Identity operations

Identity Verification Workflow Guide

Identity verification at the document or biometric layer is only half the picture. The infrastructure around an identity claim — domain age, email authentication, IP origin, device reputation — is where most fraud actually shows up.

Quick summary

  • Infrastructure signals catch synthetic identities.
  • Cheap signals first; escalate to KYC for borderline cases.
  • Persist verdicts with contributing signals.
  • Re-evaluate on sensitive events.

Infrastructure context around an identity claim

  • Origin IP reputation and hosting type.
  • Submission email domain age and authentication records.
  • Phone line type and portability history.
  • Device and browser fingerprint stability.
  • Geographic consistency across signals.

Designing the escalation

Run cheap infrastructure signals first. A clean envelope ships straight through. A flagged envelope routes to KYC, manual review, or step-up verification. This pattern keeps cost predictable while raising fraud catch rate.

Troubleshooting workflow

Run through these steps in order. Each step links to the right diagnostic tool.

  1. 1

    Score the origin IP

    Reputation and hosting type drive the first decision.

    Open IP Reputation
  2. 2

    Validate the email domain

    Age and authentication catch synthetic emails.

    Open DNS Lookup
  3. 3

    Check domain reputation

    Catch known-bad sending infrastructure.

    Open Domain Reputation
  4. 4

    Save as a verification workflow

    Resume from the dashboard on review queues.

    Open Operational dashboard

Frequently asked questions

Why does identity verification need infrastructure checks?

A real document presented from a fresh domain, a disposable phone, and a high-risk hosting IP is still operational fraud. Infrastructure context separates legitimate users from synthetic identities.

Where does this fit relative to KYC vendors?

KYC handles the document and biometric. This workflow handles the operational envelope: how the identity was submitted and from what infrastructure.

What's the order of operations?

Cheap signals first — IP, domain, email domain — then escalate to KYC for borderline cases. It keeps cost down without sacrificing accuracy.

How do I store the verification result?

Persist a structured verdict with the contributing signals and their timestamps. Re-evaluate on sensitive events, not continuously.

Monitor it continuously

Save this check, get alerts on changes, and track multiple domains in one dashboard.

Learn about monitoring