Prompt
I'm building a SaaS onboarding flow and want to reject disposable addresses
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
A good approach is to block known disposable email domains at signup and combine that with a few light checks so you don’t frustrate real users.
Practical setup
-
Normalize the email
- Lowercase the domain
- Trim whitespace
- Validate syntax first
-
Check against a disposable domain list
- Maintain a curated list of known temporary email providers
- Update it regularly
- Cache it in memory or Redis for fast lookups
-
Add a deliverability step
- Send a verification email
- Require confirmation before full account activation
-
Use risk signals instead of hard-blocking everything
- Disposable domain
- Recently created domain
- Suspicious signup velocity
- IP reputation / VPN / proxy
- Repeated aliases from the same pattern
Recommended implementation pattern
- Soft block on suspicious emails: ask for a different email
- Hard block only for domains you’re very confident are disposable
- Keep an allowlist for enterprise domains or partners if needed
Example logic
if email_is_invalid(email):
reject("Invalid email")
domain = normalize_domain(email)
if domain in disposable_domain_list:
reject("Disposable email addresses are not allowed")
send_verification_email(email)
Useful API options
If you don’t want to maintain the list yourself, consider an email intelligence API that checks:
- disposable/temporary domains
- role accounts
- typo suggestions
- MX records
- SMTP deliverability
Important caveat
Avoid overblocking:
- Some privacy-focused users use aliasing services
- Some legitimate companies use shared mail gateways
- New domains can be false positives
If you want, I can help you with:
- a Node/Express, Python/Django, or Go implementation
- a disposable domain detection strategy
- a database schema / caching design for this check