Verify emails

Prove what's in an email without showing it.

Booking confirmations, pay notifications, membership updates. Users receive emails every day that contain the facts you need. Burnt lets them prove specific claims from those emails without revealing the content.

How it works

Three steps. Zero email content exposed.

Step 01

User grants access

The user connects their email through a standard OAuth flow (like Google). They see exactly what permissions are being requested and grant consent explicitly.

Step 02

Burnt finds the relevant email

We locate the specific email that contains the fact you need verified, like a booking confirmation from an airline, a pay notification from a payroll provider, or a membership update from a loyalty program.

Step 03

Selective disclosure

Using the email's existing DKIM signature, Burnt proves a specific fact from the email content without revealing anything else. You get a verified true or false. We never store, log, or retain the email content.

Under the hood

Built on DKIM, a protocol already running billions of times a day.

Every email is already signed

When a mail server sends an email, it attaches a DKIM signature, a cryptographic proof that the email came from that domain and has not been tampered with. This is a standard spam-prevention mechanism used by virtually every major email provider.

Burnt leverages these existing signatures to let users prove facts about their emails to third parties. The user chooses which fact to reveal. Everything else stays private. The email content is processed in memory only and discarded immediately after the verification result is produced.

Selective disclosure by default

A user should not have to show their entire inbox to prove they received a flight confirmation. They should not have to forward a payroll email to prove they got paid. Burnt extracts only the specific, relevant fact and produces a verified signal. Nothing more leaves the user's control.

Verification output
{
"source": "united.com"
"dkim_verified": true
"claim": "booking_exists"
"result": true
"flight_date": "2026-01-15"
"delay_confirmed": true
"email_content": null
"timestamp": "2026-03-01T14:22:00Z"
}
What you can verify

Any fact that arrives by email becomes verifiable.

Insurance & Claims

Verify booking confirmations for flight delay claims

A claimant received a booking confirmation email from the airline. Burnt verifies the email is authentic (signed by the airline's domain), confirms the booking details, and checks for delay notifications. No screenshot uploads. No PDF forgery risk.

Leasing & Onboarding

Verify payroll emails for income confirmation

Applicants receive pay notifications from their employer's payroll system. Burnt verifies the email came from the employer's domain and confirms the pay amount meets your income threshold.

Marketing & Acquisition

Verify membership or purchase receipts for targeting

A user claims to be a member of a competitor's loyalty program. Burnt verifies they received a membership confirmation or status update email from that provider. You get verified proof of competitor status without any data partnership.

Cross-vertical

Verify any transactional email from any sender

Order confirmations, subscription receipts, account statements, appointment notifications. If a company sent the email and DKIM signed it (virtually all do), Burnt can verify specific facts from it.

Why it matters

A verification path that does not require account login.

Wider coverage than portal login

Not every source has a user portal. But almost every service sends emails. Booking confirmations, pay notifications, status updates. Email verification reaches sources that portal-based verification cannot.

Cryptographically authentic

DKIM signatures are applied by the sending mail server. The email content is mathematically proven to be unaltered. Forwarded, screenshotted, or AI-generated emails fail this check.

Selective disclosure

Users reveal only the fact being verified. The full email, including personal details, other transactions, and unrelated content, stays completely private. We never store or retain email content.

GDPR and CCPA compliant by design

Email content is processed in memory only and discarded immediately. No raw email data is logged, cached, or transmitted to anyone. The only output is the verified result.

Verify facts from email
without reading email.

See how Burnt can turn transactional emails into verified, privacy-preserving signals for your business.

No credit card required30-minute setupFree sandbox included