Get your free API key
Sign up and generate a vfx_ key from the dashboard in under a minute. A thousand verification credits land instantly, twenty-five hundred with a work email, and they never expire on you.
One GET to the validation endpoint returns the isDisposable flag alongside the full 9-check verdict & 99.99% accuracy. Block burner signups on one boolean, no signup to try it.
Read the docs for the full API and bulk jobs, or wire it into your signup.
Trusted by 500,000+ leading GTM teams of all sizes
Three steps, no SDK, no webhooks. Get a key, send one GET to the endpoint, then block on the isDisposable boolean.
Sign up and generate a vfx_ key from the dashboard in under a minute. A thousand verification credits land instantly, twenty-five hundred with a work email, and they never expire on you.
Send one GET to the validation endpoint with your key in the header, no SDK and no OAuth, from cURL, Node, or Python - any HTTP client works. Latency runs about 380 ms.
Read the isDisposable boolean and reject burner signups in one line. The full nine-check verdict rides along in the same response, so you can block hard or just flag it for review.
Not a stale blocklist dump. A continuously refreshed isDisposable flag, read alongside every other check.
A disposable email list API answers one question on every signup: is this address a real, reachable inbox, or a throwaway spun up to clear your form and disappear? Burner providers hand out inboxes that self-destruct in minutes, and those addresses fuel most fake accounts, trial abuse, and junk signups. Verifox reads the answer back as an isDisposable flag inside the same nine-check verdict, one GET request against the validation endpoint, with the full category covered in the disposable email glossary.
The disposable match is one of nine. The same engine our paid API runs weighs it against SMTP, catch-all, domain age, and reputation.
Every address runs a full RFC 5321 and RFC 5322 compliance pass before a single network call goes out. The engine catches what visual scanning misses, the double dot in [email protected], the trailing period, the IDN homograph that looks valid but resolves to a different domain.
Bundled typo suggestions let your form offer “did you mean [email protected]?” instead of rejecting silently.


Once syntax passes, the engine resolves the domain. We confirm the DNS records exist, fetch the MX record priority list in order, and verify at least one mail-exchange server is actively accepting connections right now.
Misspelled domains like gmial.com, expired domains, and parked-for-sale domains all fail this gate before the engine wastes a single SMTP roundtrip.


The engine opens a TCP connection on port 25, performs the EHLO handshake, then negotiates MAIL FROM and RCPT TO. Every server response code (220, 250, 550, 552) is parsed deterministically against the IANA enhanced-status registry.
This is the moment a mailbox proves it actually exists. No third-party guesses, no statistical heuristics, just the receiving server's own answer.


Some domains accept every email regardless of whether the mailbox exists, a setup known as a catch-all configuration. The engine sends a deterministic probe to a deliberately fake address ([email protected]); if the server returns the same 250 OK it returned for the real address, the domain is catch-all.
The verdict isn't dropped, it's flagged RISKY so you know the deliverability signal is degraded.


The engine maintains a curated registry of 10,247 disposable email providers, including Mailinator, Guerrilla Mail, 10MinuteMail, Tempmail, and the long tail of regional clones.
Any address matching the blocklist is flagged INVALID. Deliverability to a mailbox that exists for 10 minutes and is never checked is functionally zero, regardless of whether the SMTP handshake passes.


info@, support@, no-reply@, admin@, billing@. These are shared inboxes, not individuals.
The engine extracts the local-part of every address, matches it against the known role-prefix registry, and tags the result with a reduced engagement score.
You don't drop them automatically. The verdict flags them as roles so you can decide.


Fresh-spam domains registered hours ago are the single biggest source of inbound abuse. The engine queries WHOIS and RDAP for every unique domain, extracts the registration date, and flags anything under 30 days old with a “fresh” warning.
Domains aged 5+ years pick up a corresponding trust signal. The same heuristic spam filters have been using since the early 2000s, ported into the verdict.


SPF, DKIM, and DMARC together prove the sender is authorised to send from that domain.
The engine reads each policy via DNS, validates SPF includes recursively, scans six common DKIM selectors, and confirms DMARC alignment with the From: header.
A failing DMARC policy means the sender can be spoofed, so the verdict warns you before you reply.


Beyond “exists vs doesn't exist”, the engine extracts the precise mailbox state from the SMTP server's response. Full inbox (552 / 522 quota), disabled mailbox (550 5.1.1), out-of-office autoresponder, frozen account.
Each state maps to a specific retry policy. Full inbox retries in 6 hours. Disabled drops permanently. The verdict tells you which bucket the bounce belongs in so your retry logic doesn't waste cycles.


Most disposable checkers rely on stale lists, missing new burner domains. Ours runs nine paid-grade checks against a continuously refreshed list.
The same nine-check pipeline as the paid API runs on every address, free or not.
Verify your first emails right here, no account, no card.
Bulk CSV in, verified list out. Same speed on every plan.
Every address comes back already checked, with a confidence score.
Validated on a 10,000-address mixed benchmark including catch-all domains.
1,000 free on signup. 2,500 with a work email. Pay as you go after.
Processed in memory, dropped on response. SOC 2 · GDPR · CCPA.
NeverBounce and ZeroBounce both flag disposable domains. Verifox weighs the disposable match against domain age and reputation in one verdict, with a continuously-refreshed list.
Most tools reset your balance every month. Verifox sells credits that sit in your account until you spend them.
forever
1,000credits on signup
No card required
2,500 with a work email
Free includes
one time
10,000credits
$0.0059 eachSAVE 34%
Everything in Free, plus
per month
15,000credits a month
$0.0053 each
Unused credits roll over
Everything in packs, plus
One credit verifies one address; a find costs 10. All prices in USD, checkout via Stripe.
Growth leads, marketers, and engineers running real campaigns on real lists, with a verified email on every byline.

We were paying ZeroBounce a four-figure monthly bill and still landing 3% bounces on cold campaigns. Switched the pipeline to Verifox, dropped to 0.4% bounces, and cut the bill by more than 90%.

Other tools flag 30% of our B2B list as 'risky catch-all' and leave the call to us. Verifox returns a real verdict on those addresses, with a confidence score. We send more, we send safer.

We had a Gmail spam-folder problem after a bad list import. Verifox cleaned the list and the warmup ran on the same engine. Back in primary inbox in six weeks. One vendor, half the cost.

Ran a 50,000-address outbound list through Verifox before our quarterly campaign. Bounces landed at 0.7%, sender reputation didn't move, replies were up 22% over last quarter.

Their MCP server let me wire email verification directly into our internal Claude agent in about ten minutes. Zero glue code. No other vendor in this space has thought about that workflow.

Tested Verifox at 10,000 verifications per minute on a Tuesday morning. Latency held under 400ms median, no soft failures, no rate-limit walls. The vendor we benched throttled at 2,000/min.

Our SDRs were enriching from three tools and 14% of the emails were invalid before they hit the sequencer. Verifox sits in the pipeline now and the team stopped seeing 'undeliverable' replies the next week.

Bulk upload, sorted CSV back in twenty minutes, plug into our growth stack. The half-day list-hygiene project per cohort turned into something the marketing intern runs on autopilot.

Verifox returns a 0-100 confidence score per address, not just a label. We thresholded at 75 for the cold sequencer, 60 for nurture, and our deliverability team finally has a knob they can tune.

We were paying ZeroBounce a four-figure monthly bill and still landing 3% bounces on cold campaigns. Switched the pipeline to Verifox, dropped to 0.4% bounces, and cut the bill by more than 90%.

We had a Gmail spam-folder problem after a bad list import. Verifox cleaned the list and the warmup ran on the same engine. Back in primary inbox in six weeks. One vendor, half the cost.

Their MCP server let me wire email verification directly into our internal Claude agent in about ten minutes. Zero glue code. No other vendor in this space has thought about that workflow.

Our SDRs were enriching from three tools and 14% of the emails were invalid before they hit the sequencer. Verifox sits in the pipeline now and the team stopped seeing 'undeliverable' replies the next week.

Verifox returns a 0-100 confidence score per address, not just a label. We thresholded at 75 for the cold sequencer, 60 for nurture, and our deliverability team finally has a knob they can tune.

Other tools flag 30% of our B2B list as 'risky catch-all' and leave the call to us. Verifox returns a real verdict on those addresses, with a confidence score. We send more, we send safer.

Ran a 50,000-address outbound list through Verifox before our quarterly campaign. Bounces landed at 0.7%, sender reputation didn't move, replies were up 22% over last quarter.

Tested Verifox at 10,000 verifications per minute on a Tuesday morning. Latency held under 400ms median, no soft failures, no rate-limit walls. The vendor we benched throttled at 2,000/min.

Bulk upload, sorted CSV back in twenty minutes, plug into our growth stack. The half-day list-hygiene project per cohort turned into something the marketing intern runs on autopilot.

We were paying ZeroBounce a four-figure monthly bill and still landing 3% bounces on cold campaigns. Switched the pipeline to Verifox, dropped to 0.4% bounces, and cut the bill by more than 90%.

Ran a 50,000-address outbound list through Verifox before our quarterly campaign. Bounces landed at 0.7%, sender reputation didn't move, replies were up 22% over last quarter.

Our SDRs were enriching from three tools and 14% of the emails were invalid before they hit the sequencer. Verifox sits in the pipeline now and the team stopped seeing 'undeliverable' replies the next week.

Other tools flag 30% of our B2B list as 'risky catch-all' and leave the call to us. Verifox returns a real verdict on those addresses, with a confidence score. We send more, we send safer.

Their MCP server let me wire email verification directly into our internal Claude agent in about ten minutes. Zero glue code. No other vendor in this space has thought about that workflow.

Bulk upload, sorted CSV back in twenty minutes, plug into our growth stack. The half-day list-hygiene project per cohort turned into something the marketing intern runs on autopilot.

We had a Gmail spam-folder problem after a bad list import. Verifox cleaned the list and the warmup ran on the same engine. Back in primary inbox in six weeks. One vendor, half the cost.

Tested Verifox at 10,000 verifications per minute on a Tuesday morning. Latency held under 400ms median, no soft failures, no rate-limit walls. The vendor we benched throttled at 2,000/min.

Verifox returns a 0-100 confidence score per address, not just a label. We thresholded at 75 for the cold sequencer, 60 for nurture, and our deliverability team finally has a knob they can tune.
Every layer of the stack carries a third-party attestation, so you can ship into regulated industries without rebuilding your compliance posture.

Independently audited to the SOC 2 Type II standard.

Built for the EU with full GDPR data-subject rights.

California opt-out, do-not-sell, plus DSAR handling.

Information security held to the ISO 27001 standard.

AI governance aligned to the new ISO 42001 standard.
An investigation into the money leaking out of your list - and the nine checks that decide whether your email is read, or never arrives at all.

57 pages, free PDF, no signup
Common questions
The questions we get from developers and growth teams wiring disposable email blocking into a signup flow, with the real endpoints and real opinions behind our verification stack.
You call GET /v1/email-validation/:email and the JSON response includes an isDisposable flag alongside the full nine-check breakdown, so blocking a burner signup is one condition in your handler. Median latency sits around 380 ms, and sub-50 ms for cached domains.
Prefer not to write code at all? The FoxGuard widget ships with blockDisposable on by default, so your form rejects throwaway addresses before submit. Request and response shapes live in the API docs.
A disposable email is any address on a domain built to be thrown away: temporary inboxes, burner providers, and ten-minute-mail services people use to clear a signup gate without handing over a real address. Mailinator, Guerrilla Mail, Temp Mail, and thousands of lesser-known domains all fall in this bucket, and new ones appear daily.
They are the addresses most likely to fuel fake accounts, trial abuse, and junk signups, and they never convert. Disposable detection is one of the nine checks our verification engine runs on every address it sees.
No. Privacy relays forward to a real, monitored inbox, which is the opposite of a burner. The SMTP handshake in our nine-check pipeline confirms a live mailbox sits behind the relay, so those addresses come back deliverable, not disposable. The isDisposable flag is reserved for domains whose inboxes are built to self-destruct.
Unsure about one specific address? Run it through the disposable email lookup and read the per-check verdict yourself.
Continuously. The disposable-domain list our engine matches against is refreshed all day rather than shipped quarterly, so a throwaway provider that went live this morning is caught this afternoon. Freshness is the whole game here, because burner services rotate domains precisely to outrun stale blocklists.
There is a second net underneath. The engine also scores domain age as one of its nine checks, so a day-old domain raises the risk score even before it is catalogued anywhere. Details on every check sit under email verification.
Block when a signup hands out value immediately: free trials, credits, coupons, or anything a fraud ring can farm with fresh inboxes. Flag and review when the cost of a false rejection is higher than the cost of a junk row, like a newsletter or a waitlist.
The API gives you both levers: the isDisposable boolean for a hard gate, plus the overall score for softer policies. On forms, FoxGuardshows a custom message like "Disposable emails are not allowed" so legitimate users self-correct on the spot.
Static lists rot. Burner providers spin up new domains daily, and a repo updated whenever a maintainer finds time will always lag the domains doing the actual damage this week. A list match alone also says nothing about a brand-new domain nobody has catalogued yet.
Verifox pairs the continuously refreshed list with live signals: domain age, MX records, and a real SMTP handshake from the nine-check verification engine, measured at 99.99% accuracy on a 1,000-address benchmark. A text file on GitHub cannot do any of that.
Yes, because the policy is yours. The API returns the verdict; your code decides what to do with it, so allowlisting a domain is one extra condition before you check isDisposable. Nothing to configure on our side, no support ticket.
The FoxGuard widget goes one step further with per-field overrides: set data-verifox-block-disposable="false" on a specific input and that field accepts throwaway addresses even when blocking is on globally.
Yes. The tool above runs 4 checks per day with no account, no card. It executes the same nine-check engine the paid API runs, disposable-domain match included.
Create a free account and you get 1,000 credits on the spot, or 2,500 if your signup email is a work address. Past that, credits are pay-as-you-go and never expire, with volume pricing shown for your region.
Yes. POST /v1/email-validation/bulk accepts up to 100,000 emails per job, or a CSV upload, and processes roughly 10,000 emails per minute on the standard tier. Every row comes back with its own isDisposable verdict.
Smaller list and no code handy? Paste it into the free email validator instead; your free signup credits cover most small lists outright.
No. Every address, whether it arrives from the free checker above or from an API call, is verified in memory and discarded the moment the response returns. We never store, log, or sell them.
Verifox is SOC 2 Type II compliant, with the full Trust Center report available on request. The privacy policy spells out exactly what we touch and what we never keep.