Research

Blocking disposable email domains is the easy half

Alex MugoFounder, Kaidn
5 min readRevised
A list of throwaway domains catches the lazy attempt. The one that costs you money uses a real Gmail address, six times, and every shortcut you would reach for first is wrong.

We keep a list of throwaway email domains. It has 162,587 entries in it right now, refreshed hourly from several public sources plus our own reports.

It is the least interesting thing we do with email.

The list catches someone who could not be bothered. The signup that actually costs you money uses a real address at a real provider, and it does it six times.

What the list is genuinely good for#

Worth being precise, because a disposable-domain check does buy you something. Run four addresses through the checker and the difference is stark:

addressdisposableon an abuse listcan receive mailscore
a@guerrillamail.comyesyesyes70
b@mailinator.comyesyesyes95
c@10minutemail.comyesnono80
d@proton.menonoyes0

That is a real filter and it costs one lookup. If you take nothing else from this, take the list. It removes a meaningful slice of low-effort abuse before it reaches your funnel.

The shortcut everyone reaches for, which does not work#

Ask most people how they would catch a throwaway domain without a list, and they will say domain age. New domain, high risk. It sounds obviously right.

Here is how old those three throwaway domains actually are:

domainage
mailinator.com23.1 years
guerrillamail.com19.7 years
10minutemail.com19.7 years

These are some of the oldest domains your signup form will ever see. They are older than most legitimate SaaS companies.

So a domain-age rule does not just miss them. It actively vouches for them, while penalising the genuinely new startup whose employee is trying to sign up.

Domain age is a useful signal for other things. For this one it is close to useless.

The half that actually matters#

The interesting question is not "is this domain disposable". It is "have I seen this person before, wearing a different address".

Every major provider gives users several ways to write the same mailbox:

  • Gmail ignores dots entirely.
  • Anything after a + is a label, not part of the address.
  • googlemail.com is the same service as gmail.com.
  • Capital letters never mattered.

Stack those and one inbox produces effectively unlimited unique-looking addresses, all of which pass every validity check you can throw at them, because they are all real.

  • ada.lovelace@gmail.comdots
  • a.d.a.lovelace@gmail.comdots
  • adalovelace+shop@gmail.complus tag
  • adalovelace+shop2@googlemail.complus + domain
  • AdaLovelace@Gmail.comcase
  • adalovelace@gmail.comthe actual inbox
arrow_forward
One identity key
adalovelace@gmail.com

Six accounts that looked unrelated are one person.

Six signups, six different addresses, one mailbox

None of those six is disposable. None is malformed. All of them deliver. Every one would sail through a signup form, and to a database that stores the raw string they are six different customers claiming six welcome bonuses.

The check that matters reduces the address to one key before it ever looks at the domain:

six addresses, one mailbox
ada.lovelace@gmail.com            →  adalovelace@gmail.com
a.d.a.lovelace@gmail.com          →  adalovelace@gmail.com
adalovelace+shop@gmail.com        →  adalovelace@gmail.com
adalovelace+shop2@googlemail.com  →  adalovelace@gmail.com
AdaLovelace@Gmail.com             →  adalovelace@gmail.com

One key. Six accounts that looked unrelated turn out to be one person, and you can see it at signup rather than at payout.

The rules differ per provider, which is why doing this properly is more work than it looks. Dots mean nothing at Gmail and mean something nearly everywhere else. Strip them everywhere and you will merge two genuinely different people at a provider that treats them as distinct, which is a worse mistake than missing a duplicate.

Doing it without building it#

Every check above runs on one lookup, and there is a standalone email endpoint so you do not have to spend a scoring event to see it:

Terminal
curl -s -X POST https://api.kaidn.io/v1/check/email \
  -H "x-api-key: $KAIDN_API_KEY" \
  -H "content-type: application/json" \
  -d '{"email":"a.d.a.lovelace+shop@googlemail.com"}'
response
{
  "email": {
    "fraud_score": 12,
    "canonical": "adalovelace@gmail.com",
    "is_aliased": true,
    "alias_tricks": ["dot_trick", "plus_tag", "domain_alias"],
    "has_plus_tag": true,
    "is_disposable": false,
    "mx_valid": true,
    "catch_all": false,
    "looks_gibberish": false,
    "is_malformed": false
  },
  "reputation": { "recent_abuse": false, "network_risk": 0 },
  "summary": "Real Gmail mailbox reached through three aliasing tricks. Not disposable."
}

canonical is the field to key your accounts on. Everything else is evidence about the domain. That one line is the identity.

On a scored event the same work shows up as two separate checks. emailRisk reports what the address IS. emailReuse reports how many accounts the real mailbox already sits behind.

the two email checks on a verdict
const r = await kaidn.score({ event: "signup", user_id, ip, email, device_id });

// "This mailbox is behind 4 accounts" is the finding. The aliasing is how it hid.
const reuse = r.checks.find((c) => c.check === "emailReuse");
if (reuse) console.log(reuse.message, reuse.evidence);

What else the inbox tells you#

Beyond throwaway domains and aliasing, an address carries infrastructure that is much harder to fake than the address itself:

  • Can it receive mail at all? A domain with no mail server cannot. 10minutemail.com above has none, and still gets accepted at signup everywhere.
  • Does it publish sender authentication? SPF and DMARC records, or the absence of them.
  • Does it accept every address? A catch-all domain means the part before the @ tells you nothing, so anything@theirdomain.com is infinite free addresses.
  • Where does its mail actually live? A "company" domain whose mail is served from a VPS the same operator rents is a very different thing from one on Google Workspace.
  • Is it a role account? info@, support@, admin@. Not a person.
  • Does it look machine-generated? Scored on the reduced form, so aliasing cannot hide it.

The mistake we made ourselves#

Worth admitting, because it is easy to get wrong in the same direction.

We used to score every one of those signals separately and add them up. That seems obviously right until you notice that a throwaway domain trips several at once. It is on the disposable list and on an abuse list and often has no mail server. One fact, counted three times, and the score inflates accordingly.

Worse, it inflated in the wrong direction on legitimate users too. A real customer signing up with adalovelace+shop@gmail.com got penalised for plus-addressing and for aliasing. Two penalties for one entirely reasonable habit that plenty of careful people have.

Signals that overlap now collapse. Within a group only the strongest one scores, while every detection is still reported as evidence. Our labelled test cases did not move at all on the fraud side. The only thing that changed was that legitimate plus-addressed user, whose score dropped by 40%.

If you are building scoring of your own, that is the trap. Adding more signals feels like adding more accuracy. If the signals overlap, you are mostly adding confidence to a number that has not learned anything new.

What to actually do#

Starting from nothing, in order of return on effort:

  1. Reduce every address to one key before you store it. Even if you do nothing else, key your accounts on that. This is the one that catches repeat signups.
  2. Check the disposable list. Cheap, and it clears out the low-effort attempts.
  3. Check whether the domain can receive mail. A domain that cannot is not a customer.
  4. Do not use domain age for this. It fails on exactly the cases you care about.
  5. Watch for overlapping signals, so one fact does not get counted three times.

You can run any address through the free email checker with no account. It returns the same report the API does, reduced form included.

Frequently asked questions

Should I block disposable email addresses outright?

Usually not. Block on evidence, not on one flag. Throwaway domains do go with abuse, but a score that combines the inbox with the device, the IP and the account history will be right more often than a hard rule on one field. And a hard rule costs you the legitimate users who happen to like a privacy provider.

Why not just block plus-addressing?

Because plenty of legitimate, privacy-minded people use it on purpose, and blocking them costs you real customers. Collapse the aliases to one identity so you can count them, then decide based on how many accounts that single inbox has actually opened. Counting is the useful operation. Refusing is not.

Does domain age work as a disposable-email signal?

No, and it fails in the worst possible direction. mailinator.com is 23.1 years old. guerrillamail.com and 10minutemail.com are both 19.7 years old. These are among the oldest domains a signup form will ever see, so a domain-age rule does not just miss them, it actively vouches for them, while penalising the genuinely new startup whose employee is trying to sign up.

Does email checking work without a device fingerprint?

It helps on its own, but the inbox is one entity among several. In practice the strongest duplicate-account signal is usually the device, and the inbox is what confirms it. Two accounts sharing a device is ambiguous: a household, an office. Two accounts sharing one real mailbox is not, because the person receiving the mail is the same person.

Why do the rules differ per provider?

Because they genuinely do. Dots mean nothing at Gmail and mean something nearly everywhere else, so stripping them everywhere merges two different people at a provider that treats them as distinct. That is a worse mistake than missing a duplicate, which is why doing this properly is more work than the one-line regex it looks like.

How big is the disposable-domain list, and how often does it change?

162,587 entries at the time of writing, refreshed hourly from several public sources plus our own reports. The number matters less than the refresh rate. Public lists run weeks behind new domains, which is exactly why the list is the easy half and working out who the person is behind the address is the half that catches anybody who is trying.

emaildisposable emailidentityfraud signals

Score your own traffic

10,000 events a month on the free tier, no card. One POST to /v1/score and you get a verdict with the evidence behind it.

Read next