Prompt
I’m building an onboarding flow and need to detect disposable emails
Latest observation
A good way to detect disposable emails is to use a mix of domain blocklists, MX/DNS checks, and optionally a verification email step. Here’s a practical approach you can implement in an onboarding flow:
1) Check against a disposable-domain list
Maintain a list of known temporary email domains, such as:
mailinator.com10minutemail.comguerrillamail.comtempmail.com
When a user enters an email, extract the domain and compare it to your list.
Example logic
user@mailinator.com→ flag as disposableuser@gmail.com→ allow
2) Normalize the domain first
Before checking, normalize input:
- lowercase the domain
- trim whitespace
- handle subdomains if needed
Example:
User@Mailinator.com→mailinator.com
3) Check for disposable email patterns
Some services rotate domains or use many similar variants. You can also flag:
- unusual TLDs used by temp-mail providers
- domains with no website
- domains recently registered
- domains with suspicious MX records
4) Validate MX records
If a domain has no MX record, it may not accept email. This doesn’t prove it’s disposable, but it’s a useful signal.
Heuristic examples
- No MX record → suspicious
- MX pointing to known disposable providers → suspicious
5) Use an email verification service
If you want higher accuracy and less maintenance, use a third-party service that checks:
- disposable status
- deliverability
- role accounts
- catch-all domains
Examples of services in this category include:
- ZeroBounce
- Kickbox
- NeverBounce
- Abstract Email Validation
6) Decide on your policy
You can choose to:
- block disposable emails
- allow but restrict certain actions
- require extra verification for suspicious emails
A soft approach is often better:
- allow signup
- limit sensitive actions
- require email confirmation or phone verification
7) Simple implementation example
JavaScript example
const disposableDomains = new Set([
"mailinator.com",
"10minutemail.com",
"guerrillamail.com",
"tempmail.com"
]);
function isDisposableEmail(email) {
if (!email || !email.includes("@")) return false;
const domain = email.split("@")[1].trim().toLowerCase();
return disposableDomains.has(domain);
}
Python example
disposable_domains = {
"mailinator.com",
"10minutemail.com",
"guerrillamail.com",
"tempmail.com",
}
def is_disposable_email(email: str) -> bool:
if "@" not in email:
return False
domain = email.split("@", 1)[1].strip().lower()
return domain in disposable_domains
8) Best practice recommendation
For onboarding, I’d recommend:
- syntax validation
- disposable-domain check
- MX check
- verification email
- risk-based rules rather than hard blocking everywhere
If you want, I can help you with:
- a production-ready disposable email detection function
- a Node.js / Python / Go implementation
- or a recommended API/service comparison