Terms of Service
These Terms of Service ("Terms") constitute a legally binding agreement between you (whether an individual developer, organization, or enterprise entity, referred to as "Customer", "Developer", "you", or "your") and CheckSignup ("CheckSignup", "we", "us", or "our"), governing access to and use of our edge email intelligence API, developer dashboard, Model Context Protocol (MCP) server, and associated services.
1. Acceptance of Terms & Eligibility
By creating an account, generating an API key, calling the CheckSignup validation endpoint (/validate), integrating our MCP server, or accessing our developer portal, you explicitly acknowledge that you have read, understood, and agree to be bound by these Terms and our Privacy Policy.
If you are entering into these Terms on behalf of a company or other legal entity, you represent and warrant that you have full authority to bind such entity to these Terms. If you do not have such authority or do not agree with any part of these Terms, you must immediately discontinue use of the Services.
2. Description of Services & Architecture
CheckSignup provides a low-latency, real-time Email Intelligence and Fake Signup Prevention suite operating globally at the network edge. Our core capabilities include:
- Disposable Mailbox Classification: In-memory Trie matching against 75,000+ temporary email domains and 250+ MX server clustering patterns.
- Canonical Normalization: Deterministic aliasing resolution for major email providers (including Gmail plus/dot addressing, Yahoo sub-addressing, ProtonMail, and Outlook aliases).
- DNS-over-HTTPS (DoH) MX Validation: Live DNS mail exchange record queries with in-flight single-flight coalescing.
- Typo Detection Engine: Algorithmic domain similarity scoring using Levenshtein distance calculations.
- 3-State Action Directives: Machine-readable policy verdicts (
allow,review,block) with standardized 0–100 integer risk scores. - Agentic MCP Integration: Model Context Protocol endpoints allowing AI agents and autonomous bots to verify email targets.
3. Account Provisioning, Authentication & API Key Responsibilities
To access the Services programmatically, you must register through our developer gateway and provision one or more live API keys (formatted as cs_live_...).
- Key Confidentiality: You are solely responsible for maintaining the confidentiality of your API keys. You must never expose secret keys in client-side code, public GitHub repositories, or client-facing applications.
- Fail-Closed Security Gating: All API requests require a valid, active API key passed in the
X-API-KeyHTTP header. Requests lacking valid credentials will be immediately rejected with HTTP401 Unauthorizedat the network edge. - Account Activity: You are fully liable for all API requests, credit consumptions, and activities conducted under your API credentials. If you suspect key compromise, you must revoke the affected token immediately via the Developer Console.
4. Validation Credits, Pre-Settlement Ledger & Billing Terms
CheckSignup operates on an atomic, pre-settlement ledger model:
- Pre-Settlement Ledger: When an API request is received, credits are atomically deducted prior to query execution. If an account has a balance of zero, the request is immediately blocked with HTTP
402 Payment Required. - Idempotency Guarantees: Requests transmitting an
Idempotency-Keyheader will return the cached validation verdict without secondary credit deductions for duplicate requests received within 24 hours. - Onboarding Allowance & Paid Plans: New developer accounts receive 5,000 complimentary starter credits upon registration. Additional credits are purchased according to published pricing tiers (Free, Indie, Builder, Growth, or Custom Enterprise).
- Non-Refundable: Unless required by mandatory consumer protection law, all credit purchases and subscription fees are non-refundable once credited to your account.
Note on Quota Management: You can monitor real-time credit consumption, request latencies, and billing statements through the Developer Console at app.checksignup.com.
5. Acceptable Use Policy (AUP) & Prohibited Conduct
You agree to use CheckSignup exclusively for lawful purposes in compliance with all applicable local, national, and international laws. You explicitly agree NOT to:
- Use the Services to facilitate unsolicited mass email (spam), phishing campaigns, or fraudulent marketing operations.
- Attempt to weaponize the API for credential stuffing, dictionary attacks, or mass email harvesting.
- Probe, scan, or attempt to bypass our Zero-Trust Server-Side Request Forgery (SSRF) filters, private IP blocks, or edge authentication gates.
- Scrape, reverse-engineer, decompile, or bulk-extract our proprietary disposable domain lists, Trie algorithms, or MX cluster intelligence datasets.
- Exceed your assigned requests-per-second (RPS) rate limits or deliberately cause denial-of-service conditions against our edge infrastructure.
- Resell, sublicense, or redistribute raw API access to third parties without prior written authorization from CheckSignup.
6. Service Level Objectives & Graceful Degradation
We strive to maintain a 99.9% uptime availability for our validation API across our globally distributed edge network.
| Metric | Target SLO | Behavior on Deviation |
|---|---|---|
| Edge API Latency | Sub-30ms execution | Automated global edge routing to nearest compute node. |
| Upstream DNS Query | <150ms timeout ceiling | Graceful Degradation: If upstream DNS times out, the API returns a safe verdict with degraded: true rather than blocking your user registration. |
| Service Availability | 99.9% Monthly Uptime | Global redundancy across multiple edge availability zones. |
7. Data Protection, Privacy-by-Design & Zero Plaintext Persistence
CheckSignup is engineered on strict Zero-Plaintext Personally Identifiable Information (PII) Storage principles:
- Ephemeral Processing: Email queries are evaluated entirely in volatile memory at the edge node and immediately discarded after returning the HTTP response.
- Cryptographic Hashing: Audit trails and credit deduction ledgers never record raw email strings; we only store irreversible one-way SHA-256 cryptographic hashes (
SHA-256(email)) or domain names. - GDPR & SOC2 Alignment: For complete details regarding our data flows, sub-processors, and data subject rights, please inspect our Privacy Policy.
8. Intellectual Property Rights
All right, title, and interest in and to the CheckSignup Services—including our API endpoints, proprietary normalization heuristics, Trie data structures, MX cluster heuristics, algorithmic risk scoring models, documentation, logos, and brand assets—remain the exclusive property of CheckSignup and its licensors.
Subject to your ongoing compliance with these Terms, CheckSignup grants you a limited, revocable, non-exclusive, non-transferable license to access and integrate the API into your applications.
9. Disclaimer of Warranties & Limitation of Liability
PLEASE READ CAREFULLY: TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
CheckSignup does not guarantee that email classification will be 100% error-free or that every disposable or malicious mailbox will be detected. You remain solely responsible for your own user onboarding decisions, risk policies, and security configurations.
IN NO EVENT SHALL CHECKSIGNUP, ITS OFFICERS, DIRECTORS, EMPLOYEES, OR AGENTS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES (INCLUDING LOSS OF PROFITS, DATA, BUSINESS, OR GOODWILL), ARISING OUT OF OR IN CONNECTION WITH YOUR ACCESS TO OR INABILITY TO ACCESS THE SERVICES. OUR TOTAL AGGREGATE LIABILITY UNDER THESE TERMS SHALL NOT EXCEED THE TOTAL AMOUNT PAID BY YOU TO CHECKSIGNUP IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.
10. Indemnification & Account Suspension
You agree to defend, indemnify, and hold harmless CheckSignup from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or related to your breach of these Terms, violation of third-party rights, or improper use of the API.
We reserve the right to immediately suspend or permanently terminate your API keys and account access without prior notice if we detect fraudulent activity, credential abuse, AUP violations, or unauthorized high-volume probing.
11. Governing Law & Dispute Resolution
These Terms and any dispute arising out of or related to them shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of law provisions. Any legal action or proceeding arising under these Terms will be brought exclusively in the federal or state courts located in Delaware, and the parties hereby irrevocably consent to personal jurisdiction and venue therein.
12. Contact & Legal Inquiries
If you have questions regarding these Terms of Service, wish to negotiate custom enterprise terms, or need to report security vulnerabilities, please reach out to our legal and engineering team:
- Legal & Compliance: legal@checksignup.com
- Developer Support: support@checksignup.com
- Security Disclosures: security@checksignup.com