Verification DateLastEmailVerificationDate—Date of the most recent email verification.
Email Address StatusEmailAddressStatus—Current deliverability status of the email address.
Email Risk ScoreEmailageScore—Numeric risk score for the email address.
Email Score ReasonEmailageScoreReason—Reason code for the email risk score.
Fraud TypeFraudType—Type of fraud pattern detected, if any.
Email Domain Risk LevelEmailDomainRiskLevel—Risk classification of the email domain.
Email Score Risk LevelEmailageScoreRiskBand—Risk band associated with the email risk score.
IP Address Risk LevelIPAddressRiskLevel—Risk level of the IP address associated with the email.
Overall Digital Identity ScoreOverallDigitalIdentityScore—Composite digital identity risk score.
Email Address LocationEmailAddressLocation—Geographic location associated with the email address.
Email Risk LevelEmailRiskBand—Overall email risk classification band.
Fraud RiskFraudRisk—Fraud risk indicator for the email address.
Source IndustrySourceIndustry—Industry most commonly associated with this email.
Company associated with DomainDomainCompany—Company name associated with the email domain.
Domain CorporateDomainCorporate—Indicates whether the domain is a corporate domain.
Number of Social Media FriendsSmFriends—Number of social media connections associated with the email.
Image URLImageUrl—Profile image URL associated with the email address.
Email To IP ConfidenceEmailToIpConfidence—Confidence score for the email-to-IP address correlation.
Total HitsTotalHits—Number of times this email has been seen in LexisNexis systems.
Domain CountryDomainCountry—Country associated with the email domain.
Domain CategoryDomainCategory—Category classification of the email domain.
Email to Billing Address ConfidenceEmailToBillAddressConfidence—Confidence score for email-to-billing-address correlation.
First Verification DateFirstVerificationDateFirst Verification DateFirst date this email was verified anywhere in the network.
First Seen DaysFirstSeenDaysFirst Seen DaysDays since this email was first seen in the network.

Assertions

Assertion NameAssertion KeyDescription
Provided Full Name Linked to Provided Email in Identity Recordlink.fullName_EmailConfirms that the provided full name corresponds to the provided email address in identity records. Passes if a correspondence is found; fails if none is found.
Provided Country Matches IP Address Countrylink.ipAddress_addressCompares the provided country to the country of the device's IP address. Passes if they match; fails if they do not.
Email Account Existence Checktest.emailAddressExistsConfirms that the provided email address exists as an active, registered account. Passes if the email account exists; fails if it does not.
Email Address Active Checktest.emailAddressValidConfirms that the email address exists as an active account with sufficient history. Passes if activity and history is sufficient; fails if it is not.
Email Domain Exists Checktest.emailDomainExistsConfirms that the provided email domain exists and has valid DNS records. Passes if the domain is valid; fails if it does not exist or has no valid DNS records.
IP Address Local Whitelist Checktest.ipAddressTrustedConfirms that the IP address is present on the local whitelist. Passes if found on the whitelist; fails if it is not.
IP Address Country Risk Checktest.ipCountryRiskAssesses the risk level associated with the IP address country. Passes if the country risk is within acceptable levels; fails if the risk is elevated.
Email Domain Local Whitelist Checktest.isDomainTrustedConfirms that the email domain is present on the local whitelist. Passes if found on the whitelist; fails if it is not.
Email Address Local Whitelist Checktest.isEmailTrustedConfirms that the email address is present on the local whitelist. Passes if found on the whitelist; fails if it is not.
IP Address Tor Network Checktest.torNetworkIPIndicates whether the IP address is associated with the Tor network. Passes if the IP has no Tor association; fails if it does.
Phone Number Format Checktest.validPhoneFormatConfirms that the provided phone number is in a valid format. Passes if the format is valid; fails if it is not.

Testing & Expected Results

Deny path: use a known disposable address (e.g., [email protected]).

Approve path: use a standard business or personal email address.


Related Resources

→ Session Risk | → PII Validation | → Identity Verification | → Continuous Re-Authentication