New CloudWish Abuse API

Catch phishing and abuse in every email

One API call reads a message the way a security analyst would and returns labels, scores and a clear verdict. It works across many languages and plugs into rspamd, SpamAssassin or any app over plain HTTPS.

50,000 free checks every month. Need more? Talk to us.

  • Inbound and outbound mail
  • Many languages
  • Message bodies are not stored
abuse.cloudwish.com/v1/check
Inbound
From
Account Security <no-reply@acc0unt-verify.example>
Subject
Action required: your mailbox will be suspended today

We noticed unusual sign-in activity. Verify your password now or your access ends in 24 hours. acc0unt-verify.example/login

  • Phishing
  • Credential request
  • Fake urgency
  • Lookalike domain
  • en

Blockscore 0.97

Inbound
From
Envíos <seguimiento@parcel-fee.example>
Subject
Tu paquete está retenido: se requiere el pago de la tasa de envío

No pudimos entregar tu paquete. Paga la tasa de envío de 1,99 € para programar una nueva entrega: parcel-fee.example/pay

  • Scam
  • Delivery-fee lure
  • Payment request
  • es

Blockscore 0.95

Inbound
From
Dana Levi (CEO) <dana.levi.ceo@mail-northwind.example>
Subject
Re: Vendor payment, updated bank details

Please update the bank details before today’s transfer and keep this between us until it is done. I’m in meetings, so don’t call.

  • BEC
  • Payment change
  • Executive impersonation
  • Secrecy request
  • en

Reviewscore 0.84

Outbound
From
Maya Cohen <maya@studio-north.example>
Subject
Invoice 1042 for the website project

Hi, the invoice for September is attached. Let me know if anything needs changing. Thanks, Maya

  • No abuse signals
  • en

Allowscore 0.03

Illustrative example. Names, addresses and scores are made up.

Six kinds of abuse, one check

Send a message and every kind of abuse is scored at once. Each label comes with its own score, so you can treat a scam differently from a sales email.

  • Phishing

    Fake login pages, credential requests and messages that pretend to be a bank, a courier or your own IT team.

  • Business email compromise

    An impersonated executive asks for a payment, new bank details or gift cards, and asks you to keep it quiet. No link needed, which is why filters miss it.

  • Scam and fraud

    Advance-fee offers, fake invoices, prizes, romance and investment pitches.

  • Malware lures

    Delivery-fee and shared-document lures, and messages that push a booby-trapped attachment or link.

  • Spam

    Bulk and unsolicited promotion that fills inboxes and hurts a sender’s reputation.

  • Cold outreach

    Templated sales sequences sent at scale to people who never asked. Catch it on the way out before it costs you your sending reputation, or on the way in before it costs your team its time.

  • Not just English

    Abuse does not stop at English. Each message goes to the AI models that handle its language best.

    EnglishEspañolDeutschFrançaisPortuguêsand many more

From key to verdict in three steps

  1. Get your free API key

    Create a CloudWish account and generate a key. The free tier gives you 50,000 checks a month.

  2. Send the message

    Post a few fields as JSON, or the full message for best accuracy, to one HTTPS endpoint, or let our rspamd or SpamAssassin plugin send every message for you.

  3. Act on the verdict

    Get labels, scores and a verdict: allow, review or block. What happens next is up to you.

Docs

Quick start: one request, one verdict

Start with a sender, a recipient and a subject as JSON. Add the full message when you want the best accuracy.

verdict
allow, review or block
score
Overall abuse score from 0 to 1
labels
Each kind of abuse found, with its own score
language
The language it detected

Get your free API key

curl https://abuse.cloudwish.com/v1/check \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "from": "billing@example.net",
    "to": "you@example.com",
    "subject": "Invoice overdue"
  }'

A sender, a recipient and a subject are enough to get a verdict.

curl https://abuse.cloudwish.com/v1/check \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: message/rfc822" \
  --data-binary @suspicious.eml

Optional: send the full message for best accuracy.

Response

{
  "verdict": "review",
  "score": 0.64,
  "language": "en",
  "labels": [
    { "type": "phishing", "score": 0.64 }
  ],
  "request_id": "req_8f3a1c"
}

What you send is up to you

Send the whole message for the best accuracy, or hold back what you would rather not share.

  • Most detail

    Full message

    Best accuracy

    The whole email, headers and body. Send it as a raw .eml.

  • Less detail

    Without message body

    Everything except the message body.

  • Least detail

    Headers and links only

    • Subject
    • Sender and recipient domains
    • Link domains
    • Attachment types

The account owner chooses the level in the dashboard, and our server enforces it. How your data is handled

Plugs into the mail stack you already run

Use a drop-in plugin, or call the endpoint from anything that can make an HTTPS request. Same key, same verdict.

  • Plugin

    rspamd

    Add your key and rspamd scores every message with our verdict, on inbound and outbound mail.

  • Plugin

    SpamAssassin

    Same key, same verdict, added to the SpamAssassin score for every message that passes through.

  • REST

    REST and JSON

    A plain HTTPS endpoint for everything else: your app, a gateway, a helpdesk, a script. Send a few fields as JSON, or the full email, and read the verdict.

Your mail filter or app Abuse API labels + scores message verdict allow review block

Start free. Grow when you need to.

Free tier

50,000 checks a month

  • One API key, ready in minutes
  • Works with rspamd, SpamAssassin and plain REST
  • Message bodies are not stored
Get your free API key

Higher volumes

Need more than 50,000 a month?

Mail providers, hosting companies and platforms that check a lot of mail: tell us your volume and we will set up a plan that fits.

Contact us

Built to be safe to put in front of your mail

The Abuse API is operated by the team that runs CloudWish business email. Here is what happens to your data.

  • Message bodies are never stored

    Your mail is read to produce the verdict. The body is not kept afterwards.

  • Metadata is kept for 30 days

    Request metadata is kept for 30 days. Message bodies are not part of it.

  • Consent before first use

    Before the first request, the account owner confirms consent for analysis, including whether an external AI processing provider (sub-processor) may be used.

  • Local-only mode

    Local-only mode is available if you would rather no external AI processing provider is involved.

  • HTTPS and an API key

    Every request travels over HTTPS and needs your key. Nothing is open to the world.

  • Never in the way of your mail

    The verdict adds to your own filter’s score. If a check is ever slow or fails, mail keeps flowing.

You also choose how much of each message is sent. Read the privacy policy for the full detail.

Abuse API questions

What does the API return?

Every check returns a verdict (allow, review or block), an overall score, a list of labels such as phishing or BEC with a score for each, and the language it detected. You decide what each verdict does in your own pipeline.

What kinds of abuse does it catch?

Phishing, scam and fraud, business email compromise (BEC), malware lures, spam and cold outreach, in both outbound and inbound mail.

Which languages does it understand?

70 languages, from English, Spanish and German to Arabic, Hindi and Japanese. Each message is routed to the AI models that handle its language best, so mail that is not in English is not an afterthought. Accuracy is highest for widely used languages.

How do I connect it to rspamd or SpamAssassin?

Use the drop-in plugin for your filter: add your API key and the verdict is added to the message score. Anything else can call the REST endpoint directly with JSON or a raw email.

Do I have to send the whole email?

No. A sender, a recipient and a subject are enough to get a verdict. Sending the full message gives the best accuracy. The account owner chooses how much is sent in the dashboard, and our server enforces it.

Do you store my email?

Message bodies are never stored. Request metadata is kept for 30 days. Before first use, the account owner confirms consent for analysis, including whether an external AI processing provider (sub-processor) may be used. Local-only mode is available.

How accurate is it?

No classifier is perfect, which is why every result carries a score instead of a bare yes or no. We test on labelled mail in each language and tune for as few false positives on legitimate mail as we can. Set your own thresholds for allow, review and block.

What happens if the API is slow or unreachable?

It is designed to stay out of the way of your mail. The verdict adds to your own filter’s score, and if a check times out or fails, mail keeps flowing instead of being held.

What does the free tier include?

50,000 checks a month, free. Get an API key and start sending messages.

What if I need more than the free tier?

Contact us with your monthly volume and we will set up a plan for higher volumes. Talk to us.

Put an abuse check in front of your mail today.

Languages we detect and analyse

70 languages, in alphabetical order. Accuracy is highest for widely used languages.

  • Afrikaans
  • Akan
  • አማርኛAmharic
  • العربيةArabic
  • ՀայերենArmenian
  • AzərbaycancaAzerbaijani
  • БеларускаяBelarusian
  • বাংলাBengali
  • BokmålBokmal
  • БългарскиBulgarian
  • မြန်မာစာBurmese
  • CatalàCatalan
  • HrvatskiCroatian
  • ČeštinaCzech
  • DanskDanish
  • NederlandsDutch
  • English
  • Esperanto
  • EestiEstonian
  • SuomiFinnish
  • FrançaisFrench
  • ქართულიGeorgian
  • DeutschGerman
  • ΕλληνικάGreek
  • ગુજરાતીGujarati
  • עבריתHebrew
  • हिन्दीHindi
  • MagyarHungarian
  • Bahasa IndonesiaIndonesian
  • ItalianoItalian
  • 日本語Japanese
  • Basa JawaJavanese
  • ಕನ್ನಡKannada
  • ភាសាខ្មែរKhmer
  • 한국어Korean
  • Lingua LatinaLatin
  • LatviešuLatvian
  • LietuviųLithuanian
  • МакедонскиMacedonian
  • മലയാളംMalayalam
  • 普通话Mandarin
  • मराठीMarathi
  • नेपालीNepali
  • ଓଡ଼ିଆOriya
  • فارسیPersian
  • PolskiPolish
  • PortuguêsPortuguese
  • ਪੰਜਾਬੀPunjabi
  • RomânăRomanian
  • РусскийRussian
  • СрпскиSerbian
  • ChiShonaShona
  • සිංහලSinhalese
  • SlovenčinaSlovak
  • SlovenščinaSlovene
  • EspañolSpanish
  • SvenskaSwedish
  • Tagalog
  • தமிழ்Tamil
  • తెలుగుTelugu
  • ภาษาไทยThai
  • TürkçeTurkish
  • TürkmençeTurkmen
  • УкраїнськаUkrainian
  • اُردُوUrdu
  • OʻzbekchaUzbek
  • Tiếng ViệtVietnamese
  • CymraegWelsh
  • ייִדישYiddish
  • IsiZuluZulu