Is Dit Veilig? · API for business

Spot scams, inside your system.

One POST with a website, phone number or email address. Back comes a score from 0 to 10, a verdict, and every signal that produced it — each with its weight. The same engine and the same database as the free checker, with ${DOSSIERS_EN} dossiers behind it.

Request access Read the documentation
46,609 dossiers 60 checks per minute EU-hosted · GDPR every signal evidenced
What it does

Three input types, each with its own set of checks.

WEBSITE / URL
  • Domain age via RDAP at the registry itself — not an estimated whois.
  • A real TLS handshake: is there a valid certificate, or just a padlock in the address bar?
  • DNS: nameservers, and whether there is a mail server at all.
  • Hosting: IP, country and provider (ASN) — high-risk hosting counts.
  • Blocklists: URLhaus (abuse.ch), Spamhaus DBL and Google.
  • Brand impersonation, strictly: leetspeak (belast1ngd1enst), homoglyphs such as Cyrillic characters that look Latin (раypal → punycode), brand+lure compounds (ing-veilig-login), phishing on a subdomain (belastingdienst.secure-login.tk) and edit-distance typosquats.
  • Name heuristics: suspicious TLD, many hyphens or digits, extreme length, lure words.
  • Our own database: 46,609 dossiers plus visitor reports.
PHONE NUMBER
  • Normalisation to one canonical number: 06…, +31…, 0031… and 31… all resolve to the same thing.
  • Country detection from the calling code (0049 → DE, 0044 → GB).
  • Premium-rate 090x numbers and unusual country codes.
  • Our reports about that number.
  • Optional and metered: line type and carrier from a paid source (see Enrichment).
EMAIL ADDRESS
  • The domain behind the address goes through the full website analysis above.
  • Known phishing senders from our dossiers, collected per domain.
What you get back

A verdict that explains itself.

No black box. Every signal returns with a code, a weight and a sentence you can show a customer.

risk.levelsafe · low · medium · high · critical
risk.score0–10, summed from the signals below
risk.verdictone sentence, ready to display
signals[]per signal: code, weight, explanation — e.g. brandspoof (+6) “possible brand impersonation of ing”
sources[]which sources fed this verdict
checked_atwhen the check ran (ISO 8601)
meta.quotathis month’s usage and limit, in every response
Where it connects

At the moment it goes wrong.

One POST, synchronous. No SDK, no webhooks, no callbacks — the verdict is in the response.

In the transfer flow

A customer is sending money to a party they found on a site. Check the domain just before confirmation and show a warning, instead of opening a fraud case afterwards.

On posting and sending

Every URL in a listing, chat or DM gets a verdict before another user sees it.

At the support desk

An agent pastes the link or number the customer received and sees immediately whether it is known — with the reasoning for the case file.

In abuse triage

If a domain on your platform hits a feed, you see it in the same run instead of after the complaint.

At onboarding

The phone number or email domain given, as one more signal in your existing risk model.

How it works

Send a target, get a verdict.

Bearer key in the header, JSON in, JSON out. 60 calls per minute per key; the monthly quota follows your tier.

curl -X POST https://isditveilig.nl/api/v1/check \
  -H 'Authorization: Bearer idv_live_…' \
  -H 'Content-Type: application/json' \
  -d '{"type":"url","value":"https://example.com"}'
{
  "data": {
    "type": "url",
    "value": "belast1ngd1enst.nl",
    "risk": { "level": "critical", "score": 9, "verdict": "Critical — known scam or abuse." },
    "signals": [
      { "code": "brandspoof", "weight": 6, "text": "Possible brand impersonation of 'belastingdienst'" },
      { "code": "no_ssl",     "weight": 2, "text": "No valid certificate" },
      { "code": "reach_error","weight": 1, "text": "Site did not respond" }
    ],
    "sources": [ "urlhaus", "spamhaus_dbl", "google_safe_browsing", "internal_safelist", "isditveilig_reports" ],
    "checked_at": "2026-09-21T14:30:00+00:00"
  },
  "meta": {
    "rate_limit": { "limit": 60, "remaining": 59, "reset": 1747408800 },
    "quota": { "limit": 2500, "used": 1, "period_ends": "2026-10-01T00:00:00+00:00" }
  }
}
Documentation →
Enrichment

What costs extra is metered separately.

The verdict above runs entirely on our own engine and sources. A few signals we buy in — today line type and carrier for a phone number. Those sit in their own counter per tier, so your invoice stays predictable and so does ours. If your enrichment budget runs out you still get the full verdict, with enrichment.available = false attached. Never an error, never an empty response.

Pricing

Public prices, and an invoice you saw coming.

No quote needed to start. Every call tells you how much you have left, and from 80% we warn you — so you never find out after the fact what a month cost.

Free
€0
250 calls / month
Our own sources and dossiers. Stops at the limit, no credit card.
While you are still building.
Start free →
Start
€49/mo
2,500 calls / month
Adds Google Web Risk. No metered overage — you move up, not over.
When you want the cost known up front.
Request access →
Everything included
Pro
€129/mo
10,000 calls / month
800 enrichments
Then €15 per block of 1,000. Everything on: all check types and phone enrichment.
When checks run in production.
Request access →
Enterprise
Custom
From 100,000 calls a month
25,000 enrichments
Processing agreement, SLA and EU hosting included. Terms by agreement.
When procurement, security and legal get involved.
Contact us →

Anything above your included calls is billed in blocks of 1,000: one call into a new block costs a whole block.

Prefer annual? Two months free: Start €490, Pro €1,290 a year. Same terms, one invoice.
Start on your own A key in under a minute

Pick Free or Start, paste the key into your code and you are running. No sales call, no minimum commitment, cancel monthly.

Through procurement and security We supply the paperwork

Data processing agreement, SLA, DPIA support, DORA and NIS2 questionnaires, EU-only hosting, SSO and invoice billing. One call, and your security team has what it needs.

Do the sum the other way: what does it cost you today when one customer falls for it — the write-off, the chargeback, the phone call, your service desk's time? Put that next to €129 a month.

Prices exclude VAT, invoiced in EUR. Volume discounts apply above 100k calls/month.

Sources

Open feeds plus what only we have.

Every verdict cites every signal that produced it. The same sources that power the consumer site — no second-class data for B2B.

  • URLhaus (abuse.ch)
  • Spamhaus DBL
  • Google Safe Browsing / Web Risk
  • Our safelist: official Dutch domains (banks, government, telecom)
  • ${DOSSIERS_EN} of our own dossiers + visitor reports — nobody else has these
Limits

What it is not.

  • An automated assessment from public sources — not legal proof and not a guarantee.
  • Dossiers are historical: a domain reported last year may be clean today, and the other way round. The age of the evidence is included.
  • We do not render the page live: no screenshot, no behavioural analysis of scripts. On the list, not in the box today.
  • Not a blocklist subscription: you get our verdict with its sources, not the raw feeds to resell.
Why this exists

FFCheck stays free for citizens. Forever.

Is Dit Veilig? is a free consumer scam-checker. Always has been, always will be. No ads, no affiliate fees, no subscriptions for the people using it.

This API is how we sustain that. Banks, marketplaces, hosting and fraud teams pay for programmatic access to the same data citizens get for free. The same model that funds Wikipedia (free for readers) and Wikimedia Enterprise (paid for Google, Apple, Meta).

See the free check →
Request access

Tell us about your use case.

We issue keys by hand to keep quality high. You usually have a key within one business day.

We email you back within one business day. We never share your details.