For SaaS, marketplaces and consumer apps

Phone validation at signup

Check the number before you send the signup code. One lookup says whether it's a mobile, landline or VoIP line from a live carrier dip, whether a carrier deactivated it in the last 45 days, whether it's on our blacklist, and whether it can take a text. You stop paying for codes that can't arrive, and you see which signups deserve a second check.

  • US and Canadian numbers
  • From $0.0009 per lookup
  • State DNC checks free
New signups, checked
Number The lookup says Do this
(415) 555-0186 Active mobile Send the code
(737) 555-0142 VoIP line Add a step
(213) 555-0119 Landline, can't take texts Offer a voice code
(602) 555-0170 Deactivated by the carrier Oct 6 Ask for another
(917) 555-0133 On our blacklist Manual review

Fictional 555 numbers.

  • 1B+ requests served by our validation network
  • ~32% of numbers we look up are landline or VoIP

Where signups go wrong

“We pay for every verification text, even the ones that never arrive.”

About 32% of the numbers we look up are landline or VoIP. A landline comes back with action: "unsubscribe" and reason "Not a valid mobile number", so you can skip the text and offer a voice code instead.

Source: CheckThatPhone lookup data

actionreasonnanpType

“Throwaway numbers pass our SMS check.”

A code proves someone can read a text on that number right now, not who they are. dipCarrierSubType "IPES" marks a VoIP line, from a live carrier dip. Plenty of real customers use VoIP, so treat it as a reason for another step, not an automatic block.

dipCarrierSubType = IPES

“People sign up with numbers that are already dead.”

deactivationDate shows a carrier deactivation in the last 45 days, and reason names the carrier id and the date. Ask for a working number before you send a code.

deactivationDatereason

“The same person keeps coming back for another free trial.”

Compare digits, not what people typed: the API strips spaces, dashes, parentheses and + and expects 10 digits, or 11 starting with 1. Do the same before you check a number against existing accounts. One-account-per-number rules stay yours.

subscriber

Where the lookup goes in your signup flow

  1. Step 1

    Check before you send the code

    Call the API when the person submits a phone number, before your SMS provider sends anything. Pass the signup's IP as ip to get location and time zone from the IP. If action isn't "send", don't text: offer a voice code or ask for a mobile.

  2. Step 2

    Score it with your other signals

    AllowAdd a stepReview

    Weigh VoIP, a recent deactivation and the blacklist flag alongside email, device and payment signals. Allow, add a step (another factor, a card check, a smaller trial), or send to review, with thresholds you tune on your own outcomes.

  3. Step 3

    Check again before you pay out

    Before a referral bonus, a promo credit or a change to sign-in details, look the number up again and compare dipCarrier and dipOcn with what you stored at signup. A different carrier means the number moved since then.

What to do with each result

None of these proves fraud on its own. They are inputs to your rules; the allow-or-block call is yours.

If the response showsFieldDo this
Can take a text action = send Send the code.
Landline nanpType = landlinereason Don't text. Offer a voice code or ask for a mobile. The landline SMS check (+1 credit) finds landlines that can take a text (smsEligible).
VoIP dipCarrierSubType = IPES A risk input, not a block: add a step, or hold back trial credits until another signal checks out.
Deactivated by the carrier recently deactivationDatereason Don't send the code. Ask for a working number.
On our internal blacklist blackList = truereason Send to review or block. reason reads "Blacklisted Subscriber".
A different carrier than at signup dipCarrierdipOcn The number moved carriers since signup. Add a step before a payout or a change to sign-in details.
Ported dipPorted Not a recency signal: it has no date, and it isn't a SIM-swap check. Compare carrier fields over time instead.
Signup location geoStategeoSourceipResult With an ip passed, location comes from the IP; without one, from the area code. One call returns one or the other. ipResult only says the IP was valid.

A number that can't take the code

An active landline. action is "unsubscribe" with reason "Not a valid mobile number", so a text code would never arrive: offer a voice code or ask for a mobile. No IP was passed, so location and time zone come from the area code (geoSource: "area-code").

1 credit, no add-ons

Highlighted fields: action, reason, nanpType, dipCarrierType.

{
  "success": true,
  "credits_used": 1,
  "data": {
    "subscriber": "2135550119",
    "optDate": "2026-10-09T17:22:08.415Z",
    "action": "unsubscribe",
    "deliverable": "false",
    "reason": "Not a valid mobile number",
    "nanpType": "landline",
    "blackList": "false",
    "dip": "success",
    "dipLrn": "2135550119",
    "dipPorted": "false",
    "dipOcn": "9740",
    "dipCarrierSubType": "RBOC",
    "dipCarrier": "Pacific Bell",
    "dipCarrierType": "landline",
    "geoState": "CA",
    "geoCity": "los angeles",
    "geoCountry": "US",
    "timezone": "America/Los_Angeles",
    "tzOffset": 8,
    "geoSource": "area-code",
    "error": "false",
    "doNotSms": "true"
  }
}

What it costs at your signup volume

Monthly cost:

  • Early-stage app, 2,000 signups/mo: $10/mo on the 1K plan, billed monthly
  • Growing product, 25,000 signups/mo: $75/mo on the 10K plan, billed monthly
  • Consumer app at scale, 250,000 signups/mo: $250/mo on the 100K plan, billed monthly
Your monthly cost $10/mo on the 1K plan, billed monthly 2,000 signups × 1 credit = 2,000 credits. 1K plan: $5 + 1,000 × $0.005 = $10

A plain lookup, no add-ons needed for these signals. Computed from the published plans. The free plan's 500 lookups a month cover testing.

What the lookup covers, and what's still on you

The lookup gives you

  • Mobile, landline or VoIP from a live carrier dip, after porting
  • VoIP flagged as carrier sub-type IPES
  • Carrier deactivations in the last 45 days
  • Our internal blacklist
  • A send-or-not verdict (action) before you pay for a code
  • Location and time zone from the signup's IP, or from the area code

Still your job

  • Sending and checking the one-time code
  • Rate limits, bot checks and conversion monitoring on code sends, against artificially inflated traffic · UK NCSC, SMS and one-time passcodes
  • SIM-change and device-swap checks before you send a code to a phone, which NIST lists as risk indicators · NIST SP 800-63B-4, 3.1.3.3
  • Your one-account rules: what counts as a duplicate, and what happens on a match
  • Thresholds for allow, add a step or block, tuned on your own outcomes

Not legal advice.

Coverage and limits

  • No subscriber names or owner details, and no identity match: we can't tell you whose number it is.
  • No "disposable number" flag. VoIP (IPES) is the closest signal, and many VoIP users are real customers.
  • dipPorted says a number moved carriers at some point. It has no date, so it is not a recent-port or SIM-swap signal.
  • deactivationDate: data refreshed daily, with a 1 to 7 day lag, and entries expire after 45 days. It is not a reassigned-number check.
  • US and Canadian numbers only.

Phone checks at signup: common questions

Does a lookup replace the verification code?

No. The code proves the person can read a text on that number right now. The lookup runs before it: it tells you whether the number can take a text at all, and whether it looks worth a closer look, so you only pay for codes that can arrive.

Should we block VoIP numbers at signup?

Usually not outright. Many real customers use VoIP lines. Treat dipCarrierSubType "IPES" as one input: add a step, hold back trial credits, or review, and measure the result on your own signups.

Can it detect a SIM swap or a recent port?

No. A SIM swap moves a number to a new SIM at the same carrier, a different thing from a port to a new carrier (FCC 23-95, paragraphs 5 and 6). dipPorted says the number was ported at some point, with no date. To spot a carrier change, store dipCarrier and dipOcn at signup and compare them on a fresh lookup before a sensitive action.

Can it stop one person opening many accounts?

Not by itself. It doesn't link different numbers to one person or return owner names. It helps with the number part: compare the digits against existing accounts, and treat VoIP, recent deactivations and blacklisted numbers as inputs to your rules.

What about numbers outside the US and Canada?

The API covers US and Canadian numbers only. It expects 10 digits, or 11 starting with 1; anything else comes back as an invalid request, with no credit charged.

How is this different from the KYC page?

Same lookup, different job. The KYC page is about account opening at fintech and lending companies. This page is about any app that sends a code at signup and wants to keep fake accounts, trial abuse and wasted texts down.

Check the next signup before you send the code

500 free lookups a month to try it on your own signups. One credit per lookup after that.