Block disposable email addresses at signup

flags.disposable on every response, from a list rebuilt daily, plus role-account and free-provider flags for your own policy.

Disposable addresses are the free-trial abuser's tool: a mailbox that exists for ten minutes, on a domain that changes weekly. Every response carries flags.disposable, checked against a list rebuilt daily from public sources (about 75,000 domains), with parent-domain matching so a subdomain of a known provider is caught too.

The flag is a fact about the address, not a verdict: the mailbox may well exist. That is why a disposable address comes back verdict risky with suggested_action reject: real now, gone soon.

Wire it in

const v = await verify(email);           // POST /v3/verify, see the API reference
if (v.flags.disposable) return reject('Please use a permanent email address.');
if (v.flags.role_account && plan === 'trial') return reject('Please use your own address, not a shared one.');
if (v.flags.free_provider && audience === 'b2b') markLead(email, 'personal');

What to do with each answer here

flags.disposableReject on free trials and anything with a cost per account. Allow on support forms and newsletters if you like; the flag is yours to use.
flags.role_accountadmin@, info@, sales@ and about nine hundred others. Real mailboxes with nobody in particular behind them; fine for B2B contact forms, wrong for a personal account.
flags.free_providergmail.com, outlook.com and the like. A lead-quality signal for B2B forms, nothing more.
verdictStill applies. A disposable address that also does not exist is undeliverable.

What this does not do

  • A brand-new disposable domain is not on any list for a day or two. Confirmation by email remains the backstop.
  • We never flag a free provider as disposable, and we do not guess from patterns in the domain name.

Reference: the API, handling results, result codes. A free key gives you 100 verifications a month: get one.