Spam detection API
Privacy-first spam detection. One call checks the message, IP and email behind every form submission, sign-up, review or comment, and returns a spam score. No CAPTCHA. No logs by default.
40 free checks a month. No credit card.
0B+
Spam caught
0M+
Protected websites
24/7
Human support
A global blocklist behind every check
An up-to-date database of malicious emails and IPs from around the world, looked up on every request.
Every signal in one request
Send what you have. Turn on the filters you need.
Message content
Machine learning trained on real spam.
contentIP reputation
Checked against multiple IP denylists.
senderIPEmail reputation
Checked against multiple email denylists.
emailDisposable emails
Block temporary inboxes.
blockTempEmailVPN, proxy & Tor
Stop senders hiding their location.
blockVPNData center IPs
Filter bots running on cloud servers.
blockDCCountries
Allow or block by country.
allowedCountries blockedCountriesLanguages
Accept only the languages you support.
allowedLanguagesContext-aware detection
Judge each message against what your business expects.
contextHow it works
Three steps, server-side, invisible to your visitors.
Send the submission
POST the message, IP and email from your backend.
Get a score
A 0–6 Score plus the reason for each check.
Decide
Treat 3 and above as spam, or set your own threshold.
Ship it in minutes
One endpoint, one header. Examples in shell, Ruby, Python, PHP, JavaScript, Java, C# and Go are in the docs.
- https://api.oopspam.com/v1
- X-Api-Key: YOUR_API_KEY
curl --request POST \ --url https://api.oopspam.com/v1/spamdetection \ --header 'Content-Type: application/json' \ --header 'X-Api-Key: YOUR_API_KEY' \ --data '{ "content": "Dear Agent, we are unable to follow up payments...", "senderIP": "185.234.219.246", "email": "[email protected]", "blockTempEmail": true, "allowedLanguages": ["en"] }'
$ch = curl_init('https://api.oopspam.com/v1/spamdetection'); curl_setopt_array($ch, [ CURLOPT_POST => true, CURLOPT_RETURNTRANSFER => true, CURLOPT_HTTPHEADER => ['Content-Type: application/json', 'X-Api-Key: YOUR_API_KEY'], CURLOPT_POSTFIELDS => json_encode([ 'content' => $_POST['message'], 'senderIP' => $_SERVER['REMOTE_ADDR'], 'email' => $_POST['email'], ]), ]); $result = json_decode(curl_exec($ch), true); if ($result['Score'] >= 3) { /* treat as spam */ }
import requests result = requests.post( "https://api.oopspam.com/v1/spamdetection", headers={"X-Api-Key": "YOUR_API_KEY"}, json={ "content": message, "senderIP": ip, "email": email, }, ).json() is_spam = result["Score"] >= 3
const res = await fetch("https://api.oopspam.com/v1/spamdetection", { method: "POST", headers: { "Content-Type": "application/json", "X-Api-Key": process.env.OOPSPAM_KEY }, body: JSON.stringify({ content: message, senderIP: ip, email }), }); const { Score } = await res.json(); const isSpam = Score >= 3; // run on your server, never in the browser
{
"Score": 6,
"Details": {
"isIPBlocked": false,
"isEmailBlocked": true,
"isContentSpam": "spam",
"langMatch": true,
"countryMatch": false,
"numberOfSpamWords": 1,
"spamWords": ["dear"],
"isContentTooShort": false
}
}Prefer clicking to coding? Try requests in the dashboard, or import the Postman collection.
More than a spam check
Same key, same plan.
Trusted by developers and site owners
Real reviews, linked to the originals.
I'm coming from CleanTalk, who just had a major outage… I was desperate… I found OOPSpam and got this set up in 15mins, cannot be happier!
The platform does a great job of filtering out spam in a multitude of ways from location, language, email, and more! They also have a top notch client success team to help troubleshoot any integration issues that may arise.
Very clean and functional plugin. Easy to setup, quick API calls, and runs very smooth. It has caught a number of spam orders and has helped our shop tremendously.
Real humans, 24/7
Stuck on an integration? Talk directly to the developers who build the API.
Developer-to-developer support, not a ticket queue
Chat with us from the docs, or email [email protected]
Email support on every plan; priority support and live chat on higher plans
I noticed a missing country in this amazing indispensable plugin, but wasn't expecting an almost instant reply – and a fix !! The next day an update was issued and the problem sorted. Incredible support.Woodcock02 · WordPress.org
Pay per check
1 API call = 1 spam check. Pick your volume.
Every plan: unlimited websites · no logs by default · all filters · domain reputation checks
Start free →Spam detection API: common questions
What does the spam detection API check?
The message content with machine learning, plus the sender's IP and email against denylists. Optional filters block disposable emails, VPNs, data center IPs, countries and languages.
What score counts as spam?
The Score runs from 0 to 6. We recommend treating 3 and above as spam, then adjusting to your use case.
What happens when I hit my rate limit?
Once you've used all the checks in your plan, new requests are blocked: the API returns a 429 Too Many Requests error instead of a score. We notify you when this happens, so you can upgrade or wait for checks to free up. Every response also includes rate-limit headers showing how many checks you have left.
When does my rate limit reset?
There's no single reset date. We use a sliding 30-day window: your limit counts the checks you made in the last 30 days. Each check stops counting 30 days after you made it, so capacity comes back gradually, day by day, instead of all at once.
For example, if you used 5,000 checks on 1 March, those 5,000 become available again on 31 March.
Do you store the submissions I send?
No, not by default. Logging is off unless you set logIt to true.
Is there a free plan?
Yes: 40 spam checks a month, no credit card. Paid plans start at $23 a month for 25,000 checks.
Can I use it without writing code?
Yes. Use the WordPress plugin, or add oopspam to Zapier, Make or Bubble.io workflows.
Stop spam with one API call.
Contact us
Need to know more? Don't hesitate to contact us.